Connecting or editing the GCP data source requires an administrator. With a lower role you can
still open the source and read its Scans tab.
Connect your project
1
Download the Terraform template
On the GCP source, download the Terraform template. It configures a Workload Identity
pool and provider and a read-only service account.
2
Open Google Cloud Shell
Open the Google Cloud Shell console at
shell.cloud.google.com, signed in to the project you
want to connect.
3
Create a working folder
Create a folder for the Terraform and move into it:
4
Add the template
Open a new file and paste in the Terraform template you downloaded, then save it:
5
Initialize Terraform
Download the provider plugins the template needs:
6
Create the resources
Preview the plan to confirm it only creates new resources, then apply it:Each command prompts for
var.project_id. Enter the ID of the GCP project you want to
connect. When terraform apply asks you to confirm the plan, enter yes. Once it finishes,
its output holds every value you need to configure the project in Switch Trust.7
Enter the project details
On the Setup tab, copy the values from the Terraform output into the matching fields:
- Project ID and Project number
- Service account email
- WIF pool ID and WIF provider ID
8
Test the connection and add the project
Select Test connection. Switch Trust exchanges a token through the federation and reports
whether it succeeded. If it fails, check the project details and that the Terraform applied
cleanly, then try again. Then select Add project to save it.
What Switch Trust scans
Once connected, Switch Trust scans each Vertex AI location in the project and discovers your Vertex AI models and agents.The Scans tab
Open the Scans tab to see the connected project, with an overall status and the date of its latest activity. While Switch Trust is scanning, the project shows Scanning. Expand the project row to see its scans, which cover Vertex AI models and agents in each location. Each scan lists its Scan name, Status, and Started and Ended times:
The tab refreshes on its own while a scan is running, so you can watch a scan move from
In progress to Completed without reloading.
Next steps
Read your discovery results
Work out what needs attention first, whether a finding is real, and when itβs resolved
Connect another data source
Add a repository or another cloud platform to widen your inventory

