If you've come from AWS, GCP's IAM model has a few specific traps:
- Roles bind to principals, not to resources. You can't write a resource policy on a Cloud Storage bucket the way you'd write an S3 bucket policy. Permissions live at project / folder / org levels.
- Predefined roles are huge.
roles/editorgrants thousands of permissions across hundreds of services. It's almost never what you actually want. - Service accounts are first-class identities — and historically, their keys were the most-leaked GCP credential type.