The AWS RBAC model is way more robust than GCPs API based roles for a simple reason; GCP lacks identifiers for individual resources.

Related Articles