Scheduler Service Account Permissions
When the Bragi Scheduler runs as a Windows Service, the assigned service account needs SQL Server permissions on the Bragi meta database. This page lists the minimum permissions required so DBAs can grant the smallest viable set instead of db_owner or similar broad roles.
Database Scope
The scheduler only ever connects to the meta database (the database containing the bragi schema with job and worker configuration).
It does not need any permissions on warehouse databases. Warehouse access is configured separately through Bragi's per-environment connection strings, which are resolved at runtime by Bragi itself rather than by the scheduler service account.
Required Grants
The scheduler service account needs the following in the meta database:
Permission | Why |
|---|---|
Member of | Covers SELECT on |
Member of | Covers INSERT / UPDATE / DELETE on |
| The scheduler invokes stored procedures in the |
Grants are deliberately at the fixed-role and schema level, not per object. When a Bragi upgrade introduces a new stored procedure or a new table that the scheduler reads or writes, pre-existing installations continue to work without any re-granting.
What the scheduler accesses today
For reference, the scheduler currently calls the following stored procedures in the bragi schema:
Stored procedure | Purpose |
|---|---|
| Records a new job or task instance when work is scheduled |
| Updates |
| Changes the status of a job |
| Changes the status of a single task within a job |
| Updates execution state on a worker instance |
| Checks whether an in-flight worker instance has been asked to abort |
| Reads pending or action-needed instances for an environment |
| Same, scoped to a single job |
| Reads currently unfinished instances |
| Reads the latest finished instance per job |
| Reads worker instances from a point in time |
| Reads child instances of a parent worker instance |
| Toggles the per-environment scheduler pause flag |
And writes Serilog log rows directly to:
Table | Operation |
|---|---|
| INSERT |
The grants above cover all of this, plus any new stored procedures or bragi-schema tables added by future Bragi releases.
Example T-SQL
Run this against the meta database. Replace DOMAIN\BragiSchedulerSvc with the Windows account assigned to the BragiScheduler service.
What is NOT Needed
The scheduler does not require any of the following. If your DBA process defaults to granting them, they can be safely refused for this service account:
db_owner,db_ddladmin,db_securityadminDDL permissions (
CREATE,ALTER,DROP) on tables, procedures, or schemasVIEW DEFINITIONEXECUTE on
sp_send_dbmailor any system stored proceduresAny permissions on warehouse databases
Any permissions on schemas other than
bragi
Verifying the Grants
After applying the grants, start the BragiScheduler service for one environment and confirm the following from bragi.worker_log in the meta database:
An
Informationrow appears for the service starting up.After a scheduled job runs, rows appear for that job's lifecycle (start, task progress, completion).
If startup logs report permission was denied errors, the most common cause is that the Windows account is mapped to the SQL login but is not yet a member of db_datareader/db_datawriter, or has not been granted EXECUTE on the bragi schema.