Cross-engine attribute-based access controls went generally available on 1 October 2026. Supported external engines can read Unity Catalog managed tables with ABAC policies, row filters and column masks enforced, and the enforcement runs on Databricks serverless compute (release notes).
The gap this closes #
Until now, a row filter was a promise that held inside Databricks. You wrote a policy that said a sales rep sees only their region, it worked beautifully in a SQL warehouse and in a notebook, and then someone pointed Trino or Spark or an Iceberg client at the same managed table through an open endpoint and the filter wasn't in the path. The usual workaround was to stop sharing the real table. Teams built a second, pre-filtered copy per audience, or they wrapped everything in a view they could control, or they simply refused external engine access and told people to come in through a warehouse.
That pattern is expensive in the dull way: a copy per tenant, a job per copy, a drift problem nobody notices until a column changes and one audience silently stops getting a field.
With this GA, the policy travels with the table. You write the attribute rule once in Unity Catalog and a supported external reader gets the filtered result rather than the raw one.
Read the cost line before you turn it on #
The release note says enforcement happens on Databricks serverless compute, and it points at a requirements page that covers supported clients and serverless compute costs. That sentence is the whole commercial story. An external engine reading a governed table is no longer free of Databricks compute, because Databricks is doing the filtering work on the way out.
So the trade is a real one. You delete the per-audience copies and the pipelines that maintained them, and you pick up a serverless line item that scales with how often external engines read. Which side comes out ahead depends on read volume, and nobody can tell you that from a slide. Run one workload, let it bill for a cycle, and compare it against what the duplicate tables were costing you in storage and job time. The method is the same one we lay out in Cost and Performance.
There is also a scope check to do first. Supported external engines is a list, not a category, and the enforcement applies to managed tables. If your external readers are hitting external tables or an engine that isn't on the list, nothing changed for you this week.
Where this lands in the guide #
This moves the advice in Multi-Tenant and Per-User Reporting. Our default there has been that per-tenant isolation gets more reliable the closer it sits to the data, and the practical limit was that the isolation only held for clients coming through Databricks. That limit is gone for supported engines, so a single governed table with an attribute policy becomes a credible design for tenants who bring their own query engine.
It also affects Security and Identity and Tables and Storage. Attribute-based policies are worth more now than tag hygiene usually gets credit for, because the attributes that drive the filters are the same ones your auditors will ask about. If your tagging is inconsistent, this GA makes that inconsistency visible in more places at once.
What we would do first #
Find the copies. Look for the tables whose only reason to exist is that an outside tool couldn't be trusted with the original. Those are the test cases, and the one with the lowest read volume is the one to try, because it is the cheapest place to learn what enforcement costs you per scan.
Questions people ask #
Do Unity Catalog row filters apply to external engines? #
Yes, for supported external engines reading Unity Catalog managed tables. Cross-engine attribute-based access controls went generally available on 1 October 2026, enforcing ABAC policies, row filters and column masks.
Does cross-engine ABAC enforcement cost anything? #
The enforcement runs on Databricks serverless compute, and the requirements page covers supported clients and serverless compute costs, so external reads of governed tables now show up on the Databricks bill.