Send feedback
Flow roles and permissions
Stay organized with collections
Save and categorize content based on your preferences.
This page lists the IAM roles and permissions for Flow. To
search through all roles and permissions, see the role and
permission index .
Flow roles
Flow offers the following service agent roles.
Service agent roles should only be granted to service agents .
Role
Permissions
FlowService Service Agent
(roles/aisandbox.serviceAgent )
Grants FlowService Service Agent permissions to manage resources in the consumer project.
Warning: Do not grant service agent roles to any principals except
service agents .
aiplatform.endpoints.predict
logging.logEntries.create
logging.logEntries.route
serviceusage.services.use
Flow Service Agent
(roles/flow.serviceAgent )
Grants Flow Service Agent permissions to manage resources in the consumer project.
Warning: Do not grant service agent roles to any principals except
service agents .
aiplatform.endpoints.predict
logging.logEntries.create
logging.logEntries.route
serviceusage.services.use
Flow permissions
There are no IAM permissions for this service.
Send feedback
Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License , and code samples are licensed under the Apache 2.0 License . For details, see the Google Developers Site Policies . Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2026-08-13 UTC.
Need to tell us more?
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2026-08-13 UTC."],[],[]]