You prevent new authoritative resources by using: google_project_iam_member. This resource is non-authoritative.
All resources have a non-authoritative resource iam member, for example: google_cloud_run_service_iam_member , dataset case: https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/bigquery_dataset_iam