Lets a principal see an object's details but not query its contents. It sits under MANAGE, is left out of ALL PRIVILEGES, and is the only grant on the metastore that flows down to every object beneath.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains READ METADATA in context, with comparison tables and the common traps.
Terms in this definition
- Principal
A user, group or service principal: anything that can receive a privilege grant.
- MANAGE
A Unity Catalog privilege allowing a principal to grant and revoke access on an object, hand over its ownership and drop it, all without being the owner. It gives no data access by itself and is not part of
ALL PRIVILEGES. - ALL PRIVILEGES
A shortcut grant in Unity Catalog covering every privilege relevant to an object. Four are deliberately left out:
MANAGE,READ METADATAand the two external use privileges for schemas and locations. - Authorisation code
OAuth 2.0 grant used by native and web apps: the user signs in, and the app then acts on their behalf with delegated permissions.
- Metastore
The highest-level Unity Catalog container, holding metadata and permissions for a single cloud region. Each region has only one, which every workspace in that region shares, and it is not meant to be the usual boundary for isolating data.
Related terms
- Cosmos DB Built-in Data Contributor
A native data-plane role in Azure Cosmos DB. Whoever holds it can read metadata, run queries, read the change feed and perform full create, read, update and delete on items; grant it via az cosmosdb sql role assignment create.