USE CASES / DATABRICKS

Put a decision in front of your model endpoints.

GovernorAI inventories the AI surfaces in your workspace, then allows or denies individual inference calls at the Model Serving endpoints you choose — with an audit record for every decision. Turning it on changes four environment variables on one served entity. Turning it off puts your original configuration back.

Per-endpoint, opt-in Verified before it reports success Restores the exact original config
Enable, verify and restore on one served entity The endpoint configuration is snapshotted exactly as Databricks returned it, four environment variables are added to one served entity, the change is read back from Databricks before success is reported, and disable restores the captured configuration and confirms the match. ONE SERVED ENTITY, FOUR VARIABLES 01  Snapshot the config exactly as Databricks returned it, large numbers intact 02  Change four environment variables on one served entity — nothing else is touched 03  Verify read back from Databricks; update-failed, cancelled or timeout all fail closed 04  Restore disable puts the captured config back, then confirms it matches

It refuses rather than guesses: if another system's governance markers are already on the endpoint, if it would record an already-governed config as your original, or if it cannot read the change back from Databricks.

reversibleper endpointyou choose which

THE FIRST QUESTION A PLATFORM TEAM ASKS

Turning it on is reversible, and we prove it worked before saying so.

Before any capability claim, the fear has to go. The change is small, it is verified against Databricks rather than assumed, and it can be put back exactly as it was.

Guarantee
How it holds
The change is minimal
Four environment variables on a single served entity. Nothing else on the endpoint is modified.
The original is captured losslessly
The configuration is stored exactly as Databricks returned it, including integers too large for ordinary JSON handling to round-trip without silently rounding them.
Two operators cannot interleave
The operation takes a lock and re-reads the connection fresh before mutating, and the intent and recovery snapshot are written down before the change is made.
Success is read back, not assumed
After mutating, GovernorAI polls the endpoint to a terminal state. An update that fails, is cancelled, or times out is reported as a failure — never as success.
It refuses rather than guesses
It stops if another system's governance variables are already present, and it will not record an already-governed configuration as your original.
Disable is checked too
Restore compares the returned configuration against the snapshot. A later discovery re-sync will not erase the enablement state.

WHAT GETS DECIDED

A policy decision on every inference call you route through us.

Your caller posts to a GovernorAI endpoint URL instead of the Databricks /invocations URL. The endpoint name, provider and the messages or inputs are evaluated against your policy before anything reaches Databricks.

Outcome
What happens
Allow
Forwarded to your workspace endpoint. The model's response comes back unchanged.
Deny
HTTP 403, naming the policy and the rule that caused it. The call never reaches Databricks.
Authentication
A per-endpoint shared secret, compared in constant time. If no secret is set, the path fails closed.
Overload
A per-tenant circuit breaker runs before forwarding, so one tenant cannot drag the path down for another.

The ceiling, stated here rather than in a footnote. This path carries allow and deny only. There is no approval step on it — an approval or redaction rule pointed at it resolves to a deny, so do not author one. The decision is on the request; the response passes through untouched. The Databricks endpoint URL keeps working, so this is a control you route to, not an interception. You author the policy; no Databricks policy pack ships. With no matching rule the call is allowed unless your deployment is configured to fail closed, and the emergency kill switch does not apply to this path.

PER-ENDPOINT SCOPE

Different rules for different endpoints.

Governance is only useful if it can be narrow. Each governed endpoint carries its own identity plus a namespace you choose when you enable it, so fraud-scorer and support-chat can sit under different policies.

A rule matches on a tool-name pattern plus one condition on the call's arguments, such as which endpoint was invoked. There is no rule axis for a catalog, schema, table, cluster, SQL warehouse, job, model version or user identity — better to know that now than to find it in a proof of concept.

WHAT WE CAN SEE

An inventory of the AI surfaces in your workspace.

One connection per workspace, authenticated with a workspace token. Five API surfaces are read, hourly by default and on demand when you ask. Only Model Serving endpoints are governable — everything else is inventory, and enrolling one of the others is refused with a typed error rather than quietly accepted.

Surface
Status
Model Serving endpoints
Inventoried and governable. Foundation-model and Mosaic-agent classification folds onto the same endpoint row.
Unity Catalog registered models
Inventoried, not governable.
Unity Catalog functions
Inventoried once you name a catalog and schema on the connection. One per connection, and off until you do.
Vector Search indexes
Inventoried, not governable.
Clusters, jobs, SQL warehouses, notebooks, pipelines, dashboards
Not inventoried.
Account-level rollup
Not available. Twenty workspaces means twenty connections.
Unity Catalog grants, row filters, column masks
Never read and never changed.

On a very large Unity Catalog the model and function lists can under-report, and a token without catalog read permission returns an empty list rather than an error. That is why there is an on-demand connection check that confirms the token can reach the metastore and names the permissions it is missing.

YOUR WORKSPACE TOKEN

Encrypted at rest, rotatable, and verified before it replaces the old one.

The token is encrypted with AES-256-GCM using a fresh nonce per write, and the connection object the API returns carries no credential fields at all.

Rotation
What it guarantees
Verified before persisted
The new token is checked against your workspace first. If verification fails, the old one is restored.
One transaction
The write and the version bump happen together, and every running instance is told to drop its cached client. An instance that cannot subscribe to those notifications refuses to start rather than run on a stale token.
The workspace is identity
Only the secret rotates. A connection can never be quietly re-pointed at a different workspace.

Named limits. One long-lived personal access token that you mint — service-principal OAuth is not available today, and GovernorAI cannot verify or narrow the token's permissions, nor track its age or expiry. There is one platform encryption key, so bring-your-own-key and per-tenant keys are not offered, and rotating that platform key for stored workspace tokens is not supported today.

IF YOU INSTRUMENT THE CALL YOURSELF

Your own code can also get approvals and a kill switch.

The endpoint proxy is the no-code-change option, and it has a real ceiling. The SDK path is where the fuller set of outcomes is genuinely enforced — worth saying which is which rather than blurring them together.

On the SDK path
What it does
Allow, deny and approval
Python wrappers for a Databricks agent and for MLflow-served models ask GovernorAI for a decision before the call runs. A deny raises; an approval-required raises and waits for a human.
The kill switch applies
The emergency stop is enforced on this path, which it is not on the endpoint proxy.

It covers only code you change. Approvals fire from an approval rule you author — automatic risk-based escalation is off by default. No lane on any Databricks path redacts, masks or rewrites a payload.

THE BOUNDARY

What this does not cover.

A platform team that finds these limits on its own stops the deal. Here they are first.

Limit
Detail
Nothing forces traffic through us
A caller that keeps using the Databricks endpoint URL directly is ungoverned and produces no record. Enrollment is per endpoint and opt-in.
Cluster and notebook egress control
In development, not available today. Both x86-64 and arm64 pools are handled by the installer — that is build status, not availability.
No response-side control
Model output returns to the caller unchanged. No redaction, masking or output filtering anywhere in this integration.
Not governed and not discovered
Genie and AI/BI SQL, Databricks Assistant, Agent Bricks, Databricks managed MCP servers, SQL warehouse queries, jobs and notebook execution.
Unity Catalog stays yours
We read model and function metadata. We never read or change permissions. Unity Catalog governs who may touch data; GovernorAI governs agent actions at the endpoints you enroll.
No log ingestion
Inventory comes from polling your workspace APIs. MLflow traces and Unity Catalog audit logs are not ingested.
Connecting governs nothing
Discovery lists surfaces. You choose which endpoints to enroll.

THE RECORD

What lands in the audit trail, and what does not.

Each decision records the time, the endpoint-derived action name, the namespace, allow or deny, and the policy and rule that decided it, attributed to your tenant.

It is a decision record, not an inference log: the prompt, the model's response, token counts, cost and latency are not recorded. Requests rejected before policy evaluation — unknown endpoint, bad secret, circuit open — produce no record at all. Control-plane actions, such as who connected a workspace, who enabled governance on which endpoint and who rotated a token, are written to a hash-chained, tamper-evident ledger. Runtime decisions on Databricks endpoints are durable rows: not hash-chained and not signed. There is no SIEM delivery today, and no compliance evidence item is produced for a Databricks decision.

BEFORE THE CLUSTER STARTS

A cluster that cannot start ungoverned is still running an agent nobody assessed.

Pinning governance at cluster-create guarantees the decision path exists. It does not say the agent inside it should have been deployed. Assurance answers that separately, before the release, and blocks the pipeline rather than reporting after the fact.

It ships as a CI/CD gate whose exit codes mean distinct things — pass, blocked, unreachable and unauthorised are four different answers, and unreachable fails closed.

See what each domain needs →

Continue