Read Restrictions and Catalog Labels: Unifying governance across engines and catalogs
In our previous posts, we showed how open table formats, open APIs and unified governance are coming together to complete the Open Lakehouse vision. We also introduced cross-engine attribute-based access control, which allows policies defined in Unity Catalog to be enforced consistently when external engines access governed data.
Now, that vision is beginning to materialize in the open. The Apache Iceberg™ community recently advanced two important additions to the Iceberg REST Catalog: read restrictions and catalog labels. Together, they address two distinct challenges: delegating enforcement to an external engine and making governance context portable across catalogs.
In this post we will take a closer look at both new additions to the spec: how they work, key challenges they address, future opportunities for innovation, and when to use them.
Read restrictions: standardizing delegated enforcement
Read restrictions address a common engine-to-catalog scenario: an organization governs data in one catalog and wants to query it from various engines or tools.
For any governed query, three things must happen:
This is an extract. The publication continues at the source.
Read the original at the source: https://www.databricks.com/blog/read-restrictions-and-catalog-labels-unifying-governance-across-engines-and-catalogs
Officially imported this from Databricks’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Databricks — imported from official source
- Official source
- https://www.databricks.com/feed RSS
- Imported
- October 01, 2026 22:00
- Versions
- 1 recorded
- Identity
https://www.databricks.com/blog/read-restrictions-and-catalog-labels-unifying-governanc...