Databricks ABAC

Prev Next
Preproduction Feature

Note that this is a preproduction feature that is available only to preproduction Tenants

This guide provides an overview of SaaS Authorization Management for Databricks ABAC using PlainID.

Databricks ABAC is the attribute-based access control model in Databricks Unity Catalog. ABAC Policies attach at the Catalog, Schema, or Table level and apply automatically to Tables and Columns based on Governed Tags. Each Policy uses a user-defined function (UDF) to filter rows or mask column values at query time.

PlainID connects to Databricks ABAC through a Policy Orchestration Point (POP) and discovers relevant Unity Catalog objects, their Governed Tags, and ABAC Policies with their associated functions, so you can view and audit them centrally in the Platform.

Databricks ABAC is a separate integration type from Databricks.


Supported Mode

The Databricks ABAC integration supports Learn Mode.

In Learn Mode, PlainID discovers your Databricks Unity Catalog objects and ABAC Policies and displays them in the Platform. In Learn Mode, PlainID does not create, update, or deploy Policies to Databricks.

To learn about POP modes, refer to our Orchestration Workspace documentation.


Key Concepts

The Databricks ABAC integration relies on the following Unity Catalog objects:

Object Description
Catalog The top-level container for data assets in Unity Catalog.
Schema A data container for multiple Tables and other objects that helps manage the Catalog.
Table The object that ABAC Policies protect, directly, based on their Governed Tags and/or by inheritance.
Column A Column within a Table. Masking Policies protect Columns based on their Governed Tags.
Governed Tag A tag that ABAC Policies use to decide which Tables and Columns they apply to.
ABAC Policy A Unity Catalog object that applies a row filter or column mask function to Tables/Columns.

For details on Schemas, Functions, and the rest of the Unity Catalog object hierarchy, see the Unity Catalog securable objects reference. For more on ABAC, see Unity Catalog attribute-based access control (ABAC).


Supported Policy Types

PlainID discovers the following Databricks ABAC Policy types:

  • Row filter (Row Access Policy): Restricts which rows a principal can see in a Table, based on function logic that returns TRUE for rows the principal can access.
  • Column mask (Masking Policy): Controls what a principal sees in a Column, based on function logic that returns either the original value or a masked value.

Both Policy types apply to Tables. PlainID discovers Policies attached at the Catalog, Schema, and Table level, including Policies a Table inherits from its Schema or Catalog.


Discovered Objects

When you create a Databricks ABAC POP, PlainID discovers the following objects:

Databricks Object In PlainID
Catalog PlainID displays the Catalog as an ABAC Catalog. The Catalog is the discovery scope of the POP.
Schema PlainID displays the Schema as an ABAC Schema within the Catalog.
Table PlainID displays the Table as an ABAC Table and creates it as an Asset in the Tables Asset Type. Tables are the objects that ABAC Policies protect.
Column PlainID represents Columns with the Databricks ABAC Column Asset Type, which defines the Columns a Masking Policy protects. PlainID does not create an Asset for each Column.
Function (UDF) PlainID displays each function as part of the Policy that references and uses it. PlainID discovers only functions that a discovered Policy references.
Governed Tag PlainID displays Governed Tags as an Asset Attribute on Tables and Columns. For Tables that PlainID creates as Assets, the GovernedTags Asset Attribute includes the actual tags PlainID discovers for each Table (see details below).

Governed Tags

PlainID represents each Governed Tag assigned to a Table or Column as a single value in the format <tagKey>:<tagValue>. A Table with several tags carries several values.

If a Table has a tag key without a value, PlainID represents it as <tagKey>:Key-Only.

Tag in Databricks Value in PlainID
Key pii, value email pii:email
Key pii, no value pii:Key-Only

Policy Details

PlainID identifies each Policy with a Vendor Policy ID that follows the format Databricks uses:

© 2026 PlainID LTD. All rights reserved.