INTEGRATIONSCLOUD INFRASTRUCTURE
Google Cloud Platform28 OF 28 CAPABILITIES ASSESSED
Project IAM bindings and service accounts, mapped to who holds them
Project IAM bindings and service accounts read into the graph, with Google group membership granted and revoked from Ploy.
TYPE · INFRAAUTH · SERVICE ACCOUNTDOMAIN · CLOUD.GOOGLE.COM
2.1WHAT IT UNLOCKS
Three jobs this connector does on day one
PROJECT ACCESS
IAM bindings become readable access
Every binding on every project resolves to the person or service account it grants and the role it grants them, instead of a policy file read project by project.
NON-HUMAN IDENTITIES
Service accounts are identities, not strings
IAM service accounts land as records of their own, with the applications they can reach attached, so a machine identity is reviewed the way a person is.
GRANTS
Access moves through the group
Ploy adds and removes Google group membership, which is how a project role is granted and taken back. Nothing rewrites the IAM policy itself.
2.4OFTEN CONNECTED TOGETHER