I'm trying to audit the permissions available to our staff in GCP.
To do this, I'm trying to use gcloud policy-troubleshooter or the GCP Console version of same.
What I'm finding is that I cannot see role assignments that are bound to Groups. On the command line, the response includes an error like MEMBERSHIP_UNKNOWN_INFO_DENIED; the web version is less shouty: "You do not know if principal is in this group or not because you do not have permission to view group membership"
I am the Owner of the the group in question, so I'm unclear why I wouldn't have permissions. I can see group membership in the IAM Groups panel. I also can't figure out what permission I lack; there's no Audit Log entry denying the access.
How can I get access to review these permissions?