Spotter Documentation

GCP Access Management

Spotter accesses your GCP environment through its own service account:

spotter@cloud2-core-spotter.iam.gserviceaccount.com

Grant this service account the roles below. You don't create a service account yourself — you only add roles to Spotter's.

Configure organization access

Grant the service account these roles on your organization:

  • roles/securitycenter.adminViewer — read compliance findings.

  • roles/recommender.viewer — read cost optimization recommendations.

Configure billing data access

Grant the service account these roles so Spotter can read your billing export from BigQuery:

  • roles/bigquery.jobUser — on the project that hosts the billing export dataset.

  • roles/bigquery.dataViewer — on the billing export table (or its dataset).

If your billing data is spread across more than one project or dataset, repeat these two grants for each of them.