Skip to main content

Granting a whole schema

Grant every current and future table in a schema when the user's or group's responsibility justifies that scope.

When to use this​

  • Use it when a team owns or operates an entire data domain.
  • Use it when new tables in the schema should become available automatically to the same group.
  • Use it when granting table by table would create excessive maintenance and a risk of inconsistency.

Before you start​

  • Confirm the group genuinely needs the whole schema.
  • Check whether the schema holds sensitive data.
  • Set an expiry or a periodic review for broad access.

Step by step​

  1. Open Data Governance and create a new rule.
  2. Choose the user, group, or service account.
  3. Select the catalog.
  4. Choose the schema you want.
  5. Select Whole schema.
  6. Add protections where needed.
  7. Simulate, review the summary, and save.

What happens next​

  • Every current table in the schema is covered by the rule.
  • New tables in the same schema can follow the same grant.
  • The action is recorded and goes through propagation.

Common errors​

  • The schema holds unexpected sensitive data: use specific tables or protections.
  • Too broad a group: review the members before granting.
  • The access does not appear yet: wait for propagation and refresh the Explorer.

Good practice​

  • Use a whole schema only when there is a clear justification.
  • Prefer function-based groups over individual users.
  • Schedule a recurring review of broad rules.

Next steps​