Databricks Apps Adds On-Behalf-of-User Authorization for Permission-Aware Apps
Original titleNow GA: Building permission-aware Databricks Apps with on-behalf-of-user authorization
AISummary
Databricks announced general availability of on-behalf-of-user (OBO) authorization for Databricks Apps, letting apps act with the signed-in user's identity so Unity Catalog enforces that user's row filters and column masks.
Developers can request narrow API scopes such as sql:restricted-query, which allows only read-only SQL queries, while apps keep a dedicated service principal for app-owned operations.
Source: Databricks Blog · databricks.com