Read Restrictions and Catalog Labels: Unifying governance across engines and catalogs

Imported from official source

  • Read restrictions and catalog labels are two new specs from Apache Iceberg™ that help standardize how policies are enforced across engines and catalogs.
  • Both additions remove fragmented enforcement. Read restrictions delegate decisions to trusted engines; catalog labels make governance metadata portable across federated catalogs.
  • There's now a clear model for every access pattern: centralized enforcement for untrusted engines, read restrictions for trusted ones, catalog labels for catalog-to-catalog federation.
  • In our previous posts, we showed how open table formats, open APIs and unified governance are coming together to complete the Open Lakehouse vision. We also introduced cross-engine attribute-based access control, which allows policies defined in Unity Catalog to be enforced consistently when external engines access governed data.

    Now, that vision is beginning to materialize in the open. The Apache Iceberg™ community recently advanced two important additions to the Iceberg REST Catalog: read restrictions and catalog labels. Together, they address two distinct challenges: delegating enforcement to an external engine and making governance context portable across catalogs.

    In this post we will take a closer look at both new additions to the spec: how they work, key challenges they address, future opportunities for innovation, and when to use them.

    Read restrictions: standardizing delegated enforcement

    Read restrictions address a common engine-to-catalog scenario: an organization governs data in one catalog and wants to query it from various engines or tools.

    For any governed query, three things must happen:

  • The catalog receives the requesting identity and relevant context, such as subjects, groups, roles, or even identity attributes such as ‘region’
  • It evaluates policy to decide whether the user may read the table and which row filters or column masks apply.
  • A trusted compute layer enforces that decision when the data is read.
  • This is an extract. The publication continues at the source.

    Read the original at the source: https://www.databricks.com/blog/read-restrictions-and-catalog-labels-unifying-governance-across-engines-and-catalogs

    Officially imported this from Databricks’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    Databricks — imported from official source
    Official source
    https://www.databricks.com/feed RSS
    Imported
    October 01, 2026 22:00
    Versions
    1 recorded
    Identity
    https://www.databricks.com/blog/read-restrictions-and-catalog-labels-unifying-governanc...

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.