Supported Features
The SailPoint Databricks source supports the following features:
Authentication and Account Host
-
Databricks custom (vanity) account URLs for account and workspace API routing.
-
Databricks OAuth authentication through AWS Workload Identity Federation.
Note
The standard Databricks account hosts and the existing Databricks M2M and Microsoft Entra authentication types remain supported and are unchanged by default.
Account Aggregation
The source aggregates the following objects:
Account Objects
-
Users
-
Service principals
Entitlement Aggregation
The source aggregates the following entitlements:
Groups
-
Databricks groups as groups
Workspace Access
-
Workspace Permission as
workspaceEntitlements
Account Roles
-
Connected Account Roles as
accountLevelRoles
Group Aggregation
-
Aggregation of Databricks groups with connected permissions aggregated.
-
Aggregation of roles (account level).
-
Aggregation of all workspace access along with permissions.
-
Connected permissions are also aggregated.
Note
"Group Aggregation" is Databricks-specific terminology.
Provisioning Support
User Provisioning
|
Operation |
Supported |
|
Create user |
Yes |
|
Update user |
Yes |
|
Disable user |
Yes |
|
Enable user |
Yes |
|
Delete user |
Yes |
|
Add/Remove Entitlement |
Yes |
Agent Management
The Databricks source supports governance of Mosaic AI Agents (serving endpoints) at the workspace level through Dataset 2.0.
|
Feature |
Description |
|---|---|
|
Aggregation of workspace-level agents |
Discovers and aggregates Mosaic AI agents (serving endpoints) from configured Databricks workspaces. Agents are collected via Dataset 2.0 (databricks:mosaic) and exposed as resources of type std:agent (databricks:mosaic-agent). Aggregated attributes include agent ID, name, creator, timestamps, workspace details, configuration, and operational state. |
|
Activate/Deactivate agent |
Supports lifecycle management of workspace-level agents through Activate Agent and Deactivate Agent provisioning actions. |
Agent Status Mapping
During aggregation, the source normalizes the Databricks agent state object into spStatus (Active or Inactive) using the fields below.
|
spStatus |
Ready |
|---|---|
|
Active |
READY |
|
Inactive |
NOT_READY |
Note
When an agent is activated, Databricks takes approximately 2–3 minutes to fully start it. The activate (start) API returns a success (200) response immediately, but at that point the agent is still starting up and reports ready = NOT_READY with config_update = IN_PROGRESS. For the activate-agent use case only, the connector treats this transitional state as Active, since the agent is on its way to becoming ready.