Checks public IAM bindings and audit logging configuration in a Google Cloud project.
AvailableRead-only collection
What vCISO.ai observes
Public IAM policy bindings
Audit log configuration
Authorization and permissions
Google Cloud service account JSON key
Security Reviewer role
Viewer role
Cloud Platform read-only scope for short-lived token creation
Setup path
Setup remains administrator-controlled inside the authenticated workspace.
Create a service account with Security Reviewer and Viewer
Provide its project-scoped JSON key
Confirm the project ID
Run and review the first collection
Collection limitations
A limited or failed read stays visible and never becomes a passing result.
The released connector reads one configured project
Current observations focus on public IAM bindings and audit logging
Connection does not change IAM policies or project settings
Disconnect and deletion behavior
An administrator can disconnect the integration. The encrypted credential and configuration are removed locally and connector-derived evidence is expired. The customer should delete or disable the service-account key in Google Cloud.
Existing historical records remain available as review history
Connector-derived evidence is marked expired when the source is disconnected
Disconnect is organization-scoped and audit logged
A provider observation can support a control only after the right relationship and evidence are reviewed. Connecting Google Cloud does not automatically verify a control, complete a framework, or produce an audit conclusion.
Start with the roadmap
Put Google Cloud into a prioritized readiness plan.
Build the free roadmap first, then activate the AI vCISO when you are ready to connect the provider.