All integrations
GCP
Cloud
Google Cloud
IAM roles on projects and folders
On Google Cloud, Clavra grants roles as IAM conditions with an end time, so access is removed even if Clavra were offline when it expires.
What Clavra can change
Role bindings on the projects and folders you connect. Organization policies stay untouched.
Before you connect
Create a service account with Project IAM Admin on the folders you want to cover, then paste its key or use workload identity federation.
Category
Cloud
Sync
Reads projects and role bindings hourly. Adds conditional bindings that expire on their own.
Setup time
20 min