databricks Databricks Release Notes ·

Databricks: READ METADATA Privilege to Be Default for Compliance Profiles

securitydatabricksarchitect
feature

Databricks will make the READ METADATA privilege available by default for workspaces with the compliance security profile enabled in mid-October 2026. This privilege provides read-only visibility into an object's metadata, including security-sensitive details like privilege grants, row filters, column masks, and ABAC policies. It is designed for users who need to inspect and debug access controls, such as security auditors, data governance teams, and site reliability engineers. The change aims to streamline access control oversight for these specialized roles.

Features (1)
  • READ METADATA Privilege to Be Default for Compliance Security Profiles

    The READ METADATA privilege will be available by default for Databricks workspaces with the compliance security profile enabled, effective mid-October 2026. This privilege grants read-only access to an object's metadata, including sensitive information not exposed by the BROWSE privilege, such as privilege grants, row filters, column masks, and attribute-based access control (ABAC) policies. It is intended for security auditors, data governance teams, and site reliability engineers who need to inspect and debug access controls.

Read the original announcement →

https://docs.databricks.com/aws/en/release-notes/whats-coming#the-read-metadata-privilege-will-soon-be-available-by-default-for-workspaces-with-the-compliance-security-profile-enabled

Related releases