The MANAGE privilege no longer requires a usage privilege (USE CATALOG or USE SCHEMA) on the object where MANAGE is granted. This change makes MANAGE behave more consistently with object ownership.
Previously, MANAGE on a catalog or schema took effect only if you also held the appropriate usage privileges on that object. You still need usage privileges on any parent containers:
MANAGE on a catalog requires no usage privileges.
MANAGE on a schema requires USE CATALOG on the parent catalog, but no longer requires USE SCHEMA on the schema.
MANAGE on a table, view, volume, or function is unchanged. It still requires USE CATALOG on the parent catalog and USE SCHEMA on the parent schema.
All other privileges are unaffected and still require usage privileges as prerequisites, even for users with MANAGE. For example, querying a table still requires SELECT on the table, plus USE CATALOG and USE SCHEMA on the parent catalog and schema.
If you granted MANAGE broadly without also granting the corresponding usage privileges, those grants are now active, and holders can manage the object. Databricks recommends auditing existing MANAGE grants to confirm they reflect your intended access. …