Add a Service Account
In order to begin importing Service Accounts into Opal, you need to update your Opal Service Account’s Role to have the following permission:
Manage Access
In the “User Access” tab, admins can view all users that have access to a Service Account, including what role they have, when their access expires, and how they obtained the access.- In the below example, Cynthia has access to the Service Account Admin role through a group which expires in a year, whereas Roberto has direct access to the Token Creator role expiring in a day. Emanuel is an Owner of the entire GCP Organization, so he inherited that role onto the Service Account as well.

- Here we see that the Service Account has access to the Chronicle Service Agent role on the Bigquery Dataset, which it has also inherited onto all of the Dataset’s tables. We can also see that permanent access has been directly granted to the Service Account on the Events table.




