QuestionQ127

Secure Data Sharing and Consumption

An Architect must allow a group of ORDER_ADMIN users to clean up old data in an ORDERS table by deleting every record older than 5 years, without granting any privileges on that table. The group’s manager (ORDER_MANAGER) has full DELETE privileges on the table.

How can the ORDER_ADMIN role be enabled to perform this data cleanup without requiring the DELETE privilege held by the ORDER_MANAGER role?

Explanation

An owner’s-rights stored procedure executes with its owner’s privileges. A procedure owned by ORDER_MANAGER can therefore delete only rows older than five years from ORDERS, while granting ORDER_ADMIN USAGE allows it to invoke that constrained operation without receiving DELETE on the table. Snowflake documentation specifically identifies this pattern for delegating deletion of old rows without granting table DELETE privileges.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!