REVOKE DATABASE ROLE¶
Revokes a database role from an account role or another database role.
- See also:
GRANT DATABASE ROLE , GRANT ROLE , REVOKE ROLE , GRANT <privileges> … TO ROLE
Syntax¶
Parameters¶
nameSpecifies the identifier for the database role to revoke. If the identifier contains spaces or special characters, the entire string must be enclosed in double quotes. Identifiers enclosed in double quotes are also case-sensitive.
DATABASE ROLE parent_role_nameRevokes the database role from the specified database role.
ROLE parent_role_nameRevokes the database role from the specified account role.
APPLICATION app_nameRevokes the database role from the specified Snowflake Native App.
Optional parameters¶
GRANT OPTION FORIf specified, removes the ability for the recipient role to grant the database role to another role. The database role grant itself remains, so the recipient role still inherits the granted database role’s privileges.
Default: No value, which revokes the database role grant.
RESTRICT | CASCADEDetermines whether the revoke operation succeeds when the database role has been re-granted to another role. These clauses apply to
REVOKE DATABASE ROLE ... FROM ROLEandREVOKE DATABASE ROLE ... FROM DATABASE ROLE.RESTRICT: If the database role being revoked has been re-granted to another role, the REVOKE command fails.CASCADE: If the database role being revoked has been re-granted, the REVOKE command recursively revokes these dependent grants.GRANT OPTION FOR ... CASCADErevokes the dependent grants and leaves the database role grant in place without the grant option.CASCADEwithoutGRANT OPTION FORrevokes the database role grant and the dependent grants.
Default:
RESTRICT
Examples¶
Revokes the database role named analyst from the account role named SYSADMIN.
Revokes the database role named dr1 from another database role named dr2.
Revokes the database role named dr1 from the Snowflake Native App named hello_snowflake_app.
Remove only the grant option from the data_steward role. data_steward keeps the database role:
Revoke the database role from data_steward, including grants of that database role that
data_steward made: