Apply Unity Catalog row filters and column masks to restrict data access

domain: data-engineering · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Write a SQL UDF returning BOOLEAN for a row filter, or a UDF returning the masked value's type for a column mask.
  2. Apply a row filter with ALTER TABLE <table> SET ROW FILTER <function_name> ON (<col1>, <col2>) — rows where the function returns FALSE are excluded from results.
  3. Apply a column mask with ALTER TABLE <table> ALTER COLUMN <col> SET MASK <mask_function> [USING COLUMNS (<other_col>, ...)], or declare it at table creation with col_name TYPE MASK mask_func_name.
  4. Match the masking function's return type to the column — supported types include STRING, numeric types (INTEGER, FLOAT, DOUBLE, DECIMAL...), BOOLEAN, INTERVAL, and NULL.
  5. Test against Databricks Runtime 12.2 LTS or newer — earlier runtimes don't enforce row filters/column masks, and Unity Catalog fails securely by returning no data rather than unmasked data.

Known gotchas

Related routes

Grant privileges on Unity Catalog securable objects using SQL
docs.databricks.com · 6 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans