If I view the Permissions for my project in the Developer Console, I can
see the list of "Service Accounts" that have been granted either "view" or
"edit" permission to the project. However, the only detail that is provided
for that Service Account is a very brief and immutable description that is
generated by Google, such as "App Engine service account". The problem is
that there is no way for us to know
- Who generated the service account
- When it was generated, or
- What it's being used for.
In the case of a
security incident, we may need to rotate the keys for these accounts, but
have no way of mapping them to their usage or owners.