Official agent skill

Iam Helper For Policy Management

by google in google/skills

Streamlines the creation, modification, and management of IAM allow policies (v1) and deny policies (v2).

OfficialApache-2.0Auto-check passedSecurity

Install Iam Helper For Policy Management

skills CLI
$ npx skills add google/skills --skill iam-helper-for-policy-management -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install google/skills iam-helper-for-policy-management --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloud/iam-helper-for-policy-management .claude/skills/iam-helper-for-policy-management && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
iam-helper-for-policy-management
GitHub stars
21k
Token cost
~1.4k tokens
SKILL.md length
468 words
Files
3 (incl. references)
Skills in repo
150
Repo updated
First seen
Licence
Apache-2.0

At a glance

Streamlines the creation, modification, and management of IAM allow policies (v1) and deny policies (v2).

  • Works in 2 steps: Read-Only Operations (Autonomous… → Mutating Operations (Plan & Confirm…
  • Deleting IAM allow policies
  • SKILL.md covers Core Concepts & Paradigms, Workflow & Decision Tree, Execution & Safety Protocol and Supporting Links
  • Calls gcloud

What it does

Iam Helper For Policy Management is an agent skill from google/skills, published by the product's own GitHub organization. Streamlines the creation, modification, and management of IAM allow policies (v1) and deny policies (v2). Manages access control across Resource Manager resources (Organization, Folder, Project) and individual resources. Use when creating, updating, listing, or deleting IAM allow policies or deny policies. Don't use for access denial troubleshooting (use iam-helper-for-troubleshooting), temporary privileged access (use iam-helper-for-privileged-access-management), configuring VPC Service Controls, or managing…

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/v1-allow-policies.md` and `references/v2-deny-policies.md`).

It sits in Security, covering Cloud networking and Authorization and RBAC. It works with Google Cloud. The repository describes itself as: Agent Skills for Google products and technologies. The licence is Apache-2.0.

When your agent uses it

  • Deleting IAM allow policies
  • Access denial troubleshooting (use iam-helper-for-troubleshooting)
  • Temporary privileged access (use iam-helper-for-privileged-access-management)
  • Configuring VPC Service Controls

Example prompts

  • “Use the iam-helper-for-policy-management skill to streamline the creation, modification, and management of IAM allow policies (v1) and deny policies…”
  • “/iam-helper-for-policy-management”

Workflow steps

2 steps, taken from the step headings in SKILL.md.

  1. Read-Only Operations (Autonomous Execution)
  2. Mutating Operations (Plan & Confirm Protocol)

What it can do on your machine

Read from SKILL.md and the folder at commit 4b940dd. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gcloud

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • cloud.google.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Iam Helper For Policy Management loads about 1.4k tokens when it runs, and up to ~4.9k if it reads all its reference files. Until then it costs about 143 tokens; SKILL.md has 468 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~143
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from google/skills at commit 4b940dd, republished under its Apache-2.0 licence (© google). 468 words, ~1,365 tokens.

Download SKILL.mdSave it as .claude/skills/iam-helper-for-policy-management/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
iam-helper-for-policy-management
description
Streamlines the creation, modification, and management of IAM allow policies (v1) and deny policies (v2). Manages access control across Resource Manager resources (Organization, Folder, Project) and individual resources. Use when creating, updating, listing, or deleting IAM allow policies or deny policies. Don't use for access denial troubleshooting (use iam-helper-for-troubleshooting), temporary privileged access (use iam-helper-for-privileged-access-management), configuring VPC Service Controls, or managing network firewall rules.
metadata.version
1.0.0
metadata.category
Security

IAM Helper for Policy Management

Orchestrates the lifecycle and management of IAM allow and deny policies across IAM v1 (allow policies) and IAM v2 (deny policies).


Core Concepts & Paradigms

IAM operates across two policy paradigms:

  1. IAM v1 (Allow Policies): Grants roles to principals (users, service accounts, groups, domains) on specific resources. Supports Resource Manager resources (organizations, folders, projects) as well as individual resources across supported Google Cloud services.
  2. IAM v2 (Deny Policies): Sets explicit organization-, folder-, or project-level guardrails that prevent specified principals from using designated permissions, regardless of any allow policies granted. Evaluated before allow policies.

Workflow & Decision Tree

When receiving a policy management request, determine whether the operation is Read-Only or Mutating, and whether it targets IAM v1 (Allow Policies) or IAM v2 (Deny Policies):

1. Read-Only Operations (Autonomous Execution)

Read-only actions include the following:

  • IAM v1 Allow Policies: get-iam-policy on project/folder/organization, or gcloud iam list-testable-permissions //cloudresourcemanager.googleapis.com/projects/PROJECT_ID.
  • IAM v2 Deny Policies: gcloud iam policies list or gcloud iam policies get with --attachment-point and --kind=denypolicies.

For read-only actions, execute the command autonomously to inspect state, and present the query results clearly to the user.

2. Mutating Operations (Plan & Confirm Protocol)

Mutating operations include the following:

  • IAM v1 Allow Policies: add-iam-policy-binding, remove-iam-policy-binding, or set-iam-policy across project, folder, organization, or resource levels (see references/v1-allow-policies.md).
  • IAM v2 Deny Policies: create, update, or delete deny policies on attachment points (cloudresourcemanager.googleapis.com/projects/PROJECT_ID, cloudresourcemanager.googleapis.com/folders/FOLDER_ID, or cloudresourcemanager.googleapis.com/organizations/ORG_ID) using YAML/JSON policy files (see references/v2-deny-policies.md).

For mutating operations, follow the Plan & Confirm Protocol below. DO NOT execute mutating commands autonomously without prior user approval.


Show full SKILL.md (211 more words)Show less

Execution & Safety Protocol

  • Plan and Confirm (No Autonomous Mutation): Mutating allow and deny policy changes modify live security perimeters and access controls. You MUST NOT execute mutating gcloud commands directly via tool calls without explicit prior confirmation from the user. When asked to apply a mutating change, do the following:
    1. Formulate the Command: Generate the exact, fully constructed gcloud command (including all parameters such as --member, --role, --attachment-point, --kind=denypolicies, and --policy-file).
    2. Warn of Impact & Propagation: Issue a general warning that the change could impact access in a live environment and takes time to propagate across Google Cloud global infrastructure.
    3. Request User Confirmation: Prompt the user for approval before applying the changes to the live environment.
  • Post-Execution Verification: After the user approves and the mutating policy change is executed, run the corresponding verification command (see references/v1-allow-policies.md and references/v2-deny-policies.md for exact verification steps) to verify that the active state matches expectations before reporting completion.
  • Security Guardrail (Public & Blanket Access Refusal): Never grant allUsers or allAuthenticatedUsers basic roles (roles/owner, roles/editor, roles/viewer, roles/admin, roles/writer, and roles/reader) or broad permissions. Explicitly refuse blanket public access requests, explain the severe security risks of public project ownership/access, and propose scoped, least-privileged role bindings for specific authenticated identities instead.

© google, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/cloud/iam-helper-for-policy-management of google/skills.

  • SKILL.md
  • references/v1-allow-policies.md
  • references/v2-deny-policies.md

Open the folder on GitHubat commit 4b940dd

Compare with similar skills

Iam Helper For Policy Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Iam Helper For Policy Management compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Iam Helper For Policy Management this skillgoogle/skills21k—~1.4kAutomated safety check: PassApache-2.0
Implementing Zero Trust With Beyondcorpmukul975/Anthropic-Cybersecurity-Skills34k—~732Automated safety check: PassApache-2.0
Performing GCP Security Assessment With Forsetimukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.0
Implementing GCP Binary Authorizationmukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.0
Dangling DNS Finderanirudhbiyani/findmytakeover180—~1.8kAutomated safety check: PassGPL-3.0
Intrinsic Core Conceptsintrinsic-ai/intrinsic-core562—~2.6kAutomated safety check: PassApache-2.0

Similar skills

  • Implementing Zero Trust With Beyondcorp

    mukul975/Anthropic-Cybersecurity-Skills

    Configures Google BeyondCorp Enterprise Identity-Aware Proxy (IAP) as the access enforcement point for web applications, defining Access Context Manager access levels from device trust and network…

    34k GitHub stars~732 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Performing GCP Security Assessment With Forseti

    mukul975/Anthropic-Cybersecurity-Skills

    Performing comprehensive security assessments of Google Cloud Platform environments using Forseti Security, Security Command Center, and gcloud CLI to audit IAM policies, firewall rules, storage…

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Implementing GCP Binary Authorization

    mukul975/Anthropic-Cybersecurity-Skills

    Implements GCP Binary Authorization end to end, including creating KMS-backed attestors, Container Analysis notes, deploy-time policies, and signing image attestations, so that only trusted…

    34k GitHub stars~2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Dangling DNS Finder

    anirudhbiyani/findmytakeover

    Detect dangling DNS records and subdomain-takeover risks across a multi-cloud environment by running the bundled findmytakeover tool.

    180 GitHub stars~1.8k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Intrinsic Core Concepts

    intrinsic-ai/intrinsic-core

    Intrinsic Core zero-cloud architecture, core primitives (Assets, Services, Skills, Solutions, ICON), CLI inspection commands, and workspace search rules.

    562 GitHub stars~2.6k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Cb Security Hardening

    BlkLeg/CircuitBreaker

    Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx.

    201 GitHub stars~2.1k tokensUpdated 5 days ago
    Backend & APIsAuto-check passed

More from google/skills

All 150 skills in this repo
  • Official

    Query Cloud Trace spans, filter by latency thresholds or error status, correlate distributed traces with Cloud Logging, and diagnose latency bottlenecks across Google Cloud services.

    21k GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Official

    Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.

    21k GitHub stars~3.2k tokensUpdated yesterday
    Auto-check passed
  • Official

    Writes Terraform alerting policies for AI agents that emit OpenTelemetry metrics, covering reliability, cost, safety, security and quality signals on Google Cloud.

    21k GitHub stars~4.2k tokensUpdated yesterday
    Auto-check passed
  • Official

    Deploys open models or custom weights from Model Garden to Agent Platform endpoints, checks deployment status and cleans up endpoints, confirming before any change.

    21k GitHub stars~5k tokensUpdated yesterday
    Auto-check passed
  • Official

    Searches, manages and scaffolds skills in the Gemini Enterprise Agent Platform Skill Registry using bundled Python scripts and Google Cloud credentials.

    21k GitHub stars~584 tokensUpdated yesterday
    Auto-check passed
  • Designs GCP infrastructure as local Terraform, validates and scans it against best practices, then imports it to Application Design Center for deployment and troubleshooting.

    21k GitHub stars~4.4k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Iam Helper For Policy Management

What does Iam Helper For Policy Management do?

Streamlines the creation, modification, and management of IAM allow policies (v1) and deny policies (v2). Iam Helper For Policy Management is an agent skill from google/skills, published by the product's own GitHub organization. Streamlines the creation, modification, and management of IAM allow policies (v1) and deny policies (v2).

When should I use Iam Helper For Policy Management?

Iam Helper For Policy Management fits situations like: deleting IAM allow policies; access denial troubleshooting (use iam-helper-for-troubleshooting); temporary privileged access (use iam-helper-for-privileged-access-management); configuring VPC Service Controls.

How do I install Iam Helper For Policy Management in Claude Code?

Run `npx skills add google/skills --skill iam-helper-for-policy-management -a claude-code`. Or copy the skill folder (skills/cloud/iam-helper-for-policy-management in google/skills) into .claude/skills/iam-helper-for-policy-management in your project. Claude Code loads it when a task matches its description.

How do I install Iam Helper For Policy Management in Codex?

Run `npx skills add google/skills --skill iam-helper-for-policy-management -a codex`. Or copy the skill folder (skills/cloud/iam-helper-for-policy-management in google/skills) into .agents/skills/iam-helper-for-policy-management in your project. Codex loads it when a task matches its description.

Can I use Iam Helper For Policy Management in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add google/skills --skill iam-helper-for-policy-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/iam-helper-for-policy-management, .gemini/skills/iam-helper-for-policy-management, .github/skills/iam-helper-for-policy-management and .opencode/skills/iam-helper-for-policy-management in your project.

What does Iam Helper For Policy Management need to run?

Going by SKILL.md and its folder, Iam Helper For Policy Management needs the command-line tools its instructions call (gcloud).

Does Iam Helper For Policy Management access the network?

SKILL.md names 1 domain. As links in the text: cloud.google.com. This is read from the text; nothing was executed.

Is Iam Helper For Policy Management safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Iam Helper For Policy Management use?

Iam Helper For Policy Management is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Iam Helper For Policy Management use?

About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.5k tokens, read only when the agent opens those files.

What are the alternatives to Iam Helper For Policy Management?

Skills that share tags, products or a category with Iam Helper For Policy Management: Implementing Zero Trust With Beyondcorp (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Performing GCP Security Assessment With Forseti (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing GCP Binary Authorization (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Dangling DNS Finder (anirudhbiyani/findmytakeover, 180 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Iam Helper For Policy Management?

google (a GitHub organization, an official publisher) maintains it in google/skills, which has 21,097 GitHub stars. The repository holds 150 skills in this directory. The repository was last updated on October 9, 2026.

Source: google/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.