Grant Databricks Access

THIAM_HUATTAN
Valued Contributor

DatabricksQuestionIn the above printscreen of Grant Databricks Access, we see we need to give the rights to a certain Bucket at the highest level.

Why is this so?

Are we able to limit the rights to only certain directories in a bucket, when we need Databricks to have access to certain directories only?

Another more important question, why is there a need to grant Databricks access of everything (add, list, modify, delete) of the AWS account at the root level? Isn't this a security concern? Or do I misinterpret it?

Please help to clarify, thanks.