NEWFreshservice is now a Ploy integrationSee what shipped
INTEGRATIONSCLOUD INFRASTRUCTURE
Google Cloud Platform28 OF 28 CAPABILITIES ASSESSED

Project IAM bindings and service accounts, mapped to who holds them

Project IAM bindings and service accounts read into the graph, with Google group membership granted and revoked from Ploy.

TYPE · INFRAAUTH · SERVICE ACCOUNTDOMAIN · CLOUD.GOOGLE.COM
Google Cloud Platform connectorHOURLY SYNCCAPABILITIES
WHAT PLOY DOES
Sync service accounts as identitiesIAM service accounts arrive as identities in their own right, with whether each is enabled or disabled. Human users are not synced as accounts here: they appear as the IAM policy bindings that grant them access.
READ
Discover groups, IAM roles and Cloud SQL instancesThe grantable things in the project, so a role or a database has a record before anyone asks for it.
READ
Map project IAM bindings to who holds themEvery binding on a project resolves to the person or service account it grants, alongside the applications a service account can reach.
READ
Grant and revoke group membershipPloy adds and removes Google group membership, which is how a project role is granted. The IAM role bindings themselves stay read only.
WRITE
2.1WHAT IT UNLOCKS

Three jobs this connector does on day one

PROJECT ACCESS

IAM bindings become readable access

Every binding on every project resolves to the person or service account it grants and the role it grants them, instead of a policy file read project by project.

NON-HUMAN IDENTITIES

Service accounts are identities, not strings

IAM service accounts land as records of their own, with the applications they can reach attached, so a machine identity is reviewed the way a person is.

GRANTS

Access moves through the group

Ploy adds and removes Google group membership, which is how a project role is granted and taken back. Nothing rewrites the IAM policy itself.

2.3

SETUP

TYPICALLY 10 MINUTES
STEP 01

Connect with least privilege

Grant Ploy a scoped, read-only role in Google Cloud Platform to begin with.

STEP 02

Watch the first sync

Identities, roles and keys land in the graph.

STEP 03

Turn on writes

Choose which roles Ploy may grant and revoke, and who approves.

2.4OFTEN CONNECTED TOGETHER
OktaIDENTITY SOURCEGitHubSOURCE CONTROLSlackAPPROVALS
BROWSE ALL 62 INTEGRATIONS

Connect Google Cloud Platform, see it in 10 minutes.