Billing IAM is a completely separate surface from project IAM.
roles/owner on a project grants zero billing permission — and billing.admin grants zero ability to touch resources.
Billing account IAM
admin · user · viewer · costsManager
Project IAM
owner · editor · viewer — no billing access at all
Intentional separation of duties: a finance-side billing admin never incidentally gains access to production resources.
A budget only alerts — unless wired to automation
Threshold crossed50% / 90% / 100% of target
Email — informational onlyAlways-on baseline safety net
Monitoring channel — informational onlyRoutes into the same on-call paging
Pub/Sub → automationThe only path that can actually act
A flat budget that fires for expected growth teaches a team to ignore it — a forecasted-spend rule warns earlier and stays trustworthy.