Documentation / Predefined Roles
PostgreSQL Predefined Roles
Built-in roles for monitoring, maintenance, data access, server files and connection management.
Reading PostgreSQL 18.6.
16 entries; 16 recorded in PostgreSQL 18.6.
| Name and purpose | Group | Version history |
|---|---|---|
| pg_create_subscriptionpg_create_subscription pg_create_subscription allows users with CREATE permission on the database to issue CREATE SUBSCRIPTION . |
Administration | |
| pg_database_ownerpg_database_owner pg_database_owner always has exactly one implicit member: the current database owner. It cannot be granted membership in any role, and no role can be granted membership in pg_database_owner . However, like any other role, it can own objects and receive grants of access privileges. Consequently, once pg_database_owner has rights within a template database, each owner of a database instantiated from that template will possess those rights. Initially, this role owns the public schema, so each database owner governs local use of that schema. |
Administration | |
| pg_read_all_datapg_read_all_data pg_read_all_data allows reading all data (tables, views, sequences), as if having SELECT rights on those objects and USAGE rights on all schemas. This role does not bypass row-level security (RLS) policies. If RLS is being used, an administrator may wish to set BYPASSRLS on roles which this role is granted to. |
Data access | |
| pg_write_all_datapg_write_all_data pg_write_all_data allows writing all data (tables, views, sequences), as if having INSERT , UPDATE , and DELETE rights on those objects and USAGE rights on all schemas. This role does not bypass row-level security (RLS) policies. If RLS is being used, an administrator may wish to set BYPASSRLS on roles which this role is granted to. |
Data access | |
| pg_checkpointpg_checkpoint pg_checkpoint allows executing the CHECKPOINT command. |
Maintenance | |
| pg_maintainpg_maintain pg_maintain allows executing VACUUM , ANALYZE , CLUSTER , REFRESH MATERIALIZED VIEW , REINDEX , and LOCK TABLE on all relations, as if having MAINTAIN rights on those objects. |
Maintenance | |
| pg_monitorpg_monitor pg_monitor allows reading/executing various monitoring views and functions. This role is a member of pg_read_all_settings , pg_read_all_stats and pg_stat_scan_tables . |
Monitoring and statistics | |
| pg_read_all_settingspg_read_all_settings pg_read_all_settings allows reading all configuration variables, even those normally visible only to superusers. |
Monitoring and statistics | |
| pg_read_all_statspg_read_all_stats pg_read_all_stats allows reading all pg_stat_* views and use various statistics related extensions, even those normally visible only to superusers. |
Monitoring and statistics | |
| pg_stat_scan_tablespg_stat_scan_tables pg_stat_scan_tables allows executing monitoring functions that may take ACCESS SHARE locks on tables, potentially for a long time (e.g., pgrowlocks(text) in the pgrowlocks extension). |
Monitoring and statistics | |
| pg_signal_autovacuum_workerpg_signal_autovacuum_worker pg_signal_autovacuum_worker allows signaling autovacuum workers to cancel the current table's vacuum or terminate its session. See Section 9.28.2 . |
Processes and connections | |
| pg_signal_backendpg_signal_backend pg_signal_backend allows signaling another backend to cancel a query or terminate its session. Note that this role does not permit signaling backends owned by a superuser. See Section 9.28.2 . |
Processes and connections | |
| pg_use_reserved_connectionspg_use_reserved_connections pg_use_reserved_connections allows use of connection slots reserved via reserved_connections . |
Processes and connections | |
| pg_execute_server_programpg_execute_server_program pg_execute_server_program allows executing programs on the database server as the user the database runs as using COPY and other functions which allow executing a server-side program. |
Server files and programs | |
| pg_read_server_filespg_read_server_files pg_read_server_files allows reading files from any location the database can access on the server using COPY and other file-access functions. |
Server files and programs | |
| pg_write_server_filespg_write_server_files pg_write_server_files allows writing to files in any location the database can access on the server using COPY and other file-access functions. |
Server files and programs |
RecordedFirst recordedInterface or attribute changeNo longer recorded
Squares indicate presence in sampled builds, not first introduction. Select a square for the same-version definition and sources.
Reading this collection
Predefined-role privileges can expand across releases. Read the target version before granting membership; object privileges and row-level security retain their own rules.