Release· Databricks release notes

MANAGE no longer needs a USAGE grant on the same object

Holding MANAGE on an object stopped requiring the usage privilege on that object; the privileges on its parent container are still required. A behaviour change, so a permission model built before August may now grant more than it reads like.

Read the original

What to re-read