- Overview
- How to connect
- Automated checks
- Useful links
DSALTA connects to Google Cloud Platform (GCP) using read-only API access to collect compliance evidence automatically. Data feeds into your Data Library modules. Compliance checks re-run once a day at 02:00 America/New_York.
Every request is a read. DSALTA has no code path that creates, modifies, or deletes anything in your Google Cloud Platform (GCP) environment.
Read-only access. DSALTA never modifies, creates, or deletes resources in your Google Cloud Platform (GCP) environment.
What DSALTA reads
DSALTA reads every principal bound in your project’s IAM policy — users, service accounts, Google groups and domains — together with the IAM roles granted to each, which appears on your Access page; and your Google Cloud Platform (GCP) resources, which appear on your Inventory page; and open security findings, which appear on your Vulnerabilities page.DSALTA does not call GCP REST endpoints directly, so there are no URL paths to list here. It uses the official Google APIs Node.js client (thegoogleapis package), The IAM permissions below are the ones DSALTA calls. They are not a ceiling on the credential: the roles granted during setup are broader than this list, and the client authenticates with the cloud-platform scope. DSALTA still only reads.Permissions the checks require: 29 read-only IAM permissions.Show all 29 IAM permissions
Show all 29 IAM permissions
BigQuery —
bigquery.datasets.getBigtable — bigtableadmin.instances.getCloud KMS — cloudkms.cryptoKeys.get, cloudkms.cryptoKeys.getIamPolicyCompute Engine — compute.backendServices.list, compute.instances.list, compute.regionOperations.get, compute.subnetworks.get, compute.urlMaps.listGKE — container.projects.zones.clusters.getEssential Contacts — essentialcontacts.contacts.listIAM — iam.serviceAccountKeys.list, iam.serviceAccounts.get, iam.serviceAccounts.getIamPolicy, iam.serviceAccounts.list.Cloud Logging — logging.sinks.listCloud Monitoring — monitoring.alertPolicies.list, monitoring.timeSeries.listResource Manager — resourcemanager.projects.get, resourcemanager.projects.getIamPolicySecurity Command Center — securitycenter.findings.list, securitycenter.organizations.getOrganizationSettingsSpanner — spanner.instances.getCloud SQL — sqladmin.instances.get, sqladmin.instances.listCloud Storage — storage.buckets.get, storage.buckets.getIamPolicyTroubleshooting
Integration shows Disconnected
Integration shows Disconnected
There is no Reconnect button. Open Integrations → Connected, click Manage on the Google Cloud Platform (GCP) card, and check the Status tab — it shows either Connected and working properly or Connection issues detected. To restore a broken connection you must Disconnect and connect again, which permanently deletes the data and tests collected from Google Cloud Platform (GCP). Service account keys do not expire by default, so this usually means the key was deleted, the service account was removed or disabled, its roles were revoked, or an organization policy set a key validity period that has elapsed.
Data is not syncing
Data is not syncing
Verify the connected account still holds the permissions listed under Before you begin. Then open Integrations in the DSALTA sidebar, stay on the Connected tab, and click Sync from integrations at the top right. That button refreshes every connected integration at once — there is no per-integration sync control.
.png?fit=max&auto=format&n=tsMQJyneJ1xquFUo&q=85&s=4d401cc03b547d99b6f75a6bd170c334)