Auto Checks Integration Guide for GCP
Important:
You must have admin rights in your Google Cloud environment to complete the setup.
Without sufficient permissions, you won’t be able to assign the necessary roles, enable APIs, or create service accounts.
Why reconfigure?
Since the launch of the Auto Checks feature on June 10th, 2025, Kertos requires additional permissions in your GCP environment.
These permissions go beyond the original GCP integration setup. Without them, Auto Checks cannot scan and validate your cloud configurations against ISO 27001 controls.
First Time Setting Up GCP Integration?
If you haven't yet integrated GCP with Kertos, follow our full step-by-step onboarding guide here:
https://docs.kertos.io/en/article/discovery-setup-gcp
Permissions Required
To enable Auto Checks, follow these steps to create a service account with the correct roles and generate a new key file:
Step 1: Enable Required APIs
- Go to Google Cloud Console and log in with admin access
- Select your project from the top bar
- Navigate to APIs & Services → Library
- Enable the following APIs:
- Cloud Resource Manager API
- Cloud Asset API
- Compute Engine API
- Cloud SQL Admin API
Step 2: Create Service Account and Assign Roles
- Navigate to IAM & Admin → Service Accounts
- Click Create Service Account
- Name it (e.g.,
Kertos Discovery
) and click Create and Continue - Assign the following roles:
Viewer
Cloud Asset Viewer
Service Usage Consumer
Security Reviewer
- Click Continue → Done
Step 3: Generate Key for Service Account
- In the Service Accounts list, locate your new service account
- Open the Keys tab
- Click Add Key → Create new key
- Choose JSON format → Click Create
- Save the key file securely — it will be needed to complete setup in Kertos
Once this is complete, make sure to toggle "Enable Auto Checks" ON and run a sync in Kertos.