Skip to content

Add Databricks Unity Catalog access control skill - #3737

Open
arplearningsystems wants to merge 39 commits into
github:stagedfrom
arplearningsystems:add-databricks-unity-catalog-access-control-skill
Open

arplearningsystems wants to merge 39 commits into
github:stagedfrom
arplearningsystems:add-databricks-unity-catalog-access-control-skill

Conversation

@arplearningsystems

Copy link
Copy Markdown

Summary

  • Adds a Databricks Unity Catalog access control skill (RBAC, ABAC, row filters, column masks, audit queries).
  • No prior Databricks coverage existed in this repo.
  • All SQL examples tested against a live Databricks workspace.

Test plan

  • npm run skill:validate passes
  • npm run build passes, skill appears in docs/README.skills.md
  • All SQL statements verified against a live Databricks workspace

github-actions Bot and others added 9 commits June 10, 2026 04:34
Fills a gap: no Databricks coverage existed in this repo. Covers RBAC
(GRANT/REVOKE, privilege inheritance), ABAC (governed-tag CREATE POLICY),
manual row filters/column masks, and system.access audit queries.

Every SQL example was verified against live Databricks docs and tested
end-to-end against a real workspace, catching and fixing two syntax bugs
along the way.
Copilot AI balanced review requested due to automatic review settings September 24, 2026 21:21

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The Databricks guidance contains access-control and audit-query errors, and unrelated changes introduce broken links and agent-contract inconsistencies.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 2 High severity · 2 Medium severity · 10 Low severity

Open (14)
What changed in this PR

Adds a Databricks Unity Catalog access-control skill, alongside substantial unrelated website, plugin, workflow, extension, and agent updates.

Changes:

  • Adds Unity Catalog RBAC, ABAC, filtering, masking, and auditing guidance.
  • Introduces Canvas Extensions website support and several AWS/Ember resources.
  • Updates external-plugin automation, Gem agents, documentation, and utilities.
File Description
website/​src/​scripts/​pages/​index.ts Adds extension count
website/​src/​scripts/​pages/​extensions.ts Adds extensions page behavior
website/​src/​scripts/​pages/​extensions-render.ts Renders extension cards
website/​src/​pages/​index.astro Adds extensions homepage card
website/​src/​pages/​extensions.astro Adds extensions catalog page
website/​README.md Documents website development
website/​data/​tools.yml Adds Ivy Tendril
website/​astro.config.mjs Adds social metadata and navigation
skills/​rhino3d-scripts/​SKILL.md Expands Rhino troubleshooting
skills/​rhino3d-scripts/​references/​macros-and-loading.md Documents rhinocode CLI
skills/​namecheap/​SKILL.md Adds Namecheap skill
skills/​md-to-docx/​scripts/​md-to-docx.mjs Fixes entity decoding order
skills/​from-the-other-side-wiggins/​SKILL.md Adds Wiggins profile
skills/​from-the-other-side-quinn/​SKILL.md Adds Quinn profile
skills/​from-the-other-side-anitta/​SKILL.md Adds Anitta profile
skills/​excalidraw-diagram-generator/​scripts/​add-icon-to-diagram.py Configures UTF-8 output
skills/​excalidraw-diagram-generator/​scripts/​add-arrow.py Configures UTF-8 output
skills/​databricks-unity-catalog-access-control/​SKILL.md Adds Unity Catalog guidance
skills/​databricks-unity-catalog-access-control/​references/​rbac-grants.md Documents RBAC and ownership
skills/​databricks-unity-catalog-access-control/​references/​audit-queries.md Adds audit queries
skills/​conventional-branch/​SKILL.md Adds branch-naming skill
plugins/​project-documenter/​skills/​md-to-docx/​scripts/​md-to-docx.mjs Mirrors entity-decoding fix
plugins/​gem-team/​.github/​plugin/​plugin.json Updates plugin version
plugins/​external.json Updates external plugins
plugins/​ember/​skills/​from-the-other-side-wiggins/​SKILL.md Packages Wiggins profile
plugins/​ember/​skills/​from-the-other-side-quinn/​SKILL.md Packages Quinn profile
plugins/​ember/​skills/​from-the-other-side-anitta/​SKILL.md Packages Anitta profile
plugins/​ember/​README.md Lists new profiles
plugins/​ember/​.github/​plugin/​plugin.json Registers new profiles
plugins/​aws-cloud-development/​README.md Documents AWS plugin
plugins/​aws-cloud-development/​agents/​terraform-aws-planning.md Adds Terraform planner
plugins/​aws-cloud-development/​agents/​terraform-aws-implement.md Adds Terraform implementer
plugins/​aws-cloud-development/​agents/​aws-serverless-architect.md Adds serverless architect
plugins/​aws-cloud-development/​agents/​aws-principal-architect.md Adds principal architect
plugins/​aws-cloud-development/​.github/​plugin/​plugin.json Defines AWS plugin
instructions/​use-cliche-data-in-docs.instructions.md Improves placeholder guidance
instructions/​qa-engineering-best-practices.instructions.md Adds QA guidance
instructions/​powershell-pester-5.instructions.md Clarifies skipped tests
instructions/​java-junit5-assertions.instructions.md Adds JUnit guidance
instructions/​exclude-prompt-data.instructions.md Adds prompt-data rules
instructions/​dotnet-framework.instructions.md Clarifies project formats
hooks/​secrets-scanner/​scan-secrets.sh Broadens token detection
extensions/​gesture-review/​package.json Adds extension package metadata
extensions/​feedback-themes/​package.json Adds extension package metadata
extensions/​feedback-themes/​extension.mjs Adds feedback canvas
extensions/​diagram-viewer/​package.json Adds extension package metadata
extensions/​color-orb/​package.json Adds extension package metadata
extensions/​accessibility-kanban/​package.json Adds extension package metadata
eng/​update-readme.mjs Stabilizes locale sorting
eng/​generate-website-data.mjs Generates extension metadata
eng/​external-plugin-validation.mjs Changes manifest discovery
eng/​external-plugin-intake-state.mjs Adds submitter-fix state
eng/​constants.mjs Adds extensions directory
docs/​README.plugins.md Updates plugin catalog
CONTRIBUTING.md Documents quality gates
agents/​terraform-aws-planning.agent.md Adds Terraform planner
agents/​terraform-aws-implement.agent.md Adds Terraform implementer
agents/​gem-skill-creator.agent.md Revises skill-creation contract
agents/​gem-reviewer.agent.md Revises reviewer contract
agents/​gem-mobile-tester.agent.md Revises mobile testing contract
agents/​gem-implementer.agent.md Revises implementation workflow
agents/​gem-implementer-mobile.agent.md Revises mobile implementation
agents/​gem-documentation-writer.agent.md Revises documentation workflow
agents/​gem-devops.agent.md Revises DevOps workflow
agents/​gem-designer.agent.md Revises design workflow
agents/​gem-designer-mobile.agent.md Revises mobile design workflow
agents/​gem-debugger.agent.md Revises debugger output
agents/​gem-critic.agent.md Revises critique output
agents/​gem-code-simplifier.agent.md Revises simplifier output
agents/​gem-browser-tester.agent.md Revises browser testing
agents/​aws-serverless-architect.agent.md Adds AWS serverless agent
agents/​aws-principal-architect.agent.md Adds AWS architecture agent
AGENTS.md Updates intake documentation
.github/​workflows/​skill-check.yml Hardens changed-file handling
.github/​workflows/​skill-check-comment.yml Changes comment formatting
.github/​workflows/​external-plugin-rerun-intake-command.yml Removes obsolete workflow
.github/​workflows/​external-plugin-rereview.yml Changes tracker formatting
.github/​workflows/​external-plugin-rereview-command.yml Adds command reactions
.github/​workflows/​external-plugin-quality-gates.yml Adds reusable quality gates
.github/​workflows/​external-plugin-intake.yml Integrates quality gates
.github/​plugin/​marketplace.json Regenerates marketplace
.github/​extensions/​external-plugins-board/​package.json Adds board dependencies
.github/​extensions/​external-plugins-board/​package-lock.json Locks board dependencies

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

```json
{
"status": "completed | failed | in_progress | needs_revision | needs_approval",
"status": "completed | failed | in_progress | needs_revision",
- Start with `context_envelope_snapshot` as active execution context:
- Use `research_digest.relevant_files` as the initial file shortlist.
- Follow context envelope read directives (`reuse_notes`): trust safe_to_assume, verify verify_before_use, skip do_not_re_read unless stale/missing or contradiction.
- Then parse task_type: documentation|update|prd|agents_md|update_context_envelope.
"conventions": ["string"]
}
"scope": "plan | wave",
"critical_findings": ["SEVERITY file:line — issue"],
Comment on lines +64 to +66
<a href="${getGitHubUrl(
item.path
)}" class="btn btn-secondary btn-small" target="_blank" rel="noopener noreferrer" title="View on GitHub">GitHub</a>
- Retry 3x.
- JSON output only.
- Tool Execution priority: native tools → workspace tasks → scripts → raw CLI.
- Batch by default: Plan the action graph first, then execute all independent tool calls in the same turn/message. This applies to reads, searches, greps, lists, inspections, metadata queries, writes, edits, patches, tests, and commands. Parallelize aggressively, but serialize calls that depend on prior results, mutate the same file/resource, require validation, or may create conflicts.- Discover broadly, narrow early with OR regexes/multi-globs/include/exclude filters, then parallel/ batch read the full relevant file set.
Comment on lines +36 to +40
SELECT event_time, user_identity.email, action_name, request_params
FROM system.access.audit
WHERE action_name LIKE '%GRANT%' OR action_name LIKE '%REVOKE%'
ORDER BY event_time DESC
LIMIT 100;
Comment on lines +46 to +50
SELECT event_time, user_identity.email, action_name, request_params
FROM system.access.audit
WHERE action_name LIKE '%GRANT%'
AND request_params.securable_full_name = 'analytics.gold.customers'
ORDER BY event_time DESC;
Comment on lines +41 to +42
`ALL PRIVILEGES` grants every privilege applicable to that object type — use sparingly; it's
usually broader than the actual need.
Comment on lines +84 to +87
The owner:
- Can grant/revoke privileges on the object without needing an explicit `MANAGE` grant.
- Is the identity that row-filter/column-mask UDFs run **as** when attached to the object —
the owner needs access to anything those UDFs read (e.g., an entitlements table).
@@ -170,11 +170,32 @@ const base = import.meta.env.BASE_URL;
-
</div>
</a>
<a

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants