The Service account '{GcpIamServiceAccount}' has an IAM policy containing permissions that allow privilege escalation, at the project level. One or more of the existing permissions allow the service account to create new services with higher permissions than their own. The service account can then utilize these services to perform API calls that the service account may not be authorized to perform. The role containing these permissions is '{GcpIamServiceAccount.PolicyBindings.Role}'