Correction the following refers to the created key:

Possibly created by:

  gcloud iam service-accounts create ${ACCOUNT} --project=${PROJECT}
  gcloud iam service-accounts keys create ${PWD}/${ACCOUNT}.json \
  --iam-account=${EMAIL} \
Because Google Workspace does not support IAM, no IAM roles need be assigned. Instead OAuth scopes are used.

