Unity Catalog governance, access control, and observability. Use to grant or revoke access (GRANT/REVOKE), reason about the privilege model and ownership, set up row-level security and column masks, create external locations and storage credentials, define catalogs/schemas/tables/volumes, answer \"who can read this table\", and query system tables (audit, lineage, billing) or work with volume files in /Volumes/.
npx skills add https://github.com/databricks/databricks-agent-skills --skill databricks-unity-catalog
Guidance for Unity Catalog governance — access control, the privilege model,
external locations, securable DDL, and fine-grained access — plus system tables and
volume file operations.
> Before running databricks CLI commands, confirm the CLI and the subcommand exist.
> Run databricks --version — this skill assumes the unified CLI (≥ v1.0.0). Several
> subcommands shown here (experimental aitools, system-schemas, external-lineage,
> grants) vary by version or workspace availability; if one is missing or rejects a flag,
> fall back to the SQL form or the Python SDK rather than guessing. Each reference notes its
> own version floor where relevant.
Use this skill when:
Governance & access control (start here):
GRANT/REVOKE, the UC privilege model, ownership (ALTER … OWNER TO), SHOW GRANTS, "who can read/write this table?"current_user() / is_account_group_member()CREATE STORAGE CREDENTIAL, CREATE EXTERNAL LOCATION, backing external tables/volumesObservability & files:
/Volumes/)| Topic | File | Description |
|-------|------|-------------|
| Access Control | references/1-access-control.md | Privilege model, securable hierarchy, GRANT/REVOKE, ownership, inheritance, SHOW GRANTS |
| External Locations | references/2-external-locations.md | Storage credentials (AWS/Azure/GCP), external locations, validation |
| Securables DDL | references/3-securables-ddl.md | CREATE/ALTER/DROP catalogs/schemas/tables/views, comments, tags, ownership |
| Fine-Grained Access | references/4-fine-grained-access.md | Row filters, column masks, dynamic views |
| System Tables | references/5-system-tables.md | Lineage, audit, billing, compute, jobs, query history |
| Volumes | references/6-volumes.md | Volume file operations, permissions, best practices |
| Data Profiling | references/7-data-profiling.md | Data profiling, drift detection, profile metrics |
Use --json for create commands. Positional argument order differs per command and
has changed across CLI versions, so --json is the order-independent, version-stable form
shown throughout this skill.
# Create a catalog
databricks catalogs create --json '{"name": "my_catalog"}'
# Create a schema
databricks schemas create --json '{"name": "my_schema", "catalog_name": "my_catalog"}'
# Create a managed volume
databricks volumes create --json '{
"catalog_name": "my_catalog",
"schema_name": "my_schema",
"name": "my_volume",
"volume_type": "MANAGED"
}'
# List catalogs, schemas, volumes (read commands take simple positional args)
databricks catalogs list
databricks schemas list my_catalog
databricks volumes list my_catalog.my_schema
Positional create args still work if you prefer them, but the order is not uniform
across commands — this is the per-command order (and the reason --json is recommended):
| Command | Positional create order |
|---------|---------------------------|
| databricks catalogs create | NAME |
| databricks schemas create | NAME CATALOG_NAME |
| databricks volumes create | CATALOG_NAME SCHEMA_NAME NAME VOLUME_TYPE |
> CLI surface varies by version. If a databricks subcommand or positional signature is
> missing in your install, prefer --json, the SQL form, or the Python SDK rather than
> guessing flags.
databricks fs requires the dbfs: scheme prefix even for UC Volume paths — without it the CLI treats the path as local filesystem and errors with no such directory.
# List files in a volume
databricks fs ls dbfs:/Volumes/catalog/schema/volume/path/
# Upload a directory's contents to a volume (-r copies contents, not the directory itself)
databricks fs cp -r --overwrite /tmp/data dbfs:/Volumes/catalog/schema/volume/dest
# Download a file from a volume
databricks fs cp dbfs:/Volumes/catalog/schema/volume/file.csv /tmp/file.csv
# Create a directory in a volume
databricks fs mkdirs dbfs:/Volumes/catalog/schema/volume/new_folder
GRANT/REVOKE is the core governance operation. See references/1-access-control.md for the full privilege model.
-- Grant read access on a schema to a group
GRANT USE CATALOG ON CATALOG analytics TO `data_readers`;
GRANT USE SCHEMA ON SCHEMA analytics.gold TO `data_readers`;
GRANT SELECT ON SCHEMA analytics.gold TO `data_readers`;
-- Who can access this table?
SHOW GRANTS ON TABLE analytics.gold.customers;
-- Revoke
REVOKE SELECT ON SCHEMA analytics.gold FROM `data_readers`;
-- Grant access to system tables
GRANT USE CATALOG ON CATALOG system TO `data_engineers`;
GRANT USE SCHEMA ON SCHEMA system.access TO `data_engineers`;
GRANT SELECT ON SCHEMA system.access TO `data_engineers`;
-- Table lineage: What tables feed into this table?
SELECT source_table_full_name, source_column_name
FROM system.access.table_lineage
WHERE target_table_full_name = 'catalog.schema.table'
AND event_date >= current_date() - 7;
-- Audit: Recent permission changes
SELECT event_time, user_identity.email, action_name, request_params
FROM system.access.audit
WHERE action_name LIKE '%GRANT%' OR action_name LIKE '%REVOKE%'
ORDER BY event_time DESC
LIMIT 100;
-- Billing: DBU usage by workspace
SELECT workspace_id, sku_name, SUM(usage_quantity) AS total_dbus
FROM system.billing.usage
WHERE usage_date >= current_date() - 30
GROUP BY workspace_id, sku_name;
> databricks experimental aitools tools query is an experimental command. The
> experimental namespace is not guaranteed to be stable across CLI versions and may be
> absent in your install. Prefer running system-table SQL from a SQL warehouse (SQL
> editor, scheduled query) or the Python SDK (w.statement_execution.execute_statement),
> or a notebook. Use the experimental CLI only for quick ad-hoc checks.
> Getting the IDs these examples use. WAREHOUSE_ID — run databricks warehouses list
> (or copy it from a SQL warehouse's *Connection details* in the UI). METASTORE_ID (used in
> references/5-system-tables.md) — w.metastores.current().metastore_id
> via the SDK, or the Catalog UI → metastore details.
Experimental CLI form (convenience only):
databricks experimental aitools tools query --warehouse WAREHOUSE_ID "
SELECT source_table_full_name, target_table_full_name
FROM system.access.table_lineage
WHERE event_date >= current_date() - 7
"
Stable SDK fallback (works on any CLI version):
from databricks.sdk import WorkspaceClient
w = WorkspaceClient()
resp = w.statement_execution.execute_statement(
warehouse_id="WAREHOUSE_ID",
statement="""
SELECT source_table_full_name, target_table_full_name
FROM system.access.table_lineage
WHERE event_date >= current_date() - 7
LIMIT 100
""",
)
for row in resp.result.data_array or []:
print(row)
> CLI surface varies by version. If a databricks subcommand (e.g. an experimental
> tool, system-schemas, or external-lineage) is missing, fall back to the SQL warehouse
> or the Python SDK shown above rather than guessing flags.
This skill owns Unity Catalog governance: access control, the privilege model,
external locations / storage credentials, securable DDL, fine-grained access, system
tables, and volumes. For adjacent concerns, use the sibling skill instead:
WITH METRICS LANGUAGE YAML)@prod/@challenger aliasesai_mask / ai_classify (AI *transforms*, not access control — see references/4-fine-grained-access.md)These governance areas are intentionally out of scope for v0.3.0 and planned for later:
Assess Kubernetes workloads and cluster configuration for AKS Automatic compatibility. Identifies incompatibilities, generates fixes, and guides migration from AKS Standard to AKS Automatic. WHEN: migrate to AKS Automatic, check AKS Automatic readiness, validate manifests for Automatic, assess cluster for Automatic compatibility, fix deployment for Automatic compatibility, identify AKS Automatic migration blockers, is my cluster ready for AKS Automatic.
Discovers available Azure OpenAI model capacity across regions and projects. Analyzes quota limits, compares availability, and recommends optimal deployment locations based on capacity requirements. USE FOR: find capacity, check quota, where can I deploy, capacity discovery, best region for capacity, multi-project capacity search, quota analysis, model availability, region comparison, check TPM availability. DO NOT USE FOR: actual deployment (hand off to preset or customize after discovery), quota increase requests (direct user to Azure Portal), listing existing deployments.
Interactive guided deployment flow for Azure OpenAI models with full customization control. Step-by-step selection of model version, SKU (GlobalStandard/Standard/ProvisionedManaged), capacity, RAI policy (content filter), and advanced options (dynamic quota, priority processing, spillover). USE FOR: custom deployment, customize model deployment, choose version, select SKU, set capacity, configure content filter, RAI policy, deployment options, detailed deployment, advanced deployment, PTU deployment, provisioned throughput. DO NOT USE FOR: quick deployment to optimal region (use preset).
Unified Azure OpenAI model deployment skill with intelligent intent-based routing. Handles quick preset deployments, fully customized deployments (version/SKU/capacity/RAI policy), and capacity discovery across regions and projects. USE FOR: deploy model, deploy gpt, create deployment, model deployment, deploy openai model, set up model, provision model, find capacity, check model availability, where can I deploy, best region for model, capacity analysis. DO NOT USE FOR: listing existing deployments (use foundry_models_deployments_list MCP tool), deleting deployments, agent creation (use agent/create), project creation (use project/create).
Intelligently deploys Azure OpenAI models to optimal regions by analyzing capacity across all available regions. Automatically checks current region first and shows alternatives if needed. USE FOR: quick deployment, optimal region, best region, automatic region selection, fast setup, multi-region capacity check, high availability deployment, deploy to best location. DO NOT USE FOR: custom SKU selection (use customize), specific version selection (use customize), custom capacity configuration (use customize), PTU deployments (use customize).
This skill should be used when working with LaminDB, an open-source data framework for biology that makes data queryable, traceable, reproducible, and FAIR. Use when managing biological datasets (scRNA-seq, spatial, flow cytometry, etc.), tracking computational workflows, curating and validating data with biological ontologies, building data lakehouses, or ensuring data lineage and reproducibility in biological research. Covers data management, annotation, ontologies (genes, cell types, diseases, tissues), schema validation, integrations with workflow managers (Nextflow, Snakemake) and MLOps platforms (W&B, MLflow), and deployment strategies.
Latch platform for bioinformatics workflows. Build pipelines with Latch SDK, @workflow/@task decorators, deploy serverless workflows, LatchFile/LatchDir, Nextflow/Snakemake integration.
Run Python code in the cloud with serverless containers, GPUs, and autoscaling. Use when deploying ML models, running batch processing jobs, scheduling compute-intensive tasks, or serving APIs that require GPU acceleration or dynamic scaling.
Take databricks/databricks-unity-catalog from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.