Identity and Access Management (IAM) controls who can do what on which resources in GCP by binding members to roles. Following the principle of least privilege with granular, predefined, or custom roles is central to keeping a GCP environment secure.