Atlas · skill

Databricks Unity Catalog

Databricks Unity Catalog is a governance layer for organizing and controlling access to data and AI assets in Databricks. The skill involves configuring its object hierarchy, privileges and evidence of asset use so shared analytics and model workflows operate under an explicit permission model.

toolData Governance & Catalog

What it is

Unity Catalog represents governed assets as securable objects, with many data and AI objects organized in a catalog, schema and object namespace. Users, groups and service identities receive privileges over these objects, and governed operations can produce lineage and audit information. Managed and external assets differ in responsibility for underlying storage lifecycle. These distinctions matter because permission to use a catalog object is not necessarily the same as direct access to its storage location. Unity Catalog is a platform governance component rather than a complete organizational data policy, and actual enforcement depends on supported compute, integrations and configuration.

What the work involves

The practitioner designs catalog and schema boundaries around ownership, environment and access needs. They configure service identities, privileges and external storage access, then test ordinary and denied operations through the supported interfaces. Useful artifacts include a privilege matrix and a mapping from registered assets to underlying storage responsibilities. Lineage and audit records help investigate use, but coverage must be checked for the actual workload. The team also reviews broad inherited privileges and separates deployment automation from human access so routine operations do not require unnecessary administrative rights.

Illustrative example

A shared lakehouse contains general product data and restricted account information. The engineer places them in governed structures with different group privileges and gives a training job access only to the approved feature view. Tests confirm that the job can train from that view but cannot read raw restricted columns through another supported path. Lineage records then help identify which model artifacts depend on the approved dataset.

Limits and common mistakes

Catalog registration does not automatically eliminate direct-storage access or protect every external copy. Misconfigured identities and broad grants can defeat intended separation, while lineage may omit unsupported paths. The practitioner should verify enforcement with the deployed compute and interfaces rather than infer it from an asset's presence in the catalog. Governance metadata also does not establish data accuracy, lawful processing or an appropriate business purpose.

Prerequisites

No prerequisites.

Related skills

Sources and further reading

Last updated: 2026-10-10