iam-helper-for-privileged-access-management
Manages the end-to-end lifecycle of on-demand, temporary access using Privileged Access Manager (PAM)
Install / Use
npx skills add google/skills --skill iam-helper-for-privileged-access-managementInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Our assessment of iam-helper-for-privileged-access-management
iam-helper-for-privileged-access-management scores 95/100 on our quality scale, 185th of 559 Security skills we index (top 34%).
Its SKILL.md is 12 KB long, well organised into 19 sections with 8 code examples: a thorough specification that gives an agent plenty to work with.
With 20,340 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 2 days ago, so iam-helper-for-privileged-access-management is actively maintained.
- It is released under the Apache-2.0 license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
iam-helper-for-privileged-access-management compared with similar skills
All 4 of these similar skills score higher than iam-helper-for-privileged-access-management; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| iam-helper-for-privileged-access-management (this skill)by google | 95 | 20.3k | 2d ago | SKILL.md |
| algorithmic-artby anthropics | 100 | 177.9k | 3d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 3d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 5d ago | SKILL.md |
| ui-ux-pro-maxby nextlevelbuilder | 100 | 130.2k | 5d ago | SKILL.md |
Frequently asked questions
- How do I install iam-helper-for-privileged-access-management?
- Run
npx skills add google/skills --skill iam-helper-for-privileged-access-management. The install tabs above show the steps for each supported agent. - Which AI agents does iam-helper-for-privileged-access-management work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is iam-helper-for-privileged-access-management safe to use?
- It is Apache-2.0-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is iam-helper-for-privileged-access-management still maintained?
- The repository was last updated 2 days ago, so iam-helper-for-privileged-access-management is actively maintained.
Skill content
View source on GitHubname: iam-helper-for-privileged-access-management metadata: version: "1.0.0" category: Security description: >- Manages the end-to-end lifecycle of on-demand, temporary access using Privileged Access Manager (PAM). Use when a user asks to create, read, update, or delete PAM entitlements, request temporary access, or approve/deny pending PAM grants. Do NOT use for permanent IAM policy bindings, troubleshooting IAM permission errors, or general Google Cloud resource provisioning.
Privileged Access Manager (PAM)
This skill provides step-by-step guidance for planning, validating, and executing Privileged Access Manager (PAM) entitlement CRUD operations, approval workflow configurations, access elevations, and grant approval/denial workflows.
Table of Contents
- Core Concepts
- Approval Workflows & Max Request Duration
- Safety & Confirmation Strategy
- Plan-Validate-Execute Pattern
- Mode 1: Interactive Access Elevation
- Mode 2: Standalone Entitlement CRUD
- Mode 3: Approver Workflow
- Supporting Links & Resources
Core Concepts {#core-concepts}
Privileged Access Manager (PAM) replaces permanent or ambient IAM role assignments with on-demand, time-bound, and audited access elevations. Rather than appending permanent IAM policy bindings, PAM uses:
- Entitlements: Configurations defining access scopes, eligible requesters, and approvers.
- Grants: Short-lived requests created against entitlements to activate the entitlement's IAM roles.
Privileged Access (privilegedAccess)
The privilegedAccess block in an entitlement defines the precise access scope that will be granted. An access scope comprises three essential components:
- Resource: The target Google Cloud resource (Project, Folder, or Organization) where access is granted.
- Role Setup: The IAM role (
roleBindings.role) to be assigned. - Condition: (Optional) An IAM condition expression (
roleBindings.conditionExpression) restricting when or where the role applies.
Core Workflow
- Administrators create Entitlements.
- Requesters can then request Grants against these entitlements.
- If the entitlement is configured with approvals, then an approver must approve the requested grant.
- Once all necessary approval steps are completed, the grant is activated for the requested time.
- The grant automatically ends after the requested duration has elapsed, and the elevated access is removed.
Approval Workflows & Max Request Duration {#approval-workflows}
Approval Workflows (approvalWorkflow)
When sensitive environments require human approval before temporary access is
activated, configure the approvalWorkflow block in the entitlement YAML
manifest (entitlement.yaml).
approvalWorkflow:
manualApprovals:
# Optional: requires approver to supply a justification string
requireApproverJustification: true
steps:
- approvalsNeeded: 1
approverEmailRecipients:
- approver@example.com
approvers:
- principals:
- user:db-lead@my-company.com # or group:sre-leads@my-company.com
- When to include: Include
approvalWorkflowwhenever the user prompt specifies that manual approval or an approver (user or group) is required. - Outcome: When a user requests a grant against an entitlement
with
approvalWorkflow, the grant transitions toAPPROVAL_AWAITED. Requesters must await an Approver's decision (Mode 3).
Max Request Duration (maxRequestDuration)
maxRequestDuration defines the maximum single access elevation timeframe a requester
may ask for when placing a grant request.
- Flexible Configuration: Configure
maxRequestDurationaccording to the user's specific request (e.g.8 hours/28800s,1 hour/3600s,24 hours/86400s). - Default Value: If the user does NOT specify a maximum request duration,
default to
4 hours(14400s). - YAML Syntax: Always format
maxRequestDurationas a string in seconds in the entitlement YAML (e.g.,"14400s","28800s").
Safety & Confirmation Strategy {#safety-confirmation}
Adhere strictly to these workflow guards:
- Modifying / Destructive Executions (Create, Update, Delete, Approve, Deny, Revoke): Always present a plain-text summary of the planned adjustments and prompt the user for explicit confirmation (Yes/No).
- Read-Only Inspections (List, Describe, Search): Run autonomously without requesting confirmation.
- Batching Bash Commands (Reduce User Confirmations): The host environment requires user approval for every individual shell tool call. To minimize confirmation popups, combine sequential read-only and lookup commands into a single compound bash script within one tool call (e.g., combining project, folder, and organization hierarchy audits into a single multiline execution).
- Anti-Loop Strategy: If a command fails with a clear, actionable error, you may attempt to self-debug and retry. If the error is ambiguous, halt immediately, present the stderr output, and await user direction.
Plan-Validate-Execute Pattern {#plan-validate-execute}
For all modifying actions (Mode 1 Step 3, Mode 2 Create, Update, Delete, Mode 3 Approve, Deny):
- Plan: Construct the proposed parameters or read the sample entitlement structure. (For entitlement creation, load and use the template: assets/entitlement_template.yaml).
- Validate: Inspect the target configuration parameters (resource names, role bindings, duration limits) for compliance with corporate rules.
- Execute: Present the validated plan, obtain explicit user confirmation,
and run the
gcloudcommand.
Mode 1: Interactive Access Elevation {#mode-1}
When the user requests temporary access elevation as a Requester, load and
follow the detailed instructions in
references/requester.md.
Mode 2: Standalone Entitlement CRUD {#mode-2}
Follow these steps for entitlement configurations.
Required Permissions for Entitlement Admins
roles/privilegedaccessmanager.admin: Required to create, update, and delete entitlement configurations (Mode 1 Step 3andMode 2 CRUD).- Scope IAM Admin Rights: Required on the target hierarchy scope because
creating an entitlement authorizes future role evaluations and bindings on
that scope:
- Organizations:
roles/iam.securityAdmin - Folders:
roles/resourcemanager.folderAdmin - Projects:
roles/resourcemanager.projectIamAdmin
- Organizations:
roles/privilegedaccessmanager.viewer: Required to list and describe entitlements across scopes.
(Rule: For all Standalone Entitlement CRUD commands below, use the flag
matching where the entitlement is defined: pass --project=PROJECT_ID,
--folder=FOLDER_ID, or --organization=ORGANIZATION_ID).
1. Create Entitlement
- Check if
ENTITLEMENT_IDexists:
gcloud pam entitlements describe ENTITLEMENT_ID \
--location=global \
--project=PROJECT_ID
- If Exists: Halt. Ask: "The requested PAM Entitlement
ENTITLEMENT_IDalready exists. Would you like to view its details or update it instead? (View / Update / Exit)" - If NOT_FOUND: Load the template
assets/entitlement_template.yaml.
Generate IDs in lowercase using hyphen separators derived from the role name
(e.g.,
compute-adminforroles/compute.admin). Note:- You may specify multiple IAM roles under
roleBindings. - You may also include an optional IAM
conditionExpressionfor each role binding. - Legacy basic roles (e.g.,
roles/viewer,roles/editor,roles/owner) are NOT supported. Instead, use their v2 basic role equivalents (e.g.,roles/basic.viewer,roles/basic.editor,roles/basic.owner). Ensure you select a valid predefined, custom, or v2 basic role.
- You may specify multiple IAM roles under
- Set
maxRequestDurationbased on user specification (e.g."28800s"for 8 hours,"3600s"for 1 hour). If unspecified by the user, default to"14400s"(4 hours). If manual approval is specified by policy or requested by the user, configure theapprovalWorkflowblock inentitlement.yaml. PreserverequesterJustificationConfig: {unstructured: {}}. - Prompt: "You are about to create the PAM Entitlement
ENTITLEMENT_ID. Do you approve this creation? (Yes/No)" - Deploy:
gcloud pam entitlements create ENTITLEMENT_ID \
--location=global \
--entitlement-file=entitlement.yaml \
--project=PROJECT_ID
2. Read Entitlements
Run these read operations autonomously:
List all entitlements at a single scope:
gcloud pam entitlements list \
--location=global \
--project=PROJECT_ID
To list all entitlements defined across the entire resource hierarchy (project, ancestor folders, and organization), use the hierarchy listing script:
bash scripts/list_entitlements_hierarchy.sh --project=PROJECT_ID
(Or pass --folder=FOLDER_ID or --organization=ORGANIZATION_ID).
Describe target entitlement:
gcloud pam entitlements describe ENTITLEMENT_ID \
--location=global \
--project=PROJECT_ID
3. Update Entitlement
-
Run the
exportcommand to generate the current config (which includes theetag):gcloud pam entitlements export ENTITLEMENT_ID \ --location=global \ --project=PROJECT_ID > {scratch}/updated_entitlement.yamlIf missing, offer to run
listor exit. -
Edit the exported
{scratch}/updated_entitlement.yamlfile to apply the requested changes (e.g., updatingmaxRequestDuration,approvalWorkflow, oreligibleUsers). Do not alter theetag. -
Prompt: "You are about to update the PAM Entitlement
ENTITLEMENT_ID. Do you approve this update? (Yes/No)" -
Execute:
gcloud pam entitlements update ENTITLEMENT_ID \
--location=global \
--entitlement-file={scratch}/updated_entitlement.yaml \
--project=PROJECT_ID
4. Delete Entitlement
-
Verify existence using
describe. If missing, offer list/exit. -
Safety Check: An entitlement cannot be deleted if there are open grants. Before deleting, search for any
ACTIVEorSCHEDULEDgrants:gcloud pam grants list \ --entitlement=ENTITLEMENT_ID \ --location=global \ --project=PROJECT_ID \ --filter="state:(ACTIVE, SCHEDULED)"If any open grants are found, prompt the user for permission to revoke them: "There are active or scheduled grants on this entitlement. Do you authorize me to revoke them so the entitlement can be deleted? (Yes/No)"
If Yes, revoke them:
gcloud pam grants revoke GRANT_ID \ --entitlement=ENTITLEMENT_ID \ --location=global \ --project=PROJECT_ID \ --reason="Revoking to delete entitlement" -
Prompt: "You are about to permanently delete the PAM Entitlement
ENTITLEMENT_ID. Do you approve this deletion? (Yes/No)" -
Execute:
gcloud pam entitlements delete ENTITLEMENT_ID \
--location=global \
--project=PROJECT_ID
Mode 3: Approver Workflow {#mode-3}
When an Approver needs to review, approve, or reject pending grant requests,
load and follow the detailed instructions in
references/approver.md.
Truncated for display — read the full file on GitHub.
Related Skills
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG…
ui-ux-pro-max
130.2kUI/UX design intelligence for web, mobile, and desktop. This skill should be used when designing, building, reviewing, or fixing interfaces, including pages, components, design systems, accessibility, interaction, responsive layout, typography, color, charts, and stack-specific UI implementation.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
