Skip to main content

REVOKE FROM USER

Access to Dremio objects can be managed by revoking privileges from users. A privilege is the right to perform a specific action on an object.

Syntax
REVOKE { objectPrivilege | ALL } ON { <object_type> <object_name> }
FROM USER <username>
objectPrivilege
-- On Organizations
{ CONFIGURE SECURITY | CREATE CATALOG | CREATE CLOUD | CREATE PROJECT | MANAGE GRANTS } [, ...]
-- On Clouds
{ MANAGE GRANTS | MODIFY | MONITOR } [, ...]
-- On Projects
{ ALTER | ALTER REFLECTION | CREATE TABLE | DROP | EXTERNAL QUERY | MANAGE GRANTS | MODIFY | MONITOR | OPERATE | SELECT | VIEW REFLECTION | USAGE | VIEW JOB HISTORY } [, ...]
-- On Engines
{ MODIFY | MONITOR | OPERATE | USAGE } [, ...]
-- On Identity and Token Providers
{ MODIFY | MONITOR | OPERATE | USAGE } [, ...]
-- On Sources
{ ALTER | ALTER REFLECTION | CREATE TABLE | DROP | EXTERNAL QUERY | MANAGE GRANTS | MODIFY | SELECT } [, ...]
-- On Spaces
{ ALTER | ALTER REFLECTION | MANAGE GRANTS | MODIFY | SELECT } [, ...]
-- On Folders
{ ALTER | ALTER REFLECTION | CREATE TABLE | DROP | MANAGE GRANTS | SELECT } [, ...]
-- On Tables
{ ALTER | MANAGE GRANTS } [, ...]
-- On Views
{ ALTER | MANAGE GRANTS } [, ...]

Parameters

{{< sql-section file="data/sql/privileges.json" data="revokingPrivilegesParametersUser" >}}

Examples

Revoke SELECT privilege on the project from the user
REVOKE SELECT
ON PROJECT
FROM USER "user@dremio.com"
Revoke ALTER privilege on a space from a user```sql REVOKE ALTER ON SPACE Application FROM USER "user@dremio.com" ```