gcloud alpha pam grants Stay organized with collections Save and categorize content based on your preferences.
- NAME
- gcloud alpha pam grants - manage Privileged Access Manager grants
- SYNOPSIS
gcloud alpha pam grantsCOMMAND[GCLOUD_WIDE_FLAG …]
- DESCRIPTION
(ALPHA)Thegcloudpam grantscommand group lets you manage Privileged Access Manager(PAM) grants.- EXAMPLES
- To create a new grant against an entitlement with the full name
, a requested duration ofENTITLEMENT_NAME1 hour 30 minutes, a justification ofsomejustification, and two additional email recipientsabc@example.comandxyz@example.com, run:gcloudalphapamgrantscreate--entitlement=ENTITLEMENT_NAME--requested-duration=5400s--justification="some justification"--additional-email-recipients=abc@example.com,xyz@example.comTo describe a grant with the full name
, run:GRANT_NAMEgcloudalphapamgrantsdescribeGRANT_NAMETo list all grants associated with an entitlement with the full name
, run:ENTITLEMENT_NAMEgcloudalphapamgrantslist--entitlement=ENTITLEMENT_NAMETo deny a grant with the full name
and a reasonGRANT_NAMEdenialreason, run:gcloudalphapamgrantsdenyGRANT_NAME--reason="denial reason"To approve a grant with the full name
and a reasonGRANT_NAMEapprovalreason, run:gcloudalphapamgrantsapproveGRANT_NAME--reason="approval reason"To revoke a grant with the full name
and a reasonGRANT_NAMErevokereason, run:gcloudalphapamgrantsrevokeGRANT_NAME--reason="revoke reason"To search for and list all grants that you have created that are associated withan entitlement with the full name
, run:ENTITLEMENT_NAMEgcloudalphapamgrantssearch--entitlement=ENTITLEMENT_NAME--caller-relationship=had-createdTo search for and list all grants that you have approved or denied, that areassociated with an entitlement with the full name
, run:ENTITLEMENT_NAMEgcloudalphapamgrantssearch--entitlement=ENTITLEMENT_NAME--caller-relationship=had-approvedTo search for and list all grants that you can approve that are associated withan entitlement with the full name
, run:ENTITLEMENT_NAMEgcloudalphapamgrantssearch--entitlement=ENTITLEMENT_NAME--caller-relationship=can-approveTo withdraw a grant with the full name
, run:GRANT_NAMEgcloudalphapamgrantswithdrawGRANT_NAME - GCLOUD WIDE FLAGS
- These flags are available to all commands:
--help.Run
$gcloud helpfor details. - COMMANDS
is one of the following:COMMANDapprove(ALPHA)Approve a Privileged Access Manager (PAM) grant.create(ALPHA)Create a new Privileged Access Manager (PAM) grant.deny(ALPHA)Deny a Privileged Access Manager (PAM) grant.describe(ALPHA)Show details of a Privileged Access Manager (PAM) grant.list(ALPHA)List all Privileged Access Manager (PAM) grants associatedwith an entitlement.revoke(ALPHA)Revoke a Privileged Access Manager (PAM) grant.search(ALPHA)Search for and list all Privileged Access Manager (PAM)grants you have created, have approved, or can approve.withdraw(ALPHA)Withdraw a Privileged Access Manager (PAM) grant.
- NOTES
- This command is currently in alpha and might change without notice. If thiscommand fails with API permission errors despite specifying the correct project,you might be trying to access an API with an invitation-only early accessallowlist. These variants are also available:
gcloudpamgrantsgcloudbetapamgrants
Except as otherwise noted, the content of this page is licensed under theCreative Commons Attribution 4.0 License, and code samples are licensed under theApache 2.0 License. For details, see theGoogle Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2025-09-24 UTC.