List of Valid System Privileges
The following table lists the names of the valid system privileges that can be granted to and revoked from roles.
| USER_MANAGEMENT | Manage users (given in the security database) | 
| READ_RAW_PAGES | Read pages in raw format using  | 
| CREATE_USER_TYPES | Add/change/delete non-system records in  | 
| USE_NBACKUP_UTILITY | Use nbackup to create database copies | 
| CHANGE_SHUTDOWN_MODE | Shut down database and bring online | 
| TRACE_ANY_ATTACHMENT | Trace other users' attachments | 
| MONITOR_ANY_ATTACHMENT | Monitor (tables  | 
| ACCESS_SHUTDOWN_DATABASE | Access database when it is shut down | 
| CREATE_DATABASE | Create new databases (given in the security database) | 
| DROP_DATABASE | Drop this database | 
| USE_GBAK_UTILITY | Use gbak utility | 
| USE_GSTAT_UTILITY | Use gstat utility | 
| USE_GFIX_UTILITY | Use gfix utility | 
| IGNORE_DB_TRIGGERS | Instruct engine not to run DB-level triggers | 
| CHANGE_HEADER_SETTINGS | Modify parameters in DB header page | 
| SELECT_ANY_OBJECT_IN_DATABASE | Use  | 
| ACCESS_ANY_OBJECT_IN_DATABASE | Access (in any possible way) any object | 
| MODIFY_ANY_OBJECT_IN_DATABASE | Modify (up to drop) any object | 
| CHANGE_MAPPING_RULES | Change authentication mappings | 
| USE_GRANTED_BY_CLAUSE | Use  | 
| GRANT_REVOKE_ON_ANY_OBJECT | 
 | 
| GRANT_REVOKE_ANY_DDL_RIGHT | 
 | 
| CREATE_PRIVILEGED_ROLES | Use  | 
| GET_DBCRYPT_INFO | Get database encryption information | 
| MODIFY_EXT_CONN_POOL | Use command  | 
| REPLICATE_INTO_DATABASE | Use replication API to load change sets into database | 
| PROFILE_ANY_ATTACHMENT | Profile attachments of other users |