Koh W.
KW
Solution Engineer - Data & AI
Small-Business (50 or fewer emp.)
"Clean Resource Hierarchy and IAM Recommender Make Access Management Easy"
4.5/5
What do you like best about Google Cloud Identity & Access Management (IAM)?

What I like most about Google Cloud IAM is the clean, intuitive simplicity of its resource hierarchy. Unlike other cloud providers where permissions can quickly turn into a tangled web, Google’s model of Organizations, Folders, and Projects makes it much easier to manage access at scale. I especially like that I can define a high-level policy at the Folder level—for example, for a “Production” environment—and then have those permissions automatically and consistently inherited by every project underneath it. This inheritance model saves me a huge amount of manual configuration and helps reduce the chance of human error.

I also find the AI-driven IAM Recommender to be a real boost to my security posture. It’s reassuring to have something that proactively reviews my actual usage patterns and flags opportunities to remove over-privileged access. Instead of guessing whether a service account has more permissions than it needs, I can rely on clear guidance on how to reach least privilege without breaking my applications. That kind of proactive support makes it feel like I have a security expert keeping an eye on things, helping me keep my environment both lean and secure. Review collected by and hosted on G2.com.

What do you dislike about Google Cloud Identity & Access Management (IAM)?

One of my biggest frustrations is how complex it is to manage Custom Roles when the predefined roles don’t quite fit. Google offers hundreds of predefined roles, but they’re often either too broad or missing one specific permission I need. When I have to create a custom role, I’m forced to sift through thousands of granular permissions (for example, compute.instances.get vs compute.instances.list), which quickly becomes dizzying and time-consuming. If I miss even one small permission, an entire deployment can fail with a cryptic error message that isn’t always straightforward to debug.

I also dislike how troubleshooting permission issues can feel like a “black box.” Even with the Policy Troubleshooter, I still run into cases where a “Permission Denied” error pops up and it takes far too long to figure out whether the root cause is an IAM policy, an Organization Policy constraint, or a service-specific firewall rule. And while the policy management interface looks clean, it can feel sluggish in large organizations with thousands of service accounts and members, which makes searching and filtering more cumbersome than it should be. Review collected by and hosted on G2.com.

See what 56 reviewers think of Google Cloud Identity & Access Management (IAM)

4.4 out of 5 · Verified reviews from real users

Read all reviews