↑↓ select ↵ open ⌫ change scope Open full search

PG.CENTER connects PostgreSQL documentation, reference, and ecosystem knowledge. Maintained by Pigsty.

Wiki / Predefined Roles

Predefined Roles

Compare versions

Built-in roles for monitoring, maintenance, data access, server files and connection management.

Reading PostgreSQL 18.6.

16 entries; 16 recorded in PostgreSQL 18.6.

  • pg_create_subscription Administration

    pg_create_subscription

    pg_create_subscription allows users with CREATE permission on the database to issue CREATE SUBSCRIPTION .

  • pg_database_owner Administration

    pg_database_owner

    pg_database_owner always has exactly one implicit member: the current database owner. It cannot be granted membership in any role, and no role can be granted membership in pg_database_owner . However, like any other role, it can own objects and rece…

  • pg_read_all_data Data access

    pg_read_all_data

    pg_read_all_data allows reading all data (tables, views, sequences), as if having SELECT rights on those objects and USAGE rights on all schemas. This role does not bypass row-level security (RLS) policies. If RLS is being used, an administrator may…

  • pg_write_all_data Data access

    pg_write_all_data

    pg_write_all_data allows writing all data (tables, views, sequences), as if having INSERT , UPDATE , and DELETE rights on those objects and USAGE rights on all schemas. This role does not bypass row-level security (RLS) policies. If RLS is being use…

  • pg_checkpoint Maintenance

    pg_checkpoint

    pg_checkpoint allows executing the CHECKPOINT command.

  • pg_maintain Maintenance

    pg_maintain

    pg_maintain allows executing VACUUM , ANALYZE , CLUSTER , REFRESH MATERIALIZED VIEW , REINDEX , and LOCK TABLE on all relations, as if having MAINTAIN rights on those objects.

  • pg_monitor Monitoring and statistics

    pg_monitor

    pg_monitor allows reading/executing various monitoring views and functions. This role is a member of pg_read_all_settings , pg_read_all_stats and pg_stat_scan_tables .

  • pg_read_all_settings Monitoring and statistics

    pg_read_all_settings

    pg_read_all_settings allows reading all configuration variables, even those normally visible only to superusers.

  • pg_read_all_stats Monitoring and statistics

    pg_read_all_stats

    pg_read_all_stats allows reading all pg_stat_* views and use various statistics related extensions, even those normally visible only to superusers.

  • pg_stat_scan_tables Monitoring and statistics

    pg_stat_scan_tables

    pg_stat_scan_tables allows executing monitoring functions that may take ACCESS SHARE locks on tables, potentially for a long time (e.g., pgrowlocks(text) in the pgrowlocks extension).

  • pg_signal_autovacuum_worker Processes and connections

    pg_signal_autovacuum_worker

    pg_signal_autovacuum_worker allows signaling autovacuum workers to cancel the current table's vacuum or terminate its session. See Section 9.28.2 .

  • pg_signal_backend Processes and connections

    pg_signal_backend

    pg_signal_backend allows signaling another backend to cancel a query or terminate its session. Note that this role does not permit signaling backends owned by a superuser. See Section 9.28.2 .

  • pg_use_reserved_connections Processes and connections

    pg_use_reserved_connections

    pg_use_reserved_connections allows use of connection slots reserved via reserved_connections .

  • pg_execute_server_program Server files and programs

    pg_execute_server_program

    pg_execute_server_program allows executing programs on the database server as the user the database runs as using COPY and other functions which allow executing a server-side program.

  • pg_read_server_files Server files and programs

    pg_read_server_files

    pg_read_server_files allows reading files from any location the database can access on the server using COPY and other file-access functions.

  • pg_write_server_files Server files and programs

    pg_write_server_files

    pg_write_server_files allows writing to files in any location the database can access on the server using COPY and other file-access functions.

RecordedFirst recordedInterface or attribute changeNo longer recorded

Squares indicate presence in sampled builds, not first introduction. Select a square for the same-version definition and sources.

Changes in PostgreSQL 18.6 · Export JSON

Reading this collection

Predefined-role privileges can expand across releases. Read the target version before granting membership; object privileges and row-level security retain their own rules.