Learn PostgreSQL roles

On this page

Follow Acme as its first query grows into an access policy that a team can maintain. The exercises run PostgreSQL in your browser; no database setup is required.

Start with the core story or jump directly to an investigation. Each lab includes its own prepared database, and every Run resets that database, so you can experiment without completing earlier chapters.

Core story

LessonQuestion to investigate
1. The permission chainWhy can Alice connect but not query a table?
2. Capability rolesHow can several identities share scoped access?
3. Access driftWhy does access survive a membership change?
4. OwnershipWhich identity should own objects created by migrations?
5. Future objectsWhy does a new table lack the grants of an existing table?
6. Offboarding an ownerHow can an identity be retired while preserving its objects?

Advanced investigations

LessonQuestion to investigate
7. Membership mechanicsHow do inheritance, role switching, and membership administration differ?
8. Row-level securityWhy can two identities query the same table but see different rows?
9. The security reviewWhich unexpected paths still permit an operation?

Keep experimenting

The SQL playground is a sandbox for the core Acme story. Row-policy exercises have their own RLS lab.

Contextual “Explore this change” links open the plan explorer to explain what pgroles would change and what authority the model requires. The PostgreSQL labs demonstrate actual query behaviour; the explorer does not evaluate row policies.

Ready to use pgroles? Go directly to the CLI quick start or operator quick start. This course is optional.