Follow the steps below to create a custom role in the GCDS.
Log in to Google Cloud Directory Sync (GCDS).
Click on Account->Admin roles.
Click Create new role.
Enter name as Britive API Role.
Click CONTINUE.
Select the following privileges under Admin API privileges:
Organization Units->Read
Users->Read
Groups->Read
Groups->Update
Click CONTINUE.
Click CREATE ROLE.
For more information about creating and managing custom roles in Cloud Identity Sync, see Create a custom role.