Paste the JSON output of gcloud projects get-iam-policy --format=json (or any GCP IAM policy with a bindings array) to see who has which roles, in plain English, with overly broad grants flagged. Nothing is ever uploaded.
Free, unlimited, no account. If this saved you a paid tool, a small thanks is appreciated.
Say thanks β $3