---
title: Snowflake Introduces UBAC - What it Means For RBAC
description: Snowflake's new UBAC feature grants permissions directly to users, offering flexibility but potentially complicating governance compared to the traditional RBAC approach.
---

[Ippon Blog](https://blog.ippon.tech)

# [Snowflake Introduces UBAC - What it Means For RBAC](https://blog.ippon.tech/snowflake-introduces-ubac-what-it-means-for-rbac)

 Written by [Adam Tobin](https://blog.ippon.tech/author/adam-tobin) | June 4, 2025

# **User Based Access Controls**

Snowflake has introduced **User-Based Access Controls (UBAC)**, allowing administrators to grant permissions directly to individual users. This is a shift from the traditional Role-Based Access Control **(RBAC)** model, where privileges are assigned to roles, which are then granted to users.

Snowflake’s internal mechanism to determine whether or not a user has access to a specific privilege through **UBAC** is only honored if the session has USE SECONDARY ROLE set to ALL. Fortunately, this is the default setting for all users as of the 2024\_08 release bundle.

## **Wait… Secondary Roles?**

The introduction of UBAC has brought to light a feature that is not at all new, but one that many users are unaware of. Secondary roles allow a session to inherit privileges from *all* roles assigned to a user—not just the active one. In other words, secondary roles enable *aggregating all of the grants assigned to all of the roles assigned to the user*. That’s a mouthful - right? Let’s look at a quick example:

Suppose my user ATOBIN has two roles:

- ATOBIN\_OWNER: Has ownership over SAMPLE\_DB and its objects.
- ATOBIN\_USER: Has NO access to SAMPLE\_DB.

Next, suppose I set ATOBIN\_USER as my active role and run a select statement on a table inside of SAMPLE\_DB:

- With USE SECONDARY ROLES ALL - the query **succeeds**.  
    - This is because Snowflake identifies that ATOBIN\_OWNER is granted to my user, which DOES have sufficient privileges 
- With USE SECONDARY ROLES NONE -  the query **fails.** 
    -  This is because Snowflake correctly identifies that my active role, ATOBIN\_USER, does NOT have sufficient privileges.

## **Back to UBAC**

There’s not much to implementing UBAC. Users simply grant permissions directly to a user instead of to a role. Below is the difference between granting access to a procedure using both RBAC and UBAC.

## **RBAC**:

CREATE ROLE <ROLE\_NAME>;

GRANT USAGE ON PROCEDURE <PROC\_NAME> TO ROLE <ROLE\_NAME>;

GRANT ROLE <ROLE\_NAME> TO USER <USER\_NAME>;

**UBAC**:

GRANT USAGE ON PROCEDURE <PROC\_NAME> TO USER <USER\_NAME>;

Sure, UBAC saves a couple of lines of code… But does it save you time in the long run?

## **Why I think RBAC is the right choice**

UBAC adds flexibility and an additional option for control over security within an organization—and that’s great. But just because you *can* grant privileges directly to users doesn’t necessarily mean that you *should*.

In theory, skipping the creation of a role to give one person access to one object sounds efficient. In practice, it complicates governance. When privileges are assigned through roles, it’s easy for admins to audit access: just look at which users have which roles. With UBAC, you now have to check each user individually to see what direct grants they’ve been given.

## **Final Thoughts**

I fully support Snowflake adding this feature, as I believe it’s important to allow customers to secure their data in whichever way they deem best for their company. But in my view, **RBAC remains the cleaner, more scalable approach**, especially for organizations concerned with visibility, security, and maintainability.

UBAC may have its use cases, but for most teams, this feels like one of those situations that fits the motto, ‘Just because you can, doesn’t mean you should.’

I’d love to hear how others plan to use UBAC, or if anyone’s found a compelling use case I haven’t considered!

[View full post](https://blog.ippon.tech/snowflake-introduces-ubac-what-it-means-for-rbac)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Adam Tobin"
  },
  "dateModified" : "2025-06-04T19:14:11.423Z",
  "datePublished" : "2025-06-04T19:14:11Z",
  "headline" : "Snowflake Introduces UBAC - What it Means For RBAC",
  "image" : {
    "@type" : "ImageObject",
    "height" : 1080,
    "url" : "https://43687852.fs1.hubspotusercontent-na1.net/hubfs/43687852/Ippon-1.png",
    "width" : 1920
  },
  "mainEntityOfPage" : "https://blog.ippon.tech/snowflake-introduces-ubac-what-it-means-for-rbac",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "Ippon Blog"
  }
}
```