{
  "title": "DDetectiveKeyExpiryOptional",
  "description": "Optional custom role for the Cloudkeel-DD GCP connector - lets Cloudkeel-DD read this service account key's own expiry so the integration list can show it before a scan fails. Scanning works identically without this role; the credential's expiry just stays unknown until it 403s.",
  "stage": "GA",
  "includedPermissions": [
    "iam.serviceAccountKeys.get"
  ]
}
