Roles and Permissions

Roles and Permissions is a practical SQL concept used to design, query, secure, operate, or analyze relational data correctly.

Lesson content

Roles and Permissions Roles and Permissions is a practical SQL concept used to design, query, secure, operate, or analyze relational data correctly. Example GRANT SELECT ON orders TO report_reader; Key point Use the smallest correct statement, test it with representative data, and verify constraints and performance before production use. Real-life example A reporting application needs read-only access while administrators retain controlled write access. User input, changes, and recovery procedures must be safe. Advanced example -- Bind :email as a driver parameter; never concatenate input. SELECT id, name FROM users WHERE email = :email; GRANT SELECT ON orders TO report_reader; Expected result The schema or operation satisfies the stated rule, rejects invalid data, and can be verified with a repeatable query. Production check Test with empty, duplicate, null, and boundary values. Use a transaction for related writes. Inspect the execution plan before adding an index. Use parameterized queries for application input. Continue with the PicoStore database This lesson reuses picostore . Relevant tables: customers, products, orders, order_items . Keep the starter rows from the Introduction lesson so results remain comparable. Another practical example -- Bind :email through the application database driver. SELECT customer_id, name FROM customers WHERE email = :email; GRANT SELECT ON orders TO report_reader; Check the result Run the verification query, compare the returned rows with the starter data, and explain why every included or excluded row is correct. Easy example Start with a small customer table and retrieve active customers in a predictable order. SELECT customer_id, name, email FROM customers WHERE status = 'active' ORDER BY name; How to verify the easy example Run it with representative input. Confirm the expected output. Try one missing, invalid, or boundary value. Advanced example Use a CTE and a window function to rank customer revenue while keeping the query readable and testable. WITH customer_revenue AS ( SELECT customer_id, SUM(total_amount) AS revenue FROM orders WHERE order_status = 'completed' GROUP BY customer_id ) SELECT customer_id, revenue, DENSE_RANK() OVER (ORDER BY revenue DESC) AS revenue_rank FROM customer_revenue ORDER BY revenue_rank, customer_id; Advanced review Explain the tradeoffs and assumptions. Test failure, scale, security, and recovery behavior. Capture evidence from tests, execution plans, logs, or review output. Additional practical guidance Roles and Permissions: MySQL and PostgreSQL Administration commands and tools differ between MySQL and PostgreSQL. Use least privilege, parameterized queries, encrypted backups, and a tested restore or rollback procedure. Required verification Run the simple case. Test a NULL, duplicate, empty, or boundary case where relevant. Confirm the affected rows or query result. Use EXPLAIN for performance-sensitive queries.