All skills
google avatar

/iam-helper-for-privileged-access-management

@becc4b8
by googlegoogle/skills21k stars
1,698

Manages the end-to-end lifecycle of on-demand, temporary access using Privileged Access Manager (PAM). Use when a user asks to create, read, update, or delete PAM entitlements, request temporary access, or approve/deny pending PAM grants. Do NOT use for permanent IAM policy bindings, troubleshooting IAM permission errors, or general Google Cloud resource provisioning.

Use this Skill: https://skilld.dev/gh/google/skills/iam-helper-for-privileged-access-management

This session only. Nothing lands on disk.

referencesapprover.md

≈800 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Mode 3: Approver Workflow (Grants)

Follow these steps when an Approver needs to review, approve, or reject pending grant requests raised by requesters.

(Rule: Select the scope flag matching where the entitlement/grant is located: pass --project=PROJECT_ID, --folder=FOLDER_ID, or --organization=ORGANIZATION_ID).

Table of Contents

Prerequisites & Permissions {#prerequisites}

  • Approver Authorization: To become an approver, the user simply must be added to the approvers list in the entitlement's approvalWorkflow configuration. No explicit IAM roles are required.
  • Discover Grants to Approve: Approvers can directly search for grants they are authorized to approve across a project, folder, or organization using gcloud pam grants search --caller-relationship=can-approve without needing the roles/privilegedaccessmanager.viewer role or knowing specific entitlement IDs beforehand.

Step 1: Search Pending Grants {#step-1}

Approvers can search directly for pending grants awaiting their decision across a project, folder, or organization:

gcloud pam grants search \
    --caller-relationship=can-approve \
    --location=global \
    --project=PROJECT_ID

(Or pass --folder=FOLDER_ID, --organization=ORGANIZATION_ID matching the target resource hierarchy).

You can also list all grants for a specific entitlement if the entitlement ID is already known:

gcloud pam grants list \
    --entitlement=ENTITLEMENT_ID \
    --location=global \
    --project=PROJECT_ID

(Note: Read-only search/list operations run autonomously without user prompt).

Step 2: Approve Pending Grant {#step-2}

When the user asks to approve a pending PAM grant:

  1. Verify grant existence and state using gcloud pam grants describe or search.
  2. Prompt the user to provide a justification string for the approval.
  3. Prompt the user for explicit approval under Plan-Validate-Execute rules: "You are about to approve PAM Grant GRANT_ID under entitlement ENTITLEMENT_ID with reason: 'USER_PROVIDED_REASON'. Do you approve? (Yes/No)"
  4. Execute approval:
gcloud pam grants approve GRANT_ID \
    --entitlement=ENTITLEMENT_ID \
    --location=global \
    --project=PROJECT_ID \
    --reason="USER_PROVIDED_REASON"

Step 3: Deny Pending Grant {#step-3}

When the user asks to deny or reject a pending PAM grant:

  1. Verify grant existence and state using gcloud pam grants describe or search.
  2. Prompt the user to provide a justification string for the denial.
  3. Prompt the user for explicit approval under Plan-Validate-Execute rules: "You are about to deny PAM Grant GRANT_ID under entitlement ENTITLEMENT_ID with reason: 'USER_PROVIDED_REASON'. Do you approve? (Yes/No)"
  4. Execute denial:
gcloud pam grants deny GRANT_ID \
    --entitlement=ENTITLEMENT_ID \
    --location=global \
    --project=PROJECT_ID \
    --reason="USER_PROVIDED_REASON"

Source: SKILL.md on GitHub

No alerts10d3 checks · Risk SAFE
  • Gen Agent Trust Hub10d

    This skill provides structured management for Google Cloud Privileged Access Manager (PAM). It includes security-minded patterns such as manual confirmation for all modifying actions and uses official gcloud tooling. Users should review the permissions required by the skill to ensure they align with their organization's least-privilege policies.

  • Socket10d

    No alerts

  • Snyk10d

    Risk: LOW · No issues

Signed by skilld at becc4b8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 weeks ago
metadata
{
  "version": "1.0.0",
  "category": "Security"
}

README badge

README badge for google/skills/iam-helper-for-privileged-access-management