DROP ROLE command: No longer requires the MANAGE GRANTS privilege (Preview)

Attention

This behavior change is in the 2026_01 bundle.

For the current status of the bundle, refer to Bundle history.

The DROP ROLE command behaves as follows:

Before the change:

Dropping a role that is granted future grants requires a role with OWNERSHIP of that role and the MANAGE GRANTS privilege.

After the change:

Dropping a role that is granted future grants requires OWNERSHIP of that role and no additional privileges.

This BCR simplifies the introduction of container-scoped MANAGE GRANTS, and simplifies SCIM role management.

Ref: 2167