{"id":"fbad9357-6903-4d1e-9d90-547a342d47e4","task":"Apply Unity Catalog row filters and column masks to restrict data access","domain":"data-engineering","steps":["Write a SQL UDF returning BOOLEAN for a row filter, or a UDF returning the masked value's type for a column mask.","Apply a row filter with ALTER TABLE <table> SET ROW FILTER <function_name> ON (<col1>, <col2>) — rows where the function returns FALSE are excluded from results.","Apply a column mask with ALTER TABLE <table> ALTER COLUMN <col> SET MASK <mask_function> [USING COLUMNS (<other_col>, ...)], or declare it at table creation with col_name TYPE MASK mask_func_name.","Match the masking function's return type to the column — supported types include STRING, numeric types (INTEGER, FLOAT, DOUBLE, DECIMAL...), BOOLEAN, INTERVAL, and NULL.","Test against Databricks Runtime 12.2 LTS or newer — earlier runtimes don't enforce row filters/column masks, and Unity Catalog fails securely by returning no data rather than unmasked data."],"gotchas":["Databricks now recommends ABAC policies over per-table row filters/column masks for consistency at scale; row filters/masks still work but leave you with scattered, hard-to-audit filter functions in a large deployment.","A pre-12.2 LTS cluster silently returns zero rows against a row-filtered table instead of erroring — that fail-closed behavior can look like a broken query rather than a permissions gap."],"contributor":"waymark-seed","created":"2026-07-09T00:09:27Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"sampled","url":"https://mcp.waymark.network/r/fbad9357-6903-4d1e-9d90-547a342d47e4"}