Skip to content

Connect Google Cloud to Black Cat SSPM

Version française

Connect your Google Cloud project so Black Cat can review IAM bindings, service account keys, firewall rules, storage exposure, encryption keys and audit logging.

≈ 15 min · audit access · no write-capable permission

What Black Cat reads, and why

PermissionWhat it lets Black Cat doStatus
roles/iam.securityReviewerLets Black Cat review IAM bindings, service accounts and their keys across the project.Required
roles/compute.viewerLets Black Cat review firewall rules, networks and virtual machine configuration.Required
roles/storage.objectViewerLets Black Cat review Cloud Storage bucket settings such as public access and versioning.Required
roles/cloudsql.viewerLets Black Cat review Cloud SQL instances for public exposure, encryption and backups.Required
roles/cloudkms.viewerLets Black Cat review encryption keys and their rotation schedule.Required
roles/secretmanager.viewerLets Black Cat review secret metadata such as rotation and replication — never the secret values.Required
roles/container.viewerLets Black Cat review Kubernetes cluster settings and node configuration.Required
roles/logging.viewerLets Black Cat check that audit logging is switched on and covers data access.Required
roles/monitoring.viewerLets Black Cat see which alerting and notification channels are configured.Required
roles/dns.readerLets Black Cat review DNS zones and whether DNSSEC is enabled.Required
roles/bigquery.metadataViewerLets Black Cat review BigQuery dataset sharing and encryption settings — never the rows inside.Required
roles/cloudfunctions.viewerLets Black Cat review Cloud Functions, their triggers and the identities they run as.Required
roles/run.viewerLets Black Cat review Cloud Run services, their ingress settings and the identities they run as.Required
roles/orgpolicy.policyViewerLets Black Cat check organization policies such as restrictions on service account keys.Optional
roles/essentialcontacts.viewerLets Black Cat check that security contacts are registered for the project.Optional
roles/iam.denyReviewerLets Black Cat see the deny policies that restrict access.Optional

What you'll need

  • Project identifier Required — Shown on the Google Cloud console dashboard for the project.
  • Service account key (JSON) Required — The JSON key of the read-only service account you create for Black Cat.
  • Organization identifier — Optional — add it to include organization-level policies and contacts in the review.

Where to create it

What we check on Google Cloud →

Other setup guides

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications are based on publicly available documentation and may change over time.

See your own SaaS posture in 10 minutes

Run a free posture scan — no credit card required, read-only-by-default access you can revoke any time.

Run a free posture scan