Auto Checks Integration Guide for GCP

This guide is for users who have already integrated GCP with Kertos and now want to reconfigure their setup to enable the Auto Checks feature.

Important:
You must have admin rights in your Google Cloud environment to complete the setup.
Without sufficient permissions, you won’t be able to assign the necessary roles, enable APIs, or create service accounts.

Why reconfigure?
Since the launch of the Auto Checks feature on June 10th, 2025, Kertos requires additional permissions in your GCP environment.
These permissions go beyond the original GCP integration setup. Without them, Auto Checks cannot scan and validate your cloud configurations against ISO 27001 controls.

First Time Setting Up GCP Integration?

If you haven't yet integrated GCP with Kertos, follow our full step-by-step onboarding guide here:
https://docs.kertos.io/en/article/discovery-setup-gcp 


Permissions Required

To enable Auto Checks, follow these steps to create a service account with the correct roles and generate a new key file:

Step 1: Enable Required APIs

  1. Go to Google Cloud Console and log in with admin access
  2. Select your project from the top bar
  3. Navigate to APIs & Services → Library
  4. Enable the following APIs:
  5. Cloud Resource Manager API
  6. Cloud Asset API
  7. Compute Engine API
  8. Cloud SQL Admin API

Step 2: Create Service Account and Assign Roles

  1. Navigate to IAM & Admin → Service Accounts
  2. Click Create Service Account
  3. Name it (e.g., Kertos Discovery) and click Create and Continue
  4. Assign the following roles:
  5. Viewer
  6. Cloud Asset Viewer
  7. Service Usage Consumer
  8. Security Reviewer
  9. Click ContinueDone

Step 3: Generate Key for Service Account

  1. In the Service Accounts list, locate your new service account
  2. Open the Keys tab
  3. Click Add Key → Create new key
  4. Choose JSON format → Click Create
  5. Save the key file securely — it will be needed to complete setup in Kertos

Once this is complete, make sure to toggle "Enable Auto Checks" ON and run a sync in Kertos.

 

Was this article helpful?