CSA LoomCSA Loom
Home
Ctrl K
Sign in
HomeWorkspacesBrowse
Lakehouse catalogSearchMarketplaceData productsConnectionsGovernance
Real-Time IntelligenceData ScienceOrchestration (Warp)Estate builderAgent MeshDeveloper
DeploymentWorkload hubScheduler
LineageAssetsMonitorReportsCopilot
  1. Home
  2. Unified catalog

One catalog across your Loom workspaces, Microsoft Purview, and Databricks Unity Catalog — search, govern, and grant access without leaving Loom. (Fabric OneLake is opt-in.)
SearchFederated search across Purview, Unity Catalog, and OneLake.BrowseTree view: source → workspace → schema/domain → asset.PermissionsLoom roles that fan out to Purview RBAC, UC GRANTs, and Fabric roles.Unity CatalogFull Unity Catalog: objects, grants, storage, sharing — Databricks (Commercial) or OSS (Gov).MetastoresRegistered Databricks metastores, Purview accounts, OneLake regions.LineageFederated lineage graph rolling up Purview + UC + Fabric edges.

Permissions

Federated
Grant access to catalog assets without leaving Loom. Pick a source, securable, principal, and role, and the request fans out to the right back-end privileges automatically — Databricks Unity Catalog GRANTs and Fabric/OneLake roles — so one Loom role maps to the native permissions each platform expects. Every grant is a real POST (no mocked principals or fake grants) and the outcome lands in a live, sortable audit log below the form. Use Permissions to provision least-privilege access and to keep a reviewable trail of who was granted what.
One role, mapped to the right privilegesPick a securable, a principal, and a single Loom role. Loom fans the role out to the correct back-end grants automatically — Unity Catalog privileges for Databricks securables, Fabric workspace roles for OneLake — so you never hand-write GRANT statements. Every change is a real backend call and is recorded in the session audit log below.Learn more
Grant a role

Pick a securable, a principal, and a Loom role. Loom maps the role to Unity Catalog privileges or Fabric workspace roles per the table in docs.

Which governed store to grant against.
Mapped to back-end privileges automatically.
e.g. adb-1234567890.12.azuredatabricks.net
The Unity Catalog object class.
Three-level name, e.g. main.bronze.customers
Issue real GRANT statements via a running warehouse.
UPN, group object id, or service-principal app id.