Manage Unity Catalog grants
manage_uc_grantsShow, grant, and revoke Unity Catalog privileges on any securable, including inherited grants.
Instructions
Show, grant and revoke Unity Catalog privileges on any securable (catalog, schema, table/view, volume, function, external_location, storage_credential, connection, share, metastore, ...).
get returns direct grants, get_effective includes privileges inherited from parents. grant/revoke require principal + privileges and always show the principal's before/after direct privileges in the plan. ALL_PRIVILEGES is rejected unless allow_all_privileges=true; grants to 'account users' are flagged.
Safety classification: get, get_effective = READ_ONLY+SECURITY_SENSITIVE; grant = SECURITY_SENSITIVE+WRITE; revoke = DESTRUCTIVE+SECURITY_SENSITIVE.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| action | Yes | get: direct grants; get_effective: incl. inherited; grant / revoke privileges. | |
| confirm | No | Set to true ONLY after the user has reviewed the plan returned by a previous call with status 'confirmation_required'. Required for destructive/security-sensitive actions. | |
| dry_run | No | If true, validate and return the planned change without executing it. | |
| full_name | Yes | Full name of the securable, e.g. 'main.sales.orders' (metastore: the metastore id). | |
| page_size | No | Max items to return (server caps this). | |
| principal | No | User email, group name or service principal application id. Required for grant/revoke; optional filter for get. | |
| page_token | No | next_page_token from a previous response. | |
| privileges | No | Privileges for grant/revoke, e.g. ['SELECT', 'USE_SCHEMA'] (spaces allowed: 'USE CATALOG'). | |
| securable_type | Yes | Securable type: agent_service, catalog, clean_room, connection, credential, external_location, external_metadata, function, mcp_service, metastore, model, model_provider_service, model_service, pipeline, provider, recipient, schema, share, skill, staging_table, storage_credential, table, volume. Views use 'table'. | |
| allow_all_privileges | No | Must be true to grant ALL_PRIVILEGES. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| data | No | ||
| page | No | ||
| plan | No | ||
| tool | Yes | ||
| action | No | ||
| safety | No | ||
| status | No | success | |
| summary | Yes | ||
| warnings | No | ||
| next_steps | No | Suggested follow-up calls. | |
| request_id | No |