Permissions, Privileges, and Uninstallation
Last updated
This section combines all post-setup administration details, including privilege rationale, cleanup, and uninstallation.
Minimal required app privileges
BIND SERVICE ENDPOINT – Allows the app to bind its internal web/API service endpoint
EXECUTE TASK – Enables scheduled automation
Client-managed resources
Compute Pools, Warehouses, External Access Integrations, and Network Rules are owned, paid for, and controlled by the client.
Benefits
Cost control (all billable compute is client-managed)
Security control (client defines allowed external hosts)
Full app functionality with minimal privileges

There is no automated revoke of previously granted privileges during updates.
Manually remove older grants except: keep BIND SERVICE ENDPOINT and EXECUTE TASK in place.
If services were altered, recreate connections to avoid confusion from legacy configurations.
In Installed Apps, open the app row menu (⋮) → Uninstall.

Confirm to complete removal.

After uninstall
Re-install follows the same process and produces a new Application URL.
Secrets for connectors are destroyed → reconfigure connectors.
Schedules are deleted → re-enable scheduling after re-install.
Last updated