How to prevent direct workspace changes in Databricks by vendors / external users?

koti521
New Contributor II

Hi Team,

I’m looking for guidance on workspace governance and change control in Databricks, specifically related to vendor access.

We recently observed that workspace-level changes seem to be applied directly, and we want to understand how this is happening and how to better control it.

Is it possible for the Databricks (service provider) internal team to apply direct changes to a customer workspace (such as policies, configurations, or settings), and if so, how can organizations enforce controls to ensure all workspace changes are applied only through approved mechanisms with full auditability?

can you find out from Databricks how workspace changes are applied directly from vendor?