Secure schema information

The schema information and corresponding operation information is stored in system and system_schema keyspaces.

When HCD Unified Authentication is enabled, non-superuser roles are granted access to certain system and schema tables by default. The following table describes the default access levels.

Roles with SUPERUSER privileges have full access to all system and schema tables.

Keyspace Table Default access

system

local

FULL

All roles have full access to the local table to support essential cluster functionality.

system

peers

FULL

All roles have full access to the peers table to support essential cluster functionality.

system

size_estimates

FULL

system

available_ranges

FULL

system

sstable_activity

NONE

system

IndexInfo

NONE

system

built_views

NONE

system

views_builds_in_progress

NONE

system

batches

NONE

system

paxos

NONE

system

peer_events

NONE

system

range_xfers

NONE

system

compaction_history

NONE

system

transferred_ranges

NONE

system

prepared_statements

NONE

system

repairs

NONE

system_schema

aggregates

FULL

system_schema

columns

FULL

system_schema

dropped_columns

FULL

system_schema

hidden_columns

FULL

system_schema

functions

FULL

system_schema

indexes

FULL

system_schema

keyspaces

FULL

system_schema

tables

FULL

system_schema

triggers

FULL

system_schema

types

FULL

system_schema

views

FULL

system_auth

All tables

NONE

By default, roles without superuser privileges have no access to this keyspace. To allow access, grant SELECT permission on this keyspace or a specific table.

system_traces

All tables

NONE

By default, roles without superuser privileges have no access to this keyspace. To allow access, grant SELECT permission on this keyspace or a specific table.

system_distributed

All tables

NONE

By default, roles without superuser privileges have no access to this keyspace. To allow access, grant SELECT permission on this keyspace or a specific table.

Example

The following uses an internal non-superuser account, martin.

  1. Create internal login role using cqlsh:

    CREATE ROLE martin WITH LOGIN = true AND PASSWORD = 'password';
  2. Login as martin:

    LOGIN martin
  3. Count the number of tables in system_schema.tables that martin can list:

    SELECT count(*) FROM system_schema.tables;

    The results is the number of tables that exist cluster-wide.

     count
    -------
        75
    
    (1 rows)

Was this helpful?

Give Feedback

How can we improve the documentation?

© Copyright IBM Corporation 2026 | Privacy policy | Terms of use |  Manage Privacy Choices

Apache, Apache Cassandra, Cassandra, Apache Tomcat, Tomcat, Apache Lucene, Apache Solr, Apache Hadoop, Hadoop, Apache Pulsar, Pulsar, Apache Spark, Spark, Apache TinkerPop, TinkerPop, Apache Kafka and Kafka are either registered trademarks or trademarks of the Apache Software Foundation or its subsidiaries in Canada, the United States and/or other countries. Kubernetes is the registered trademark of the Linux Foundation.

General Inquiries: Contact IBM