See the system
Understand storage, compute, identity, and catalog boundaries before provisioning an AI application.
Separate storage, compute, and control
Cloud object storage holds durable files. Compute reads and transforms data. The platform’s control features coordinate resources, permissions, jobs, and metadata. These are related but distinct layers with different failure and cost characteristics.
Draw which identity accesses which resource through which network path. A successful notebook query does not prove that the eventual application service identity can access the same table, nor that an end user should receive every row.
Learn the workspace vocabulary
A workspace organizes development and operational resources. Catalogs and schemas organize governed data objects. Tables represent structured data; volumes support governed file access in suitable configurations. Compute options vary by workload and platform availability.
Learn concepts before memorizing console clicks. Document the exact cloud, region, account features, and runtime used for a lab. Platform menus and feature names can change while the underlying access and lifecycle concepts remain useful.
Design least-privilege access
A person, application, and deployment pipeline should not all share a powerful credential. Assign distinct identities and the minimum documented permissions for their tasks. Verify both allowed and denied operations.
Unity Catalog governance is part of the data boundary, but the application still needs a deliberate strategy for representing user entitlements. Avoid assuming the application’s broad service access automatically becomes per-user authorization.
Keep environments and credentials separate
Development, test, and production should have explicit configuration and appropriate data boundaries. A name prefix alone does not isolate permissions. Review who can deploy, who can read secrets, and which systems an environment can reach.
Use supported identity flows and secret handling. Never put access tokens in notebooks, downloadable assets, or screenshots. Establish credential rotation and revocation expectations with the platform owner.
Control lifecycle and cost
Compute, search resources, model calls, and storage can all contribute to cost. A notebook finishing does not imply every provisioned resource stopped billing. Before a lab, identify billable resources, expected usage, and cleanup responsibilities.
Free or trial environments may not support all required features. Offer a local conceptual exercise, then label managed-platform verification incomplete until it is actually performed. Reproducibility includes teardown, not just setup.
Worked scenario
An analyst can query a table in a notebook, but the deployed app fails. The app runs under a separate identity with different grants. Diagnose the actual identity, target catalog/schema, documented privileges, and network path instead of copying the analyst’s personal credential into the service.
Practical assignment
- Choose one cloud and record environment availability.
- List required privileges before provisioning.
- Create a synthetic governed dataset where access permits.
- Verify one allowed and one denied operation per role.
- Capture the architecture and resource inventory.
- Run cleanup and record managed checks not performed.
What to submit
Submit the artifacts named above, a short explanation of your decisions, and evidence of the checks you performed. Distinguish measured results from estimates and designs from executed integrations.
| Review dimension | Submission evidence |
|---|---|
| Correctness | Show the expected behavior and a meaningful counterexample. |
| Reproducibility | State setup, inputs, versions, and what was actually executed. |
| Delivery judgment | Explain the client impact, alternative, and unresolved assumption. |
| Operational boundary | Identify permissions, failure behavior, and any resource cleanup. |
Knowledge check
Answer guide
- No. The app may use a different identity, network path, and permissions.
- Account requirements, billable resources, and cleanup. Availability and charges depend on the selected environment.
- Distinct least-privilege identities. Separate identities support constrained permissions, audit, and revocation.
References & next step
Platform examples are environment-dependent. Start with the official documentation in the reference library and verify the exact cloud, region, privileges, and versions you use.
Open the official reference library
Editorial edition: 5 October 2026. The local reference lab is executed locally; this course does not claim a live Databricks deployment.