Identity and Access Management (IAM)
When you log in to the Google Cloud console with a newly created super admin user, right after its Cloud Identity is configured, a Google Cloud organization resource will be automatically created once you accept the terms and conditions. In addition, the organization will be linked to your billing.
As a first step after logging in as a super admin, you should go to the IAM section of IAM & Admin and assign the Organization Administrator role to the previously created gcp-organization-admins
group, as shown in the following screenshot. Next, you can log in as a member of this group, start configuring resources, and provide other users with permissions. This way, you will avoid using a super admin account to manage Google Cloud resources. The role and permissions assignment process will be explained in detail in the following sections.

Figure 12.9 – Assigning the Organization Administrator role to the gcp-organization...