DROP ROLE command: No longer requires the MANAGE GRANTS privilege (Preview)¶
Attention
This behavior change is in the 2026_01 bundle.
For the current status of the bundle, refer to Bundle history.
The DROP ROLE command behaves as follows:
- Before the change:
Dropping a role that is granted future grants requires a role with OWNERSHIP of that role and the MANAGE GRANTS privilege.
- After the change:
Dropping a role that is granted future grants requires OWNERSHIP of that role and no additional privileges.
This BCR simplifies the introduction of container-scoped MANAGE GRANTS, and simplifies SCIM role management.
Ref: 2167