Proactive Alert Investigation
Gemini Cloud Assist Proactive Mode autonomously investigates Google Cloud alerts in the background using a dedicated system-provisioned agent identity rather than an active user session, producing system-generated investigation results.
Recorded characteristics
- Function
- When Proactive Mode is enabled, Gemini Cloud Assist runs autonomously in the background and continuously investigates alerts. Google documents that autonomous background tasks such as investigating alerts run under a dedicated agent identity rather than an active user session. Investigation output consists of Observations (insights drawn from logs, configurations and metrics, with citations back to source data), synthesised probable root causes presented as hypotheses where uncertain, and recommended next troubleshooting steps or fixes. Proactive results are tagged as "System generated" in the Google Cloud console. Google does not document the proactive investigation itself applying those fixes. Completion of a background task publishes a google.cloud.geminicloudassist.task.v1.completed event that a customer may separately route through Eventarc to their own destinations; that routing is customer-built automation outside this capability.
- Data access
- By default the agent identity is restricted to read-only telemetry and logs. Google states that Gemini Cloud Assist only accesses the data explicitly authorised through the IAM roles granted to its agent identity, limited to read-only access for services such as Cloud Monitoring, Cloud Logging and Cloud Asset Inventory, and that it cannot access data in databases or storage buckets unless those permissions are explicitly granted. Alert information and relevant resource information for supported Google Cloud products are in scope. Administrators may grant additional roles beyond the documented starting points (Support User, Service Usage Consumer), so the effective access ceiling is whatever the administrator authorises rather than a fixed set. Proactive investigation of alerts does not support log-based alerts.
- Actions
- Read only
- External actions
- Unknown
- Human confirmation
- Not established
- Permission basis
- Dedicated agent identity
- Administrative control
- A project administrator must explicitly enable Proactive Mode in the Gemini Cloud Assist settings panel and grant access; enabling it automatically provisions the dedicated agent identity. The Gemini Cloud Assist Admin role holds the permission to enable proactive agents. Administrators grant IAM roles to the agent identity principal (a project-scoped principal of the form principal://agents.global.org-ORG_NUMBER.system.id.goog/.../projects/PROJECT_NUMBER/locations/global/agents/cloud), controlling scope of access. Required APIs (geminicloudassist.googleapis.com, appoptimize.googleapis.com) must be enabled. Organisation policy custom constraints can restrict principal types. All autonomous actions are audit-logged in Cloud Audit Logs, subject to the relevant log type being enabled. Investigations are limited to a single Google Cloud project or App Hub application.
- Default state
- Disabled
- Availability
- Private preview. Google states that proactive cost optimization and proactive alert investigations are in private preview and are only available to users with a Premium Support contract, subject to the Pre-GA Offering Terms and the Gemini for Google Cloud Trusted Tester Program. Separately, as of 10 April 2026 creating, running and editing investigations are available only to users with a Premium Support contract or who have requested access through their account team.
- Licensing
- Requires a Premium Support contract; use of the preview is governed by the Google Cloud Agreement, the Pre-GA Offering Terms and the Trusted Tester Program terms. No separate per-capability pricing is documented.
- External model or provider
- Not publicly established for this capability. Google does not name a specific Gemini model version for proactive alert investigation, and no model is inferred from the Gemini brand.
- Limitations and uncertainty
- Private preview with a Premium Support prerequisite. Log-based alerts are not supported for proactive investigation. Supported products for investigations are an enumerated list, and not all resources within supported products are supported. Investigation scope is a single project or App Hub application. Default agent access is read-only telemetry and logs, but administrators may grant broader roles, so real-world access varies by deployment. No remediation or state-changing operation by the proactive investigation itself is documented, so the read-only classification reflects documented behaviour rather than an explicit vendor statement that the agent can never change state. Google does not document a confirmation step for proactive runs because no state-changing action is established; human confirmation is therefore recorded as not established rather than not required. Google does not establish whether the capability can act outside its Google Cloud environment, so external action is unknown. The underlying model is not published.
Evidence
- Agent identity concepts — Gemini Cloud Assist
Supports: Function · Data access · Actions · Human confirmation · Permission basis · Admin controls · Availability · Limitations · External model · General · Primary source
Autonomous background tasks such as investigating alerts run under a dedicated agent identity, without an active user session.
By default the agent is restricted to read-only telemetry and logs and cannot access sensitive data in databases or storage buckets unless specifically authorised.
Proactive results are tagged as System generated; state-changing actions requiring explicit consent are documented only for the end-user identity chat mode.
Explicit consent for resource mutations is documented for the end-user identity mode; no confirmation behaviour is documented for proactive agent-identity investigation.
Autonomous background tasks use a dedicated agent identity, a system-provisioned IAM principal unique to the project.
Administrators manage the agent identity through configurable permissions, scoped access and audit logging.
Proactive alert investigations are in private preview and only available to users with a Premium Support contract.
Proactive investigation of alerts does not support log-based alerts.
No specific model is identified for proactive alert investigation in Google's documentation.
Gemini Cloud Assist operates in two identity modes: end-user identity for chat and interactive requests, agent identity for autonomous background tasks.
- Set up Proactive Mode — Gemini Cloud Assist
Supports: Function · Data access · Permission basis · Admin controls · Default state · Primary source
Proactive Mode allows Gemini Cloud Assist to run autonomously in the background, continuously investigating alerts.
Gemini Cloud Assist only accesses data explicitly authorised through the agent identity's IAM roles, limited to read-only access for Cloud Monitoring, Cloud Logging and Cloud Asset Inventory.
The agent identity is automatically provisioned when Proactive Mode is enabled and administrators must explicitly grant it IAM roles; its principal is project-scoped.
A project administrator must explicitly enable Proactive Mode, grant access, enable the required APIs and grant IAM roles to the agent identity.
A project administrator needs to explicitly enable Proactive Mode before it operates.
- Troubleshoot issues with Gemini Cloud Assist investigations
Supports: Function · Data access · Actions · Availability · Limitations · Primary source
Investigations produce observations, identify probable root causes as hypotheses, and recommend next troubleshooting steps.
Observations are based on review of logs, configurations and metrics, with citations to the source data.
Documented output is analysis and recommendation; no remediation performed by the investigation itself is documented.
As of 10 April 2026, creating, running and editing investigations require a Premium Support contract or access requested through an account team.
Supported products are enumerated, not all resources within supported products are supported, and an investigation is limited to a single project or App Hub application.
- Automate actions based on Proactive Agent results
Supports: External actions · Primary source
Task completion publishes an event that a customer may route through Eventarc to their own services; this is customer-built automation, not documented agent action outside the environment.
- Cloud IAM requirements for using Cloud Assist
Supports: Permission basis · Admin controls · Primary source
Gemini Cloud Assist IAM roles distinguish user permissions from the roles granted to agent identities for background tasks.
The Gemini Cloud Assist Admin role carries the permission to enable proactive agents and grant permissions on agents.
- Gemini Cloud Assist audit logging
Supports: Admin controls · Primary source
Gemini Cloud Assist investigation methods are audited and generate Admin Activity or Data Access audit logs.