Unity catalog enabled workspace -Is there any way to disable workflow/job creation for certain users
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-03-2025 11:15 AM
Databricks offers a robust platform with a variety of features, including data ingestion, engineering, science, dashboards, and applications. However, I believe that some features, such as workflow/job creation, alerts, dashboards, and Genie, being available to all users by default complicates large-scale management. Databricks should enable workspace administrators to manage user access to these features more effectively.
I don't see a valid reason for these features to be universally accessible to all users. For example, in a production Databricks workspace, any user with access can create workflows, alerts, dashboards, and Genie, which is inappropriate since end users should not be able to modify anything directly in production.
I have raised this issue with Databricks support and posted in the community, but I am surprised that it has not been implemented yet. If others share my viewpoint, please consider voting/Like this post to get attention from data bricks team..
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-03-2025 11:21 AM
You can set this users to not to be able to create clusters, this way they wont be able to create jobs and will only be able to use the clusters already created and assigned to them. To do this you can go to settings > Identity and Access > Users or specific group and under entitlements toggle off Unrestricted cluster creation.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-03-2025 11:25 AM
@Walter_C - none of the users have "Unrestricted cluster creation" in our workspaces. as i mentioned it is not only about jobs but other features as well are openly available to all users (alerts, dashboards, and Genie).
suggested is neither a solution nor a workaround. appreciate if you can take this up with product team.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-03-2025 11:27 AM
There is a feature request open for a more direct way to only restrict jobs which is currently being considered for the future, the idea tracking id is DB-I-8064
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-03-2025 11:34 AM
I understand your concern, as you have mentioned as of now there is no way to restrict this at the workspace level, I know that there is also another feature request DB-I-4199 which is to assign a read only role in the workspace that allow users to only see what they are being assigned to but this is also something that is being considered for the future.

