Databricks connector
Discovery, enforcement (including Unity Catalog column masks), access intelligence, migration import and grant drift.
Before you start
- A Unity Catalog–enabled workspace.
- An OAuth service principal for Trinitis (recommended).
- A SQL warehouse the service principal can use.
- A metastore admin to grant access to the system audit tables.
What Trinitis reads
- Catalog, schema, table and column metadata from Unity Catalog
- Existing grants
- The system.access.audit table, for access intelligence
Trinitis stores metadata only. It never copies data values out of Databricks.
What Trinitis writes
- Unity Catalog grants for approved policies
- Column masks (functions created in governed schemas)
- Workspace groups and membership
Trinitis writes only policies you have approved, into Databricks's own native controls.
Required privileges
Grant only what you need for the capabilities you plan to use.
Discovery (per catalog)
- USE CATALOG
- BROWSE
Discovery and enforcement (per governed schema)
- USE SCHEMA
- SELECT
- MANAGE
- CREATE FUNCTION
Access intelligence (granted by a metastore admin)
- USE CATALOG system
- USE SCHEMA system.access
- SELECT ON system.access.audit
SQL warehouse
- SQL entitlement
- "Can use" on the SQL warehouse
Group provisioning and mask verification
- Workspace "Admin access" entitlement
About the SELECT privilege
This platform exposes no metadata-only option, so the SELECT privilege that reveals column metadata is the same privilege that can read rows. Trinitis reads only schema and column metadata and stores no row values, but the credential is capable of reading data and should be evaluated on that basis.
See Security for how this compares across platforms.
Steps
- Create the OAuth service principal and grant the privileges above for the capabilities you want.
- Sign in at app.trinitis.ai and open Connections → Add Connection → Databricks.
- Enter the connection details for the workspace, SQL warehouse and OAuth service principal.
- Click Test Connection. A green banner means Trinitis has full visibility; a yellow banner means access is limited and lists the privileges to add.
- Click Scan Now. Discovered objects appear under Resources, with sensitive columns tagged automatically from their names.