gcp Google Cloud release notes ·

Google SecOps: Write Permissions Removed from chronicle.readonly OAuth Scope

securitygcpdeprecationengineer
deprecation

Google SecOps is deprecating write permissions from the `chronicle.readonly` OAuth scope, effective January 25, 2027. This change will restrict the scope exclusively to read operations, enhancing security posture by adhering to the principle of least privilege. Workflows currently using `chronicle.readonly` for write operations must be updated to utilize the `chronicle` OAuth scope instead. Users can continue to leverage `chronicle.readonly` for its intended read operations after the change takes effect.

Deprecations (1)
  • Google SecOps Deprecation of write permissions from the chronicle.readonly OAuth scope

    Deprecation of write permissions from the chronicle.readonly OAuth scope Effective January 25, 2027, write permissions will be removed from the chronicle.readonly OAuth scope, restricting it strictly to read operations. You can continue using chronicle.readonly for read operations. Make sure you update any workflows performing write operations to use the chronicle OAuth scope.

Read the original announcement →

https://docs.cloud.google.com/release-notes#September_11_2026

Related releases