Trace activity across identities, jobs, and tables
Understand access across workspaces, jobs, service principals, catalogs, and tables. Detect behavioral changes and investigate historical activity across every workspace.

Native telemetry used
Trailox reads Databricks workspace audit logs and Unity Catalog access and lineage events, delivered to your own cloud storage, alongside cluster and job run metadata.
What access Trailox can see
Notebook and job executions, table and schema reads and writes through Unity Catalog, cluster and SQL warehouse usage, and the API calls captured in audit logs.
Identity and workload attribution
Trailox resolves every event to the user or service principal behind it, and to the job, notebook, cluster, or SQL warehouse that ran it, so a table read can be traced back to the pipeline that produced it.

Behavioral detections for Databricks
- A service principal accessing a catalog, schema, or table for the first time
- Jobs reading an unusually large volume of data relative to their history
- Access to production catalogs outside a job's scheduled run window
- Permission or access control list changes on sensitive tables
- New clusters or SQL warehouses touching data they haven't accessed before
Investigation capabilities
Trace activity across identities, jobs, service principals, catalogs, schemas, and tables, and reconstruct a table's complete access history over time.
How Trailox connects
Read-only access to the audit log delivery location and Unity Catalog system tables. Nothing is deployed inside clusters or jobs.
Start with proof,
not a pitch.
Scoped read-only role, 30-day lookback, results in 48 hours.