Google IAM Policy Troubleshooter says allowed, but a storage request still fails
A service’s storage request is denied. In this illustrative case, Policy Troubleshooter reports that the named principal has the permission on the resource. The team has not checked whether the actual call crosses a VPC Service Controls boundary. Does the allowed result settle the whole access question?