Queries and required privileges

These tables list the query types and the privileges required to execute them.

Tables and views

Query Required Privileges

SELECT ... FROM s.t

SELECT on table t
USAGE on schema s

SELECT ... FROM ext.s.t

SELECT on external catalog ext

INSERT INTO s.t

INSERT on table t
USAGE on schema s

UPDATE s.t

UPDATE on table t
USAGE on schema s

DELETE FROM s.t

DELETE on table t
USAGE on schema s

TRUNCATE TABLE s.t

TRUNCATE on table t
USAGE on schema s

CREATE TABLE s.t

CREATE TABLE on schema s
(or on the catalog, if the schema name is not specified)

CREATE VIEW s.v

CREATE VIEW on schema s
(or on the catalog, if the schema name is not specified)

ALTER TABLE s.t

ALTER on table t
USAGE on schema s

DROP TABLE s.t

DROP on table t
USAGE on schema s

DROP VIEW s.v

DROP on view v
USAGE on schema s

DESCRIBE TABLE s.t

USAGE on schema s
Any privilege on table t

GRANT ... ON TABLE s.t

ADMIN on schema s

Schemas and catalog

Query Required Privileges

CREATE SCHEMA s

CREATE SCHEMA on catalog

ALTER SCHEMA s

ALTER on schema s

DROP SCHEMA s

OWNERSHIP or ADMIN on schema s

GRANT ... ON ALL TABLES IN SCHEMA s

ADMIN on schema s

GRANT ... ON SCHEMA s

ADMIN on schema s

GRANT ... ON CATALOG

ADMIN on catalog

Users and roles

Query Required Privileges

CREATE USER u

CREATE USER on the catalog
ADMIN on the pool if DEFAULT WORKER POOL is named

ALTER USER u

OWNERSHIP or ADMIN on the user u

ALTER USER u IDENTIFIED BY PASSWORD ...

Nothing, if u is you
otherwise OWNERSHIP or ADMIN on the user u

ALTER USER u SET DEFAULT WORKER POOL w

OWNERSHIP or ADMIN on the user u
ADMIN on the pool w

DROP USER u

OWNERSHIP or ADMIN on the user u
(but not if u is you)

CREATE ROLE r

CREATE ROLE on the catalog

ALTER ROLE r

OWNERSHIP on role r or ADMIN

DROP ROLE r

OWNERSHIP on role r or ADMIN

GRANT ROLE r TO x

OWNERSHIP on role r or ADMIN

REVOKE ROLE r FROM x

OWNERSHIP on role r or ADMIN

USE ROLE r

Holding r

CREATE AGENT a

CREATE USER on the catalog

ALTER AGENT a

OWNERSHIP or ADMIN on the user a

API tokens

Each of these acts on your own account unless FOR USER u names somebody else, in which case it asks about that user.

Query Required Privileges

CREATE API TOKEN ... FOR USER u

CREATE API TOKEN on the user u

ALTER API TOKEN ... FOR USER u

OWNERSHIP or ADMIN on the user u

DROP API TOKEN ... FOR USER u

OWNERSHIP or ADMIN on the user u

DROP ALL API TOKENS FOR USER u

OWNERSHIP or ADMIN on the user u

SHOW API TOKENS FOR USER u

Any privilege on the user u

Worker pools

Query Required Privileges

CREATE WORKER POOL w

CREATE WORKER POOL on the catalog

ALTER WORKER POOL w

OWNERSHIP or ADMIN on the worker pool w

DROP WORKER POOL w

OWNERSHIP or ADMIN on the worker pool w

USE WORKER POOL w

USAGE on the worker pool w

Identity providers

Query Required Privileges

CREATE IDP i

ADMIN on the catalog

ALTER IDP i

OWNERSHIP or ADMIN on identity provider i

DROP IDP i

OWNERSHIP or ADMIN on identity provider i

SHOW IDPS

ADMIN on the catalog