Databricks offers a ton of features and is adding more almost daily. However, I still have a wishlist of things I'd love to see: 1. ABAC GRANT and DENY I love tags in Databricks and ABAC provides a ton of value when used right. But currently ABAC only covers Row Level Filtering and Column Masking. Having this on actual securables as either a GRANT or DENY would be huge. 2. Tagging support for more securables Tags are amazingly powerful and will only continue to grow in importance. For best leverage, it's critical that more securables can be tagged. Currently Vector Search Indexes and Endpoints aren't covered yet. 3. More granular Vector Search Index ACLs The Vector Search Index is a powerful tool, but currently you can only share it while also allowing others to change it. A READ ONLY or USE ONLY permission would be great. 4. Serverless Base Environment via API The GUI isn't working well yet, but having this capability over the SDK would be valuable from a platform management perspective. 5. UNDROP for Schemas and Catalogs There's UNDROP TABLE, but once you drop a schema with managed tables, you need to call support. An UNDROP SCHEMA would address these difficult woopsies. 6. VIEW_PERMISSIONS permission To see permissions on a securable you don't own, you need MANAGE. From an operational standpoint, it would be better to view ALL permissions without MANAGE access—just to validate. 7. Role Based Exclusive Access. Some workspaces are now made to address the issue that people can be part of teams where data cannot be combined. In this case Role Based Exclusive Access is brilliant. What's on your Databricks wishlist? #Databricks #UnityCatalog #DataEngineering #DataPlatform #ABAC #DataGovernance #DataSecurity #CloudData #BigData #DataArchitecture
Number 6 is also high on my list. And a more granular access control for folders in Volumes.
Ability to keep an all purpose cluster running during set hours, for example business hours.
To validate accesses is really needed and the MANAGE Permission is too powerful. Also the known issue with the system tables and the manage permission would be nice to be addressed to be able to automate reporting.
This is a solid list. Commenting so it reaches Databricks product team
#6 is much needed 👍🏻
Number 6; And keeping the tree of unity catalog expanded on recent clicked items.
5 would be very nice to have!
#6 imho, May leak important information about principals that not always be accessible by other persons