Detect & govern
Once your estate is scanned, Mortar turns it into a worklist and a workflow.
Risks
The Risks page is a triage worklist, not a raw dump. Findings are grouped by severity and type:
- Escalation - a group or principal holding
ALL_PRIVILEGES/MANAGE. - Effectively public - an everyone-group reaching a sensitivity-tagged catalog.
- Privileged admin, SP takeover, token minter, storage bypass, empty privileged group, and more.
Noise is dampened at the source: findings on dormant catalogs (backup, old, test) are demoted with a reason, and duplicate findings across a shared metastore fold into one. You can accept a finding with a reason and an optional expiry, or turn member-specific findings into removal reviews in one click.
Drift
Every scan diffs against the previous one. Drift shows what changed - members added or removed, new grants, new workspace-object permissions, secret scopes, ABAC policies - classified by severity so a risky change stands out from routine churn. With a warehouse configured, drift is attributed to the actor who made it. Expected churn (nightly IdP sync) can be auto-acknowledged with saved patterns.
Access reviews and certifications
- Change queue - admin- and steward-authored membership changes that execute back to Databricks under the approver's own identity, with segregation-of-duties enforced.
- Certifications - periodic campaigns where reviewers certify or revoke each membership. Overdue campaigns escalate; a revoke can flag access for removal. Evidence is a content-hashed, audit-ready PDF/HTML export.
- Just-in-time access - time-bounded access requests that auto-expire, with approvals routed to a unified inbox.
Compliance policies
Write your access rules as policy-as-code (YAML) and Mortar evaluates them
against every scan. Rules cover required and forbidden grants, ownership,
cardinality caps, unused access, workspace settings, and tag-scoped matches.
Violations are diffable over time, waivable with a reason, and auto-fixable
where a safe GRANT/REVOKE exists. Built-in packs cover common baselines
(best practices, SOC 2, HIPAA, PCI, CIS).
Notifications
Route drift and compliance alerts to Slack, email, PagerDuty, or Opsgenie by severity. Quiet hours hold non-critical alerts and digest them at the next active window; critical always pages.