Hi Yufei, Thanks for sending this to the list. Dedicated SEMANTIC_MODEL_* privileges look right to me, and the names match the policy analog well (READ/WRITE rather than READ_PROPERTIES/WRITE_PROPERTIES).
Two things I'd keep explicit: - Model privileges should stay independent of table/view privileges in both directions. Deferring source-access checks is fine. - CATALOG_MANAGE_CONTENT and CATALOG_MANAGE_METADATA covering semantic models is the right compatibility story. I wouldn't also treat NAMESPACE_FULL_METADATA or CATALOG_FULL_METADATA as umbrellas here, those mean "full metadata of the namespace/catalog entity" today, and tables/views/policies don't inherit that way. The grant type and the LIST/CREATE split onto namespace/catalog scope look good. WDYT? Thanks, Prithvi S On Sat, Sep 12, 2026 at 5:41 AM Yufei Gu <[email protected]> wrote: > Hi everyone, > > I'd like to get feedback on the API changes in PR #5492 ( > https://github.com/apache/polaris/pull/5492), as suggested during review. > > Today, all semantic model operations require a single privilege, > CATALOG_MANAGE_CONTENT. This PR adds dedicated privileges for list, create, > read, write, drop, full metadata access, and grant management. This enables > finer grant access control, similar to what we implemented for Iceberg > tables/views and Polaris policies. > > Any thoughts on the API shape or privilege names? > > Yufei >
