Unity Catalog is Databricks' central governance layer. It manages access control, auditing, lineage and discovery for data and AI assets across all workspaces in an account, from one place.
Why it was introduced
Before it, each workspace had its own Hive metastore, with its own permissions. A company with ten workspaces had ten places to manage access, with no shared lineage or audit. Unity Catalog moves all of that into one account-level metastore, so a policy written once applies everywhere.
Three-level namespace
SELECT * FROM prod.sales.orders; -- catalog.schema.table
Catalogs are the top level (often one per environment or domain), then schemas, then tables, views, volumes, functions and ML models. Permissions can be granted at any level and are inherited downwards.
GRANT USE CATALOG ON CATALOG prod TO `analysts`; GRANT USE SCHEMA, SELECT ON SCHEMA prod.sales TO `analysts`;
What it provides
- Fine-grained access: table and column permissions, plus row filters and column masks that apply at query time.
- Lineage: automatic capture of how tables and columns are derived from each other, down to column level, across notebooks, jobs and dashboards.
- Audit logs of who accessed what.
- Tags and comments, and search, for discovery.
- Volumes for governing non-tabular files, and governance of functions and registered models.
- Managed storage locations and credentials, so users do not handle cloud keys.
Open source and interoperability
Unity Catalog has an open-source version. It can also expose tables through an Iceberg REST catalog interface, so other engines can read governed tables.
What to say
Highlight the three things interviewers like: one governance layer across workspaces, catalog.schema.table naming, and column-level lineage. Mention that you grant privileges to groups, not individual users, and that it replaces the older per-workspace Hive metastore for new work.