---
summary: The tenant and realm hierarchy, naming rules, console roles and privilege
  profiles.
title: Tenants, realms and names
path: concepts/tenancy
status: published
---

# Tenants, realms and names

A tenant is your organisation. A realm is a namespace inside it that you delegate to a team. Databases and accounts belong to exactly one realm and live on exactly one cluster.

## Naming rules

Every database and account has a physical name `<tenant>_<realm>_<name>`.

| Element | Rule |
|---|---|
| Tenant and realm slug | 2–16 characters, lowercase letters and digits, starts with a letter, no underscore or hyphen |
| Database or account name | 1–30 characters, lowercase letters, digits and single underscores, starts with a letter |
| Physical name | at most 64 characters |

Some names are reserved, for example `mysql`, `sys`, `test`, `root`, `admin`, `default`, `all` and `new`. Account names can reach 64 characters; tools that assume MySQL's 32-character user-name limit may not accept the longest combinations.

## Console roles

| Role | May |
|---|---|
| Tenant admin | everything in every realm; create and delete realms; manage tenant admins and API tokens; purge a deleted database's backups; see usage |
| Realm admin | everything in the realm, including its members |
| Realm operator | create and delete databases and accounts, rotate passwords, change grants, restore and export databases |
| Realm viewer | read configuration, connection information and usage |

Roles are given to users or groups from your identity provider. They control the console and API only; they are not MariaDB accounts.

## Privilege profiles

Grants are expressed as a profile on a scope — never as a raw privilege list.

| Profile | For | Privileges |
|---|---|---|
| `dba` | migrations, schema owners | all database-level privileges except `GRANT OPTION` and `EVENT` |
| `readwrite` | application runtime | `SELECT, INSERT, UPDATE, DELETE, EXECUTE, SHOW VIEW, CREATE TEMPORARY TABLES, LOCK TABLES` |
| `readonly` | reporting | `SELECT, SHOW VIEW, EXECUTE` |

The scope is either one database or the whole realm. A realm-scope `dba` account may run `CREATE DATABASE acme_shop_<anything>` over SQL; Scuttle picks such databases up within five minutes and shows them in the console.

## Account settings

Accounts always require TLS. You may restrict an account to source networks (IPv4 networks, and single IPv6 addresses), set a connection limit (default 100, up to 500) and a maximum statement time. You can change your own password with `SET PASSWORD`; a rotation from the console overwrites it.
