Google Cloud IAM is the service that governs access across Google Cloud, letting administrators define who can do what on which resources. It uses a policy model of members, roles, and resources to enforce least-privilege access with fine-grained, predefined, and custom roles. Its resource hierarchy allows policies to be inherited from organization down through folders and projects for consistent governance.