Folder

GCP folder / AWS OU.

class: AdministrativeBoundary

Realizing resources

gcp gcp

resourcescopeenumeraterequired permissions
gcp:resourcemanager:folder global cloudresourcemanager.folders.list resourcemanager.folders.list

Exposure sites

None.

Rules that touch Folder 5

Deregistering an OU from Control Tower governance (or reparenting accounts) removes the inherited SCP guardrails from those accounts.
Principal with iam.denypolicies.update or .delete can remove/weaken a deny policy, upgrading the edges it was blocking.
Modify the project, folder, or org IAM policy's auditConfigs to remove DATA_READ/DATA_WRITE log types, suppressing Data Access audit log generation for targeted GCP services at the IAM policy level.
move · open · esc close