account_admin
or the resource owner.
Privileges can be granted to custom roles by account_admin
or the resource owner. For example, the owner of a table can grant SELECT
privileges on that table to a custom role.
For more information about creating roles, see creating a custom role via SQL or the Firebolt UI.