Bragi Docs Help

Scheduler Service Account Permissions

When the Bragi Scheduler runs as a Windows Service, the assigned service account needs SQL Server permissions on the Bragi meta database. This page lists the minimum permissions required so DBAs can grant the smallest viable set instead of db_owner or similar broad roles.

Database Scope

The scheduler only ever connects to the meta database (the database containing the bragi schema with job and worker configuration).

It does not need any permissions on warehouse databases. Warehouse access is configured separately through Bragi's per-environment connection strings, which are resolved at runtime by Bragi itself rather than by the scheduler service account.

Required Grants

The scheduler service account needs the following in the meta database:

Permission

Why

Member of db_datareader

Covers SELECT on bragi tables for any code that reads directly rather than through a stored procedure

Member of db_datawriter

Covers INSERT / UPDATE / DELETE on bragi tables, including Serilog log writes to bragi.worker_log

GRANT EXECUTE ON SCHEMA::bragi

The scheduler invokes stored procedures in the bragi schema for every job-state change and read

Grants are deliberately at the fixed-role and schema level, not per object. When a Bragi upgrade introduces a new stored procedure or a new table that the scheduler reads or writes, pre-existing installations continue to work without any re-granting.

What the scheduler accesses today

For reference, the scheduler currently calls the following stored procedures in the bragi schema:

Stored procedure

Purpose

bragi.add_worker_instance

Records a new job or task instance when work is scheduled

bragi.update_job_config_scheduler_fields

Updates LastSubmitted, LastCompleted, NextScheduled on a job

bragi.update_job_status

Changes the status of a job

bragi.update_job_task_status

Changes the status of a single task within a job

bragi.update_not_null_columns_on_worker_instance

Updates execution state on a worker instance

bragi.should_abort_worker_instance

Checks whether an in-flight worker instance has been asked to abort

bragi.get_unfinished_or_action_needed_worker_instances

Reads pending or action-needed instances for an environment

bragi.get_unfinished_or_action_needed_worker_instances_for_job

Same, scoped to a single job

bragi.get_unfinished_worker_instances

Reads currently unfinished instances

bragi.get_latest_finished_for_jobs

Reads the latest finished instance per job

bragi.get_worker_instances

Reads worker instances from a point in time

bragi.get_worker_instances_from_parent

Reads child instances of a parent worker instance

bragi.set_scheduler_pause_state

Toggles the per-environment scheduler pause flag

And writes Serilog log rows directly to:

Table

Operation

bragi.worker_log

INSERT

The grants above cover all of this, plus any new stored procedures or bragi-schema tables added by future Bragi releases.

Example T-SQL

Run this against the meta database. Replace DOMAIN\BragiSchedulerSvc with the Windows account assigned to the BragiScheduler service.

-- Map the Windows login into the meta database CREATE USER [DOMAIN\BragiSchedulerSvc] FOR LOGIN [DOMAIN\BragiSchedulerSvc]; -- Fixed-role membership for table reads and writes ALTER ROLE db_datareader ADD MEMBER [DOMAIN\BragiSchedulerSvc]; ALTER ROLE db_datawriter ADD MEMBER [DOMAIN\BragiSchedulerSvc]; -- Stored procedure execution across the bragi schema GRANT EXECUTE ON SCHEMA::bragi TO [DOMAIN\BragiSchedulerSvc];

What is NOT Needed

The scheduler does not require any of the following. If your DBA process defaults to granting them, they can be safely refused for this service account:

  • db_owner, db_ddladmin, db_securityadmin

  • DDL permissions (CREATE, ALTER, DROP) on tables, procedures, or schemas

  • VIEW DEFINITION

  • EXECUTE on sp_send_dbmail or any system stored procedures

  • Any permissions on warehouse databases

  • Any permissions on schemas other than bragi

Verifying the Grants

After applying the grants, start the BragiScheduler service for one environment and confirm the following from bragi.worker_log in the meta database:

  1. An Information row appears for the service starting up.

  2. After a scheduled job runs, rows appear for that job's lifecycle (start, task progress, completion).

If startup logs report permission was denied errors, the most common cause is that the Windows account is mapped to the SQL login but is not yet a member of db_datareader/db_datawriter, or has not been granted EXECUTE on the bragi schema.

02 October 2026