CertSafari
    Databricks Certified Data Analyst Associate· Lessons

    Domain 9 · Lesson 39/39

    Unity Catalog Table Ownership and Secure Storage Best Practices

    Apply best practices for storage and management to ensure data security, including table ownership and PII protection.

    10 min read
    2.56% of exam
    3 sources
    Published 3 Oct 2026
    Docs as of 30 Sep 2026

    What you will be able to do

    • Explain why production objects should be owned by groups and not by the person who created them
    • Tell object ownership apart from the MANAGE privilege, and decide when to delegate each one
    • Use catalog and schema usage privileges as guardrails against over-sharing by table owners
    • Pick managed storage and table types that keep data inside Unity Catalog governance

    Key concept

    Object ownership — Every Unity Catalog object has one owner. The owner holds every privilege on it and decides who else gets access. Securing data mostly comes down to deciding who that owner should be and how far their grants can reach.

    1.Who should own a table

    Ownership is the most powerful thing you can hold on a Unity Catalog object. The owner has every privilege on it, can grant privileges to others, and can transfer ownership itself. Ownership also starts out personal: whoever creates an object becomes its first owner. If nobody changes that, a production table stays tied to one person's account. That person's access, availability and mistakes then decide who can reach the data.

    Databricks' first rule follows from this: "Assign object ownership to groups, especially if objects are used in production." It also says production catalogs and schemas should always be owned by groups, not individual users. With group ownership, a team holds administrative control together, and changes in membership are handled in the group, not by reassigning objects one at a time.

    If you want to share administrative power without giving away ownership, use the MANAGE privilege. Owners can grant MANAGE to delegate ownership abilities on an object to other principals. MANAGE lets someone grant and revoke privileges on an object, transfer its ownership, and delete it, all without being the owner. Note that ALL PRIVILEGES is not a substitute: it includes all privileges except MANAGE, EXTERNAL USE LOCATION, and EXTERNAL USE SCHEMA. Ownership also reaches downward: catalog and schema owners can transfer ownership of any object in the catalog or schema. The guidance is to put either ownership or MANAGE with "a group that is responsible for administration of grants on the object", and to be sparing with both.

    Checkpoint 1 of 6· Check yourself

    A data engineering team wants three senior engineers to be able to grant access to a production table and drop it if needed, while the table's ownership stays with the platform group. What fits best?

    Checkpoint 2 of 6· Exam question

    A data analyst created a production sales table under their personal user account. Ahead of a team reorganization, the data platform team wants the table's ownership tied to the analytics group rather than the original creator, so that future privilege grants and audits survive staff turnover. Which SQL statement correctly transfers ownership?

    Sources1

    2.Limiting what owners and editors can share

    Group ownership settles who controls a table. The next risk is that a table owner shares it too widely. Unity Catalog guards against this at the container level. Reading a table needs USE CATALOG on its catalog and USE SCHEMA on its schema, as well as SELECT on the table. Only catalog and schema owners, or users with MANAGE, can grant those usage privileges. So a table owner who grants SELECT to an outsider has not opened the table to them. In Databricks' words, this "prevents table owners from granting access outside approved boundaries."

    This gives a simple team layout: create a schema per team and grant USE SCHEMA and CREATE TABLE only to that team, plus USE CATALOG on the parent catalog. Grant usage privileges only to users who should be able to see or query the data inside.

    Two more practices close the remaining gaps. First, views: by default only a view's owner can edit its definition, because an editor could otherwise rewrite the view to read data they are not allowed to see. To let several people edit a view safely, transfer its ownership to a group and grant that group access to the source tables. Every member can then edit it, but only within what the group can see. Second, writes: "Reserve direct MODIFY access to production tables for service principals." People read production data, and automated pipelines write it.

    Checkpoint 3 of 6· Check yourself

    Why does Unity Catalog, by default, let only the owner of a view edit its definition?

    Checkpoint 4 of 6· Exam question

    A data analyst who owns a Unity Catalog view tries to transfer its ownership directly to an external contractor's individual user account, someone who is not a member of any group the analyst belongs to. The `ALTER VIEW ... OWNER TO` statement fails with a permissions error. What explains this restriction?

    Sources21

    3.Keeping storage inside Unity Catalog's control

    Privileges only protect data if every access goes through Unity Catalog. Managed tables and volumes live in a managed storage location, which can be set at the metastore, catalog or schema level. Data lands in the lowest location available in that hierarchy. Catalogs are the main unit of data isolation, so Databricks says to give preference to catalog-level storage. Metastore-level storage was needed in early Unity Catalog environments but no longer is. If you do create one, use a dedicated bucket.

    The key storage rule is about bypass: "Do not use a bucket that can be accessed from outside of Unity Catalog." If an external service or principal reads the files directly, access control and auditability on managed tables and volumes are compromised. On the same grounds, do not reuse a bucket that is or was used for your DBFS root file system.

    Checkpoint 5 of 6· Check yourself

    A team suggests pointing a catalog's managed storage at an existing bucket that an external reporting service already reads directly. What is the security problem?

    Sources1

    4.Choosing managed tables for governance

    Unity Catalog governs every table you register in it. With a managed table, it also controls where the files are stored and how long they exist: dropping the table permanently deletes the files after an 8-day retention period. With an external table, you choose the location, and the files stay in place when the table is dropped. Databricks recommends managed tables for most use cases and for all new tables, because they let you use Unity Catalog's governance capabilities in full.

    External tables still have valid uses, for example during a Hive metastore upgrade or for non-Delta or non-Iceberg formats. The security concern is letting outside readers and writers reach their files directly, because doing so "bypasses Unity Catalog access control, auditing, and lineage." If external access cannot be avoided, limit it to reads and send all writes through Databricks and Unity Catalog. Databricks also recommends one external location per schema.

    Three different meanings of "manage" in Unity Catalog
    TermMeaningApplies to
    "Managed by Unity Catalog"Unity Catalog governs access, auditing, and lineage for the objectAll registered objects, including external tables and volumes
    Managed table or managed volumeUnity Catalog also controls the storage location and data lifecycle in your cloud accountTables and volumes only
    MANAGE privilegeLets a user assign or revoke privileges on, transfer ownership of, and delete an object without being the ownerAll Unity Catalog securable objects

    Checkpoint 6 of 6· Match them up

    Match each term to what it actually means

    Tap a term, then the definition that fits it.

    Sources13

    Exam traps

    Each one states something that sounds right. Open it to see what is actually true.

    1. 1.It's fine for the engineer who created a production table to stay its owner, since they understand it best.Why is that wrong?

      The creator becomes the first owner only by default. Best practice is to reassign ownership of production objects to a group so control doesn't depend on one person.

      Covered in Who should own a table

    2. 2.A table owner can give anyone access to their table just by granting SELECT.Why is that wrong?

      Readers also need USE CATALOG and USE SCHEMA on the parents. Only catalog and schema owners or MANAGE holders can grant those, so the table owner can't share past those boundaries.

      Covered in Limiting what owners and editors can share

    3. 3.An external table is not governed by Unity Catalog, while a managed table is.Why is that wrong?

      Unity Catalog governs access to every registered object, external tables included. "Managed" only refers to who controls the file location and lifecycle.

      Covered in Choosing managed tables for governance

    Sources

    Every claim above is drawn from one of these pages, quoted as it was written on the date shown.

    1. 1.
      “Assign object ownership to groups, especially if objects are used in production.”
      ↩︎ Who should own a table
      “Always assign ownership of production catalogs and schemas to groups, not individual users.”
      ↩︎ Who should own a table
      “Catalog and schema owners can transfer ownership of any object in the catalog or schema.”
      ↩︎ Who should own a table
      “configure ownership or grant the MANAGE privilege on all objects to a group that is responsible for administration of grants on the object”
      ↩︎ Who should own a table
      “Be sparing in your assignment of ownership and the MANAGE privilege.”
      ↩︎ Who should own a table
      “which includes all privileges except MANAGE, EXTERNAL USE LOCATION, and EXTERNAL USE SCHEMA”
      ↩︎ Who should own a table
      “It is typical to create a schema per team and grant USE SCHEMA and CREATE TABLE only to that team”
      ↩︎ Limiting what owners and editors can share
      “Reserve direct MODIFY access to production tables for service principals.”
      ↩︎ Limiting what owners and editors can share
      “Do not use a bucket that can be accessed from outside of Unity Catalog.”
      ↩︎ Keeping storage inside Unity Catalog's control
      “Give preference to catalog-level storage as your primary unit of data isolation.”
      ↩︎ Keeping storage inside Unity Catalog's control
      “Do not reuse a bucket that is or was used for your DBFS root file system.”
      ↩︎ Keeping storage inside Unity Catalog's control
      “Doing so bypasses Unity Catalog access control, auditing, and lineage.”
      ↩︎ Choosing managed tables for governance
      “If you must allow external access to external tables, limit it to reads, with all writes happening through Databricks and Unity Catalog.”
      ↩︎ Choosing managed tables for governance
      “An object's owner has all privileges on the object, such as SELECT and MODIFY on a table,”
      ↩︎ Key concept
      “Assign object ownership to groups, especially if objects are used in production.”
      ↩︎ Exam trap 1
      “The creator of any object is its first owner. Creators should reassign ownership to appropriate groups.”
      ↩︎ Prediction
      “Owners can grant the MANAGE privilege to delegate ownership abilities on an object to other principals.”
      ↩︎ Checkpoint
      “This prevents privilege escalation where an editor could modify the view to access unauthorized data.”
      ↩︎ Checkpoint
      “access control and auditability on managed tables and volumes are compromised”
      ↩︎ Checkpoint
    2. 2.
      “this prevents table owners from granting access outside approved boundaries”
      ↩︎ Limiting what owners and editors can share
      “this prevents table owners from granting access outside approved boundaries”
      ↩︎ Exam trap 2
    3. 3.
      “Data files are permanently deleted after an 8-day retention period”
      ↩︎ Choosing managed tables for governance
      “When people say that an object is managed by Unity Catalog, they typically mean that Unity Catalog governs access to it.”
      ↩︎ Exam trap 3
      “When people say that an object is managed by Unity Catalog, they typically mean that Unity Catalog governs access to it.”
      ↩︎ Checkpoint

    Continue to page 2 of 2

    Protecting PII with Governed Tags, ABAC, Row Filters and Column Masks

    Spotted a mistake, or was something unclear? Tell us.