IAM trust policy
Settings → Workspace → Log Export provides a trust policy containing your workspace audience and Macroscope’s export service account ID. Use those exact values in a role with a Custom trust policy:accounts.google.com:oaud to the token’s aud claim; accounts.google.com:aud maps to azp. Do not substitute one for the other or register a separate OIDC provider for this integration.
Bucket permissions
Keep the bucket private. Grant the role bucket-location access and write access to your export prefix:macroscope/ prefix. Match the resource to your configured prefix. For SSE-KMS with a customer-managed key, also grant the role kms:GenerateDataKey and kms:Encrypt on that key and allow access in its key policy.
Optional s3:DeleteObject access lets Macroscope clean up stale part files after a re-export. Consumers must ignore unlisted parts regardless.
Export settings
Saving validates role assumption and bucket writes before enabling exports. Settings show the next run, last successful window, and latest failure.
Pausing preserves configuration. Resuming starts at the next scheduled window. Deleting configuration stops exports without deleting existing S3 objects.