Detect & govern

Once your estate is scanned, Mortar turns it into a worklist and a workflow.

Risks

The Risks page is a triage worklist, not a raw dump. Findings are grouped by severity and type:

  • Escalation - a group or principal holding ALL_PRIVILEGES / MANAGE.
  • Effectively public - an everyone-group reaching a sensitivity-tagged catalog.
  • Privileged admin, SP takeover, token minter, storage bypass, empty privileged group, and more.

Noise is dampened at the source: findings on dormant catalogs (backup, old, test) are demoted with a reason, and duplicate findings across a shared metastore fold into one. You can accept a finding with a reason and an optional expiry, or turn member-specific findings into removal reviews in one click.

Drift

Every scan diffs against the previous one. Drift shows what changed - members added or removed, new grants, new workspace-object permissions, secret scopes, ABAC policies - classified by severity so a risky change stands out from routine churn. With a warehouse configured, drift is attributed to the actor who made it. Expected churn (nightly IdP sync) can be auto-acknowledged with saved patterns.

Access reviews and certifications

  • Change queue - admin- and steward-authored membership changes that execute back to Databricks under the approver's own identity, with segregation-of-duties enforced.
  • Certifications - periodic campaigns where reviewers certify or revoke each membership. Overdue campaigns escalate; a revoke can flag access for removal. Evidence is a content-hashed, audit-ready PDF/HTML export.
  • Just-in-time access - time-bounded access requests that auto-expire, with approvals routed to a unified inbox.

Compliance policies

Write your access rules as policy-as-code (YAML) and Mortar evaluates them against every scan. Rules cover required and forbidden grants, ownership, cardinality caps, unused access, workspace settings, and tag-scoped matches. Violations are diffable over time, waivable with a reason, and auto-fixable where a safe GRANT/REVOKE exists. Built-in packs cover common baselines (best practices, SOC 2, HIPAA, PCI, CIS).

Notifications

Route drift and compliance alerts to Slack, email, PagerDuty, or Opsgenie by severity. Quiet hours hold non-critical alerts and digest them at the next active window; critical always pages.