Sometimes it's needed to create the required user or role and grant it the privileges to work correctly with an app role. The plan is to adjust config's privileges in a way that it revokes only these privileges that were granted by the config itself.