Privileged Access Manager
Privileged Access Manager (PAM) grants a role for a limited time when a person asks for it, instead of a standing binding. The GCP Enterprise Baseline uses it for every Owner and organization-admin grant of the lead groups, with a 12-hour maximum and a second lead's approval where the scope is wide.
What it does
An entitlement names the roles it grants, the resource it grants them on (an organization, a folder or a project), the principals eligible to request it and the longest grant they may ask for. A request carries a justification. When the entitlement has an approval workflow, a named approver must accept the request, with a justification of their own, before the grant starts. The grant is a temporary IAM binding that Privileged Access Manager removes when it expires, and every request, approval and grant is written to the audit logs.
How BuiltForProd uses it
The pam unit (environments/core/identity/global) creates four entitlements:
entitlements = var.enable_pam ? {
"platform-leads-core" = { parent = local.core, group = var.group_emails["platform_leads"], approvers = [], roles = ["roles/owner"] }
"platform-leads-plat" = { parent = local.plat, group = var.group_emails["platform_leads"], approvers = [], roles = ["roles/owner"] }
"devops-leads-plat" = { parent = local.plat, group = var.group_emails["devops_leads"], approvers = [var.group_emails["platform_leads"]], roles = ["roles/owner"] }
"platform-leads-org" = { parent = local.org, group = var.group_emails["platform_leads"], approvers = [var.group_emails["platform_leads"]], roles = ["roles/resourcemanager.organizationAdmin", "roles/orgpolicy.policyAdmin"] }
} : {}
| Entitlement | Grants | On | Eligible | Approval |
|---|---|---|---|---|
acme-platform-leads-core | Owner | folder core | acme-platform-leads | none |
acme-platform-leads-plat | Owner | folder plat | acme-platform-leads | none |
acme-devops-leads-plat | Owner | folder plat | acme-devops-leads | one platform lead |
acme-platform-leads-org | Organization Administrator, Organization Policy Administrator | the organization | acme-platform-leads | another platform lead |
Every request may last at most 12 hours (max_request_duration = 43200s) and needs a justification. pam_notification_emails in environments/core/identity/identity.hcl adds mailboxes that hear about every request besides the approvers; it is empty by default. The unit also grants the organization's PAM service agent the role it needs before any entitlement can exist.
Without an active grant the leads keep only the viewer bundle that Identity and Access Management gives them, so day-to-day work happens read-only and every change of the landing zone goes through a pull request that CI applies.
The switch. enable_pam = true is the default in identity.hcl. With false the pam unit creates nothing and groups-iam binds Owner on the folders to the lead groups as standing access, with no time limit and no approval.
Terms you will see
| Term | Meaning |
|---|---|
| Entitlement | The definition of a grant someone may request: roles, scope, eligibility. |
| Eligible principal | A group whose members may request the entitlement. |
| Grant | One approved, time-bound activation of an entitlement. |
| Approval workflow | The step in which a named approver must accept a request. |
max_request_duration | The longest grant a requester may ask for: 12 hours. |
Where to read more
- GCP Enterprise Baseline overview for how people reach the platform.
- Cloud Identity for the lead groups.
- Least privilege for time-bound administrative access.