Skip to main content

BigQuery Access Setup

Step 1: Create a New Service Account in the GCP project you want Pavo to access

For example: <sa_name>@<project>.iam.gserviceaccount.com

Step 2: Grant BigQuery Permissions

In case of BQ data in multiple projects, grant the created SA access across all the projects.
  • In the Google Cloud Console, switch to the project that contains the BigQuery data you want us to read.
  • In the left navigation bar, go to IAM & Admin → IAM.
  • Click Grant access
  • In New principals, enter: name of the created sa <sa_name>@<project>.iam.gserviceaccount.com
  • In Role, add the following roles (you may need to add multiple):
BigQuery Metadata Viewer
Category: BigQuery → BigQuery Metadata Viewer
Role ID: roles/bigquery.metadataViewer
If you prefer CLI:
BigQuery Job User
Category: BigQuery → BigQuery Job User
Role ID: roles/bigquery.jobUser
If you prefer CLI:
BigQuery Resource Viewer
Category: BigQuery → BigQuery Resource Viewer
Role ID: roles/bigquery.resourceViewer
(This role includes the bigquery.jobs.listAll permission required to query INFORMATION_SCHEMA.JOBS / JOBS_BY_PROJECT.)
If you prefer CLI:
  • Click Save.

Step 3: Create Analysis Dataset (Optional)

Only required if you want Pavo to run analysis queries that create temporary tables.
  1. Create a new BigQuery dataset named pavo_dataset (this specific name is required for temporary tables during analysis).
  2. Grant the service account the BigQuery Data Editor role for this dataset.

Step 4: Download JSON Key

  1. In the GCP Console, go to IAM & Admin → Service Accounts.
  2. Click on the service account you created.
  3. Go to Keys → Add Key → Create new key → JSON.
  4. Download the JSON key file.

Step 5: Add the Connector in Pavo

Navigate to Settings → Data sources and click Add source. Data sources page Select BigQuery from the connector list. Connector picker Upload the JSON key file you downloaded in Step 4 and click Connect. BigQuery connector Pavo stores the key encrypted and never returns it. Once connected, syncing begins automatically.