Resource Hierarchy
Overview
Google Cloud uses a resource hierarchy to organize cloud environments.
Think of it like a company structure.
A company has departments, departments have teams, and teams work on products. Google Cloud uses a similar structure for cloud resources.
At a high level, the hierarchy is:
- Organization
- Folders
- Projects
- Resources
This structure affects permissions, billing, ownership, and governance.
Hierarchy Levels
Each level has a different job.
| Level | Purpose | Example |
|---|---|---|
| Organization | Represents the company or domain | example.com |
| Folder | Groups projects by department or environment | Engineering, Finance, or Production |
| Project | Contains actual cloud resources | web-app-prod or data-analytics-dev |
| Resource | The service object created inside a project | VM instance, storage bucket, or BigQuery set |
Notes:
- The organization is the root container.
- Folders are optional, but they become important when many teams, applications, or environments exist.
- Projects are the main workspace for building.
- Every service resource belongs to a project.
Organization
The organization node represents the company behind the Google Cloud account.
It is linked to a Google Workspace or Cloud Identity account, and it acts as the top-level parent for folders and projects.
Use the organization level for broad controls that should apply across the business.
Examples:
- Grant billing visibility to finance teams.
- Apply security guardrails across all projects.
- Define high-level ownership and administration boundaries.
- Prevent unmanaged personal projects from becoming the center of production systems.
Note: A personal Gmail account can use Google Cloud, but it does not provide a Google Cloud organization by itself.
Folders
Folders group projects inside an organization.
They can represent business units, teams, environments, regions, or compliance boundaries.
Common folder patterns include:
EngineeringFinanceProductionDevelopmentEU-DataShared-Services
Folders can also contain other folders.
For example:
Organization
Engineering
Web-Team
Production
Development
This structure makes access control and governance easier to manage at scale.
Projects
A project is the fundamental container for Google Cloud resources.
This is where most day-to-day cloud work happens.
A project controls:
- Which APIs are enabled.
- Which billing account is attached.
- Which IAM permissions apply.
- Which resources are created.
- Which logs, quotas, and labels apply.
Use projects to separate workloads, teams, environments, and billing concerns.
Example project names:
corporate-website-prodcorporate-website-devdata-platform-testshared-network-prod
Project Identifiers
Google Cloud projects have several identifiers.
| Identifier | Purpose | Can Change |
|---|---|---|
| Project name | Human-friendly display name | Yes |
| Project ID | Globally unique project identifier | No |
| Project number | Google-generated numeric identifier | No |
The project name is like a nickname.
The project ID is the permanent identifier used by commands, APIs, service accounts, logs, and resource names.
Choose the project ID carefully before creating the project.