Spotter accesses your GCP environment through its own service account:
spotter@cloud2-core-spotter.iam.gserviceaccount.com
Grant this service account the roles below. You don't create a service account yourself — you only add roles to Spotter's.
Configure organization access
Grant the service account these roles on your organization:
-
roles/securitycenter.adminViewer— read compliance findings. -
roles/recommender.viewer— read cost optimization recommendations.
Configure billing data access
Grant the service account these roles so Spotter can read your billing export from BigQuery:
-
roles/bigquery.jobUser— on the project that hosts the billing export dataset. -
roles/bigquery.dataViewer— on the billing export table (or its dataset).
If your billing data is spread across more than one project or dataset, repeat these two grants for each of them.