Table Access Control

Access Control on Tables and the Catalog

Open-source Spark 129 has no GRANT on tables: any user who can run a Spark job can read whatever the job's credentials can read in storage. Table-, row- and column-level rules therefore live in a governed catalog or in the platform, and Spark must ask it.

Where data access is enforced for Spark
Layer Examples What it controls
Storage permissions S3 bucket policies, GCS IAM, ADLS ACLs, HDFS permissions Whole files and prefixes
Governed catalog Unity Catalog (OSS v0.6.0, 20 Aug 2026), Apache Polaris 1.8.0 129 , AWS 24 Lake Formation Tables, columns, rows, credential vending
Policy engine Apache Ranger 2.9.0 with Hive/Spark plugins Fine-grained SQL policies, audit
Managed platform Databricks 2,717 Unity Catalog, Fabric OneLake security All of the above, enforced by the runtime

The modern pattern is credential vending: the job authenticates as a principal, asks the catalog for a table, and receives short-lived storage credentials scoped to that table's files, so the job never holds broad keys. Row filters and column masks only work when the engine enforces them; a plain Spark job given raw storage access bypasses every rule in the catalog. Lakehouses, Data Quality and Governance sets up a REST catalog for BookNest's lakehouse and Securing the Warehouse shows the equivalent controls inside a warehouse.