The recommended predefined role is Chronicle API Admin (roles/chronicle.admin). Alternatively, if your security policies require more granular control, you can create a custom IAM role with the ...