The lock was already in place, but the key was hidden in the licensing model. Databricks access control doesn’t start with who you are. It starts with what you’ve paid for, what tier you are on, and which features are unlocked in your workspace.
Databricks uses a tiered licensing model to determine access control capabilities. Unified data access policies, fine-grained permissions, and workspace-level restrictions are not equally available. The Standard tier offers basic workspace permissions. The Premium tier adds role-based access control (RBAC) and cluster-level permissions. The Enterprise tier brings advanced security integrations, audit logging, and compliance features.
Access control combines licensing with configuration. Even if you configure ACLs for notebooks, clusters, and jobs, your licensing tier decides if those controls can actually enforce restrictions. Permissions are managed through groups, service principals, and identity federation. Each feature—workspace object permissions, table ACLs, cluster policies—has a licensing prerequisite.