DROP RESTRICTED SESSION SCOPE

Removes the specified restricted session scope from the current/specified schema.

RSS is a shorthand alias for RESTRICTED SESSION SCOPE. You can use either form in this statement.

See also:

CREATE RESTRICTED SESSION SCOPE , ALTER RESTRICTED SESSION SCOPE , SHOW RESTRICTED SESSION SCOPES , DESCRIBE RESTRICTED SESSION SCOPE

Syntax

DROP { RESTRICTED SESSION SCOPE | RSS } [ IF EXISTS ] <name>

Parameters

name

Identifier for the restricted session scope to drop.

If the identifier contains spaces or special characters, the entire string must be enclosed in double quotes. Identifiers enclosed in double quotes are also case-sensitive.

For more details, see Identifier requirements.

Access control requirements

A role used to execute this operation must have the following privileges at a minimum:

PrivilegeObjectNotes
OWNERSHIPRestricted session scopeOWNERSHIP is a special privilege on an object that is automatically granted to the role that created the object, but can also be transferred using the GRANT OWNERSHIP command to a different role by the owning role (or any role with the MANAGE GRANTS privilege).

Operating on an object in a schema requires at least one privilege on the parent database and at least one privilege on the parent schema.

For instructions on creating a custom role with a specified set of privileges, see Creating custom roles.

For general information about roles and privilege grants for performing SQL actions on securable objects, see Overview of Access Control.

Usage notes

  • If anything still references the object by fully qualified name, Snowflake blocks the drop. Remove or update that reference first.
  • When the IF EXISTS clause is specified and the target object doesn’t exist, the command completes successfully without returning an error.

Example

DROP RESTRICTED SESSION SCOPE mydb.governance.agent_scope;