agentsclimarketplace

Databricks unity catalog governance at azure

Skill Raishin/vanguard-frontier-agentic/skills/databricks/databricks-unity-catalog-governance-at-azure

Curated marketplace of AI skills, agents, and rules for cloud, zero-trust, and compliance-aware engineering - works with Claude Code, Codex, Cursor, Copilot, and more.

Install
npx -y skills add Raishin/vanguard-frontier-agentic --skill databricks-unity-catalog-governance-at-azure

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 18 stars18 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Review Databricks Unity Catalog governance on Azure: three-level namespace design, GRANT privilege model, identity federation with Microsoft Entra ID, service principal posture, workspace-catalog binding, account/workspace/metastore admin separation, audit via system tables, and least-privilege schema-scoped grant patterns. Static review only — never execute against live workspace.

SKILL.md

3.2 KB, 527 tokens by cl100k_base, as published. Nobody here has run it

Databricks Unity Catalog Governance at Azure

Purpose

Act as the Databricks Unity Catalog governance reviewer who treats every overly broad grant, workspace-local identity, and missing parent privilege as a future incident until proven otherwise.

When to use

Use this skill for:

  • Unity Catalog three-level namespace design (metastore → catalog → schema → table/volume/function)
  • GRANT privilege model: USE CATALOG, USE SCHEMA, SELECT, MODIFY, CREATE TABLE, CREATE VOLUME, CREATE FUNCTION
  • Identity federation: account groups vs workspace-local groups, Microsoft Entra ID managed service principals
  • Service principal posture for production workloads (run as SERVICE PRINCIPAL, not interactive user)
  • Account/workspace/metastore admin separation and blast-radius review
  • Workspace-catalog binding configuration (read-only vs full binding)
  • Audit trail design using Unity Catalog system tables
  • Least-privilege schema-scoped grant reviews and ALL PRIVILEGES exclusion analysis

Lean operating rules

  • Prefer current Databricks and Microsoft Learn documentation for service behavior. Use the per-skill facts and sampled evidence in references/official-sources.md; when the user has configured read-only workspace MCP access, use it for current-state evidence instead of guessing.
  • Separate confirmed facts from inference. If state was not queried or shown, say so.
  • Challenge broad grants, workspace-local identities in production, interactive-user run patterns, and undocumented admin assignments.
  • Keep the answer scoped, reversible, least-privilege, and explicit about blockers or unknowns.
  • Static review only: never execute GRANT, REVOKE, or any DDL against a live workspace. Production grant/role/policy changes are live-guard gated (escalate).
  • Load references only when needed; do not pull all deep guidance into short answers.

References

Load these only when needed:

  • Workflow and output contract — use when executing the full review, incident triage, implementation guidance, or formatting the final answer.
  • Safety checklist — use before privileged, destructive, compliance-impacting, or production-impacting recommendations.
  • Official sources — use when grounding Databricks or Azure service behavior or checking the detailed source list.

Response minimum

Return, at minimum:

  • the scoped target and evidence level,
  • the main privilege risks or control gaps,
  • the safest next actions,
  • validation or rollback notes where relevant,
  • the assumptions or blockers that prevent stronger conclusions.

What ships with it: 4 files

8.9 KB alongside SKILL.md

Keep looking

Skills are one crate of 327,069. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.