Skip to main content
Question

Policy Troubleshooter v3beta returns PAB_ACCESS_STATE_UNKNOWN_INFO

  • October 9, 2026
  • 0 replies
  • 1 view

DegreeCapDev

Hello,

We are implementing a secure account deletion workflow using Google Cloud Run, IAM, Firebase Authentication, and Firestore.

During our pre-deployment security checks, Google Cloud Policy Troubleshooter v3beta returns HTTP 200, but its evaluation includes:

  • PAB_ACCESS_STATE_UNKNOWN_INFO

  • Overall access state: UNKNOWN_INFO

Environment:

  • API: policytroubleshooter.googleapis.com

  • Endpoint: POST /v3beta/iam:troubleshoot

  • Resource type: Google Cloud service account

  • Permission: iam.serviceAccounts.getIamPolicy

  • The requesting principal has the Project Owner role.

What we have verified:

  • Policy Troubleshooter API is enabled.

  • The API request succeeds with HTTP 200.

  • Direct IAM policy reads and permission checks succeed.

  • The result was reproduced in separate requests.

  • The response does not establish whether a Principal Access Boundary policy applies.

Questions:

  1. What causes PAB_ACCESS_STATE_UNKNOWN_INFO in Policy Troubleshooter v3beta?

  2. Does this indicate insufficient permissions to inspect PAB policies, or can it be a limitation of the API?

  3. How can we determine whether a PAB policy applies to the principal?

  4. Is there a supported method to obtain a definitive effective-permission result covering IAM allow, deny, and PAB policies?

  5. If additional permissions are necessary, what is the minimum required role or permission?

We want to resolve this without granting unnecessarily broad IAM permissions or treating an UNKNOWN result as ALLOW.

Any guidance or official documentation would be appreciated.

Thank you!