This page lists the IAM roles to be granted and APIs to be enabled in order to execute the Forseti Terraform module.
For this module to work, you need the following roles enabled on the Service Account:
On the organization:
On the project:
On the host project (when using shared VPC)
For this module to work, you need the following APIs enabled on the Forseti project: