Support temporary or customer-managed log-sink permissions for GCE real-time anomaly detection
Customers currently need to grant the DoiT service account logging.sinks.create and logging.sinks.update permissions at the organization level to set up GCP Real-time Anomalies. Because these permissions can create or modify sinks containing sensitive logs, customers would like to revoke them after setup and approve any future changes. Today, health checks and automated repair depend on these permissions, so revoking them can mark the integration unhealthy and trigger offboarding.
They need to support GCE real-time anomaly detection with temporary log-sink management permissions or a customer-managed sink, retaining health monitoring and providing an approved repair process when changes are required.
This would provide a more least-privilege model while preserving monitoring and recovery capabilities.
References: Zendesk #331013 · CMP-52671