Add Databricks Unity Catalog access control skill - #3737
Open
arplearningsystems wants to merge 39 commits into
Open
arplearningsystems wants to merge 39 commits into
arplearningsystems wants to merge 39 commits into
Conversation
Fills a gap: no Databricks coverage existed in this repo. Covers RBAC (GRANT/REVOKE, privilege inheritance), ABAC (governed-tag CREATE POLICY), manual row filters/column masks, and system.access audit queries. Every SQL example was verified against live Databricks docs and tested end-to-end against a real workspace, catching and fixing two syntax bugs along the way.
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The Databricks guidance contains access-control and audit-query errors, and unrelated changes introduce broken links and agent-contract inconsistencies.
Get a fresh assessment by requesting another Copilot review.
Review effort: Balanced
Findings: 2
Open (14)
Output schema omits required needs_approval status · New Advertised task type does not match its execution handler · New Output schema omits details for needs_revision findings · New GitHub link uses blob URL for an extension directory · New Two execution rules are concatenated into one list item · New UDF dependency access is assigned to the wrong principal · New Runtime dependency access must be granted to the UDF owner · New Permission audit query uses incorrect actions and no date filter · New Checklist conflates UDF dependency access with EXECUTE privileges · New Audit query uses incorrect action casing and lacks date bounds · New Object audit query uses incorrect casing and scans all history · New ALL PRIVILEGES excludes sensitive Databricks privileges · New Ownership section conflates table ownership with UDF definer rights · New PR scope mixes unrelated changes and lacks coherent validation · New
What changed in this PR
Adds a Databricks Unity Catalog access-control skill, alongside substantial unrelated website, plugin, workflow, extension, and agent updates.
Changes:
- Adds Unity Catalog RBAC, ABAC, filtering, masking, and auditing guidance.
- Introduces Canvas Extensions website support and several AWS/Ember resources.
- Updates external-plugin automation, Gem agents, documentation, and utilities.
| File | Description |
|---|---|
website/src/scripts/pages/index.ts |
Adds extension count |
website/src/scripts/pages/extensions.ts |
Adds extensions page behavior |
website/src/scripts/pages/extensions-render.ts |
Renders extension cards |
website/src/pages/index.astro |
Adds extensions homepage card |
website/src/pages/extensions.astro |
Adds extensions catalog page |
website/README.md |
Documents website development |
website/data/tools.yml |
Adds Ivy Tendril |
website/astro.config.mjs |
Adds social metadata and navigation |
skills/rhino3d-scripts/SKILL.md |
Expands Rhino troubleshooting |
skills/rhino3d-scripts/references/macros-and-loading.md |
Documents rhinocode CLI |
skills/namecheap/SKILL.md |
Adds Namecheap skill |
skills/md-to-docx/scripts/md-to-docx.mjs |
Fixes entity decoding order |
skills/from-the-other-side-wiggins/SKILL.md |
Adds Wiggins profile |
skills/from-the-other-side-quinn/SKILL.md |
Adds Quinn profile |
skills/from-the-other-side-anitta/SKILL.md |
Adds Anitta profile |
skills/excalidraw-diagram-generator/scripts/add-icon-to-diagram.py |
Configures UTF-8 output |
skills/excalidraw-diagram-generator/scripts/add-arrow.py |
Configures UTF-8 output |
skills/databricks-unity-catalog-access-control/SKILL.md |
Adds Unity Catalog guidance |
skills/databricks-unity-catalog-access-control/references/rbac-grants.md |
Documents RBAC and ownership |
skills/databricks-unity-catalog-access-control/references/audit-queries.md |
Adds audit queries |
skills/conventional-branch/SKILL.md |
Adds branch-naming skill |
plugins/project-documenter/skills/md-to-docx/scripts/md-to-docx.mjs |
Mirrors entity-decoding fix |
plugins/gem-team/.github/plugin/plugin.json |
Updates plugin version |
plugins/external.json |
Updates external plugins |
plugins/ember/skills/from-the-other-side-wiggins/SKILL.md |
Packages Wiggins profile |
plugins/ember/skills/from-the-other-side-quinn/SKILL.md |
Packages Quinn profile |
plugins/ember/skills/from-the-other-side-anitta/SKILL.md |
Packages Anitta profile |
plugins/ember/README.md |
Lists new profiles |
plugins/ember/.github/plugin/plugin.json |
Registers new profiles |
plugins/aws-cloud-development/README.md |
Documents AWS plugin |
plugins/aws-cloud-development/agents/terraform-aws-planning.md |
Adds Terraform planner |
plugins/aws-cloud-development/agents/terraform-aws-implement.md |
Adds Terraform implementer |
plugins/aws-cloud-development/agents/aws-serverless-architect.md |
Adds serverless architect |
plugins/aws-cloud-development/agents/aws-principal-architect.md |
Adds principal architect |
plugins/aws-cloud-development/.github/plugin/plugin.json |
Defines AWS plugin |
instructions/use-cliche-data-in-docs.instructions.md |
Improves placeholder guidance |
instructions/qa-engineering-best-practices.instructions.md |
Adds QA guidance |
instructions/powershell-pester-5.instructions.md |
Clarifies skipped tests |
instructions/java-junit5-assertions.instructions.md |
Adds JUnit guidance |
instructions/exclude-prompt-data.instructions.md |
Adds prompt-data rules |
instructions/dotnet-framework.instructions.md |
Clarifies project formats |
hooks/secrets-scanner/scan-secrets.sh |
Broadens token detection |
extensions/gesture-review/package.json |
Adds extension package metadata |
extensions/feedback-themes/package.json |
Adds extension package metadata |
extensions/feedback-themes/extension.mjs |
Adds feedback canvas |
extensions/diagram-viewer/package.json |
Adds extension package metadata |
extensions/color-orb/package.json |
Adds extension package metadata |
extensions/accessibility-kanban/package.json |
Adds extension package metadata |
eng/update-readme.mjs |
Stabilizes locale sorting |
eng/generate-website-data.mjs |
Generates extension metadata |
eng/external-plugin-validation.mjs |
Changes manifest discovery |
eng/external-plugin-intake-state.mjs |
Adds submitter-fix state |
eng/constants.mjs |
Adds extensions directory |
docs/README.plugins.md |
Updates plugin catalog |
CONTRIBUTING.md |
Documents quality gates |
agents/terraform-aws-planning.agent.md |
Adds Terraform planner |
agents/terraform-aws-implement.agent.md |
Adds Terraform implementer |
agents/gem-skill-creator.agent.md |
Revises skill-creation contract |
agents/gem-reviewer.agent.md |
Revises reviewer contract |
agents/gem-mobile-tester.agent.md |
Revises mobile testing contract |
agents/gem-implementer.agent.md |
Revises implementation workflow |
agents/gem-implementer-mobile.agent.md |
Revises mobile implementation |
agents/gem-documentation-writer.agent.md |
Revises documentation workflow |
agents/gem-devops.agent.md |
Revises DevOps workflow |
agents/gem-designer.agent.md |
Revises design workflow |
agents/gem-designer-mobile.agent.md |
Revises mobile design workflow |
agents/gem-debugger.agent.md |
Revises debugger output |
agents/gem-critic.agent.md |
Revises critique output |
agents/gem-code-simplifier.agent.md |
Revises simplifier output |
agents/gem-browser-tester.agent.md |
Revises browser testing |
agents/aws-serverless-architect.agent.md |
Adds AWS serverless agent |
agents/aws-principal-architect.agent.md |
Adds AWS architecture agent |
AGENTS.md |
Updates intake documentation |
.github/workflows/skill-check.yml |
Hardens changed-file handling |
.github/workflows/skill-check-comment.yml |
Changes comment formatting |
.github/workflows/external-plugin-rerun-intake-command.yml |
Removes obsolete workflow |
.github/workflows/external-plugin-rereview.yml |
Changes tracker formatting |
.github/workflows/external-plugin-rereview-command.yml |
Adds command reactions |
.github/workflows/external-plugin-quality-gates.yml |
Adds reusable quality gates |
.github/workflows/external-plugin-intake.yml |
Integrates quality gates |
.github/plugin/marketplace.json |
Regenerates marketplace |
.github/extensions/external-plugins-board/package.json |
Adds board dependencies |
.github/extensions/external-plugins-board/package-lock.json |
Locks board dependencies |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| ```json | ||
| { | ||
| "status": "completed | failed | in_progress | needs_revision | needs_approval", | ||
| "status": "completed | failed | in_progress | needs_revision", |
| - Start with `context_envelope_snapshot` as active execution context: | ||
| - Use `research_digest.relevant_files` as the initial file shortlist. | ||
| - Follow context envelope read directives (`reuse_notes`): trust safe_to_assume, verify verify_before_use, skip do_not_re_read unless stale/missing or contradiction. | ||
| - Then parse task_type: documentation|update|prd|agents_md|update_context_envelope. |
| "conventions": ["string"] | ||
| } | ||
| "scope": "plan | wave", | ||
| "critical_findings": ["SEVERITY file:line — issue"], |
Comment on lines
+64
to
+66
| <a href="${getGitHubUrl( | ||
| item.path | ||
| )}" class="btn btn-secondary btn-small" target="_blank" rel="noopener noreferrer" title="View on GitHub">GitHub</a> |
| - Retry 3x. | ||
| - JSON output only. | ||
| - Tool Execution priority: native tools → workspace tasks → scripts → raw CLI. | ||
| - Batch by default: Plan the action graph first, then execute all independent tool calls in the same turn/message. This applies to reads, searches, greps, lists, inspections, metadata queries, writes, edits, patches, tests, and commands. Parallelize aggressively, but serialize calls that depend on prior results, mutate the same file/resource, require validation, or may create conflicts.- Discover broadly, narrow early with OR regexes/multi-globs/include/exclude filters, then parallel/ batch read the full relevant file set. |
Comment on lines
+36
to
+40
| SELECT event_time, user_identity.email, action_name, request_params | ||
| FROM system.access.audit | ||
| WHERE action_name LIKE '%GRANT%' OR action_name LIKE '%REVOKE%' | ||
| ORDER BY event_time DESC | ||
| LIMIT 100; |
Comment on lines
+46
to
+50
| SELECT event_time, user_identity.email, action_name, request_params | ||
| FROM system.access.audit | ||
| WHERE action_name LIKE '%GRANT%' | ||
| AND request_params.securable_full_name = 'analytics.gold.customers' | ||
| ORDER BY event_time DESC; |
Comment on lines
+41
to
+42
| `ALL PRIVILEGES` grants every privilege applicable to that object type — use sparingly; it's | ||
| usually broader than the actual need. |
Comment on lines
+84
to
+87
| The owner: | ||
| - Can grant/revoke privileges on the object without needing an explicit `MANAGE` grant. | ||
| - Is the identity that row-filter/column-mask UDFs run **as** when attached to the object — | ||
| the owner needs access to anything those UDFs read (e.g., an entitlements table). |
| @@ -170,11 +170,32 @@ const base = import.meta.env.BASE_URL; | |||
| - | |||
| </div> | |||
| </a> | |||
| <a | |||
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Summary
Test plan