Granting a whole schema
Grant every current and future table in a schema when the user's or group's responsibility justifies that scope.
When to use this
- Use it when a team owns or operates an entire data domain.
- Use it when new tables in the schema should become available automatically to the same group.
- Use it when granting table by table would create excessive maintenance and a risk of inconsistency.
Before you start
- Confirm the group genuinely needs the whole schema.
- Check whether the schema holds sensitive data.
- Set an expiry or a periodic review for broad access.
Step by step
- Open Data Governance and create a new rule.
- Choose the user, group, or service account.
- Select the catalog.
- Choose the schema you want.
- Select Whole schema.
- Add protections where needed.
- Simulate, review the summary, and save.
What happens next
- Every current table in the schema is covered by the rule.
- New tables in the same schema can follow the same grant.
- The action is recorded and goes through propagation.
Common errors
- The schema holds unexpected sensitive data: use specific tables or protections.
- Too broad a group: review the members before granting.
- The access does not appear yet: wait for propagation and refresh the Explorer.
Good practice
- Use a whole schema only when there is a clear justification.
- Prefer function-based groups over individual users.
- Schedule a recurring review of broad rules.
Next steps
Was this page helpful?
Report a problem on this pageDo not send passwords, keys, tokens, or customer data.