User assigned with ‘Service Account User’ or ‘Service Account Token Creator’ roles at project level
Granting the 'iam.serviceAccountUser' or 'iam.serviceAserviceAccountTokenCreatorccountUser' roles to a user for a project gives the user access to all service accounts...