Skip to main content
DSALTA connects to Google Cloud Platform (GCP) using read-only API access to collect compliance evidence automatically. Data feeds into your Data Library modules. Compliance checks re-run once a day at 02:00 America/New_York.
Read-only access. DSALTA never modifies, creates, or deletes resources in your Google Cloud Platform (GCP) environment.

What DSALTA reads

DSALTA reads every principal bound in your project’s IAM policy — users, service accounts, Google groups and domains — together with the IAM roles granted to each, which appears on your Access page; and your Google Cloud Platform (GCP) resources, which appear on your Inventory page; and open security findings, which appear on your Vulnerabilities page.DSALTA does not call GCP REST endpoints directly, so there are no URL paths to list here. It uses the official Google APIs Node.js client (the googleapis package), The IAM permissions below are the ones DSALTA calls. They are not a ceiling on the credential: the roles granted during setup are broader than this list, and the client authenticates with the cloud-platform scope. DSALTA still only reads.Permissions the checks require: 29 read-only IAM permissions.
BigQuerybigquery.datasets.getBigtablebigtableadmin.instances.getCloud KMScloudkms.cryptoKeys.get, cloudkms.cryptoKeys.getIamPolicyCompute Enginecompute.backendServices.list, compute.instances.list, compute.regionOperations.get, compute.subnetworks.get, compute.urlMaps.listGKEcontainer.projects.zones.clusters.getEssential Contactsessentialcontacts.contacts.listIAMiam.serviceAccountKeys.list, iam.serviceAccounts.get, iam.serviceAccounts.getIamPolicy, iam.serviceAccounts.list.Cloud Logginglogging.sinks.listCloud Monitoringmonitoring.alertPolicies.list, monitoring.timeSeries.listResource Managerresourcemanager.projects.get, resourcemanager.projects.getIamPolicySecurity Command Centersecuritycenter.findings.list, securitycenter.organizations.getOrganizationSettingsSpannerspanner.instances.getCloud SQLsqladmin.instances.get, sqladmin.instances.listCloud Storagestorage.buckets.get, storage.buckets.getIamPolicy
Every request is a read. DSALTA has no code path that creates, modifies, or deletes anything in your Google Cloud Platform (GCP) environment.

Troubleshooting

There is no Reconnect button. Open Integrations → Connected, click Manage on the Google Cloud Platform (GCP) card, and check the Status tab — it shows either Connected and working properly or Connection issues detected. To restore a broken connection you must Disconnect and connect again, which permanently deletes the data and tests collected from Google Cloud Platform (GCP). Service account keys do not expire by default, so this usually means the key was deleted, the service account was removed or disabled, its roles were revoked, or an organization policy set a key validity period that has elapsed.
Verify the connected account still holds the permissions listed under Before you begin. Then open Integrations in the DSALTA sidebar, stay on the Connected tab, and click Sync from integrations at the top right. That button refreshes every connected integration at once — there is no per-integration sync control.