sarahbhord
Databricks Employee
Databricks Employee

Hey @emanueol!

Good question - While UC is designed to provide a governance layer across managed tables, external tables, foreign catalogs (via query and catalog federation), and shares, there are architectural limitations when data is accessed outside Databricks compute.

Unity Catalog's row filters and column masks are enforced at query time within Databricks. When you query a Lakebase synced table directly via PostgreSQL (bypassing Databricks SQL warehouses), UC's access controls cannot be enforced because the query execution happens entirely within the PostgreSQL engine. 

We do expect to add more integrated support for permissions between Lakebase and Unity Catalog in the future.