Skip to content
TechFabric

For Platform and security leads who have to defend the setup to someone else

Data & AI governance

TechFabric provides data and AI governance consulting on Databricks. We design Unity Catalog governance that holds in an audit, with catalogue and schema structure, grants that match how teams are organised, lineage that survives change, and the permissions boundary for applications and agents running under their own service principal, from 80 Databricks-certified engineers.

9 common questions, answered below ↓

An agent is a user

Unity Catalog designed so grants hold, lineage survives a refactor, and an agent inherits permissions instead of routing around them.

Governance gets bought after the first uncomfortable question, and by then the estate already exists. The work is deciding who can see what, proving it, and keeping lineage intact while data moves.

On Databricks that means catalogue and schema design that matches how your teams are actually organised, grants expressed through groups so joining a team is what changes access, and lineage that still resolves after a table is rebuilt. The part most teams haven't thought about yet is agents.

An agent with a service principal is a user, and if it reads through a path that bypasses your grants then your grants are decorative. We draw that permissions boundary in the first conversation, because giving an agent reach into production data before the line exists is an incident with a date on it.

The evidence lives in the system tables. Audit in system. access. audit, lineage in system. access. table_lineage and column_lineage, so an examiner's question is a query rather than a reconstruction.

  • Catalogue, schema and grant design that matches how your teams actually work
  • Row filters, column masks and attribute-based policies where a grant on the table isn't fine enough
  • Lineage that survives a refactor, so an audit question has an answer rather than a reconstruction
  • Agents and applications running under their own service principal, inheriting your permissions
  • Evaluation gates on promotion, so a failing check blocks a release instead of filing a ticket

How an engagement works

01

Talk to an engineer

A real conversation about your initiative with a senior engineer who has built this before. Not a sales call. What you are trying to build, what has been tried, and what is realistic.

02

Discovery and scoping

Two to three weeks to clarify requirements, evaluate where AI fits, and define realistic scope. On AI work this is also where success gets defined precisely enough to score, because a goal nobody can measure cannot be hillclimbed. You get a plan you can act on before committing to a larger engagement.

03

The right team, daily demos

We put the team the work actually needs on it and show you running software every day. Built with the same rigor as any enterprise system: tested, monitored, documented.

04

Production and beyond

Deployed and running under real load, handling real business processes. Ongoing support and team continuity for whatever comes next.

FAQ

Data & AI governance, answered

What does data governance consulting actually include?

At TechFabric it starts with an inventory of what's true today. Which grants exist, where lineage breaks, which tables nobody has queried in a year, and what an examiner would find.

Then the design work, which is catalogue and schema structure, a grant model expressed through groups, row filters and column masks where a table-level grant isn't fine enough, and the audit evidence pulled from system tables so the answer to a question is a query. The two-week Databricks Health Check at /databricks/health-check is the named way to start.

We already have Unity Catalog turned on. Is that governance?

It's the substrate, not the answer. Turning it on gives you somewhere to express grants; it doesn't decide who should have them, whether lineage still resolves after a rebuild, or what an agent is allowed to touch. Most of the engagements we take start from a working Unity Catalog and an estate nobody can defend in a meeting.

What is an AI governance framework, in practice?

The written answer to four questions. Which data each model and agent may read, under whose identity it acts, what it's allowed to do without a person approving, and what gets recorded so you can reconstruct a decision afterwards. On Databricks the enforcement half already exists.

Agents run under a service principal that inherits Unity Catalog permissions, AI Gateway logs the calls, and the audit table records the access. The framework is the policy that decides what those settings should be, and we write it with your security lead rather than for them.

How do you govern an AI agent?

The same way you govern a person, which is the point most teams miss. The agent runs under its own service principal and inherits Unity Catalog permissions rather than being handed a broad token.

What it may do is a policy decision made before it's built, not a setting adjusted after something goes wrong. Fabric Tower at /accelerators/fabric-tower is what we use when a squad of agents needs watching rather than one.

Do you do data quality and master data as part of this?

Yes, where the governance question turns out to be a definition question, which it usually does. Two teams both call a column revenue and both are right, and no grant fixes that.

We write the definitions down with whoever owns each number, put the quality checks into the pipeline so a bad load stops instead of landing, and handle the master data reconciliation that sits underneath. The pipeline half of that work is at /services/data-engineering.

Does this slow delivery down?

Retrofitting it does. Designing it alongside the pipeline doesn't, and it's considerably cheaper than the alternative, which is discovering during a security review that the grants don't hold. We put the permissions boundary in the first architecture conversation for exactly that reason.

Can you help us pass an audit we already have scheduled?

The first thing we establish is what's actually true: which grants exist, where lineage breaks, and what an examiner would find today. That inventory is quick, and it tells you what's reachable before the date rather than after it.

Most of the evidence an auditor asks for is already in system. access. audit and the lineage tables; the work is knowing which query answers which question.

Do you govern data outside Databricks too?

Yes. We're a Microsoft Solutions Partner with a Data & AI designation, and a lot of the estates we govern have Power BI, Dynamics 365 or Azure SQL in them.

Row-level security in Power BI, the connection that lets a report inherit Unity Catalog permissions, and the Azure side of the identity model are all in scope, because a governance model that stops at the workspace boundary isn't one.

How does a governance engagement start, and what does it cost?

With the two-week Databricks Health Check, which is fixed fee and reads the estate as it stands, including the grants and the lineage. You get a scorecard and a written recommendation whether or not you continue. Longer work is scoped against that document rather than against a brief, so the second number is known before anyone commits to it.