Manage Global Role Administrators of a Standalone Role

A global role administrator is any user granted the MANAGE ROLES system privilege. However, not all roles can be managed by global role administrators.

When creating a new role, if you specify at least one role administrator, global role administrators will be unable to manage the role. This is because the MANAGE ROLES system privilege is not automatically granted to the role during creation.

For this reason, it is recommended that role administrators not be specified when creating a new role. They should be added after the fact. This ensures that every role can be successfully managed by both role and global role administrators.

By default, at least one role administrator or global role administrator with a login password must exist at all times for each role. This minimum requirement is validated before you can remove the global role administrator or role administrator from a role, or remove a role administrator's administrative rights on a role. The minimum requirement is a configurable database option (MIN_ROLE_ADMINS).

Related concepts
Manage Standalone Role Administrators
Related tasks
Creating a Standalone Role
Deleting a Standalone Role
Adding a Grantee to a Standalone Role
Changing a Grantee's Administrative Rights on a Standalone Role
Removing a Grantee from a Standalone Role
Adding a Role to a Standalone Role
Changing Administrative Rights on an Underlying Role of a Standalone Role
Removing a Role from a Standalone Role
Adding a System Privilege to a Standalone Role
Changing Administrative Rights on a Privilege Granted to a Standalone Role
Removing a System Privilege from a Standalone Role
Generating Standalone Role DDL Commands
Viewing or Modifying Role-Based Standalone Role Properties
Related reference
Role-Based Standalone Role Privilege Summary