CanRemoveMember
Membership removal - mostly destructive/persistence, not escalation; not walked by default.
Derivation
| nature | explicit |
|---|
Rules that emit CanRemoveMember 1
Principal with cloudidentity.groups.memberships.delete (or group Manager/Owner) can remove members from the target group, enabling member deprovisioning or audit-trail destruction.
gcpderived