DESCRIBE RESTRICTED SESSION SCOPE

Describes the properties of a restricted session scope, including the YAML definition body.

DESCRIBE can be abbreviated to DESC. RSS is a shorthand alias for RESTRICTED SESSION SCOPE. You can use either form in this statement.

See also:

CREATE RESTRICTED SESSION SCOPE , ALTER RESTRICTED SESSION SCOPE , DROP RESTRICTED SESSION SCOPE , SHOW RESTRICTED SESSION SCOPES

Syntax

{ DESCRIBE | DESC } { RESTRICTED SESSION SCOPE | RSS } <name>

Parameters

name

Identifier for the restricted session scope to describe.

If the identifier contains spaces or special characters, the entire string must be enclosed in double quotes. Identifiers enclosed in double quotes are also case-sensitive.

For more details, see Identifier requirements.

Access control requirements

A role used to execute this SQL command must have at least one of the following privileges at a minimum:

PrivilegeObject
USAGE, MODIFY, or OWNERSHIPRestricted session scope

Operating on an object in a schema requires at least one privilege on the parent database and at least one privilege on the parent schema.

For instructions on creating a custom role with a specified set of privileges, see Creating custom roles.

For general information about roles and privilege grants for performing SQL actions on securable objects, see Overview of Access Control.

Usage notes

  • To post-process the output of this command, you can use the pipe operator (->>) or the RESULT_SCAN function. Both constructs treat the output as a result set that you can query.

    For example, you can use the pipe operator or RESULT_SCAN function to select specific columns from the SHOW command output or filter the rows.

    When you refer to the output columns, use double-quoted identifiers for the column names. For example, to select the output column type, specify SELECT "type".

    You must use double-quoted identifiers because the output column names for SHOW commands are in lowercase. The double quotes ensure that the column names in the SELECT list or WHERE clause match the column names in the SHOW command output that was scanned.

Output

The output of the command includes the following columns, which describe the properties and metadata of the object:

ColumnDescription
created_onDate and time when the restricted session scope was created.
nameName of the restricted session scope.
commentComment for the restricted session scope, if any.
definitionYAML document that defines the privilege ceiling.

Example

DESC RESTRICTED SESSION SCOPE mydb.governance.agent_scope;