TRAILOX FOR DATABRICKS

Trace activity across identities, jobs, and tables

Understand access across workspaces, jobs, service principals, catalogs, and tables. Detect behavioral changes and investigate historical activity across every workspace.

Trailox Databricks access overview

Native telemetry used

Trailox reads Databricks workspace audit logs and Unity Catalog access and lineage events, delivered to your own cloud storage, alongside cluster and job run metadata.

What access Trailox can see

Notebook and job executions, table and schema reads and writes through Unity Catalog, cluster and SQL warehouse usage, and the API calls captured in audit logs.

Identity and workload attribution

Trailox resolves every event to the user or service principal behind it, and to the job, notebook, cluster, or SQL warehouse that ran it, so a table read can be traced back to the pipeline that produced it.

Trailox Databricks identities, resolved to user and service principal

Behavioral detections for Databricks

  • A service principal accessing a catalog, schema, or table for the first time
  • Jobs reading an unusually large volume of data relative to their history
  • Access to production catalogs outside a job's scheduled run window
  • Permission or access control list changes on sensitive tables
  • New clusters or SQL warehouses touching data they haven't accessed before

Investigation capabilities

Trace activity across identities, jobs, service principals, catalogs, schemas, and tables, and reconstruct a table's complete access history over time.

How Trailox connects

Read-only access to the audit log delivery location and Unity Catalog system tables. Nothing is deployed inside clusters or jobs.

Start with proof,
not a pitch.

Scoped read-only role, 30-day lookback, results in 48 hours.