APPLY AGGREGATION POLICY |
Grants the ability to add and drop an aggregation policy on a table or view. |
This global privilege also allows executing the DESCRIBE operation on tables and views. |
APPLY AUTHENTICATION POLICY |
Grants the ability to add or drop an authentication policy on the Snowflake account or a user in the Snowflake account. |
|
APPLY CONTACT |
Grants the ability to associate or detach a contact with an object. |
|
APPLY FEATURE POLICY |
Grants the ability to apply a feature policy for an account or on a specific object. |
|
APPLY JOIN POLICY |
Grants the ability to add and drop a join policy on a table or view. |
This global privilege also allows executing the DESCRIBE operation on tables and views. |
APPLY MASKING POLICY |
Grants the ability to set a Column-level Security masking policy on a table or view column and to set a masking policy on a tag. |
This global privilege also allows executing the DESCRIBE operation on tables and views. |
APPLY ROW ACCESS POLICY |
Grants the ability to add and drop a row access policy on a table or view. |
This global privilege also allows executing the DESCRIBE operation on tables and views. |
APPLY PACKAGES POLICY |
Grants the ability to add or drop a packages policy on the Snowflake account. |
|
APPLY PASSWORD POLICY |
Grants the ability to add or drop a password policy on the Snowflake account or a user in the Snowflake account. |
|
APPLY PRIVACY POLICY |
Grants the ability to add and drop a privacy policy on a table or view. |
This global privilege also allows executing the DESCRIBE operation on tables and views. |
APPLY PROJECTION POLICY |
Grants the ability to add and drop a projection policy on a table or view. |
This global privilege also allows executing the DESCRIBE operation on tables and views. |
APPLY SESSION POLICY |
Grants the ability to set or unset a session policy on an account or user. |
|
APPLY TAG |
Grants the ability to add or drop a tag on a Snowflake object. |
|
ATTACH POLICY |
Grants the ability to activate a network policy by associating it with your account. |
|
AUDIT |
Grants the ability to set the ENABLE_UNREDACTED_QUERY_SYNTAX_ERROR and ENABLE_UNREDACTED_SECURE_OBJECT_ERROR user parameters. |
|
BIND SERVICE ENDPOINT |
Enables the ability to create a service that supports public endpoints. For more information about public endpoints, see Ingress: Using a service from outside Snowflake |
Must be granted by the ACCOUNTADMIN role. |
CREATE ACCOUNT |
Enables a data provider to create a new managed account (i.e. reader account). For more details, see Manage reader accounts. |
Must be granted by the ACCOUNTADMIN role. |
CREATE COMPUTE POOL |
Enables creating a compute pool to run a Snowpark Container Services service. |
Must be granted by the ACCOUNTADMIN role. |
CREATE DATABASE |
Enables creating a new database. |
Must be granted by the ACCOUNTADMIN role. |
CREATE EXTERNAL VOLUME |
Enables creating a new external volume for Apache Icebergâ„¢ tables. |
|
CREATE FEATURE POLICY |
Enables creating a new feature policy. |
|
CREATE FAILOVER GROUP |
Enables creating a new failover group. |
Must be granted by the ACCOUNTADMIN role. |
CREATE REPLICATION GROUP |
Enables creating a new replication group. |
Must be granted by the ACCOUNTADMIN role. |
CREATE ROLE |
Enables creating a new role. |
|
CREATE USER |
Enables creating a new user. |
|
CREATE DATA EXCHANGE LISTING |
Enables creating a new Data Exchange listing. |
Must be granted by the ACCOUNTADMIN role. |
CREATE INTEGRATION |
Enables creating a new catalog, notification, security, or storage integration. |
Must be granted by the ACCOUNTADMIN role. |
CREATE NETWORK POLICY |
Enables creating a new network policy. |
|
CREATE ORGANIZATION LISTING |
Enables creating a new organization listing. |
|
CREATE ORGANIZATION PROFILE |
Enables creating a new organization profile. |
|
CREATE ORGANIZATION USER |
Enables creating a new organization user. |
Must be granted by the GLOBALORGADMIN role in the organization account. |
CREATE ORGANIZATION USER GROUP |
Enables creating a new organization user group. |
Must be granted by the GLOBALORGADMIN role in the organization account. |
CREATE SHARE |
Enables a data provider to create a new share. For more details, see Enable non-ACCOUNTADMIN roles to perform data sharing tasks. |
Must be granted by the ACCOUNTADMIN role. |
CREATE WAREHOUSE |
Enables creating a new virtual warehouse. |
Must be granted by the ACCOUNTADMIN role. |
EXECUTE ALERT |
Grants the ability to execute alerts owned by the role. For serverless alerts to run, the role that has the OWNERSHIP privilege on the alert must also have the global EXECUTE MANAGED ALERT privilege. |
Must be granted by the ACCOUNTADMIN role. |
EXECUTE AUTO CLASSIFICATION |
Grants the ability to set a classification profile on a schema to implement automatic sensitive data classification. |
Must be granted by the ACCOUNTADMIN role. |
EXECUTE DATA METRIC FUNCTION |
Enables using serverless compute resources when calling a data metric function. |
|
EXECUTE MANAGED ALERT |
Grants the ability to create alerts that rely on serverless compute resources. Only required to create serverless alerts. The role that has the OWNERSHIP privilege on a serverless alert must have both the EXECUTE MANAGED ALERT and the EXECUTE ALERT privilege for the alert to run. |
|
EXECUTE MANAGED TASK |
Grants the ability to create tasks that rely on serverless compute resources. Only required for serverless tasks. The role that has the OWNERSHIP privilege on a task must have both the EXECUTE MANAGED TASK and the EXECUTE TASK privilege for the task to run. |
Must be granted by the ACCOUNTADMIN role. |
EXECUTE TASK |
Grants the ability to run tasks owned by the role. For serverless tasks to run, the role that has the OWNERSHIP privilege on the task must also have the global EXECUTE MANAGED TASK privilege. |
Must be granted by the ACCOUNTADMIN role. |
IMPORT SHARE |
Enables a data consumer to view shares shared with their account. Also grants the ability to create databases from shares; requires the global CREATE DATABASE privilege. For more details, see Enable non-ACCOUNTADMIN roles to perform data sharing tasks. |
Must be granted by the ACCOUNTADMIN role. |
IMPORT ORGANIZATION LISTING |
Enables a provider to install a listing or to perform a query without installing the listing. |
|
IMPORT ORGANIZATION USER GROUPS |
Grants the ability to add an organization user group to a regular account, which imports users into the account. |
Must be granted by the ACCOUNTADMIN role. |
MANAGE ACCOUNTS |
Grants the ability to manage the lifecycle of accounts (for example, creating and deleting). |
Must be granted by the GLOBALORGADMIN role in the organization account. |
MANAGE ACCOUNT SUPPORT CASES |
Grants the ability to view, comment on, and manage all Support cases for the current account in Snowsight. |
|
MANAGE GRANTS |
Enables granting or revoking privileges on objects for which the role is not the owner. |
Must be granted by the SECURITYADMIN role (or higher). |
MANAGE LISTING AUTO FULFILLMENT |
Grants the ability to publish listings to remote regions using Cross-Cloud Auto-Fulfillment and manage auto-fulfillment settings for listings. |
In the organization account, must be granted by the GLOBALORGADMIN role. In all other accounts, must be granted by the ACCOUNTADMIN role after that role has been delegated privileges by the ORGADMIN role. |
MANAGE ORGANIZATION CONTACTS |
Grants the ability to manage the contacts of an organization. |
Must be granted by the GLOBALORGADMIN role in the organization account. |
MANAGE ORGANIZATION SUPPORT CASES |
Grants the ability to view, comment on, and manage all Support cases that were opened by the current user in Snowsight. |
|
MANAGE ORGANIZATION TERMS |
Grants the ability to manage the legal terms for an organization. |
Must be granted by the GLOBALORGADMIN role in the organization account. |
MANAGE ORGANIZATION USER |
Grants the ability to manage organization users. |
Must be granted by the GLOBALORGADMIN role in the organization account. |
MANAGE ORGANIZATION USER GROUP |
Grants the ability to manage organization user groups. |
Must be granted by the GLOBALORGADMIN role in the organization account. |
MANAGE SHARE TARGET |
Grants the ability to manage (ALTER) share targets. |
|
MANAGE USER SUPPORT CASES |
Grants the ability to view, comment on, and manage all Support cases for the current user in Snowsight. |
|
MANAGE WAREHOUSES |
Grants the ability to perform operations that require MODIFY, MONITOR, and OPERATE privileges on warehouses in the same account. |
Must be granted by the ACCOUNTADMIN role. |
MODIFY LOG LEVEL |
Enables setting the level of log messages captured for stored procedures and UDFs in the current account. |
For more information, see LOG_LEVEL. |
MODIFY METRIC LEVEL |
Enables setting the level of metrics data captured for stored procedures and UDFs in the current account. |
For more information, see METRIC_LEVEL. |
MODIFY SESSION LOG LEVEL |
Enables setting the level of log messages captured for stored procedures and UDFs invoked in the current session. |
For more information, see LOG_LEVEL. |
MODIFY SESSION METRIC LEVEL |
Enables setting the level of metrics data captured for stored procedures and UDFs invoked in the current session. |
For more information, see METRIC_LEVEL. |
MODIFY TRACE LEVEL |
Enables setting the level of trace events captured for stored procedures and UDFs in the current account. |
When tracing events, you must also set the LOG_LEVEL parameter to one of its supported values. For more information, see TRACE_LEVEL. |
MODIFY SESSION TRACE LEVEL |
Enables setting the level of trace events captured for stored procedures and UDFs invoked in the current session. |
When tracing events, you must also set the LOG_LEVEL parameter to one of its supported values. For more information, see TRACE_LEVEL. |
MONITOR EXECUTION |
Grants the ability to monitor any pipes or tasks in the account. |
Must be granted by the ACCOUNTADMIN role. The USAGE privilege is also required on each database and schema that stores these objects. |
MONITOR ON ACCOUNT |
Grants the ability to describe connections, resolve any object and session, and show capacity groups, locks, login events, query history by warehouse, REST history events, task history, and transactions. |
|
MONITOR SECURITY |
Grants the ability to call system functions pertaining to Customer-managed keys. |
|
MONITOR USAGE |
Grants the ability to monitor account-level usage and historical information for databases and warehouses; for more details, see Enabling non-account administrators to monitor usage and billing history in the Classic Console. Additionally grants the ability to view managed accounts using SHOW MANAGED ACCOUNTS. |
Must be granted by the ACCOUNTADMIN role. |
OVERRIDE SHARE RESTRICTIONS |
Grants the ability to set value for the SHARE_RESTRICTIONS parameter on a share which enables a Business Critical provider account to add a consumer account (with non-Business Critical edition) to a share. |
For more details, see Enable sharing from a Business critical account to a non-business critical account. |
PURCHASE DATA EXCHANGE LISTING |
Grants the ability to purchase a paid listing. |
See Paying for listings. |
READ SESSION |
Grants the ability to read session context. |
Must be granted by the ACCOUNTADMIN role. |
REPLICATE |
Grants the ability to change the REPLICABLE_WITH_FAILOVER_GROUPS setting for databases and schemas. |
|
RESOLVE ALL |
Grants the ability to resolve all objects in the account, which outputs the object in the corresponding SHOW command. |
|
ALL [ PRIVILEGES ] |
Grants all global privileges. |
|