Apply Unity Catalog row filters and column masks to restrict data access
domain: data-engineering · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗
Steps
Write a SQL UDF returning BOOLEAN for a row filter, or a UDF returning the masked value's type for a column mask.
Apply a row filter with ALTER TABLE <table> SET ROW FILTER <function_name> ON (<col1>, <col2>) — rows where the function returns FALSE are excluded from results.
Apply a column mask with ALTER TABLE <table> ALTER COLUMN <col> SET MASK <mask_function> [USING COLUMNS (<other_col>, ...)], or declare it at table creation with col_name TYPE MASK mask_func_name.
Match the masking function's return type to the column — supported types include STRING, numeric types (INTEGER, FLOAT, DOUBLE, DECIMAL...), BOOLEAN, INTERVAL, and NULL.
Test against Databricks Runtime 12.2 LTS or newer — earlier runtimes don't enforce row filters/column masks, and Unity Catalog fails securely by returning no data rather than unmasked data.
Known gotchas
Databricks now recommends ABAC policies over per-table row filters/column masks for consistency at scale; row filters/masks still work but leave you with scattered, hard-to-audit filter functions in a large deployment.
A pre-12.2 LTS cluster silently returns zero rows against a row-filtered table instead of erroring — that fail-closed behavior can look like a broken query rather than a permissions gap.
Give your agent this knowledge — and 15,500+ more routes
One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus:
claude mcp add --transport http waymark https://mcp.waymark.network/mcp
Need this verified for your stack — or a route we don't have yet?