<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to override ABAC policies in Data Governance</title>
    <link>https://community.databricks.com/t5/data-governance/how-to-override-abac-policies/m-p/169709#M3001</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/98366"&gt;@cpayne_vax&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;I’ve run into this exact inheritance trap while architecting platforms with Unity Catalog.&lt;/P&gt;&lt;P&gt;Because UC always prioritizes the most restrictive policy to prevent accidental data leaks, fighting the catalog-to-schema inheritance is a losing battle. If Catalog A enforces a policy based on a tag, Schema 1 cannot safely override it if both rules trigger off the exact same tag condition.&lt;/P&gt;&lt;P&gt;Here is the cleanest way I handle this without creating a management nightmare: &lt;STRONG&gt;Stop trying to override the policy, and instead branch the tags.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Keep all your policy management at the Catalog level, but use mutually exclusive tag values to trigger them using the WHEN clause.&lt;/P&gt;&lt;H3&gt;1. Define Mutually Exclusive Tags&lt;/H3&gt;&lt;P&gt;Instead of a single boolean tag, use a key-value tag structure to represent the access tiers:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Tag Key: Security_Tier -&amp;gt; Value: Standard&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Tag Key: Security_Tier -&amp;gt; Value: Privileged_Exception&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;2. Create Tag-Conditioned Policies at the Catalog Level&lt;/H3&gt;&lt;P&gt;Create two distinct masking policies directly on the Catalog, using WHEN has_tag_value() to ensure they never overlap.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The Standard Policy:&lt;/STRONG&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;PRE&gt;&lt;SPAN class=""&gt;CREATE&lt;/SPAN&gt; &lt;SPAN class=""&gt;OR&lt;/SPAN&gt; REPLACE POLICY catalog_standard_masking
&lt;SPAN class=""&gt;ON&lt;/SPAN&gt; CATALOG `catalog_a`
&lt;SPAN class=""&gt;COLUMN&lt;/SPAN&gt; MASK default_masking_udf
&lt;SPAN class=""&gt;TO&lt;/SPAN&gt; `account users`
&lt;SPAN class=""&gt;EXCEPT&lt;/SPAN&gt; `Unmasked users`
&lt;SPAN class=""&gt;FOR&lt;/SPAN&gt; COLUMNS
&lt;SPAN class=""&gt;WHEN&lt;/SPAN&gt; has_tag_value(&lt;SPAN class=""&gt;'Security_Tier'&lt;/SPAN&gt;, &lt;SPAN class=""&gt;'Standard'&lt;/SPAN&gt;);&lt;/PRE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;STRONG&gt;The Privileged Policy:&lt;/STRONG&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;PRE&gt;&lt;SPAN class=""&gt;CREATE&lt;/SPAN&gt; &lt;SPAN class=""&gt;OR&lt;/SPAN&gt; REPLACE POLICY catalog_privileged_masking
&lt;SPAN class=""&gt;ON&lt;/SPAN&gt; CATALOG `catalog_a`
&lt;SPAN class=""&gt;COLUMN&lt;/SPAN&gt; MASK privileged_masking_udf
&lt;SPAN class=""&gt;TO&lt;/SPAN&gt; `account users`
&lt;SPAN class=""&gt;EXCEPT&lt;/SPAN&gt; `Unmasked users`, `Privileged Users`
&lt;SPAN class=""&gt;FOR&lt;/SPAN&gt; COLUMNS
&lt;SPAN class=""&gt;WHEN&lt;/SPAN&gt; has_tag_value(&lt;SPAN class=""&gt;'Security_Tier'&lt;/SPAN&gt;, &lt;SPAN class=""&gt;'Privileged_Exception'&lt;/SPAN&gt;);&lt;/PRE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;H3&gt;3. Apply the Tags Downstream&lt;/H3&gt;&lt;P&gt;Apply Security_Tier: Standard to your standard schemas (like Schema 2) and apply Security_Tier: Privileged_Exception to Schema 1.&lt;/P&gt;&lt;P&gt;By doing this, you avoid the inheritance clash entirely. A column in Schema 1 only triggers the privileged policy, so the restrictive standard policy never fires. You manage just two policies at the very top of your dozen catalogs, and you control all your exceptions purely by tagging the data correctly downstream.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Thu, 24 Sep 2026 14:27:25 GMT</pubDate>
    <dc:creator>ShamenParis</dc:creator>
    <dc:date>2026-09-24T14:27:25Z</dc:date>
    <item>
      <title>How to override ABAC policies</title>
      <link>https://community.databricks.com/t5/data-governance/how-to-override-abac-policies/m-p/169705#M3000</link>
      <description>&lt;P&gt;I'm struggling with the best way to handle ABAC inheritance. Here's the situation:&lt;/P&gt;&lt;P&gt;We have tags deployed in table columns across a dozen catalogs and their schemas. In general, certain tags should have column masking policies applied so that our user base cannot see unmasked data. However, there are overrides.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Imagine:&lt;BR /&gt;Catalog A&lt;BR /&gt;-&amp;gt; Schema 1&lt;BR /&gt;-&amp;gt; Schema 2&lt;BR /&gt;Catalog B&lt;BR /&gt;-&amp;gt; Schema 3&lt;/P&gt;&lt;P&gt;I have a group "Unmasked users" that get unmasking everywhere, so I've applied policies on both catalogs with "Unmasked users" in the EXCEPT list. But for Schema 1 specifically, I also need "Privileged Users" to have UNMASKING.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I create a policy to apply at the Schema 1 level with "Privileged Users" in the EXCEPT list. But here's the catch: because "Schema 1" inherits the policy that is applied on Catalog A which only allows "Unmasked users," then the more restrictive policy applies and "Privileged Users" can't see masked data.&lt;/P&gt;&lt;P&gt;The ways I see to get what I'm after:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Stop applying policies at the catalog level. This would make management immensely more complicated.&lt;/LI&gt;&lt;LI&gt;Add "Privileged Users" to the policy at Catalog A. This would mean this group also gets unmasked access to Schema 2, which is unacceptable.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Ideally I'd be able to override the inherited policy, but I see no way to do this. What's the best way to accomplish this goal? (And bear in mind that my example here is very simple, but I have over a dozen catalogs with hundreds of schemas, which makes option 1 unbearable.)&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2026 13:58:05 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/how-to-override-abac-policies/m-p/169705#M3000</guid>
      <dc:creator>cpayne_vax</dc:creator>
      <dc:date>2026-09-24T13:58:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to override ABAC policies</title>
      <link>https://community.databricks.com/t5/data-governance/how-to-override-abac-policies/m-p/169709#M3001</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/98366"&gt;@cpayne_vax&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;I’ve run into this exact inheritance trap while architecting platforms with Unity Catalog.&lt;/P&gt;&lt;P&gt;Because UC always prioritizes the most restrictive policy to prevent accidental data leaks, fighting the catalog-to-schema inheritance is a losing battle. If Catalog A enforces a policy based on a tag, Schema 1 cannot safely override it if both rules trigger off the exact same tag condition.&lt;/P&gt;&lt;P&gt;Here is the cleanest way I handle this without creating a management nightmare: &lt;STRONG&gt;Stop trying to override the policy, and instead branch the tags.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Keep all your policy management at the Catalog level, but use mutually exclusive tag values to trigger them using the WHEN clause.&lt;/P&gt;&lt;H3&gt;1. Define Mutually Exclusive Tags&lt;/H3&gt;&lt;P&gt;Instead of a single boolean tag, use a key-value tag structure to represent the access tiers:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Tag Key: Security_Tier -&amp;gt; Value: Standard&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Tag Key: Security_Tier -&amp;gt; Value: Privileged_Exception&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;2. Create Tag-Conditioned Policies at the Catalog Level&lt;/H3&gt;&lt;P&gt;Create two distinct masking policies directly on the Catalog, using WHEN has_tag_value() to ensure they never overlap.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The Standard Policy:&lt;/STRONG&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;PRE&gt;&lt;SPAN class=""&gt;CREATE&lt;/SPAN&gt; &lt;SPAN class=""&gt;OR&lt;/SPAN&gt; REPLACE POLICY catalog_standard_masking
&lt;SPAN class=""&gt;ON&lt;/SPAN&gt; CATALOG `catalog_a`
&lt;SPAN class=""&gt;COLUMN&lt;/SPAN&gt; MASK default_masking_udf
&lt;SPAN class=""&gt;TO&lt;/SPAN&gt; `account users`
&lt;SPAN class=""&gt;EXCEPT&lt;/SPAN&gt; `Unmasked users`
&lt;SPAN class=""&gt;FOR&lt;/SPAN&gt; COLUMNS
&lt;SPAN class=""&gt;WHEN&lt;/SPAN&gt; has_tag_value(&lt;SPAN class=""&gt;'Security_Tier'&lt;/SPAN&gt;, &lt;SPAN class=""&gt;'Standard'&lt;/SPAN&gt;);&lt;/PRE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;STRONG&gt;The Privileged Policy:&lt;/STRONG&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;PRE&gt;&lt;SPAN class=""&gt;CREATE&lt;/SPAN&gt; &lt;SPAN class=""&gt;OR&lt;/SPAN&gt; REPLACE POLICY catalog_privileged_masking
&lt;SPAN class=""&gt;ON&lt;/SPAN&gt; CATALOG `catalog_a`
&lt;SPAN class=""&gt;COLUMN&lt;/SPAN&gt; MASK privileged_masking_udf
&lt;SPAN class=""&gt;TO&lt;/SPAN&gt; `account users`
&lt;SPAN class=""&gt;EXCEPT&lt;/SPAN&gt; `Unmasked users`, `Privileged Users`
&lt;SPAN class=""&gt;FOR&lt;/SPAN&gt; COLUMNS
&lt;SPAN class=""&gt;WHEN&lt;/SPAN&gt; has_tag_value(&lt;SPAN class=""&gt;'Security_Tier'&lt;/SPAN&gt;, &lt;SPAN class=""&gt;'Privileged_Exception'&lt;/SPAN&gt;);&lt;/PRE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;H3&gt;3. Apply the Tags Downstream&lt;/H3&gt;&lt;P&gt;Apply Security_Tier: Standard to your standard schemas (like Schema 2) and apply Security_Tier: Privileged_Exception to Schema 1.&lt;/P&gt;&lt;P&gt;By doing this, you avoid the inheritance clash entirely. A column in Schema 1 only triggers the privileged policy, so the restrictive standard policy never fires. You manage just two policies at the very top of your dozen catalogs, and you control all your exceptions purely by tagging the data correctly downstream.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 24 Sep 2026 14:27:25 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/how-to-override-abac-policies/m-p/169709#M3001</guid>
      <dc:creator>ShamenParis</dc:creator>
      <dc:date>2026-09-24T14:27:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to override ABAC policies</title>
      <link>https://community.databricks.com/t5/data-governance/how-to-override-abac-policies/m-p/169710#M3002</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;You're reading the behavior right, and there is no override mechanism. The docs are explicit about how in-scope policies combine: the engine "Identifies all policies whose scope covers the queried table", checks TO/EXCEPT per policy, and then "Only one distinct row filter can resolve at runtime for a given table and a given user, and only one distinct column mask can resolve for a given column and a given user." Nothing at a child level cancels a parent policy. In your case the catalog policy simply still applies to Privileged Users (they're in its TO, not its EXCEPT), so they get masked. If two different masks ever did resolve for the same user, you wouldn't get "most restrictive wins", you'd get an error (MULTIPLE_MASKS) and the table becomes unreadable for that user.&lt;BR /&gt;&lt;A href="https://docs.databricks.com/aws/en/data-governance/unity-catalog/abac/policy-evaluation" target="_blank" rel="noopener"&gt;link 1&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://docs.databricks.com/aws/en/data-governance/unity-catalog/abac/requirements" target="_blank" rel="noopener"&gt;link 2&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The documented lever you're missing is the WHEN clause combined with tag inheritance. has_tag in WHEN "checks tags set directly on the table or inherited from a parent catalog or schema", and NOT is allowed in the condition. So you keep one policy per catalog and carve schemas out of it with a governed tag:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Create a governed tag, say mask_scope, and set mask_scope = privileged on Schema 1. Every table in it inherits the tag for policy evaluation.&lt;/LI&gt;&lt;LI&gt;Catalog A policy: ... TO account users EXCEPT unmasked_users FOR TABLES WHEN NOT has_tag_value('mask_scope', 'privileged') MATCH COLUMNS has_tag('pii') AS c ON COLUMN c&lt;/LI&gt;&lt;LI&gt;Schema 1 policy: same mask UDF, TO account users EXCEPT unmasked_users, privileged_users FOR TABLES MATCH COLUMNS has_tag('pii') AS c ON COLUMN c&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Schema 2 keeps the catalog policy untouched, Schema 1 is governed only by its own policy, and since both policies use the same UDF there's no conflict risk even during the transition. SHOW EFFECTIVE POLICIES ON TABLE ... is how you verify what actually lands on a table.&lt;BR /&gt;&lt;A href="https://docs.databricks.com/aws/en/data-governance/unity-catalog/abac/core-concepts" target="_blank" rel="noopener"&gt;link 3&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://docs.databricks.com/aws/en/data-governance/unity-catalog/abac/policies" target="_blank" rel="noopener"&gt;link 4&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Three caveats from the docs worth respecting at your scale. Tagging is a security boundary ("If a user can change tags on a data asset, they can change which policies apply to it"), so lock ASSIGN on that tag to your governance group. Tag changes take a few minutes to propagate. And there's a quota of 20 principals per policy across TO and EXCEPT, so keep the exemptions as groups, not individual users.&lt;/P&gt;&lt;P&gt;With a dozen catalogs and hundreds of schemas, you end up with one policy per catalog plus one per exception schema, which is about as small as this can get.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2026 14:28:25 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/how-to-override-abac-policies/m-p/169710#M3002</guid>
      <dc:creator>ThomazNeto</dc:creator>
      <dc:date>2026-09-24T14:28:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to override ABAC policies</title>
      <link>https://community.databricks.com/t5/data-governance/how-to-override-abac-policies/m-p/169729#M3003</link>
      <description>&lt;P&gt;Thank you both,&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/231077"&gt;@ShamenParis&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/245135"&gt;@ThomazNeto&lt;/a&gt;. This really helps. Let me restate and generalize what I think I'm hearing so that I get it straight in my head.&lt;/P&gt;&lt;P&gt;The reality is that I don't have just 1 "privileged users" group. I have many, each allowed to view unmasked data related to their job functions. Imagine groups for: Finance team, Patient team, Security team, etc. So I create a managed tag called "mask_scope" and each schema will have a value for this tag that corresponds to the team(s) that can see unmasked data. Some schemas will have multiple, and this presents a snag. Tags can't have multiple values when applied, which means I'd have to create a CROSS apply of sorts, where allowable values could be "Finance,Security" and "Patients,Security" and "Finance."&lt;/P&gt;&lt;P&gt;So all that said, here's my new sketch:&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Catalog A&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;-&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt; Schema &lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;-&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt; Schema &lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;-&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt; Schema &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Catalog B&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;-&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt; Schema &lt;/SPAN&gt;&lt;SPAN&gt;4&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;-&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt; Schema &lt;/SPAN&gt;&lt;SPAN&gt;5&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Catalog C&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;-&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt; Schema &lt;/SPAN&gt;&lt;SPAN&gt;6&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;STRONG&gt;Requirements&lt;/STRONG&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Finance can see Schema &lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Security can see Schema &lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Finance and Security can see Schema &lt;/SPAN&gt;&lt;SPAN&gt;4&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;No one can read A&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;, B&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;5&lt;/SPAN&gt;&lt;SPAN&gt;, or C&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;6&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Normies can't read anything&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Tags&lt;/STRONG&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Catalog A,B,C&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; standard&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Schema &lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt; &lt;SPAN&gt;mask_scope &lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt; &lt;SPAN&gt;Finance&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Schema &lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt; &lt;SPAN&gt;mask_scope &lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt; &lt;SPAN&gt;Security&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Schema &lt;/SPAN&gt;&lt;SPAN&gt;4&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt; &lt;SPAN&gt;mask_scope &lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt; &lt;SPAN&gt;Finance,Security&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Policies&lt;/STRONG&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;SPAN&gt;Applied on catalogs A,B,C to account users, WHEN &lt;/SPAN&gt;&lt;SPAN&gt;tag &lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt; &lt;SPAN&gt;standard&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Applied on catalog A to account users, EXCEPT Finance, WHEN &lt;/SPAN&gt;&lt;SPAN&gt;tag &lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt; &lt;SPAN&gt;Finance&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Applied on catalog A to account users, EXCEPT Security, WHEN &lt;/SPAN&gt;&lt;SPAN&gt;tag &lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt; &lt;SPAN&gt;Security&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Applied on catalog B to account users, EXCEPT Finance and Security, WHEN &lt;/SPAN&gt;&lt;SPAN&gt;tag &lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt; &lt;SPAN&gt;Finance,Security&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;STRONG&gt;Effective&lt;/STRONG&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Schemas &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;5&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;6&lt;/SPAN&gt;&lt;SPAN&gt; inherit standard tag, no one can read them&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Finance can read Schema &lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;SPAN&gt; because of policy &lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Security can read Schema &lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;SPAN&gt; because of policy &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Finance and Security can read schema &lt;/SPAN&gt;&lt;SPAN&gt;4&lt;/SPAN&gt;&lt;SPAN&gt; because of policy &lt;/SPAN&gt;&lt;SPAN&gt;4&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;Am I missing anything? Again, thank you both for helping expand my thinking on this!&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 24 Sep 2026 15:52:34 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/how-to-override-abac-policies/m-p/169729#M3003</guid>
      <dc:creator>cpayne_vax</dc:creator>
      <dc:date>2026-09-24T15:52:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to override ABAC policies</title>
      <link>https://community.databricks.com/t5/data-governance/how-to-override-abac-policies/m-p/169732#M3004</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/98366"&gt;@cpayne_vax&lt;/a&gt;&amp;nbsp;you've mapped this out perfectly.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/245135"&gt;@ThomazNeto&lt;/a&gt;&amp;nbsp;really nailed the &lt;STRONG&gt;WHEN NOT&lt;/STRONG&gt;&amp;nbsp;approach, which is the real lifesaver here. By using &lt;STRONG&gt;WHEN NOT has_tag('mask_scope')&lt;/STRONG&gt;&amp;nbsp;for your default policy, you don't even need to manually apply a 'standard' tag to Catalogs A, B, and C. The default just applies everywhere automatically, and you only lift a finger to tag your exceptions (Schemas 1, 2, and 4).&lt;/P&gt;&lt;P&gt;Regarding your &lt;STRONG&gt;Finance,Security&lt;/STRONG&gt;&amp;nbsp;snag: your workaround is exactly the right approach. If you tried applying two separate tags to trigger two separate policies on the same column, Databricks wouldn't grant access to both—it would throw a&amp;nbsp;&lt;STRONG&gt;MULTIPLE_MASKS&lt;/STRONG&gt;&amp;nbsp;error and lock it down. Creating a combined tag value and a dedicated policy for that specific combo is the native way to handle it.&lt;/P&gt;&lt;P&gt;As an architect, my only tweak to your sketch is how you deploy it: &lt;STRONG&gt;deploy &lt;I&gt;all&lt;/I&gt; those policy permutations to &lt;I&gt;all&lt;/I&gt; your catalogs.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Don't just apply the Finance policy to Catalog A and the Combo policy to Catalog B. Apply them all everywhere. That way, if a schema in Catalog C suddenly needs&amp;nbsp;&lt;STRONG&gt;Finance,Security&lt;/STRONG&gt;&amp;nbsp;access tomorrow, you just apply the tag and the logic is already sitting there waiting for it.&lt;/P&gt;&lt;P&gt;Manage those few combination policies centrally (via Terraform or a Python loop) and you're good to go. You've got this entirely straight in your head!&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 24 Sep 2026 16:19:59 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/how-to-override-abac-policies/m-p/169732#M3004</guid>
      <dc:creator>ShamenParis</dc:creator>
      <dc:date>2026-09-24T16:19:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to override ABAC policies</title>
      <link>https://community.databricks.com/t5/data-governance/how-to-override-abac-policies/m-p/169735#M3005</link>
      <description>&lt;P&gt;Awesome. Thank you both again, this is fairly simple to implement with our terraform code. You both gave great answers so I don't know who to accept as solution! I'll just pick the last response.&lt;/P&gt;&lt;P&gt;Thanks again!&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2026 17:03:14 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/how-to-override-abac-policies/m-p/169735#M3005</guid>
      <dc:creator>cpayne_vax</dc:creator>
      <dc:date>2026-09-24T17:03:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to override ABAC policies</title>
      <link>https://community.databricks.com/t5/data-governance/how-to-override-abac-policies/m-p/169850#M3006</link>
      <description>&lt;P class=""&gt;&lt;SPAN&gt;The scalable way to handle this is to keep the catalog-level policy, but use a governed tag and a WHEN condition to carve out the schema-level exception.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;You don't need to remove the catalog-level policy or add "Privileged Users" to the catalog-level EXCEPT list.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;For example, define a governed tag such as:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;mask_scope = privileged&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Apply this tag to Schema 1.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Because tags are inherited for ABAC policy evaluation, the tables under Schema 1 will effectively have this tag as well.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Then modify the Catalog A policy so that it does not apply to objects with this exception tag.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Conceptually:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Catalog A policy:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;TO: Users&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;EXCEPT: Unmasked Users&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;WHEN:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;NOT has_tag_value('mask_scope', 'privileged')&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;MATCH COLUMNS:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;has_tag('sensitive')&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;This means the catalog-level policy continues to protect the entire catalog, except for objects under schemas that have mask_scope = privileged.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Then create a Schema 1 policy for the specific exception:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;TO: Users&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;EXCEPT: Unmasked Users, Privileged Users&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;MATCH COLUMNS:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;has_tag('sensitive')&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;The result is:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Catalog A&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Schema 1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Unmasked Users → Unmasked&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Privileged Users → Unmasked&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Other Users → Masked&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Schema 2&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Unmasked Users → Unmasked&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Privileged Users → Masked&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Other Users → Masked&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;This gives you the desired behavior without having to manage policies individually for hundreds of schemas.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;The important idea is that the lower-level policy isn't actually "overriding" the inherited policy. Instead, the inherited catalog policy is conditionally prevented from applying to the exception schema, and the schema-level policy handles that schema.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;This also scales well because the default behavior remains at the catalog level. You only need to tag the schemas that require an exception.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;For example:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Catalog A&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;├── Schema 1 → mask_scope = privileged&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;├── Schema 2 → no exception tag&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;├── Schema 3 → no exception tag&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;└── Schema 4 → no exception tag&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Only Schema 1 requires additional configuration.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;I would also recommend using:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;SHOW EFFECTIVE POLICIES ON SCHEMA &lt;/SPAN&gt;&lt;SPAN&gt;Catalog A&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;Schema 1&lt;/SPAN&gt;&lt;SPAN&gt;;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;to verify which policies are being inherited and applied.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;This approach aligns with the Databricks recommendation to keep policies at the highest applicable scope while using governed tags and policy conditions to handle exceptions. Governed tags can be inherited from catalogs and schemas during ABAC evaluation.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;So, in short:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Keep the catalog-level policy → Add an exception tag to Schema 1 → Use WHEN NOT on the catalog policy → Add the schema-specific policy for Privileged Users.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This avoids the administrative overhead of moving everything to schema-level policies and prevents Privileged Users from getting unmasked access to Schema 2.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2026 16:33:21 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/how-to-override-abac-policies/m-p/169850#M3006</guid>
      <dc:creator>Srini_Pesala</dc:creator>
      <dc:date>2026-09-25T16:33:21Z</dc:date>
    </item>
  </channel>
</rss>

