ConditionalPolicy

Condition-bearing binding / Conditional Access / deny assignment.

class: Policy

Realizing resources

gcp gcp

resourcescopeenumeraterequired permissions
gcp:accesscontextmanager:access-policy global accesscontextmanager.accessPolicies.list accesscontextmanager.accessPolicies.list

Exposure sites

None.

Rules that touch ConditionalPolicy 15

A principal who can delete the owning Blueprint/Managed-App or remove a deny-effect policy assignment can lift the guardrail suppressing inherited control edges.
Identity that can grant policyAdmin at access policy scope gains full perimeter control.
Principal with iam.denypolicies.update or .delete can remove/weaken a deny policy, upgrading the edges it was blocking.
A principal who can modify or escape a guardrail (SCP / Org Policy / deny assignment) upgrades the edges that guardrail was suppressing from BLOCKED to their underlying state.
?cap
move · open · esc close