---
title: "POST /v1/{+parent}/workloads"
method: POST
path: "/v1/{+parent}/workloads"
tags: ["organizations"]
---

# POST /v1/{+parent}/workloads

`POST /v1/{+parent}/workloads`

Creates Assured Workload.

## Path parameters

- `parent` string, required

## Query parameters

- `externalId` string

## Request body

- GoogleCloudAssuredworkloadsV1Workload — A Workload object for managing highly regulated workloads of cloud customers.
  - `partnerServicesBillingAccount` string — Optional. Billing account necessary for purchasing services from Sovereign Partners. This field is required for creating SIA/PSN/CNTXT/Telefonica partner workloads. The caller should have 'billing.resourceAssociations.create' IAM permission on this billing-account. The format of this string is billingAccounts/AAAAAA-BBBBBB-CCCCCC
  - `partnerPermissions` GoogleCloudAssuredworkloadsV1WorkloadPartnerPermissions — Permissions granted to the AW Partner SA account for the customer workload
    - `dataLogsViewer` boolean — Optional. Allow the partner to view inspectability logs and monitoring violations.
    - `assuredWorkloadsMonitoring` boolean — Optional. Allow partner to view violation alerts.
    - `accessTransparencyLogsSupportCaseViewer` boolean — Optional. Allow partner to view support case details for an AXT log
    - `serviceAccessApprover` boolean — Optional. Allow partner to view access approval logs.
  - `saaEnrollmentResponse` GoogleCloudAssuredworkloadsV1WorkloadSaaEnrollmentResponse — Signed Access Approvals (SAA) enrollment response.
    - `setupStatus` 'SETUP_STATE_UNSPECIFIED' | 'STATUS_PENDING' | 'STATUS_COMPLETE' — Output only. Indicates SAA enrollment status of a given workload.
    - `setupErrors` string[] — Indicates SAA enrollment setup error if any.
  - `labels` object — Optional. Labels applied to the workload.
  - `etag` string — Optional. ETag of the workload, it is calculated on the basis of the Workload contents. It will be used in Update & Delete operations.
  - `name` string — Optional. The resource name of the workload. Format: organizations/{organization}/locations/{location}/workloads/{workload} Read-only.
  - `resources` GoogleCloudAssuredworkloadsV1WorkloadResourceInfo[] — Output only. The resources associated with this workload. These resources will be created when creating the workload. If any of the projects already exist, the workload creation will fail. Always read only.
    - `resourceId` string, int64 — Output only. Resource identifier. For a project this represents project_number.
    - `resourceType` 'RESOURCE_TYPE_UNSPECIFIED' | 'CONSUMER_PROJECT' | 'CONSUMER_FOLDER' | 'ENCRYPTION_KEYS_PROJECT' | 'KEYRING' — Indicates the type of resource.
  - `kajEnrollmentState` 'KAJ_ENROLLMENT_STATE_UNSPECIFIED' | 'KAJ_ENROLLMENT_STATE_PENDING' | 'KAJ_ENROLLMENT_STATE_COMPLETE' — Output only. Represents the KAJ enrollment state of the given workload.
  - `compliantButDisallowedServices` string[] — Output only. Urls for services which are compliant for this Assured Workload, but which are currently disallowed by the ResourceUsageRestriction org policy. Invoke RestrictAllowedResources endpoint to allow your project developers to use these services in their environment.
  - `partner` 'PARTNER_UNSPECIFIED' | 'LOCAL_CONTROLS_BY_S3NS' | 'SOVEREIGN_CONTROLS_BY_T_SYSTEMS' | 'SOVEREIGN_CONTROLS_BY_SIA_MINSAIT' | 'SOVEREIGN_CONTROLS_BY_PSN' | 'SOVEREIGN_CONTROLS_BY_CNTXT' | 'SOVEREIGN_CONTROLS_BY_CNTXT_NO_EKM' | 'SPAIN_DATA_BOUNDARY_BY_TELEFONICA' — Optional. Partner regime associated with this workload.
  - `violationNotificationsEnabled` boolean — Optional. Indicates whether the e-mail notification for a violation is enabled for a workload. This value will be by default True, and if not present will be considered as true. This should only be updated via updateWorkload call. Any Changes to this field during the createWorkload call will not be honored. This will always be true while creating the workload.
  - `complianceRegime` 'COMPLIANCE_REGIME_UNSPECIFIED' | 'ASSURED_WORKLOADS_FOR_PARTNERS' | 'AUSTRALIA_DATA_BOUNDARY_AND_SUPPORT' | 'CANADA_DATA_BOUNDARY_AND_SUPPORT' | 'DATA_BOUNDARY_FOR_CANADA_CONTROLLED_GOODS' | 'DATA_BOUNDARY_FOR_CANADA_PROTECTED_B' | 'DATA_BOUNDARY_FOR_CJIS' | 'DATA_BOUNDARY_FOR_FEDRAMP_HIGH' | 'DATA_BOUNDARY_FOR_FEDRAMP_MODERATE' | 'DATA_BOUNDARY_FOR_IL2' | 'DATA_BOUNDARY_FOR_IL4' | 'DATA_BOUNDARY_FOR_IL5' | 'DATA_BOUNDARY_FOR_IRS_PUBLICATION_1075' | 'DATA_BOUNDARY_FOR_ITAR' | 'EU_DATA_BOUNDARY_AND_SUPPORT' | 'ISRAEL_DATA_BOUNDARY_AND_SUPPORT' | 'JAPAN_DATA_BOUNDARY' | 'SWITZERLAND_DATA_BOUNDARY_WITH_ACCESS_JUSTIFICATIONS' | 'KSA_DATA_BOUNDARY_WITH_ACCESS_JUSTIFICATIONS' | 'REGIONAL_DATA_BOUNDARY' | 'US_DATA_BOUNDARY_AND_SUPPORT' | 'US_DATA_BOUNDARY_FOR_HEALTHCARE_AND_LIFE_SCIENCES' | 'US_DATA_BOUNDARY_FOR_HEALTHCARE_AND_LIFE_SCIENCES_WITH_SUPPORT' | 'AU_REGIONS_AND_US_SUPPORT' | 'CA_PROTECTED_B' | 'CA_REGIONS_AND_SUPPORT' | 'CANADA_CONTROLLED_GOODS' | 'CJIS' | 'EU_REGIONS_AND_SUPPORT' | 'FEDRAMP_HIGH' | 'FEDRAMP_MODERATE' | 'HEALTHCARE_AND_LIFE_SCIENCES_CONTROLS' | 'HEALTHCARE_AND_LIFE_SCIENCES_CONTROLS_US_SUPPORT' | 'HIPAA' | 'HITRUST' | 'IL2' | 'IL4' | 'IL5' | 'IRS_1075' | 'ISR_REGIONS' | 'ISR_REGIONS_AND_SUPPORT' | 'ITAR' | 'JP_REGIONS_AND_SUPPORT' | 'KSA_REGIONS_AND_SUPPORT_WITH_SOVEREIGNTY_CONTROLS' | 'REGIONAL_CONTROLS' | 'US_REGIONAL_ACCESS' — Required. Immutable. Compliance Regime associated with this workload.
  - `kmsSettings` GoogleCloudAssuredworkloadsV1WorkloadKMSSettings — Settings specific to the Key Management Service.
    - `nextRotationTime` string, google-datetime — Required. Input only. Immutable. The time at which the Key Management Service will automatically create a new version of the crypto key and mark it as the primary.
    - `rotationPeriod` string, google-duration — Required. Input only. Immutable. [next_rotation_time] will be advanced by this period when the Key Management Service automatically rotates a key. Must be at least 24 hours and at most 876,000 hours.
  - `ekmProvisioningResponse` GoogleCloudAssuredworkloadsV1WorkloadEkmProvisioningResponse — External key management systems(EKM) Provisioning response
    - `ekmProvisioningState` 'EKM_PROVISIONING_STATE_UNSPECIFIED' | 'EKM_PROVISIONING_STATE_PENDING' | 'EKM_PROVISIONING_STATE_FAILED' | 'EKM_PROVISIONING_STATE_COMPLETED' — Output only. Indicates Ekm enrollment Provisioning of a given workload.
    - `ekmProvisioningErrorDomain` 'EKM_PROVISIONING_ERROR_DOMAIN_UNSPECIFIED' | 'UNSPECIFIED_ERROR' | 'GOOGLE_SERVER_ERROR' | 'EXTERNAL_USER_ERROR' | 'EXTERNAL_PARTNER_ERROR' | 'TIMEOUT_ERROR' — Indicates Ekm provisioning error if any.
    - `ekmProvisioningErrorMapping` 'EKM_PROVISIONING_ERROR_MAPPING_UNSPECIFIED' | 'INVALID_SERVICE_ACCOUNT' | 'MISSING_METRICS_SCOPE_ADMIN_PERMISSION' | 'MISSING_EKM_CONNECTION_ADMIN_PERMISSION' — Detailed error message if Ekm provisioning fails
  - `displayName` string — Required. The user-assigned display name of the Workload. When present it must be between 4 to 30 characters. Allowed characters are: lowercase and uppercase letters, numbers, hyphen, and spaces. Example: My Workload
  - `provisionedResourcesParent` string — Input only. The parent resource for the resources managed by this Assured Workload. May be either empty or a folder resource which is a child of the Workload parent. If not specified all resources are created under the parent organization. Format: folders/{folder_id}
  - `complianceStatus` GoogleCloudAssuredworkloadsV1WorkloadComplianceStatus — Represents the Compliance Status of this workload
    - `acknowledgedResourceViolationCount` integer — Number of current resource violations which are not acknowledged.
    - `acknowledgedViolationCount` integer — Number of current orgPolicy violations which are acknowledged.
    - `activeResourceViolationCount` integer — Number of current resource violations which are acknowledged.
    - `activeViolationCount` integer — Number of current orgPolicy violations which are not acknowledged.
  - `resourceMonitoringEnabled` boolean — Output only. Indicates whether resource monitoring is enabled for workload or not. It is true when Resource feed is subscribed to AWM topic and AWM Service Agent Role is binded to AW Service Account for resource Assured workload.
  - `resourceSettings` GoogleCloudAssuredworkloadsV1WorkloadResourceSettings[] — Input only. Resource properties that are used to customize workload resources. These properties (such as custom project id) will be used to create workload resources if possible. This field is optional.
    - `displayName` string — User-assigned resource display name. If not empty it will be used to create a resource with the specified name.
    - `resourceId` string — Resource identifier. For a project this represents project_id. If the project is already taken, the workload creation will fail. For KeyRing, this represents the keyring_id. For a folder, don't set this value as folder_id is assigned by Google.
    - `resourceType` 'RESOURCE_TYPE_UNSPECIFIED' | 'CONSUMER_PROJECT' | 'CONSUMER_FOLDER' | 'ENCRYPTION_KEYS_PROJECT' | 'KEYRING' — Indicates the type of resource. This field should be specified to correspond the id to the right project type (CONSUMER_PROJECT or ENCRYPTION_KEYS_PROJECT)
  - `createTime` string, google-datetime — Output only. Immutable. The Workload creation timestamp.
  - `billingAccount` string — Optional. The billing account used for the resources which are direct children of workload. This billing account is initially associated with the resources created as part of Workload creation. After the initial creation of these resources, the customer can change the assigned billing account. The resource name has the form `billingAccounts/{billing_account_id}`. For example, `billingAccounts/012345-567890-ABCDEF`.
  - `enableSovereignControls` boolean — Optional. Indicates the sovereignty status of the given workload. Currently meant to be used by Europe/Canada customers.
  - `workloadOptions` GoogleCloudAssuredworkloadsV1WorkloadWorkloadOptions — Options to be set for the given created workload.
    - `kajEnrollmentType` 'KAJ_ENROLLMENT_TYPE_UNSPECIFIED' | 'KEY_ACCESS_TRANSPARENCY_OFF' — Optional. Specifies type of KAJ Enrollment if provided.

## Response `200`

Successful response

---

[API](https://skmtc.dev/google/apis/assuredworkloads.md) · [All operations](https://skmtc.dev/google/apis/assuredworkloads/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/google/assuredworkloads/revisions/bff5f680b449/schema)
