Administrator mapping
User subjects bound to the organization-level Organization Admin role (org-admin) are synchronized as SQLWorkspace engine SUPERUSER identities. The legacy admin role is treated the same way.
Other cloud roles and service-account subjects are not included in this mapping. A cloud role that permits SQLWorkspace management does not otherwise grant permissions inside the engine.
Engine administrator privileges are required for operations such as managing engine users and privileges. A SUPERUSER can also perform object operations that another SQL identity is not permitted to perform.
Identity lifecycle
When a qualifying user is added to an organization role binding, each SQLWorkspace reconciles that user into its engine. When the user is removed from all qualifying bindings, the managed engine identity is reconciled withoutSUPERUSER privileges.
Manage the cloud role binding instead of manually changing the synchronized user’s administrator status inside the engine.