GRANT DATABASE ROLE

Assigns a database role to an account role, another database role, or a user. A user with OWNERSHIP privilege on a database role can grant that database role to either an account role, another database role, or a user in the same database. Granting a database role to another role creates a “parent-child” relationship (also referred to as a role hierarchy) between the database role and the other role. For specific limitations on database roles, see Database roles and role hierarchies.

See also:

REVOKE DATABASE ROLE , GRANT ROLE , REVOKE ROLE , GRANT <privileges> … TO ROLE

Syntax

GRANT DATABASE ROLE <name> TO { DATABASE ROLE <parent_role_name> | ROLE <parent_role_name> } [ WITH GRANT OPTION ]

GRANT DATABASE ROLE <name> TO USER <user_name>

GRANT DATABASE ROLE <name> TO APPLICATION <app_name>

Parameters

name

Specifies the identifier (name) for the database role; must be unique in the database in which the database role is created.

If the identifier contains spaces or special characters, the entire string must be enclosed in double quotes. Identifiers enclosed in double quotes are also case-sensitive.

For more information, see Identifier requirements.

If the identifier is not fully qualified in the form of db_name.database_role_name, the command looks for the database role in the current database for the session.

ROLE parent_role_name

Grants the database role to the specified account role.

DATABASE ROLE parent_role_name

Grants the database role to the specified database role. If the parent role is a database role and the identifier is not fully qualified in the form of db_name.database_role_name, the command looks for the database role in the current database for the session.

APPLICATION app_name

Grants the database role to the specified Snowflake Native App.

USER user_name

Grants the database role to the specified user.

WITH GRANT OPTION

If specified, allows the recipient role to grant the database role to other roles. The recipient can include WITH GRANT OPTION on those grants.

Default: No value, which means the recipient role can’t grant the database role to other roles. The recipient still inherits the privileges of the granted database role.

Note

WITH GRANT OPTION is valid on a grant to an account role or a database role. GRANT DATABASE ROLE ... TO USER ... WITH GRANT OPTION isn’t supported.

For revoke behavior, see REVOKE DATABASE ROLE.

Access control requirements

A role used to execute this operation must have the following privileges at a minimum:

Privilege or roleObjectNotes
OWNERSHIPDatabase roleOWNERSHIP is a special privilege on an object that is automatically granted to the role that created the object, but can also be transferred using the GRANT OWNERSHIP command to a different role by the owning role (or any role with the MANAGE GRANTS privilege).

A role that was granted the database role with WITH GRANT OPTION can also grant that database role to other roles.

Examples

Grants the database role analyst to the SYSADMIN role:

GRANT DATABASE ROLE analyst TO ROLE SYSADMIN;

Grants the database role dr1 to the database role dr2:

GRANT DATABASE ROLE dr1 TO DATABASE ROLE dr2;

Grants the database role db1 to the Snowflake Native App named hello_snowflake_app:

GRANT DATABASE ROLE db1 TO APPLICATION hello_snowflake_app;

Grants the database role dr3 to the user user1:

GRANT DATABASE ROLE dr3 TO USER user1;

Grant the database role analyst to the account role data_steward and allow data_steward to grant analyst to other roles:

GRANT DATABASE ROLE mydb.analyst TO ROLE data_steward WITH GRANT OPTION;