OrganizationAdmin | Includes all grants from the other system-managed roles, plus Describe, Select, Create, Modify, Manage grants, and Pass grants across the entire warehouse. |
UserAdmin | Manages principals, roles, and permission definitions; manages Application and Agent API keys; delegates access across all resource categories. Includes principal Modify, Enable, and Disable definitions, whose operations are not implemented yet. |
SecurityAdmin | Manages catalog registrations, connections, roles, and permission definitions. Delegates catalog and connection access. Does not itself grant principal administration, compute execution, or warehouse data access. |
JobOperator | Execute and Abort on all compute engines. No warehouse data grants. |
TokenSelfAdmin | Describe, Create, and Revoke for API keys owned by Self—the principal using the role. |
Public | Contains no permissions. Grants no compute or data access by itself. |