We discussed the Identity and Access Management bits of the GCP, and in that context, we observed that human identities are not actually defined in the GCP, rather they are seamlessly obtained from gsuite. Programmatic identities (service accounts) do in fact exist solely within the GCP though, as do roles.
Now, the reality of many organizations is that different teams manage the gsuite and GCP components. gsuite identities are often set up when a new employee joins the firm as a part of an onboarding process and might be organizationally linked to corporate IT, or even HR. GCP, on the other hand, is likely to be a core technology function that rolls up into the CTO.
This can have real practical implementations for how things get done. Say, for instance, that the GSuite team and the GCP teams don't get along well. Each time a new user joins...