> ## Documentation Index
> Fetch the complete documentation index at: https://developer.kyberis.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Databricks permissions

> A least-privilege map of who needs what across the app, notebooks, and jobs.

## Workspace roles

| Actor | Needs | Why |
| - | - | - |
| Workspace admin (one-time) | Create the secret scope and ACLs; create the Databricks App and its secret resources | Setup only |
| Analyst using the app | **Can use** on the app | Opens the app; never sees credentials |
| Analyst running notebooks | **READ** on the `kyberis` secret scope, access to the Git folder, and cluster attach | `dbutils.secrets.get` of the API key |
| Job service principal | **READ** on the `kyberis` secret scope, read on the source table, write on the output table | Scheduled enrichment runs |
| App service principal | **READ** on the `kyberis` secret scope, granted automatically via the app secret resources | Injecting environment variables at app start |

## What the integration does not need

* No workspace admin rights at runtime.
* No Unity Catalog metastore privileges beyond the tables you point the notebooks
  at.
* No cluster-scoped init scripts, and no cluster environment variables.
* No permissions in the Kyberis product beyond a standard customer API key with
  default read scopes. The integration performs read-only enrichment calls and
  never mutates Kyberis data.

## Sharing outputs

Enrichment output tables contain threat verdicts about your indicators. Treat
them like any security telemetry: grant table access via Unity Catalog to the
security team's groups, and avoid granting broad workspace-wide `SELECT`. Nothing
in the output rows contains credentials — see
[Data handling and privacy](/integrations/databricks/privacy).
