Official agent skill

Google Cloud PAM Helper

by google in google/skills

Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.

OfficialApache-2.0Auto-check passedSecurity

Install Google Cloud PAM Helper

skills CLI
$ npx skills add google/skills --skill iam-helper-for-privileged-access-management -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install google/skills iam-helper-for-privileged-access-management --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloud/iam-helper-for-privileged-access-management .claude/skills/iam-helper-for-privileged-access-management && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
iam-helper-for-privileged-access-management
GitHub stars
21k
Token cost
~3.2k tokens
SKILL.md length
1,188 words
Files
6 (incl. scripts, references, assets)
Skills in repo
150
Repo updated
First seen
Licence
Apache-2.0

At a glance

Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.

  • Works in 4 steps: Create Entitlement → Read Entitlements → Update Entitlement → …
  • Requesting temporary elevated access through PAM
  • SKILL.md covers Table of Contents, Core Concepts {#core-concepts}, Approval Workflows & Max… and Safety & Confirmation Strategy…, plus 5 more sections
  • Runs Shell scripts from its folder; calls gcloud and bash

What it does

This skill guides the agent through Privileged Access Manager (PAM) work in Google Cloud, where on-demand, time-bound, audited access replaces permanent IAM role bindings. Administrators define entitlements covering the resource (project, folder or organization), the IAM role, an optional condition, eligible requesters and approvers. Requesters then open grants against them, approvers act on those grants, and a grant ends automatically once its duration has passed.

The skill is organized in three modes: interactive access elevation, standalone entitlement create, read, update and delete, and an approver workflow. It follows a plan-validate-execute pattern with a confirmation strategy before changes, and covers approval workflow settings in the entitlement YAML manifest and the maximum request duration. Bundled files include an entitlement template, requester and approver references and shell scripts that list the entitlement hierarchy and search eligible entitlements. It is not meant for permanent IAM bindings, IAM permission error troubleshooting or general resource provisioning.

When your agent uses it

  • Requesting temporary elevated access through PAM
  • Creating or updating a PAM entitlement for a project or folder
  • Approving or denying pending PAM grants
  • Finding which entitlements you are eligible to request

Example prompts

  • “Request two hours of access on the payments project through PAM.”
  • “Create a PAM entitlement that lets the on-call group elevate to a viewer role with manager approval.”
  • “List the pending PAM grants waiting for my approval.”
  • “Search the entitlements I am eligible to request on the staging folder.”

Requirements

  • Access to Google Cloud Privileged Access Manager
  • Permissions that match your role as administrator, requester or approver

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Create Entitlement
  2. Read Entitlements
  3. Update Entitlement
  4. Delete Entitlement

What it can do on your machine

Read from SKILL.md and the folder at commit 4b940dd. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • gcloud
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • cloud.google.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Google Cloud PAM Helper loads about 3.2k tokens when it runs, and up to ~5.5k if it reads all its reference files. Until then it costs about 104 tokens; SKILL.md has 1,188 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~104
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from google/skills at commit 4b940dd, republished under its Apache-2.0 licence (© google). 1,188 words, ~3,179 tokens.

Download SKILL.mdSave it as .claude/skills/iam-helper-for-privileged-access-management/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
iam-helper-for-privileged-access-management
description
Manages the end-to-end lifecycle of on-demand, temporary access using Privileged Access Manager (PAM). Use when a user asks to create, read, update, or delete PAM entitlements, request temporary access, or approve/deny pending PAM grants. Do NOT use for permanent IAM policy bindings, troubleshooting IAM permission errors, or general Google Cloud resource provisioning.
metadata.version
1.0.0
metadata.category
Security

Privileged Access Manager (PAM)

This skill provides step-by-step guidance for planning, validating, and executing Privileged Access Manager (PAM) entitlement CRUD operations, approval workflow configurations, access elevations, and grant approval/denial workflows.

Table of Contents

Core Concepts {#core-concepts}

Privileged Access Manager (PAM) replaces permanent or ambient IAM role assignments with on-demand, time-bound, and audited access elevations. Rather than appending permanent IAM policy bindings, PAM uses:

  • Entitlements: Configurations defining access scopes, eligible requesters, and approvers.
  • Grants: Short-lived requests created against entitlements to activate the entitlement's IAM roles.
Privileged Access (privilegedAccess)

The privilegedAccess block in an entitlement defines the precise access scope that will be granted. An access scope comprises three essential components:

  • Resource: The target Google Cloud resource (Project, Folder, or Organization) where access is granted.
  • Role Setup: The IAM role (roleBindings.role) to be assigned.
  • Condition: (Optional) An IAM condition expression (roleBindings.conditionExpression) restricting when or where the role applies.
Core Workflow
  1. Administrators create Entitlements.
  2. Requesters can then request Grants against these entitlements.
  3. If the entitlement is configured with approvals, then an approver must approve the requested grant.
  4. Once all necessary approval steps are completed, the grant is activated for the requested time.
  5. The grant automatically ends after the requested duration has elapsed, and the elevated access is removed.

Approval Workflows & Max Request Duration {#approval-workflows}

Approval Workflows (approvalWorkflow)

When sensitive environments require human approval before temporary access is activated, configure the approvalWorkflow block in the entitlement YAML manifest (entitlement.yaml).

yaml
approvalWorkflow:
  manualApprovals:
    # Optional: requires approver to supply a justification string
    requireApproverJustification: true
    steps:
    - approvalsNeeded: 1
      approverEmailRecipients:
      - approver@example.com
      approvers:
      - principals:
        - user:db-lead@my-company.com  # or group:sre-leads@my-company.com
  • When to include: Include approvalWorkflow whenever the user prompt specifies that manual approval or an approver (user or group) is required.
  • Outcome: When a user requests a grant against an entitlement with approvalWorkflow, the grant transitions to APPROVAL_AWAITED. Requesters must await an Approver's decision (Mode 3).
Max Request Duration (maxRequestDuration)

maxRequestDuration defines the maximum single access elevation timeframe a requester may ask for when placing a grant request.

  • Flexible Configuration: Configure maxRequestDuration according to the user's specific request (e.g. 8 hours / 28800s, 1 hour / 3600s, 24 hours / 86400s).
  • Default Value: If the user does NOT specify a maximum request duration, default to 4 hours (14400s).
  • YAML Syntax: Always format maxRequestDuration as a string in seconds in the entitlement YAML (e.g., "14400s", "28800s").

Safety & Confirmation Strategy {#safety-confirmation}

Adhere strictly to these workflow guards:

  • Modifying / Destructive Executions (Create, Update, Delete, Approve, Deny, Revoke): Always present a plain-text summary of the planned adjustments and prompt the user for explicit confirmation (Yes/No).
  • Read-Only Inspections (List, Describe, Search): Run autonomously without requesting confirmation.
  • Batching Bash Commands (Reduce User Confirmations): The host environment requires user approval for every individual shell tool call. To minimize confirmation popups, combine sequential read-only and lookup commands into a single compound bash script within one tool call (e.g., combining project, folder, and organization hierarchy audits into a single multiline execution).
  • Anti-Loop Strategy: If a command fails with a clear, actionable error, you may attempt to self-debug and retry. If the error is ambiguous, halt immediately, present the stderr output, and await user direction.

Plan-Validate-Execute Pattern {#plan-validate-execute}

For all modifying actions (Mode 1 Step 3, Mode 2 Create, Update, Delete, Mode 3 Approve, Deny):

  1. Plan: Construct the proposed parameters or read the sample entitlement structure. (For entitlement creation, load and use the template: assets/entitlement_template.yaml).
  2. Validate: Inspect the target configuration parameters (resource names, role bindings, duration limits) for compliance with corporate rules.
  3. Execute: Present the validated plan, obtain explicit user confirmation, and run the gcloud command.

Mode 1: Interactive Access Elevation {#mode-1}

When the user requests temporary access elevation as a Requester, load and follow the detailed instructions in references/requester.md.


Mode 2: Standalone Entitlement CRUD {#mode-2}

Follow these steps for entitlement configurations.

Required Permissions for Entitlement Admins
  • roles/privilegedaccessmanager.admin: Required to create, update, and delete entitlement configurations (Mode 1 Step 3 and Mode 2 CRUD).
  • Scope IAM Admin Rights: Required on the target hierarchy scope because creating an entitlement authorizes future role evaluations and bindings on that scope:
    • Organizations: roles/iam.securityAdmin
    • Folders: roles/resourcemanager.folderAdmin
    • Projects: roles/resourcemanager.projectIamAdmin
  • roles/privilegedaccessmanager.viewer: Required to list and describe entitlements across scopes.

(Rule: For all Standalone Entitlement CRUD commands below, use the flag matching where the entitlement is defined: pass --project=PROJECT_ID, --folder=FOLDER_ID, or --organization=ORGANIZATION_ID).

Show full SKILL.md (475 more words)Show less
1. Create Entitlement
  1. Check if ENTITLEMENT_ID exists:
bash
gcloud pam entitlements describe ENTITLEMENT_ID \
    --location=global \
    --project=PROJECT_ID
  • If Exists: Halt. Ask: "The requested PAM Entitlement ENTITLEMENT_ID already exists. Would you like to view its details or update it instead? (View / Update / Exit)"
  • If NOT_FOUND: Load the template assets/entitlement_template.yaml. Generate IDs in lowercase using hyphen separators derived from the role name (e.g., compute-admin for roles/compute.admin). Note:
    • You may specify multiple IAM roles under roleBindings.
    • You may also include an optional IAM conditionExpression for each role binding.
    • Legacy basic roles (e.g., roles/viewer, roles/editor, roles/owner) are NOT supported. Instead, use their v2 basic role equivalents (e.g., roles/basic.viewer, roles/basic.editor, roles/basic.owner). Ensure you select a valid predefined, custom, or v2 basic role.
  • Set maxRequestDuration based on user specification (e.g. "28800s" for 8 hours, "3600s" for 1 hour). If unspecified by the user, default to "14400s" (4 hours). If manual approval is specified by policy or requested by the user, configure the approvalWorkflow block in entitlement.yaml. Preserve requesterJustificationConfig: {unstructured: {}}.
  • Prompt: "You are about to create the PAM Entitlement ENTITLEMENT_ID. Do you approve this creation? (Yes/No)"
  • Deploy:
bash
gcloud pam entitlements create ENTITLEMENT_ID \
    --location=global \
    --entitlement-file=entitlement.yaml \
    --project=PROJECT_ID
2. Read Entitlements

Run these read operations autonomously:

List all entitlements at a single scope:

bash
gcloud pam entitlements list \
    --location=global \
    --project=PROJECT_ID

To list all entitlements defined across the entire resource hierarchy (project, ancestor folders, and organization), use the hierarchy listing script:

bash
bash scripts/list_entitlements_hierarchy.sh --project=PROJECT_ID

(Or pass --folder=FOLDER_ID or --organization=ORGANIZATION_ID).

Describe target entitlement:

bash
gcloud pam entitlements describe ENTITLEMENT_ID \
    --location=global \
    --project=PROJECT_ID
3. Update Entitlement
  1. Run the export command to generate the current config (which includes the etag):

    bash
    gcloud pam entitlements export ENTITLEMENT_ID \
        --location=global \
        --project=PROJECT_ID > {scratch}/updated_entitlement.yaml

    If missing, offer to run list or exit.

  2. Edit the exported {scratch}/updated_entitlement.yaml file to apply the requested changes (e.g., updating maxRequestDuration, approvalWorkflow, or eligibleUsers). Do not alter the etag.

  3. Prompt: "You are about to update the PAM Entitlement ENTITLEMENT_ID. Do you approve this update? (Yes/No)"

  4. Execute:

bash
gcloud pam entitlements update ENTITLEMENT_ID \
    --location=global \
    --entitlement-file={scratch}/updated_entitlement.yaml \
    --project=PROJECT_ID
4. Delete Entitlement
  1. Verify existence using describe. If missing, offer list/exit.

  2. Safety Check: An entitlement cannot be deleted if there are open grants. Before deleting, search for any ACTIVE or SCHEDULED grants:

    bash
    gcloud pam grants list \
        --entitlement=ENTITLEMENT_ID \
        --location=global \
        --project=PROJECT_ID \
        --filter="state:(ACTIVE, SCHEDULED)"

    If any open grants are found, prompt the user for permission to revoke them: "There are active or scheduled grants on this entitlement. Do you authorize me to revoke them so the entitlement can be deleted? (Yes/No)"

    If Yes, revoke them:

    bash
    gcloud pam grants revoke GRANT_ID \
        --entitlement=ENTITLEMENT_ID \
        --location=global \
        --project=PROJECT_ID \
        --reason="Revoking to delete entitlement"
  3. Prompt: "You are about to permanently delete the PAM Entitlement ENTITLEMENT_ID. Do you approve this deletion? (Yes/No)"

  4. Execute:

bash
gcloud pam entitlements delete ENTITLEMENT_ID \
    --location=global \
    --project=PROJECT_ID

Mode 3: Approver Workflow {#mode-3}

When an Approver needs to review, approve, or reject pending grant requests, load and follow the detailed instructions in references/approver.md.


For further information on working with Privileged Access Manager, refer to:

© google, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references, assets) in skills/cloud/iam-helper-for-privileged-access-management of google/skills.

  • SKILL.md
  • assets/entitlement_template.yaml
  • references/approver.md
  • references/requester.md
  • scripts/list_entitlements_hierarchy.sh
  • scripts/search_eligible_entitlements.sh

Open the folder on GitHubat commit 4b940dd

Compare with similar skills

Google Cloud PAM Helper next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Google Cloud PAM Helper compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Google Cloud PAM Helper this skillgoogle/skills21k—~3.2kAutomated safety check: PassApache-2.0
Cloud Auditbriiirussell/cybersecurity-skills413—~1.3kAutomated safety check: NotesMIT
Container Securityhardw00t/ai-security-arsenal105—~2.8kAutomated safety check: PassNone
Auditing Cloud With Cis Benchmarksmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Implementing Cloud Security Posture Managementmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Implementing Zero Trust With Beyondcorpmukul975/Anthropic-Cybersecurity-Skills34k—~732Automated safety check: PassApache-2.0

Similar skills

  • Cloud Audit

    briiirussell/cybersecurity-skills

    Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.

    413 GitHub stars~1.3k tokensUpdated 4 mo ago
    SecurityAuto-check: notes
  • Container Security

    hardw00t/ai-security-arsenal

    Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…

    105 GitHub stars~2.8k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Auditing Cloud With Cis Benchmarks

    mukul975/Anthropic-Cybersecurity-Skills

    Audit AWS, Azure, and GCP environments against the CIS Foundations Benchmarks by running automated scans with tools like Prowler and ScoutSuite, interpreting failed controls, and tracking…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Implementing Cloud Security Posture Management

    mukul975/Anthropic-Cybersecurity-Skills

    Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Implementing Zero Trust With Beyondcorp

    mukul975/Anthropic-Cybersecurity-Skills

    Configures Google BeyondCorp Enterprise Identity-Aware Proxy (IAP) as the access enforcement point for web applications, defining Access Context Manager access levels from device trust and network…

    34k GitHub stars~732 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Performing GCP Security Assessment With Forseti

    mukul975/Anthropic-Cybersecurity-Skills

    Performing comprehensive security assessments of Google Cloud Platform environments using Forseti Security, Security Command Center, and gcloud CLI to audit IAM policies, firewall rules, storage…

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from google/skills

All 150 skills in this repo
  • Official

    Query Cloud Trace spans, filter by latency thresholds or error status, correlate distributed traces with Cloud Logging, and diagnose latency bottlenecks across Google Cloud services.

    21k GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Official

    Writes Terraform alerting policies for AI agents that emit OpenTelemetry metrics, covering reliability, cost, safety, security and quality signals on Google Cloud.

    21k GitHub stars~4.2k tokensUpdated yesterday
    Auto-check passed
  • Official

    Deploys open models or custom weights from Model Garden to Agent Platform endpoints, checks deployment status and cleans up endpoints, confirming before any change.

    21k GitHub stars~5k tokensUpdated yesterday
    Auto-check passed
  • Official

    Searches, manages and scaffolds skills in the Gemini Enterprise Agent Platform Skill Registry using bundled Python scripts and Google Cloud credentials.

    21k GitHub stars~584 tokensUpdated yesterday
    Auto-check passed
  • Designs GCP infrastructure as local Terraform, validates and scans it against best practices, then imports it to Application Design Center for deployment and troubleshooting.

    21k GitHub stars~4.4k tokensUpdated yesterday
    Auto-check passed
  • Official

    Analyzes BigQuery slot use, query costs and execution bottlenecks from INFORMATION_SCHEMA to diagnose slow queries, slot contention and unpartitioned scans.

    21k GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Google Cloud PAM Helper

What does Google Cloud PAM Helper do?

Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants. This skill guides the agent through Privileged Access Manager (PAM) work in Google Cloud, where on-demand, time-bound, audited access replaces permanent IAM role bindings. Administrators define entitlements covering the resource (project, folder or organization), the IAM role, an optional condition, eligible requesters and approvers.

When should I use Google Cloud PAM Helper?

Google Cloud PAM Helper fits situations like: requesting temporary elevated access through PAM; creating or updating a PAM entitlement for a project or folder; approving or denying pending PAM grants; finding which entitlements you are eligible to request.

How do I install Google Cloud PAM Helper in Claude Code?

Run `npx skills add google/skills --skill iam-helper-for-privileged-access-management -a claude-code`. Or copy the skill folder (skills/cloud/iam-helper-for-privileged-access-management in google/skills) into .claude/skills/iam-helper-for-privileged-access-management in your project. Claude Code loads it when a task matches its description.

How do I install Google Cloud PAM Helper in Codex?

Run `npx skills add google/skills --skill iam-helper-for-privileged-access-management -a codex`. Or copy the skill folder (skills/cloud/iam-helper-for-privileged-access-management in google/skills) into .agents/skills/iam-helper-for-privileged-access-management in your project. Codex loads it when a task matches its description.

Can I use Google Cloud PAM Helper in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add google/skills --skill iam-helper-for-privileged-access-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/iam-helper-for-privileged-access-management, .gemini/skills/iam-helper-for-privileged-access-management, .github/skills/iam-helper-for-privileged-access-management and .opencode/skills/iam-helper-for-privileged-access-management in your project.

What does Google Cloud PAM Helper need to run?

Going by SKILL.md and its folder, Google Cloud PAM Helper needs a shell for the scripts in its folder and the command-line tools its instructions call (gcloud and bash). Our summary lists: Access to Google Cloud Privileged Access Manager; Permissions that match your role as administrator, requester or approver.

Does Google Cloud PAM Helper access the network?

SKILL.md names 1 domain. As links in the text: cloud.google.com. This is read from the text; nothing was executed.

Is Google Cloud PAM Helper safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Google Cloud PAM Helper use?

Google Cloud PAM Helper is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Google Cloud PAM Helper use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.3k tokens, read only when the agent opens those files.

What are the alternatives to Google Cloud PAM Helper?

Skills that share tags, products or a category with Google Cloud PAM Helper: Cloud Audit (briiirussell/cybersecurity-skills, 413 stars), Container Security (hardw00t/ai-security-arsenal, 105 stars), Auditing Cloud With Cis Benchmarks (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Implementing Cloud Security Posture Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Google Cloud PAM Helper?

google (a GitHub organization, an official publisher) maintains it in google/skills, which has 21,097 GitHub stars. The repository holds 150 skills in this directory. The repository was last updated on October 9, 2026.

Source: google/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.