OceanBase logo

OceanBase

A unified distributed database ready for your transactional, analytical, and AI workloads.

DEPLOY YOUR WAY

OceanBase Cloud

The best way to deploy and scale OceanBase

OceanBase Enterprise

Run and manage OceanBase on your infra

TRY OPEN SOURCE

OceanBase Community Edition

The free, open-source distributed database

OceanBase seekdb

Open source AI native search database

Customer Stories

Real-world success stories from enterprises across diverse industries.

View All
BY USE CASES

Mission-Critical Transactions

Global & Multicloud Application

Elastic Scaling for Peak Traffic

Real-time Analytics

Active Geo-redundancy

Database Consolidation

Resources

Comprehensive knowledge hub for OceanBase.

Blog

Live Demos

Training & Certification

Documentation

Official technical guides, tutorials, API references, and manuals for all OceanBase products.

View All
PRODUCTS

OceanBase Cloud

OceanBase Database

Tools

Connectors and Middleware

QUICK START

OceanBase Cloud

OceanBase Database

BEST PRACTICES

Practical guides for utilizing OceanBase more effectively and conveniently

Company

Learn more about OceanBase – our company, partnerships, and trust and security initiatives.

About OceanBase

Partner

Trust Center

Contact Us

International - English
中国站 - 简体中文
日本 - 日本語
Sign In
Start on Cloud

A unified distributed database ready for your transactional, analytical, and AI workloads.

DEPLOY YOUR WAY

OceanBase Cloud

The best way to deploy and scale OceanBase

OceanBase Enterprise

Run and manage OceanBase on your infra

TRY OPEN SOURCE

OceanBase Community Edition

The free, open-source distributed database

OceanBase seekdb

Open source AI native search database

Customer Stories

Real-world success stories from enterprises across diverse industries.

View All
BY USE CASES

Mission-Critical Transactions

Global & Multicloud Application

Elastic Scaling for Peak Traffic

Real-time Analytics

Active Geo-redundancy

Database Consolidation

Comprehensive knowledge hub for OceanBase.

Blog

Live Demos

Training & Certification

Documentation

Official technical guides, tutorials, API references, and manuals for all OceanBase products.

View All
PRODUCTS
OceanBase CloudOceanBase Database
ToolsConnectors and Middleware
QUICK START
OceanBase CloudOceanBase Database
BEST PRACTICES

Practical guides for utilizing OceanBase more effectively and conveniently

Learn more about OceanBase – our company, partnerships, and trust and security initiatives.

About OceanBase

Partner

Trust Center

Contact Us

Start on Cloud
编组
All Products
    • Databases
    • iconOceanBase Database
    • iconOceanBase Cloud
    • iconOceanBase Tugraph
    • iconInteractive Tutorials
    • iconOceanBase Best Practices
    • Tools
    • iconOceanBase Cloud Platform
    • iconOceanBase Migration Service
    • iconOceanBase Developer Center
    • iconOceanBase Migration Assessment
    • iconOceanBase Admin Tool
    • iconOceanBase Loader and Dumper
    • iconOceanBase Deployer
    • iconKubernetes operator for OceanBase
    • iconOceanBase Diagnostic Tool
    • iconOceanBase Binlog Service
    • Connectors and Middleware
    • iconOceanBase Database Proxy
    • iconEmbedded SQL in C for OceanBase
    • iconOceanBase Call Interface
    • iconOceanBase Connector/C
    • iconOceanBase Connector/J
    • iconOceanBase Connector/ODBC
    • iconOceanBase Connector/NET
icon

OceanBase Database

SQL - V4.4.2

    Download PDF

    OceanBase logo

    The Unified Distributed Database for the AI Era.

    Follow Us
    Products
    OceanBase CloudOceanBase EnterpriseOceanBase Community EditionOceanBase seekdb
    Resources
    DocsBlogLive DemosTraining & Certification
    Company
    About OceanBaseTrust CenterLegalPartnerContact Us
    Follow Us

    © OceanBase 2026. All rights reserved

    Cloud Service AgreementPrivacy PolicySecurity
    Contact Us
    Document Feedback
    1. Documentation Center
    2. OceanBase Database
    3. SQL
    4. V4.4.2
    iconOceanBase Database
    SQL - V 4.4.2
    SQL
    KV
    • V 4.4.2
    • V 4.3.5
    • V 4.3.3
    • V 4.3.1
    • V 4.3.0
    • V 4.2.5
    • V 4.2.2
    • V 4.2.1
    • V 4.2.0
    • V 4.1.0
    • V 4.0.0
    • V 3.1.4 and earlier

    Overview of role management

    Last Updated:2026-04-02 06:23:56  Updated
    share
    What is on this page
    References

    folded

    share

    The Oracle-compatible mode of OceanBase Database supports role management.

    In Oracle-compatible mode, a role is a combination of system and object privileges. By using roles, you can easily manage user privileges.

    Roles have the following characteristics:

    • Roles can be granted system or object privileges.

    • Roles can be granted other roles, that is, roles can include other roles.

    • A user can be granted multiple roles, and a role can also be granted to multiple users.

    Currently, OceanBase Database has the following system roles by default:

    • CONNECT role

      This role provides the CREATE SESSION privilege, which is a system privilege. To grant the CREATE SESSION privilege to a user, you can grant this privilege directly or grant the CONNECT role to the user.

    • RESOURCE role

      This role provides the following system privileges: CREATE CLUSTER, CREATE INDEXTYPE, CREATE OPERATOR, CREATE PROCEDURE, CREATE SEQUENCE, CREATE TABLE, CREATE TRIGGER, and CREATE TYPE.

      You can view the privileges included in this role by querying the DBA_SYS_PRIVS dictionary view.

    • DBA role

      This role is powerful and provides a large number of system privileges, such as DELETE ANY TABLE and GRANT ANY PRIVILEGE.

      You can view the privileges included in this role by querying the DBA_SYS_PRIVS dictionary view.

      Notice

      To ensure database security, grant this role only when necessary.

    • PUBLIC role

      This role applies to all users in a tenant. By default, no privilege is granted to this role.

      If you grant a privilege to the PUBLIC role, all users in the tenant have the privilege. This means that all users can immediately perform operations that are authorized by the privilege.

      Notice

      To ensure database security, only grant a privilege to this role when it is necessary.

    • STANDBY_REPLICATION role

      This role applies to network-based physical standby database scenarios. You can grant this role to a user dedicated for accessing views in the primary tenant. This way, related information in the primary tenant can be accessed from a standby tenant during synchronization.

      By default, this role has the CREATE SESSION system privilege and the privilege to query the following views:

      • GV$OB_LOG_STAT
      • GV$OB_UNITS
      • GV$OB_PARAMETERS
      • DBA_OB_ACCESS_POINT
      • DBA_OB_TENANTS
      • DBA_OB_LS
      • DBA_OB_LS_HISTORY

      To view the privileges of the role, query the DBA_SYS_PRIVS dictionary view.

    References

    For more information about how to manage roles, see the following topics:

    • Create a role

    • Grant a role to another role

    • Grant a role to a user

    • Activate or deactivate roles for a user

    • View roles

    • Modify a role

    • Revoke a role

    • Drop a role

    Previous topic

    Privilege delegation
    Last

    Next topic

    Create a role
    Next
    What is on this page
    References