Skip to main content
Identity and access management (IAM) connects who is acting to what they may do. Permissions and role assignments are scoped to an organization; access in one organization does not grant access in another.

How access fits together

A principal can hold several roles, and their grants combine. Only Allow permissions are supported: a role with fewer permissions does not cancel access granted by another role. Creating a permission grants no access until it belongs to an assigned role. For an IAM-controlled action, the required grant must match the action and resource scope. Without it, access is denied.

Compute and data access

Compute permissions control whether a principal can run or abort work on an engine. Warehouse permissions control which data the principal can read or change. Running a query against the warehouse needs both appropriate compute and data access. Catalog and connection permissions separately control discovery and management of registrations. They do not grant access inside an external database. Start with Roles to choose a built-in role or create a custom one. Use Resources and actions for the complete permission reference.