1 Answers
Hello Pacolo,
From Google’s documentation:
In Cloud IAM, you grant access to members. Members can be of the following types:
Google Account
Service account
Google group
G Suite domain
Cloud Identity domain
So when you say " but the group members are controlled outside GCP" they are not outside really. I encourage you to read https://cloud.google.com/iam/docs/overview and look at the picture there to get a good idea. Hope this helps. Thanks