Unity Catalog row filters, column masks & ABAC policies
manage_uc_security_policiesControl Unity Catalog fine-grained access by getting, setting, or dropping row filters and column masks, plus create, update, or delete ABAC policies with confirmation.
Instructions
Manage Unity Catalog fine-grained access control.
Actions:
get(table_name): current row filter + column masks (from table metadata) and ABAC policies in effect.
set_row_filter(table_name, function_name, using_columns) / drop_row_filter(table_name)
set_column_mask(table_name, column_name, function_name, using_columns?) / drop_column_mask(table_name, column_name) These run ALTER TABLE DDL on a SQL warehouse (warehouse_id optional).
list_policies(securable_type, securable_fullname, include_inherited?) / get_policy(+policy_name)
create_policy(securable_type, securable_fullname, policy_name, spec) - spec uses PolicyInfo fields: to_principals, for_securable_type, policy_type (POLICY_TYPE_ROW_FILTER|POLICY_TYPE_COLUMN_MASK), row_filter {function_name, using}, column_mask {function_name, on_column, using}, match_columns, when_condition, except_principals, comment.
update_policy(..., policy_name, spec, update_mask?) / delete_policy(..., policy_name) All changes are security-sensitive: call without confirm to get a plan showing current vs new state, then repeat with confirm=true. Change responses include an audit block (who/what/when).
Safety classification: get, list_policies, get_policy = READ_ONLY+SECURITY_SENSITIVE; set_row_filter, set_column_mask, create_policy, update_policy = SECURITY_SENSITIVE+WRITE; drop_row_filter, drop_column_mask, delete_policy = DESTRUCTIVE+SECURITY_SENSITIVE+WRITE.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| spec | No | Request body fields for create/update, using the Databricks REST API field names (snake_case). Unknown fields are rejected. | |
| action | Yes | get: current row filter, column masks and ABAC policies on table_name; list_policies / get_policy: ABAC policies on a securable; set_row_filter / drop_row_filter / set_column_mask / drop_column_mask: table-bound UDF filters/masks (SQL DDL on a warehouse); create_policy / update_policy / delete_policy: ABAC policies. | |
| confirm | No | Set to true ONLY after the user has reviewed the plan returned by a previous call with status 'confirmation_required'. Required for destructive/security-sensitive actions. | |
| dry_run | No | If true, validate and return the planned change without executing it. | |
| page_size | No | Max items to return (server caps this). | |
| page_token | No | next_page_token from a previous response. | |
| table_name | No | Table full name catalog.schema.table. | |
| column_name | No | Column for set_column_mask / drop_column_mask. | |
| policy_name | No | ABAC policy name (get/update/delete/create). | |
| update_mask | No | update_policy: comma-separated fields to update (default: the keys present in spec). | |
| warehouse_id | No | SQL warehouse for filter/mask DDL (default: configured/auto-selected). | |
| function_name | No | Fully qualified SQL UDF catalog.schema.function used as row filter or column mask. | |
| using_columns | No | set_row_filter: table columns passed to the filter UDF, in order ([] for none). set_column_mask: additional columns passed after the masked column (USING COLUMNS). | |
| securable_type | No | ABAC policies: type of the securable the policy is defined on. | |
| include_inherited | No | list_policies/get: include policies inherited from parent schema/catalog (get defaults to true). | |
| securable_fullname | No | ABAC policies: full name of that catalog / schema / table. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| data | No | ||
| page | No | ||
| plan | No | ||
| tool | Yes | ||
| action | No | ||
| safety | No | ||
| status | No | success | |
| summary | Yes | ||
| warnings | No | ||
| next_steps | No | Suggested follow-up calls. | |
| request_id | No |