Learn PostgreSQL roles
On this page
Follow Acme as its first query grows into an access policy that a team can maintain. The exercises run PostgreSQL in your browser; no database setup is required.
Start with the core story or jump directly to an investigation. Each lab includes its own prepared database, and every Run resets that database, so you can experiment without completing earlier chapters.
Core story
| Lesson | Question to investigate |
|---|---|
| 1. The permission chain | Why can Alice connect but not query a table? |
| 2. Capability roles | How can several identities share scoped access? |
| 3. Access drift | Why does access survive a membership change? |
| 4. Ownership | Which identity should own objects created by migrations? |
| 5. Future objects | Why does a new table lack the grants of an existing table? |
| 6. Offboarding an owner | How can an identity be retired while preserving its objects? |
Advanced investigations
| Lesson | Question to investigate |
|---|---|
| 7. Membership mechanics | How do inheritance, role switching, and membership administration differ? |
| 8. Row-level security | Why can two identities query the same table but see different rows? |
| 9. The security review | Which unexpected paths still permit an operation? |
Keep experimenting
The SQL playground is a sandbox for the core Acme story. Row-policy exercises have their own RLS lab.
Contextual “Explore this change” links open the plan explorer to explain what pgroles would change and what authority the model requires. The PostgreSQL labs demonstrate actual query behaviour; the explorer does not evaluate row policies.
Ready to use pgroles? Go directly to the CLI quick start or operator quick start. This course is optional.