GRANT ROLE¶
Assigns a role to a user or another role:
- Granting a role to another role creates a “parent-child” relationship between the roles (also referred to as a role hierarchy).
- Granting a role to a user enables the user to perform all operations allowed by the role (through the access privileges granted to the role).
For more details, see Overview of Access Control.
Syntax¶
Parameters¶
nameSpecifies the identifier for the role to grant. If the identifier contains spaces or special characters, the entire string must be enclosed in double quotes. Identifiers enclosed in double quotes are also case-sensitive.
ROLE parent_role_nameGrants the role to the specified role.
USER user_nameGrants the role to the specified user.
WITH GRANT OPTIONIf specified, allows the recipient role to grant the role to other roles. The recipient can include
WITH GRANT OPTIONon those grants.Default: No value, which means the recipient role can’t grant the role to other roles. The recipient still inherits the privileges of the granted role.
Note
WITH GRANT OPTIONis valid on a grant to a role.GRANT ROLE ... TO USER ... WITH GRANT OPTIONisn’t supported.The same clause is supported for database roles. See GRANT DATABASE ROLE.
Access control requirements¶
A role used to execute this operation must have the following privileges at a minimum:
| Privilege | Object | Notes |
|---|---|---|
| OWNERSHIP | Role | Role that is granted to a user or another role. |
Alternatively, use a role with the global MANAGE GRANTS privilege. Only the SECURITYADMIN role, or a higher role, has this privilege by default. The privilege can be granted to additional roles as needed.
A role that was granted the role with WITH GRANT OPTION can also grant that role to other roles.
Operating on an object in a schema requires at least one privilege on the parent database and at least one privilege on the parent schema.
For instructions on creating a custom role with a specified set of privileges, see Creating custom roles.
For general information about roles and privilege grants for performing SQL actions on securable objects, see Overview of Access Control.
Usage notes¶
- The system-defined roles, including PUBLIC, do not need to be granted to other roles because the role hierarchy for these roles is defined and maintained by Snowflake.
- Only a grant
that includes
WITH GRANT OPTIONlets the recipient grant that role to other roles. - To remove only the grant option, or to control grants that were made from it, see REVOKE ROLE.
- SHOW GRANTS
TO ROLElists a role grant as theUSAGEprivilege on the granted role. Thegrant_optioncolumn isTRUEwhen the role was granted withWITH GRANT OPTION.
Examples¶
Grant the analyst role to the data_steward role and allow data_steward to grant analyst to
other roles:
The data_steward role can then grant analyst: