IAM Policy Troubleshooter answers one specific question: can this principal use this permission on this resource, and why. Rather than making you manually trace through every allow and deny policy attached to a resource and everything it inherits from its project, folder, and organization above it, the tool walks that entire chain for you and shows exactly which policy, at which level, produced the final answer.
This covers running a check, then what to actually do with a result that does not match what you expected.
Complete Process of IAM Policy Troubleshooter
Open the console, then
Open Menu > IAM & Admin > Troubleshooter

Enter the email address of the principal you want to check, select the resource, and select the permission. Click Check Access.

The tool shows whether that principal can use that permission on that resource, and which specific policy is responsible for the result.

Two things explain most results that do not match what you expected from looking at a role assignment alone.
When a result does not match what you expected, the troubleshooter’s explanation will point to the specific policy and the specific level in the hierarchy responsible, which is usually faster than guessing.
Seeing every allow and deny policy that affects a result, including ones inherited from a parent organization or folder you do not have direct visibility into, generally requires the Security Reviewer role at the organization level. Without it, you may only see part of the picture for a resource whose access is partly controlled higher up the hierarchy than your own permissions reach.
That covers using IAM Policy Troubleshooter properly, including the deny policies and inheritance behavior the original page never mentioned. To go further, explore Prwatech’s Google Cloud training program, which includes placement assistance.