<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What does &amp;quot;Agent-Ready Data Governance&amp;quot; actually mean in production? in Data Governance</title>
    <link>https://community.databricks.com/t5/data-governance/what-does-quot-agent-ready-data-governance-quot-actually-mean-in/m-p/163204#M2909</link>
    <description>&lt;P class=""&gt;Databricks introduced several governance capabilities for the agentic era, including Unity Catalog Business Semantics, AI Gateway, and agent-ready governance.&lt;/P&gt;&lt;P&gt;My question is:&lt;/P&gt;&lt;P&gt;In a large enterprise with 20+ business domains, how are you governing:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Agent permissions&lt;/LI&gt;&lt;LI&gt;Tool permissions&lt;/LI&gt;&lt;LI&gt;Vector Search access&lt;/LI&gt;&lt;LI&gt;Business glossary&lt;/LI&gt;&lt;LI&gt;MCP tools&lt;/LI&gt;&lt;LI&gt;Prompt governance&lt;/LI&gt;&lt;LI&gt;Cross-domain reasoning&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Would love to hear how people are implementing this in production.&lt;/P&gt;</description>
    <pubDate>Thu, 16 Jul 2026 15:37:12 GMT</pubDate>
    <dc:creator>Bitrip007</dc:creator>
    <dc:date>2026-07-16T15:37:12Z</dc:date>
    <item>
      <title>What does "Agent-Ready Data Governance" actually mean in production?</title>
      <link>https://community.databricks.com/t5/data-governance/what-does-quot-agent-ready-data-governance-quot-actually-mean-in/m-p/163204#M2909</link>
      <description>&lt;P class=""&gt;Databricks introduced several governance capabilities for the agentic era, including Unity Catalog Business Semantics, AI Gateway, and agent-ready governance.&lt;/P&gt;&lt;P&gt;My question is:&lt;/P&gt;&lt;P&gt;In a large enterprise with 20+ business domains, how are you governing:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Agent permissions&lt;/LI&gt;&lt;LI&gt;Tool permissions&lt;/LI&gt;&lt;LI&gt;Vector Search access&lt;/LI&gt;&lt;LI&gt;Business glossary&lt;/LI&gt;&lt;LI&gt;MCP tools&lt;/LI&gt;&lt;LI&gt;Prompt governance&lt;/LI&gt;&lt;LI&gt;Cross-domain reasoning&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Would love to hear how people are implementing this in production.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2026 15:37:12 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/what-does-quot-agent-ready-data-governance-quot-actually-mean-in/m-p/163204#M2909</guid>
      <dc:creator>Bitrip007</dc:creator>
      <dc:date>2026-07-16T15:37:12Z</dc:date>
    </item>
    <item>
      <title>Re: What does "Agent-Ready Data Governance" actually mean in production?</title>
      <link>https://community.databricks.com/t5/data-governance/what-does-quot-agent-ready-data-governance-quot-actually-mean-in/m-p/163357#M2910</link>
      <description>&lt;DIV class="relative basis-auto flex-col -mb-(--composer-overlap-px) pb-(--composer-overlap-px) [--composer-overlap-px:28px] grow flex"&gt;
&lt;DIV class="flex flex-col text-sm"&gt;
&lt;DIV class="qMYqUG_convSearchResultHighlightRoot"&gt;
&lt;DIV class="" data-is-intersecting="true" data-turn-id-container="request-WEB:71d4366b-094a-44cc-b4da-5a592e56f096-1"&gt;
&lt;SECTION class="text-token-text-primary w-full focus:outline-none has-data-writing-block:pointer-events-none [&amp;amp;:has([data-writing-block])&amp;gt;*]:pointer-events-auto R6Vx5W_threadScrollVars scroll-mb-[calc(var(--scroll-root-safe-area-inset-bottom,0px)+var(--thread-response-height))] scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))]" dir="auto" data-turn="assistant" data-testid="conversation-turn-2" data-turn-id-container="request-WEB:71d4366b-094a-44cc-b4da-5a592e56f096-1" data-turn-id="request-WEB:71d4366b-094a-44cc-b4da-5a592e56f096-1"&gt;
&lt;DIV class="text-base my-auto mx-auto pb-15 [--thread-content-margin:var(--thread-content-margin-xs,calc(var(--spacing)*4))] @w-sm/main:[--thread-content-margin:var(--thread-content-margin-sm,calc(var(--spacing)*6))] @w-lg/main:[--thread-content-margin:var(--thread-content-margin-lg,calc(var(--spacing)*16))] px-(--thread-content-margin)"&gt;
&lt;DIV class="[--thread-content-max-width:40rem] @w-lg/main:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 group/turn-messages focus-visible:outline-hidden relative flex w-full min-w-0 flex-col agent-turn" data-conversation-screenshot-content=""&gt;
&lt;DIV class="flex max-w-full flex-col gap-4 grow"&gt;
&lt;DIV class="min-h-8 text-message relative flex w-full flex-col items-end gap-2 text-start break-words whitespace-normal outline-none keyboard-focused:focus-ring [.text-message+&amp;amp;]:mt-1" dir="auto" tabindex="0" data-turn-start-message="true" data-message-model-slug="gpt-5-5" data-message-id="0aef0de9-99ba-40dc-adee-b1115a67a3a2" data-message-author-role="assistant"&gt;
&lt;DIV class="flex w-full flex-col gap-1 empty:hidden"&gt;
&lt;DIV class="markdown prose dark:prose-invert wrap-break-word w-full dark markdown-new-styling"&gt;
&lt;P class="PDq2pG_selectionAnchorContainer" data-end="260" data-start="0"&gt;"Agent-ready data governance" is mostly marketing language for applying existing Unity Catalog primitives to AI workloads. The actual production mechanics are less novel than the branding suggests. Here's how each of your items maps to what's really available:&lt;/P&gt;
&lt;P data-end="825" data-start="262"&gt;&lt;STRONG data-end="305" data-start="262"&gt;Agent permissions and tool permissions.&lt;/STRONG&gt; Agents deployed as model serving endpoints run under a service principal. You scope that service principal's UC privileges exactly like you would a Spark job: &lt;CODE data-end="492" data-start="465"&gt;GRANT EXECUTE ON FUNCTION&lt;/CODE&gt; for UC functions used as tools, &lt;CODE data-end="533" data-start="525"&gt;SELECT&lt;/CODE&gt; on tables the agent needs, and endpoint-level ACLs for the serving endpoint itself. For MCP tools, they can be registered as Unity Catalog securables and governed with the same grant/revoke model. One service principal per agent (or per agent group) makes this manageable across 20+ domains.&lt;/P&gt;
&lt;P data-end="1342" data-start="827"&gt;&lt;STRONG data-end="852" data-start="827"&gt;Vector Search access.&lt;/STRONG&gt; UC governs the index at the schema level, CREATE TABLE privilege is required to create one, and endpoint-level ACLs control who can query it. The big limitation to know upfront: row/column-level security is NOT supported on Vector Search today. If you need data isolation within an index (e.g., one index serving multiple domains with different access rights), you have to implement filtering at the application layer using the filter API rather than relying on the platform to enforce it.&lt;/P&gt;
&lt;P data-end="1758" data-start="1344"&gt;&lt;STRONG data-end="1366" data-start="1344"&gt;Prompt governance.&lt;/STRONG&gt; This is handled through AI Gateway guardrails. You attach service policies to a model service or MCP service endpoint. Policies run on both input and output, and you can layer built-in ones (PII detection, jailbreak detection, unsafe content) with custom ones backed by a UC function. For cross-domain deployments, you configure different policies per endpoint rather than one global policy.&lt;/P&gt;
&lt;P data-end="2117" data-start="1760"&gt;&lt;STRONG data-end="1782" data-start="1760"&gt;Business glossary.&lt;/STRONG&gt; Unity Catalog's Business Semantics (formerly "AI-ready metadata") lets you attach natural-language descriptions, synonyms, and semantic labels to tables and columns. This is what feeds Genie and helps agents understand what data means without you hardcoding it in every prompt. Governance here is just standard UC metadata management.&lt;/P&gt;
&lt;P data-end="2465" data-start="2119"&gt;&lt;STRONG data-end="2133" data-start="2119"&gt;MCP tools.&lt;/STRONG&gt; Registered through AI Gateway as UC securables. You control which identities can invoke which MCP server, apply service policies per server, and track usage through system tables. The pattern teams are using in production is to register one MCP server per domain and grant access to agents in that domain's service principal group.&lt;/P&gt;
&lt;P data-end="3054" data-start="2467"&gt;&lt;STRONG data-end="2494" data-start="2467"&gt;Cross-domain reasoning.&lt;/STRONG&gt; This is the least mature piece and the most architecture-dependent. The platform doesn't have a native concept of "cross-domain agent federation." What you actually build is either a supervisor/orchestrator agent that routes to domain-specific agents, or a single agent with tools spanning multiple domains where access is controlled at the tool/function level. The governance in that case is: does the agent's service principal have privileges on all the UC objects across the domains it needs to touch? That's a grant management question, not a new feature.&lt;/P&gt;
&lt;P data-is-only-node="" data-is-last-node="" data-end="3343" data-start="3056"&gt;In practice, teams handling 20+ domains are leaning heavily on groups and group-based grants rather than per-agent grants, and using separate catalogs or schemas per domain so you can apply coarse-grained catalog/schema-level grants without managing hundreds of object-level permissions.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/SECTION&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="thread-bottom-container" class="sticky bottom-0 z-10 group/thread-bottom-container relative isolate w-full basis-auto has-data-has-thread-error:pt-2 has-data-has-thread-error:[box-shadow:var(--sharp-edge-bottom-shadow)] md:border-transparent md:pt-0 dark:border-white/20 md:dark:border-transparent print:hidden pointer-events-none [--thread-content-max-width:40rem] @w-lg/main:[--thread-content-max-width:48rem] Ejxyja_threadFooterContentFade flex flex-col"&gt;
&lt;DIV id="thread-bottom"&gt;
&lt;DIV&gt;
&lt;DIV class="text-base mx-auto [--thread-content-margin:var(--thread-content-margin-xs,calc(var(--spacing)*4))] @w-sm/main:[--thread-content-margin:var(--thread-content-margin-sm,calc(var(--spacing)*6))] @w-lg/main:[--thread-content-margin:var(--thread-content-margin-lg,calc(var(--spacing)*16))] px-(--thread-content-margin)"&gt;
&lt;DIV&gt;
&lt;DIV class="[--thread-content-max-width:40rem] @w-lg/main:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 mb-(--thread-component-gap,24px) pointer-events-auto"&gt;
&lt;DIV class="w-full"&gt;
&lt;DIV class="pointer-events-auto relative z-1 flex h-(--composer-container-height,100%) max-w-full flex-(--composer-container-flex,1) flex-col"&gt;&lt;FORM class="group/composer w-full" autocomplete="off" data-type="unified-composer"&gt;
&lt;DIV class="hidden"&gt;&lt;INPUT id="upload-files" tabindex="-1" multiple="multiple" type="file" /&gt;&lt;/DIV&gt;
&lt;/FORM&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Sun, 19 Jul 2026 08:57:42 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/what-does-quot-agent-ready-data-governance-quot-actually-mean-in/m-p/163357#M2910</guid>
      <dc:creator>iyashk-DB</dc:creator>
      <dc:date>2026-07-19T08:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: What does "Agent-Ready Data Governance" actually mean in production?</title>
      <link>https://community.databricks.com/t5/data-governance/what-does-quot-agent-ready-data-governance-quot-actually-mean-in/m-p/165117#M2947</link>
      <description>&lt;PRE&gt;Great thread and iyashk-DB's breakdown is solid on the mechanics. &lt;BR /&gt;One thing worth adding from running this in production at enterprise scale, the piece most teams miss (myself included, first time round) is the evidence layer, &lt;BR /&gt;agent-ready governance isn't just configuring grants and policies, it's being able to prove they held at any point in time.

Three practical additions:
1. Build your agent activity query set early.
The system tables are your raw material for audit: system.access.audit (service_name aibiGenie, aibiMCP, &lt;BR /&gt;aiAgentFramework), system.access.assistant_events, system.access.column_lineage. &lt;BR /&gt;Standardize the queries you run monthly before an auditor asks — you don't want to be reverse-engineering &lt;BR /&gt;event schemas under deadline. Start here:
https://docs.databricks.com/aws/en/admin/system-tables/
https://docs.databricks.com/aws/en/admin/system-tables/audit-logs

2. Map agent governance to controls, not features.
For SOC 2 / ISO 27001, auditors don't care about "AI Gateway guardrails" as a noun,&lt;BR /&gt;they care about the control: who can invoke what, with what data, and evidence that it was enforced. &lt;BR /&gt;Keep a mapping doc: agent/tool/vector-index → service principal → UC grants → guardrail policy → system-table evidence query. &lt;BR /&gt;Review it on the same cadence as your other access reviews. &lt;BR /&gt;The AI governance guide is a good frame for this:
https://docs.databricks.com/aws/en/ai-gateway/ai-governance

3. Watch for drift between policy and reality.
The risk isn't the initial grant model, it's the accumulation of exceptions (temporary grants, new MCP servers, &lt;BR /&gt;new tools registered). A monthly diff of "what's registered as a securable vs. what's actually being invoked" catches exceptions before &lt;BR /&gt;they become audit findings. For MCP specifically:
https://docs.databricks.com/aws/en/ai-gateway/govern-mcp-service

The 20-domain question really is a grants-management + evidence-management problem, not a platform feature problem, which is good news: the fundamentals (groups, catalogs per domain, service principals per agent) scale cleanly and the system-table audit trail gives you the proof layer on top.&lt;/PRE&gt;</description>
      <pubDate>Sat, 08 Aug 2026 00:26:25 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/what-does-quot-agent-ready-data-governance-quot-actually-mean-in/m-p/165117#M2947</guid>
      <dc:creator>empire_labs</dc:creator>
      <dc:date>2026-08-08T00:26:25Z</dc:date>
    </item>
    <item>
      <title>Re: What does "Agent-Ready Data Governance" actually mean in production?</title>
      <link>https://community.databricks.com/t5/data-governance/what-does-quot-agent-ready-data-governance-quot-actually-mean-in/m-p/165224#M2950</link>
      <description>&lt;P class=""&gt;One thing I’d be interested in hearing from teams running this across multiple business domains is how they handle &lt;STRONG&gt;business ownership and consistency of definitions&lt;/STRONG&gt;. Technical access controls can restrict what an agent can see or invoke, but how are organizations ensuring that the agent interprets metrics and business terms consistently across domains?&lt;/P&gt;&lt;P&gt;Especially when the same metric can have different definitions across finance, sales, or operations, is the business glossary becoming part of the governance process rather than just metadata?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2026 06:46:50 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/what-does-quot-agent-ready-data-governance-quot-actually-mean-in/m-p/165224#M2950</guid>
      <dc:creator>kartikchoudhary</dc:creator>
      <dc:date>2026-08-10T06:46:50Z</dc:date>
    </item>
  </channel>
</rss>

