Skip to main content
SQL Workspaces use separate permission layers for cloud resources and SQLWorkspace engine operations. Permission in one layer does not automatically grant the same level of permission in the other. For example, a user who can manage a SQLWorkspace in the Cloud Console is not necessarily an administrator inside its SQLWorkspace engine.

Private Preview administrator mapping

During Private Preview, user subjects bound to the organization-level Organization Admin role (org-admin) are synchronized as SQLWorkspace engine superusers. The legacy admin role is treated the same way. Other cloud roles and service-account subjects are not included in this mapping. The same engine permissions apply whether a user submits SQL through SQL Studio or a native PostgreSQL client.

Cloud resource access

Understand access to SQLWorkspace and SQLCatalog resources.

SQLWorkspace engine access

Understand SQL identities and engine administrator access.