<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>datartist</title><description>Lakehouse architecture, retrieval systems, and the parts of data engineering that resist being tidied up.</description><link>https://blog.datartist.win/</link><language>en</language><copyright>© 2026 David Leconte</copyright><item><title>Six Things Called Catalog, One Credential Underneath</title><link>https://blog.datartist.win/articles/six-things-called-catalog/</link><guid isPermaLink="true">https://blog.datartist.win/articles/six-things-called-catalog/</guid><description>Table truth in the lakehouse has converged on the Iceberg REST catalog. A six-layer model for what did not converge, where Databricks, Snowflake and IBM actually stand, and the credential question underneath it all.</description><pubDate>Mon, 31 Aug 2026 09:00:00 GMT</pubDate><content:encoded>&lt;div class=&quot;wrap&quot;&gt;
&lt;div class=&quot;col&quot;&gt;

&lt;p class=&quot;eyebrow&quot;&gt;Lakehouse architecture &amp;middot; Part one of two&lt;/p&gt;
&lt;h1&gt;Six Things Called Catalog, One Credential Underneath&lt;/h1&gt;
&lt;p class=&quot;dek&quot;&gt;Table truth in the lakehouse has converged on one protocol. Everything above it has not, and the reason is a credential. A layer model for the parts that still differ, where Databricks, Snowflake and IBM actually stand in August 2026, and the question nobody puts in the diagram.&lt;/p&gt;
&lt;p class=&quot;byline&quot;&gt;David Leconte &amp;middot; 31 August 2026 &amp;middot; 17 min read&lt;/p&gt;

&lt;div class=&quot;disclosure&quot;&gt;&lt;b&gt;Disclosure.&lt;/b&gt; I work at IBM France, as a Customer Success Engineer in the Data &amp;amp; AI team for Horizon Customers. This is written in a personal capacity and is not an IBM publication. I have a stake in one of the platforms discussed. Every factual claim is sourced to primary documentation with a retrieval date of 31 August 2026; each platform, IBM&apos;s included, receives a real criticism; and where the documentation is silent, contradictory, or merely announced, I say which. The postings on this site are my own and do not necessarily represent IBM&amp;rsquo;s positions, strategies or opinions.&lt;/div&gt;

&lt;p class=&quot;lead&quot;&gt;The interesting part of the lakehouse catalog question is settled, and the part that replaced it is barely being discussed.&lt;/p&gt;

&lt;p&gt;Table truth &amp;mdash; what makes a set of Parquet files a table with a schema, snapshots and commits &amp;mdash; has converged. All three major estates now serve the Apache Iceberg REST catalog specification. Unity Catalog implements it and vends credentials to external engines.&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn2&quot; id=&quot;fr2&quot;&gt;2&lt;/a&gt;&lt;/sup&gt; Snowflake&apos;s Horizon exposes it natively, powered by Apache Polaris, which graduated to a Top-Level Project at the Apache Software Foundation in February 2026.&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn31&quot; id=&quot;fr31&quot;&gt;31&lt;/a&gt;&lt;/sup&gt; IBM&apos;s Metadata Service implements &lt;q&gt;selected APIs&lt;/q&gt; from both the Iceberg REST and Unity Catalog specifications.&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn40&quot; id=&quot;fr40&quot;&gt;40&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;So the read path is contractually convergent, and every remaining difference has moved somewhere else. Upward, into who may write and under what authority, whether a policy survives leaving its perimeter, whether a semantic definition is portable. And downward, into a mechanism that almost every architecture diagram draws as a single arrow and that turns out to decide the whole governance question: &lt;b&gt;what exactly the catalog hands an engine when it says yes.&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;You cannot see any of it while &quot;catalog&quot; remains one word.&lt;/p&gt;

&lt;p class=&quot;cap&quot;&gt;&lt;b&gt;How to read this.&lt;/b&gt; The first half builds the instrument &amp;mdash; a six-layer model, a table of false friends, and where the three platforms actually stand in August 2026. The second half, from &lt;i&gt;The credential question&lt;/i&gt; onward, is the part I had not seen written down anywhere and is where the argument earns its keep. If the layer model is already familiar to you, skip straight there.&lt;/p&gt;

&lt;h2&gt;One word, six jobs&lt;/h2&gt;

&lt;p&gt;Databricks says &lt;i&gt;Unity Catalog&lt;/i&gt; and means a governance perimeter. Snowflake says &lt;i&gt;Horizon Catalog&lt;/i&gt; and means a control surface, while &lt;i&gt;Open Catalog&lt;/i&gt; means a hosted Apache Polaris, while a &lt;i&gt;database&lt;/i&gt; is what actually namespaces tables. IBM says &lt;i&gt;catalog&lt;/i&gt; and may mean a watsonx.data object binding storage to engines, or the metastore behind it, or a governance construct, or a Presto engine binding, or a Db2 system catalog.&lt;/p&gt;

&lt;p&gt;These are not synonyms across vendors, and not reliably synonyms within one. The consequence is worse than imprecision: a comparison conducted across mismatched layers is &lt;b&gt;unfalsifiable&lt;/b&gt;, because no evidence can settle a claim whose subject changes between speakers.&lt;/p&gt;

&lt;p&gt;The fix is to stop treating &quot;catalog&quot; as an object and start treating it as a stack of jobs. Each layer answers exactly one question. An object belongs to the layer whose question it answers &amp;mdash; and if it answers two, a vendor has collapsed layers, which is a design decision with a price attached.&lt;/p&gt;

&lt;div class=&quot;wide scroll&quot;&gt;
&lt;svg class=&quot;diag&quot; viewBox=&quot;0 0 1080 420&quot; xmlns=&quot;http://www.w3.org/2000/svg&quot; role=&quot;img&quot;
  aria-label=&quot;Six catalog layers from L1 storage registration at the bottom to L6 distribution at the top, each with the single question it answers. To the right, a schematic time axis shows six lifecycle bars starting and ending at different points: storage registration outlives the table, table truth is bounded by DDL, engine bindings appear and disappear as separate short segments, governance policy runs as two successive versions, semantics extends beyond both ends, and a share is revoked while the table still lives.&quot;&gt;
  &lt;text class=&quot;lane&quot; x=&quot;8&quot; y=&quot;20&quot;&gt;The six layers &amp;mdash; one question each&lt;/text&gt;
  &lt;text class=&quot;lane&quot; x=&quot;660&quot; y=&quot;20&quot;&gt;Independent lifecycles (schematic time &amp;rarr;)&lt;/text&gt;
  &lt;g class=&quot;bx f-pink&quot;&gt;&lt;rect x=&quot;8&quot; y=&quot;34&quot; width=&quot;600&quot; height=&quot;50&quot; rx=&quot;7&quot;/&gt;
    &lt;text class=&quot;t1&quot; x=&quot;22&quot; y=&quot;54&quot;&gt;L6 &amp;middot; Distribution&lt;/text&gt;
    &lt;text class=&quot;t2i&quot; x=&quot;22&quot; y=&quot;70&quot;&gt;How is it productised and exchanged beyond the perimeter?&lt;/text&gt;&lt;/g&gt;
  &lt;g class=&quot;bx f-purp&quot;&gt;&lt;rect x=&quot;8&quot; y=&quot;92&quot; width=&quot;600&quot; height=&quot;50&quot; rx=&quot;7&quot;/&gt;
    &lt;text class=&quot;t1&quot; x=&quot;22&quot; y=&quot;112&quot;&gt;L5 &amp;middot; Semantics&lt;/text&gt;
    &lt;text class=&quot;t2i&quot; x=&quot;22&quot; y=&quot;128&quot;&gt;What does it mean?&lt;/text&gt;&lt;/g&gt;
  &lt;g class=&quot;bx f-coral&quot;&gt;&lt;rect x=&quot;8&quot; y=&quot;150&quot; width=&quot;600&quot; height=&quot;50&quot; rx=&quot;7&quot;/&gt;
    &lt;text class=&quot;t1&quot; x=&quot;22&quot; y=&quot;170&quot;&gt;L4 &amp;middot; Governance&lt;/text&gt;
    &lt;text class=&quot;t2i&quot; x=&quot;22&quot; y=&quot;186&quot;&gt;Who may do what to it, and what has been done?&lt;/text&gt;&lt;/g&gt;
  &lt;g class=&quot;bx f-blue&quot;&gt;&lt;rect x=&quot;8&quot; y=&quot;208&quot; width=&quot;600&quot; height=&quot;50&quot; rx=&quot;7&quot;/&gt;
    &lt;text class=&quot;t1&quot; x=&quot;22&quot; y=&quot;228&quot;&gt;L3 &amp;middot; Engine binding&lt;/text&gt;
    &lt;text class=&quot;t2i&quot; x=&quot;22&quot; y=&quot;244&quot;&gt;How does a given engine resolve and reach the table?&lt;/text&gt;&lt;/g&gt;
  &lt;g class=&quot;bx f-teal&quot;&gt;&lt;rect x=&quot;8&quot; y=&quot;266&quot; width=&quot;600&quot; height=&quot;50&quot; rx=&quot;7&quot;/&gt;
    &lt;text class=&quot;t1&quot; x=&quot;22&quot; y=&quot;286&quot;&gt;L2 &amp;middot; Technical catalog (table truth)&lt;/text&gt;
    &lt;text class=&quot;t2i&quot; x=&quot;22&quot; y=&quot;302&quot;&gt;What makes these files a table &amp;mdash; schema, snapshots, commits?&lt;/text&gt;&lt;/g&gt;
  &lt;g class=&quot;bx f-gray&quot;&gt;&lt;rect x=&quot;8&quot; y=&quot;324&quot; width=&quot;600&quot; height=&quot;50&quot; rx=&quot;7&quot;/&gt;
    &lt;text class=&quot;t1&quot; x=&quot;22&quot; y=&quot;344&quot;&gt;L1 &amp;middot; Storage registration&lt;/text&gt;
    &lt;text class=&quot;t2i&quot; x=&quot;22&quot; y=&quot;360&quot;&gt;Where do the bytes live, and under which credentials?&lt;/text&gt;&lt;/g&gt;
  &lt;line class=&quot;axis&quot; x1=&quot;640&quot; y1=&quot;382&quot; x2=&quot;1064&quot; y2=&quot;382&quot;/&gt;
  &lt;text class=&quot;el&quot; x=&quot;700&quot; y=&quot;396&quot; text-anchor=&quot;middle&quot;&gt;CREATE TABLE&lt;/text&gt;
  &lt;text class=&quot;el&quot; x=&quot;946&quot; y=&quot;396&quot; text-anchor=&quot;middle&quot;&gt;DROP TABLE&lt;/text&gt;
  &lt;line class=&quot;axis&quot; x1=&quot;700&quot; y1=&quot;30&quot; x2=&quot;700&quot; y2=&quot;378&quot; stroke-dasharray=&quot;3 4&quot;/&gt;
  &lt;line class=&quot;axis&quot; x1=&quot;946&quot; y1=&quot;30&quot; x2=&quot;946&quot; y2=&quot;378&quot; stroke-dasharray=&quot;3 4&quot;/&gt;
  &lt;g class=&quot;bx f-pink&quot;&gt;&lt;rect x=&quot;770&quot; y=&quot;46&quot; width=&quot;150&quot; height=&quot;26&quot; rx=&quot;5&quot;/&gt;
    &lt;text class=&quot;t2&quot; x=&quot;845&quot; y=&quot;63&quot; text-anchor=&quot;middle&quot;&gt;share revoked early&lt;/text&gt;&lt;/g&gt;
  &lt;g class=&quot;bx f-purp&quot;&gt;&lt;rect x=&quot;648&quot; y=&quot;104&quot; width=&quot;416&quot; height=&quot;26&quot; rx=&quot;5&quot;/&gt;
    &lt;text class=&quot;t2&quot; x=&quot;856&quot; y=&quot;121&quot; text-anchor=&quot;middle&quot;&gt;metric definition outlives the table it reads&lt;/text&gt;&lt;/g&gt;
  &lt;g class=&quot;bx f-coral&quot;&gt;&lt;rect x=&quot;672&quot; y=&quot;162&quot; width=&quot;180&quot; height=&quot;26&quot; rx=&quot;5&quot;/&gt;
    &lt;text class=&quot;t2&quot; x=&quot;762&quot; y=&quot;179&quot; text-anchor=&quot;middle&quot;&gt;policy v1&lt;/text&gt;&lt;/g&gt;
  &lt;g class=&quot;bx f-coral&quot;&gt;&lt;rect x=&quot;860&quot; y=&quot;162&quot; width=&quot;170&quot; height=&quot;26&quot; rx=&quot;5&quot;/&gt;
    &lt;text class=&quot;t2&quot; x=&quot;945&quot; y=&quot;179&quot; text-anchor=&quot;middle&quot;&gt;policy v2&lt;/text&gt;&lt;/g&gt;
  &lt;g class=&quot;bx f-blue&quot;&gt;&lt;rect x=&quot;716&quot; y=&quot;220&quot; width=&quot;86&quot; height=&quot;26&quot; rx=&quot;5&quot;/&gt;
    &lt;text class=&quot;t2&quot; x=&quot;759&quot; y=&quot;237&quot; text-anchor=&quot;middle&quot;&gt;engine A&lt;/text&gt;&lt;/g&gt;
  &lt;g class=&quot;bx f-blue&quot;&gt;&lt;rect x=&quot;820&quot; y=&quot;220&quot; width=&quot;76&quot; height=&quot;26&quot; rx=&quot;5&quot;/&gt;
    &lt;text class=&quot;t2&quot; x=&quot;858&quot; y=&quot;237&quot; text-anchor=&quot;middle&quot;&gt;engine B&lt;/text&gt;&lt;/g&gt;
  &lt;g class=&quot;bx f-blue&quot;&gt;&lt;rect x=&quot;906&quot; y=&quot;220&quot; width=&quot;70&quot; height=&quot;26&quot; rx=&quot;5&quot;/&gt;
    &lt;text class=&quot;t2&quot; x=&quot;941&quot; y=&quot;237&quot; text-anchor=&quot;middle&quot;&gt;engine C&lt;/text&gt;&lt;/g&gt;
  &lt;g class=&quot;bx f-teal&quot;&gt;&lt;rect x=&quot;700&quot; y=&quot;278&quot; width=&quot;246&quot; height=&quot;26&quot; rx=&quot;5&quot;/&gt;
    &lt;text class=&quot;t2&quot; x=&quot;823&quot; y=&quot;295&quot; text-anchor=&quot;middle&quot;&gt;bounded by DDL&lt;/text&gt;&lt;/g&gt;
  &lt;g class=&quot;bx f-gray&quot;&gt;&lt;rect x=&quot;662&quot; y=&quot;336&quot; width=&quot;402&quot; height=&quot;26&quot; rx=&quot;5&quot;/&gt;
    &lt;text class=&quot;t2&quot; x=&quot;863&quot; y=&quot;353&quot; text-anchor=&quot;middle&quot;&gt;bucket persists after DROP&lt;/text&gt;&lt;/g&gt;
&lt;/svg&gt;&lt;p class=&quot;cap&quot;&gt;The layers are separable because their lifecycles are. The dashed verticals are the table&apos;s own birth and death; every bar that crosses them, stops short of them, or repeats between them belongs to a clock the table does not control.&lt;/p&gt;
&lt;/div&gt;

&lt;p&gt;That right-hand panel is the argument, not decoration. The same physical table carries six independently-clocked lifecycles at once: a storage registration that outlives it, because the bucket persists after &lt;code&gt;DROP&lt;/code&gt;; a table truth bounded by DDL; engine bindings created and dropped per engine without touching the table; policies versioned on their own cadence; a semantic definition that survives re-platforming, because a &quot;gross margin&quot; metric outlives the table it reads; and a share revoked while the table lives on.&lt;/p&gt;

&lt;p&gt;Six independent lifecycles, six layers. Any claim that one object governs all of this is a claim about &lt;i&gt;collapse&lt;/i&gt;.&lt;/p&gt;

&lt;p class=&quot;cap&quot;&gt;&lt;b&gt;A note on the numbering.&lt;/b&gt; L1 to L6 is my own convention for this analysis, not a vendor&apos;s. IBM, for instance, documents three access levels of its own and the label &quot;L4&quot; appears nowhere in its corpus. Use the layers as a lens, not as terminology to quote back at anyone.&lt;/p&gt;

&lt;h2&gt;The hourglass&lt;/h2&gt;

&lt;p&gt;Draw the market as it stands and it makes an hourglass. Many engines above, many storage systems below, and in the middle a single narrow protocol that everything now passes through.&lt;/p&gt;

&lt;p&gt;Hourglasses are what happens when an industry agrees on exactly one thing. The internet has one at IP; the container ecosystem has one at the OCI image. The shape is diagnostic: above and below the waist, variety proliferates cheaply, because anything that speaks the waist protocol composes with everything else that does. That is precisely what has happened to table truth. An engine written against the Iceberg REST specification reads tables owned by any of the three platforms, and a table can sit on any object store any of them supports.&lt;/p&gt;

&lt;p&gt;What makes this particular hourglass worth drawing is that &lt;b&gt;it is only an hourglass in the middle&lt;/b&gt;. Look at what sits above the engines and the pattern breaks completely.&lt;/p&gt;

&lt;div class=&quot;wide scroll&quot;&gt;
&lt;svg class=&quot;diag&quot; viewBox=&quot;0 0 1080 540&quot; xmlns=&quot;http://www.w3.org/2000/svg&quot; role=&quot;img&quot;
  aria-label=&quot;An hourglass diagram. In the middle band, eight query engines converge through narrowing lines onto a single narrow box labelled Iceberg REST Catalog specification, then widen out again to six storage systems below. Above the engines sit three tall, separate towers labelled Databricks Unity Catalog, Snowflake Horizon, and IBM Ranger or Knowledge Catalog, containing governance, semantics and distribution. The three towers do not touch each other and there are no connections between them, illustrating that the layers above table truth have not converged on any shared contract.&quot;&gt;
  &lt;text class=&quot;lane&quot; x=&quot;8&quot; y=&quot;18&quot;&gt;Above the waist &amp;mdash; L4 governance, L5 semantics, L6 distribution: three perimeters, no shared contract&lt;/text&gt;
  &lt;g class=&quot;bx f-coral&quot;&gt;&lt;rect x=&quot;8&quot; y=&quot;28&quot; width=&quot;340&quot; height=&quot;128&quot; rx=&quot;8&quot;/&gt;
    &lt;text class=&quot;t1&quot; x=&quot;26&quot; y=&quot;50&quot;&gt;Unity Catalog&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;26&quot; y=&quot;68&quot;&gt;grants &amp;middot; ABAC &amp;middot; RBAC &amp;middot; masks &amp;middot; row filters&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;26&quot; y=&quot;84&quot;&gt;metric views &amp;middot; Domains &amp;middot; Pages&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;26&quot; y=&quot;100&quot;&gt;OpenSharing &amp;middot; Marketplace &amp;middot; Clean Rooms&lt;/text&gt;
    &lt;text class=&quot;t2i&quot; x=&quot;26&quot; y=&quot;122&quot;&gt;one grant model, one metastore per region&lt;/text&gt;
    &lt;text class=&quot;t2i&quot; x=&quot;26&quot; y=&quot;140&quot;&gt;policies exist only inside this boundary&lt;/text&gt;&lt;/g&gt;
  &lt;g class=&quot;bx f-coral&quot;&gt;&lt;rect x=&quot;368&quot; y=&quot;28&quot; width=&quot;340&quot; height=&quot;128&quot; rx=&quot;8&quot;/&gt;
    &lt;text class=&quot;t1&quot; x=&quot;386&quot; y=&quot;50&quot;&gt;Snowflake Horizon&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;386&quot; y=&quot;68&quot;&gt;masking &amp;middot; row access &amp;middot; tags &amp;middot; Trust Center&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;386&quot; y=&quot;84&quot;&gt;Semantic Views &amp;middot; Autopilot&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;386&quot; y=&quot;100&quot;&gt;Sharing &amp;middot; Marketplace &amp;middot; Clean Rooms&lt;/text&gt;
    &lt;text class=&quot;t2i&quot; x=&quot;386&quot; y=&quot;122&quot;&gt;enforcement for external engines works by&lt;/text&gt;
    &lt;text class=&quot;t2i&quot; x=&quot;386&quot; y=&quot;140&quot;&gt;routing the query back through Snowflake&lt;/text&gt;&lt;/g&gt;
  &lt;g class=&quot;bx f-coral&quot;&gt;&lt;rect x=&quot;728&quot; y=&quot;28&quot; width=&quot;344&quot; height=&quot;128&quot; rx=&quot;8&quot;/&gt;
    &lt;text class=&quot;t1&quot; x=&quot;746&quot; y=&quot;50&quot;&gt;Apache Ranger &amp;nbsp;&lt;tspan font-weight=&quot;400&quot;&gt;xor&lt;/tspan&gt;&amp;nbsp; IBM Knowledge Catalog&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;746&quot; y=&quot;68&quot;&gt;one policy engine per instance &amp;middot; enforced in-engine&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;746&quot; y=&quot;84&quot;&gt;watsonx BI semantic model &amp;middot; glossary&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;746&quot; y=&quot;100&quot;&gt;no marketplace equivalent&lt;/text&gt;
    &lt;text class=&quot;t2i&quot; x=&quot;746&quot; y=&quot;122&quot;&gt;≥4 distinct governance stacks across the estate&lt;/text&gt;
    &lt;text class=&quot;t2i&quot; x=&quot;746&quot; y=&quot;140&quot;&gt;Ranger covers Spark; Knowledge Catalog does not&lt;/text&gt;&lt;/g&gt;
  &lt;text class=&quot;t2i&quot; x=&quot;8&quot; y=&quot;176&quot; fill=&quot;#993c1d&quot;&gt;No interchange standard exists at these layers &amp;mdash; no equivalent of the Iceberg REST contract for policy, semantics or distribution.&lt;/text&gt;

  &lt;text class=&quot;lane&quot; x=&quot;8&quot; y=&quot;206&quot;&gt;Engines&lt;/text&gt;
  &lt;g class=&quot;bx f-purp&quot; font-size=&quot;9.5&quot;&gt;
    &lt;rect x=&quot;8&quot; y=&quot;216&quot; width=&quot;122&quot; height=&quot;30&quot; rx=&quot;6&quot;/&gt;&lt;text class=&quot;t2&quot; x=&quot;69&quot; y=&quot;235&quot; text-anchor=&quot;middle&quot;&gt;Apache Spark&lt;/text&gt;
    &lt;rect x=&quot;142&quot; y=&quot;216&quot; width=&quot;122&quot; height=&quot;30&quot; rx=&quot;6&quot;/&gt;&lt;text class=&quot;t2&quot; x=&quot;203&quot; y=&quot;235&quot; text-anchor=&quot;middle&quot;&gt;Trino&lt;/text&gt;
    &lt;rect x=&quot;276&quot; y=&quot;216&quot; width=&quot;122&quot; height=&quot;30&quot; rx=&quot;6&quot;/&gt;&lt;text class=&quot;t2&quot; x=&quot;337&quot; y=&quot;235&quot; text-anchor=&quot;middle&quot;&gt;DuckDB&lt;/text&gt;
    &lt;rect x=&quot;410&quot; y=&quot;216&quot; width=&quot;122&quot; height=&quot;30&quot; rx=&quot;6&quot;/&gt;&lt;text class=&quot;t2&quot; x=&quot;471&quot; y=&quot;235&quot; text-anchor=&quot;middle&quot;&gt;PyIceberg&lt;/text&gt;
    &lt;rect x=&quot;544&quot; y=&quot;216&quot; width=&quot;122&quot; height=&quot;30&quot; rx=&quot;6&quot;/&gt;&lt;text class=&quot;t2&quot; x=&quot;605&quot; y=&quot;235&quot; text-anchor=&quot;middle&quot;&gt;Flink&lt;/text&gt;
    &lt;rect x=&quot;678&quot; y=&quot;216&quot; width=&quot;122&quot; height=&quot;30&quot; rx=&quot;6&quot;/&gt;&lt;text class=&quot;t2&quot; x=&quot;739&quot; y=&quot;235&quot; text-anchor=&quot;middle&quot;&gt;Presto&lt;/text&gt;
    &lt;rect x=&quot;812&quot; y=&quot;216&quot; width=&quot;122&quot; height=&quot;30&quot; rx=&quot;6&quot;/&gt;&lt;text class=&quot;t2&quot; x=&quot;873&quot; y=&quot;235&quot; text-anchor=&quot;middle&quot;&gt;Snowflake&lt;/text&gt;
    &lt;rect x=&quot;946&quot; y=&quot;216&quot; width=&quot;126&quot; height=&quot;30&quot; rx=&quot;6&quot;/&gt;&lt;text class=&quot;t2&quot; x=&quot;1009&quot; y=&quot;235&quot; text-anchor=&quot;middle&quot;&gt;Databricks SQL&lt;/text&gt;&lt;/g&gt;
  &lt;g stroke=&quot;#8a8880&quot; stroke-width=&quot;1&quot; fill=&quot;none&quot; opacity=&quot;.75&quot;&gt;
    &lt;path d=&quot;M69 246 L470 300&quot;/&gt;&lt;path d=&quot;M203 246 L490 300&quot;/&gt;&lt;path d=&quot;M337 246 L510 300&quot;/&gt;&lt;path d=&quot;M471 246 L528 300&quot;/&gt;
    &lt;path d=&quot;M605 246 L552 300&quot;/&gt;&lt;path d=&quot;M739 246 L570 300&quot;/&gt;&lt;path d=&quot;M873 246 L590 300&quot;/&gt;&lt;path d=&quot;M1009 246 L610 300&quot;/&gt;&lt;/g&gt;

  &lt;g class=&quot;bx f-teal&quot;&gt;&lt;rect x=&quot;410&quot; y=&quot;300&quot; width=&quot;260&quot; height=&quot;52&quot; rx=&quot;8&quot; stroke-width=&quot;2.4&quot;/&gt;
    &lt;text class=&quot;t1&quot; x=&quot;540&quot; y=&quot;322&quot; text-anchor=&quot;middle&quot;&gt;Iceberg REST Catalog&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;540&quot; y=&quot;340&quot; text-anchor=&quot;middle&quot;&gt;the one contract all three now serve&lt;/text&gt;&lt;/g&gt;
  &lt;text class=&quot;t2i&quot; x=&quot;690&quot; y=&quot;322&quot; fill=&quot;#085041&quot;&gt;L2 &amp;mdash; table truth.&lt;/text&gt;
  &lt;text class=&quot;t2i&quot; x=&quot;690&quot; y=&quot;336&quot; fill=&quot;#085041&quot;&gt;Converged. This is the solved problem.&lt;/text&gt;

  &lt;g stroke=&quot;#8a8880&quot; stroke-width=&quot;1&quot; fill=&quot;none&quot; opacity=&quot;.75&quot;&gt;
    &lt;path d=&quot;M470 352 L96 406&quot;/&gt;&lt;path d=&quot;M490 352 L266 406&quot;/&gt;&lt;path d=&quot;M510 352 L436 406&quot;/&gt;
    &lt;path d=&quot;M570 352 L606 406&quot;/&gt;&lt;path d=&quot;M590 352 L776 406&quot;/&gt;&lt;path d=&quot;M610 352 L963 406&quot;/&gt;&lt;/g&gt;
  &lt;text class=&quot;lane&quot; x=&quot;8&quot; y=&quot;400&quot;&gt;Storage&lt;/text&gt;
  &lt;g class=&quot;bx f-gray&quot; font-size=&quot;9.5&quot;&gt;
    &lt;rect x=&quot;8&quot; y=&quot;406&quot; width=&quot;176&quot; height=&quot;30&quot; rx=&quot;6&quot;/&gt;&lt;text class=&quot;t2&quot; x=&quot;96&quot; y=&quot;425&quot; text-anchor=&quot;middle&quot;&gt;Amazon S3&lt;/text&gt;
    &lt;rect x=&quot;196&quot; y=&quot;406&quot; width=&quot;140&quot; height=&quot;30&quot; rx=&quot;6&quot;/&gt;&lt;text class=&quot;t2&quot; x=&quot;266&quot; y=&quot;425&quot; text-anchor=&quot;middle&quot;&gt;ADLS Gen2&lt;/text&gt;
    &lt;rect x=&quot;348&quot; y=&quot;406&quot; width=&quot;176&quot; height=&quot;30&quot; rx=&quot;6&quot;/&gt;&lt;text class=&quot;t2&quot; x=&quot;436&quot; y=&quot;425&quot; text-anchor=&quot;middle&quot;&gt;Google Cloud Storage&lt;/text&gt;
    &lt;rect x=&quot;536&quot; y=&quot;406&quot; width=&quot;140&quot; height=&quot;30&quot; rx=&quot;6&quot;/&gt;&lt;text class=&quot;t2&quot; x=&quot;606&quot; y=&quot;425&quot; text-anchor=&quot;middle&quot;&gt;IBM COS&lt;/text&gt;
    &lt;rect x=&quot;688&quot; y=&quot;406&quot; width=&quot;176&quot; height=&quot;30&quot; rx=&quot;6&quot;/&gt;&lt;text class=&quot;t2&quot; x=&quot;776&quot; y=&quot;425&quot; text-anchor=&quot;middle&quot;&gt;MinIO &amp;middot; Ceph &amp;middot; Ozone&lt;/text&gt;
    &lt;rect x=&quot;876&quot; y=&quot;406&quot; width=&quot;196&quot; height=&quot;30&quot; rx=&quot;6&quot;/&gt;&lt;text class=&quot;t2&quot; x=&quot;974&quot; y=&quot;425&quot; text-anchor=&quot;middle&quot;&gt;on-premises object storage&lt;/text&gt;&lt;/g&gt;

  &lt;rect x=&quot;8&quot; y=&quot;456&quot; width=&quot;1064&quot; height=&quot;60&quot; rx=&quot;7&quot; fill=&quot;none&quot; stroke=&quot;#185fa5&quot; stroke-width=&quot;1.6&quot; stroke-dasharray=&quot;6 4&quot;/&gt;
  &lt;text class=&quot;t1&quot; x=&quot;26&quot; y=&quot;476&quot; fill=&quot;#185fa5&quot;&gt;And running straight through the waist: the credential&lt;/text&gt;
  &lt;text class=&quot;t2&quot; x=&quot;26&quot; y=&quot;491&quot; fill=&quot;#0c447c&quot;&gt;To let an engine read the bytes, the catalog hands it a storage credential &amp;mdash; scoped to a path prefix,&lt;/text&gt;
  &lt;text class=&quot;t2&quot; x=&quot;26&quot; y=&quot;506&quot; fill=&quot;#0c447c&quot;&gt;carrying the catalog&apos;s service identity, not the user&apos;s. Everything in the top band becomes unenforceable the moment it does.&lt;/text&gt;
&lt;/svg&gt;
&lt;p class=&quot;cap&quot;&gt;Convergence at the waist, divergence everywhere above it. The dashed band is the subject of the second half of this article.&lt;/p&gt;
&lt;/div&gt;

&lt;p&gt;The waist is real and it is the good news: an engine written against the Iceberg REST specification can read tables owned by any of the three. That is a genuine, hard-won interoperability win, and it happened fast.&lt;/p&gt;

&lt;p&gt;The top band is the part that gets glossed over. There is &lt;b&gt;no interchange standard at all&lt;/b&gt; for governance, semantics or distribution. No Iceberg-REST equivalent for a policy. Every enforcement model is proprietary to its perimeter, every semantic definition is expressed in a vendor&apos;s own object, and the only way to move policy between estates is to re-implement it. When someone tells you the lakehouse is now open, ask which band they mean.&lt;/p&gt;

&lt;h2&gt;The false friends&lt;/h2&gt;

&lt;p&gt;Six words survive translation between vendors while changing referent, which is the precise definition of a false friend. Read the column, not the word.&lt;/p&gt;

&lt;div class=&quot;wide scroll&quot;&gt;
&lt;table&gt;
&lt;thead&gt;&lt;tr&gt;&lt;th style=&quot;width:16%&quot;&gt;Word&lt;/th&gt;&lt;th style=&quot;width:28%&quot;&gt;Databricks&lt;/th&gt;&lt;th style=&quot;width:28%&quot;&gt;Snowflake&lt;/th&gt;&lt;th style=&quot;width:28%&quot;&gt;IBM estate&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;&lt;b&gt;&quot;catalog&quot;&lt;/b&gt;&lt;/td&gt;&lt;td&gt;Top namespace level inside Unity Catalog (&lt;code&gt;catalog.schema.table&lt;/code&gt;)&lt;/td&gt;&lt;td&gt;Historically nothing &amp;mdash; the namespace is a &lt;i&gt;database&lt;/i&gt;; now Horizon and Open Catalog contexts&lt;/td&gt;&lt;td&gt;A watsonx.data object binding storage and metastore to engines; or a governance catalog; or a Presto catalog; or a Db2 system catalog&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;b&gt;&quot;metastore&quot;&lt;/b&gt;&lt;/td&gt;&lt;td&gt;The Unity Catalog region-level root object&lt;/td&gt;&lt;td&gt;An internal service, never user-named&lt;/td&gt;&lt;td&gt;The Metadata Service &amp;mdash; table truth since version 2.1&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn39&quot; id=&quot;fr39&quot;&gt;39&lt;/a&gt;&lt;/sup&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;b&gt;&quot;share&quot;&lt;/b&gt;&lt;/td&gt;&lt;td&gt;An OpenSharing object, protocol-backed&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn5&quot; id=&quot;fr5&quot;&gt;5&lt;/a&gt;&lt;/sup&gt;&lt;/td&gt;&lt;td&gt;A grant of database objects to consumer accounts&lt;/td&gt;&lt;td&gt;Not a first-class object; nearest equivalent is REST-catalog exposure or a data product&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;b&gt;&quot;semantic layer&quot;&lt;/b&gt;&lt;/td&gt;&lt;td&gt;Metric views, Domains and Pages, the latter in Beta&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn7&quot; id=&quot;fr7&quot;&gt;7&lt;/a&gt;&lt;/sup&gt;&lt;/td&gt;&lt;td&gt;Semantic Views&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn30&quot; id=&quot;fr30&quot;&gt;30&lt;/a&gt;&lt;/sup&gt;&lt;/td&gt;&lt;td&gt;watsonx BI semantic model, single region&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn47&quot; id=&quot;fr47&quot;&gt;47&lt;/a&gt;&lt;/sup&gt;; business glossary&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;b&gt;&quot;open catalog&quot;&lt;/b&gt;&lt;/td&gt;&lt;td&gt;Unity Catalog OSS &amp;mdash; a Linux Foundation sandbox project&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn8&quot; id=&quot;fr8&quot;&gt;8&lt;/a&gt;&lt;/sup&gt;&lt;/td&gt;&lt;td&gt;&lt;b&gt;A product name&lt;/b&gt;: managed Polaris, closed to new first-use accounts&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn16&quot; id=&quot;fr16&quot;&gt;16&lt;/a&gt;&lt;/sup&gt;&lt;/td&gt;&lt;td&gt;The Metadata Service&apos;s Iceberg REST and Unity-compatible endpoints&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn40&quot; id=&quot;fr40b&quot;&gt;40&lt;/a&gt;&lt;/sup&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;b&gt;&quot;governance&quot;&lt;/b&gt;&lt;/td&gt;&lt;td&gt;Grants, ABAC, now RBAC, lineage &amp;mdash; one stack&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn6&quot; id=&quot;fr6&quot;&gt;6&lt;/a&gt;&lt;/sup&gt;&lt;/td&gt;&lt;td&gt;Horizon &amp;mdash; one stack&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn17&quot; id=&quot;fr17&quot;&gt;17&lt;/a&gt;&lt;/sup&gt;&lt;/td&gt;&lt;td&gt;Ranger &lt;i&gt;xor&lt;/i&gt; Knowledge Catalog, plus AI governance, plus engine-native &amp;mdash; several stacks&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn42&quot; id=&quot;fr42&quot;&gt;42&lt;/a&gt;&lt;/sup&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;

&lt;p&gt;The costliest is &quot;open catalog&quot;. In two estates it is a common noun; in the third it is a registered product name for a service that no longer accepts new first-use accounts. A team saying &quot;we&apos;re standardising on the open catalog&quot; has said nothing verifiable until someone asks which one.&lt;/p&gt;

&lt;h2&gt;Where the three stand&lt;/h2&gt;

&lt;h3&gt;Databricks &amp;mdash; collapse by extension&lt;/h3&gt;

&lt;p&gt;Unity Catalog spans five of the six layers, from table truth to distribution, under one grant model and one metastore per region. Managed Iceberg reached general availability alongside Delta on 21 May 2026&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn1&quot; id=&quot;fr1&quot;&gt;1&lt;/a&gt;&lt;/sup&gt;, and August 2026 alone added role-based access control at GA on the 19th, sharing of managed Iceberg tables on the 14th, and three separate ABAC extensions.&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn6&quot; id=&quot;fr6b&quot;&gt;6&lt;/a&gt;&lt;/sup&gt; Classification is native and agent-driven&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn9&quot; id=&quot;fr9&quot;&gt;9&lt;/a&gt;&lt;/sup&gt;, and business semantics now ship as metric views, Domains and Pages, where &lt;q&gt;A Page is a governed, authoritative definition of a business concept&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn7&quot; id=&quot;fr7b&quot;&gt;7&lt;/a&gt;&lt;/sup&gt; &amp;mdash; a business glossary in all but name.&lt;/p&gt;

&lt;p&gt;The cost of the collapse comes in three parts. Policies, metrics, shares and audit exist &lt;i&gt;only&lt;/i&gt; inside the Unity Catalog boundary. Federated catalogs are read-only, with internal Hive metastores the sole exception&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn3&quot; id=&quot;fr3&quot;&gt;3&lt;/a&gt;&lt;/sup&gt;, and credential vending is explicitly unsupported on foreign Iceberg tables.&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn2&quot; id=&quot;fr2b&quot;&gt;2&lt;/a&gt;&lt;/sup&gt; And the open-source escape hatch is partial: Unity Catalog OSS remains a Linux Foundation &lt;b&gt;sandbox&lt;/b&gt; project.&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn8&quot; id=&quot;fr8b&quot;&gt;8&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;

&lt;h3&gt;Snowflake &amp;mdash; open at the bottom, re-centred at the top&lt;/h3&gt;

&lt;p&gt;Snowflake genuinely opened table truth, contributed Polaris to the ASF, and made an unusually specific anti-fork commitment:&lt;/p&gt;

&lt;blockquote&gt;&quot;Horizon Catalog uses Apache Polaris as its catalog engine, the same open source project anyone can download and operate themselves&amp;hellip; We are not shipping a separate &apos;community edition&apos; that behaves differently from what we run in production.&quot;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn29&quot; id=&quot;fr29&quot;&gt;29&lt;/a&gt;&lt;/sup&gt;&lt;/blockquote&gt;

&lt;p&gt;Read that alongside the fact that Open Catalog, the managed Polaris service, no longer accepts new first-use accounts and new customers are pointed at Horizon.&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn16&quot; id=&quot;fr16b&quot;&gt;16&lt;/a&gt;&lt;/sup&gt; The strategy legible from the artefacts is to commoditise the layer where a competitor led, and differentiate above it.&lt;/p&gt;

&lt;p&gt;Which makes the governance claim the one to examine, and it will not survive the next section intact.&lt;/p&gt;

&lt;h3&gt;IBM &amp;mdash; six layers, no single owner&lt;/h3&gt;

&lt;p&gt;IBM occupies every layer with a different product at each. The convergence point is table truth: the Metadata Service implements &lt;q&gt;selected APIs from the Iceberg REST Catalog and Unity Catalog Open API spec&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn40&quot; id=&quot;fr40c&quot;&gt;40&lt;/a&gt;&lt;/sup&gt;. &lt;b&gt;Selected&lt;/b&gt; is load-bearing, and IBM says so &amp;mdash; multi-level namespace creation is unsupported, and Presto cannot query views created through the REST catalog API, an incompatibility that extends to Spark-created views too. Still, it makes watsonx.data the only one of the three whose technical catalog natively speaks a competitor&apos;s contract.&lt;/p&gt;

&lt;p&gt;The fragmentation is at governance: an instance integrates with &lt;q&gt;only one of the following policy engines&lt;/q&gt; &amp;mdash; Apache Ranger or IBM Knowledge Catalog, not both.&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn42&quot; id=&quot;fr42b&quot;&gt;42&lt;/a&gt;&lt;/sup&gt; And the choice is not symmetric. Ranger&apos;s service types cover Presto &lt;i&gt;and&lt;/i&gt; Spark&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn43&quot; id=&quot;fr43&quot;&gt;43&lt;/a&gt;&lt;/sup&gt;, while IBM documents Knowledge Catalog governance for &lt;q&gt;Presto (C++), and Presto (Java) engines&lt;/q&gt; only. &lt;b&gt;IBM&apos;s own governance product covers fewer of IBM&apos;s own engines than the Apache alternative does.&lt;/b&gt; Above that, the semantic layer runs in a single region&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn47&quot; id=&quot;fr47b&quot;&gt;47&lt;/a&gt;&lt;/sup&gt; and there is no marketplace equivalent to what the other two ship.&lt;/p&gt;

&lt;h2&gt;&quot;Bidirectional&quot; means three things&lt;/h2&gt;

&lt;p&gt;Every vendor here uses &quot;bidirectional interoperability&quot; for capabilities that are not the same capability. As of today there are three distinct directions with three different maturities, and conflating them is the most common technical error in these conversations.&lt;/p&gt;

&lt;p&gt;The confusion is not accidental, and it is not quite dishonest either. Each direction genuinely is a form of writing across a catalog boundary, so each genuinely earns the adjective. What the shared phrase hides is that they answer different questions. &lt;i&gt;Outbound&lt;/i&gt; asks whether this platform can act as a client of someone else&apos;s catalog. &lt;i&gt;Inbound&lt;/i&gt; asks whether this platform will let someone else&apos;s engine mutate tables it owns. &lt;i&gt;Through&lt;/i&gt; asks whether this platform will broker access to tables nobody here owns. A team that needs the second and is sold the first has bought a working feature that does not solve its problem.&lt;/p&gt;

&lt;p&gt;They also carry different risk. Outbound writes put your data in a catalog you control, executed by an engine you are already paying for. Inbound writes hand mutation rights over your tables to an engine you may not operate, under a credential discussed later in this article. The maturity dates below matter, but the authority question matters more and does not appear on any release note.&lt;/p&gt;

&lt;div class=&quot;wide scroll&quot;&gt;
&lt;svg class=&quot;diag&quot; viewBox=&quot;0 0 1080 300&quot; xmlns=&quot;http://www.w3.org/2000/svg&quot; role=&quot;img&quot;
  aria-label=&quot;Three panels showing the three write directions. Outbound: Snowflake&apos;s engine writes into a foreign catalog such as Glue or Unity, generally available since October 2025. Inbound: an external engine such as Spark or Trino writes into tables Snowflake owns, generally available since May 2026. Through: an external engine reaches through Horizon into a foreign catalog&apos;s tables, in preview since August 2026, with Horizon acting as broker rather than owner.&quot;&gt;
  &lt;g class=&quot;bx f-steel&quot;&gt;&lt;rect x=&quot;8&quot; y=&quot;8&quot; width=&quot;348&quot; height=&quot;26&quot; rx=&quot;6&quot;/&gt;&lt;text class=&quot;t1&quot; x=&quot;182&quot; y=&quot;26&quot; text-anchor=&quot;middle&quot;&gt;1 &amp;middot; OUTBOUND&lt;/text&gt;&lt;/g&gt;
  &lt;g class=&quot;bx f-steel&quot;&gt;&lt;rect x=&quot;366&quot; y=&quot;8&quot; width=&quot;348&quot; height=&quot;26&quot; rx=&quot;6&quot;/&gt;&lt;text class=&quot;t1&quot; x=&quot;540&quot; y=&quot;26&quot; text-anchor=&quot;middle&quot;&gt;2 &amp;middot; INBOUND&lt;/text&gt;&lt;/g&gt;
  &lt;g class=&quot;bx f-steel&quot;&gt;&lt;rect x=&quot;724&quot; y=&quot;8&quot; width=&quot;348&quot; height=&quot;26&quot; rx=&quot;6&quot;/&gt;&lt;text class=&quot;t1&quot; x=&quot;898&quot; y=&quot;26&quot; text-anchor=&quot;middle&quot;&gt;3 &amp;middot; THROUGH&lt;/text&gt;&lt;/g&gt;
  &lt;defs&gt;
    &lt;marker id=&quot;ar&quot; markerWidth=&quot;9&quot; markerHeight=&quot;9&quot; refX=&quot;8&quot; refY=&quot;4.5&quot; orient=&quot;auto&quot;&gt;&lt;path d=&quot;M0,1 L8.5,4.5 L0,8 z&quot; fill=&quot;#185fa5&quot;/&gt;&lt;/marker&gt;
    &lt;marker id=&quot;arp&quot; markerWidth=&quot;9&quot; markerHeight=&quot;9&quot; refX=&quot;8&quot; refY=&quot;4.5&quot; orient=&quot;auto&quot;&gt;&lt;path d=&quot;M0,1 L8.5,4.5 L0,8 z&quot; fill=&quot;#854f0b&quot;/&gt;&lt;/marker&gt;
  &lt;/defs&gt;

  &lt;g class=&quot;bx f-blue&quot;&gt;&lt;rect x=&quot;20&quot; y=&quot;60&quot; width=&quot;150&quot; height=&quot;44&quot; rx=&quot;7&quot;/&gt;
    &lt;text class=&quot;t2&quot; x=&quot;95&quot; y=&quot;79&quot; text-anchor=&quot;middle&quot;&gt;Snowflake engine&lt;/text&gt;&lt;text class=&quot;t2&quot; x=&quot;95&quot; y=&quot;94&quot; text-anchor=&quot;middle&quot;&gt;owns the query&lt;/text&gt;&lt;/g&gt;
  &lt;path d=&quot;M172 82 H 200&quot; stroke=&quot;#185fa5&quot; stroke-width=&quot;2&quot; fill=&quot;none&quot; marker-end=&quot;url(#ar)&quot;/&gt;
  &lt;g class=&quot;bx f-gray&quot;&gt;&lt;rect x=&quot;204&quot; y=&quot;60&quot; width=&quot;140&quot; height=&quot;44&quot; rx=&quot;7&quot;/&gt;
    &lt;text class=&quot;t2&quot; x=&quot;274&quot; y=&quot;79&quot; text-anchor=&quot;middle&quot;&gt;foreign catalog&lt;/text&gt;&lt;text class=&quot;t2&quot; x=&quot;274&quot; y=&quot;94&quot; text-anchor=&quot;middle&quot;&gt;Glue &amp;middot; Unity&lt;/text&gt;&lt;/g&gt;
  &lt;text class=&quot;t2&quot; x=&quot;20&quot; y=&quot;128&quot;&gt;Catalog-linked databases. Snowflake writes into&lt;/text&gt;
  &lt;text class=&quot;t2&quot; x=&quot;20&quot; y=&quot;143&quot;&gt;tables whose truth is owned elsewhere.&lt;/text&gt;
  &lt;g class=&quot;bx f-teal&quot;&gt;&lt;rect x=&quot;20&quot; y=&quot;158&quot; width=&quot;324&quot; height=&quot;24&quot; rx=&quot;5&quot;/&gt;&lt;text class=&quot;t2&quot; x=&quot;32&quot; y=&quot;174&quot;&gt;GA 17 Oct 2025 &amp;mdash; Unity on Azure only from 6 Apr 2026&lt;/text&gt;&lt;/g&gt;
  &lt;text class=&quot;t2i&quot; x=&quot;20&quot; y=&quot;200&quot;&gt;CTAS limitations documented.&lt;/text&gt;

  &lt;g class=&quot;bx f-purp&quot;&gt;&lt;rect x=&quot;378&quot; y=&quot;60&quot; width=&quot;150&quot; height=&quot;44&quot; rx=&quot;7&quot;/&gt;
    &lt;text class=&quot;t2&quot; x=&quot;453&quot; y=&quot;79&quot; text-anchor=&quot;middle&quot;&gt;Spark &amp;middot; Trino&lt;/text&gt;&lt;text class=&quot;t2&quot; x=&quot;453&quot; y=&quot;94&quot; text-anchor=&quot;middle&quot;&gt;external engine&lt;/text&gt;&lt;/g&gt;
  &lt;path d=&quot;M530 82 H 558&quot; stroke=&quot;#185fa5&quot; stroke-width=&quot;2&quot; fill=&quot;none&quot; marker-end=&quot;url(#ar)&quot;/&gt;
  &lt;g class=&quot;bx f-coral&quot;&gt;&lt;rect x=&quot;562&quot; y=&quot;60&quot; width=&quot;140&quot; height=&quot;44&quot; rx=&quot;7&quot;/&gt;
    &lt;text class=&quot;t2&quot; x=&quot;632&quot; y=&quot;79&quot; text-anchor=&quot;middle&quot;&gt;Snowflake-managed&lt;/text&gt;&lt;text class=&quot;t2&quot; x=&quot;632&quot; y=&quot;94&quot; text-anchor=&quot;middle&quot;&gt;Iceberg tables&lt;/text&gt;&lt;/g&gt;
  &lt;text class=&quot;t2&quot; x=&quot;378&quot; y=&quot;128&quot;&gt;The engine holds vended credentials and writes&lt;/text&gt;
  &lt;text class=&quot;t2&quot; x=&quot;378&quot; y=&quot;143&quot;&gt;to tables Snowflake owns.&lt;/text&gt;
  &lt;g class=&quot;bx f-teal&quot;&gt;&lt;rect x=&quot;378&quot; y=&quot;158&quot; width=&quot;324&quot; height=&quot;24&quot; rx=&quot;5&quot;/&gt;&lt;text class=&quot;t2&quot; x=&quot;390&quot; y=&quot;174&quot;&gt;read GA 6 Feb 2026 &amp;middot; write preview 16 Mar &amp;middot; &lt;tspan font-weight=&quot;700&quot;&gt;write GA 26 May 2026&lt;/tspan&gt;&lt;/text&gt;&lt;/g&gt;
  &lt;text class=&quot;t2i&quot; x=&quot;378&quot; y=&quot;200&quot;&gt;No writes at all to tables carrying fine-grained policies.&lt;/text&gt;

  &lt;g class=&quot;bx f-purp&quot;&gt;&lt;rect x=&quot;736&quot; y=&quot;60&quot; width=&quot;126&quot; height=&quot;44&quot; rx=&quot;7&quot;/&gt;
    &lt;text class=&quot;t2&quot; x=&quot;799&quot; y=&quot;79&quot; text-anchor=&quot;middle&quot;&gt;Trino &amp;middot; DuckDB&lt;/text&gt;&lt;text class=&quot;t2&quot; x=&quot;799&quot; y=&quot;94&quot; text-anchor=&quot;middle&quot;&gt;PyIceberg&lt;/text&gt;&lt;/g&gt;
  &lt;path d=&quot;M864 82 H 886&quot; stroke=&quot;#854f0b&quot; stroke-width=&quot;2&quot; fill=&quot;none&quot; marker-end=&quot;url(#arp)&quot;/&gt;
  &lt;g class=&quot;bx f-amber&quot;&gt;&lt;rect x=&quot;890&quot; y=&quot;60&quot; width=&quot;80&quot; height=&quot;44&quot; rx=&quot;7&quot;/&gt;
    &lt;text class=&quot;t2&quot; x=&quot;930&quot; y=&quot;79&quot; text-anchor=&quot;middle&quot;&gt;Horizon&lt;/text&gt;&lt;text class=&quot;t2&quot; x=&quot;930&quot; y=&quot;94&quot; text-anchor=&quot;middle&quot;&gt;as broker&lt;/text&gt;&lt;/g&gt;
  &lt;path d=&quot;M972 82 H 994&quot; stroke=&quot;#854f0b&quot; stroke-width=&quot;2&quot; fill=&quot;none&quot; marker-end=&quot;url(#arp)&quot;/&gt;
  &lt;g class=&quot;bx f-gray&quot;&gt;&lt;rect x=&quot;998&quot; y=&quot;60&quot; width=&quot;74&quot; height=&quot;44&quot; rx=&quot;7&quot;/&gt;
    &lt;text class=&quot;t2&quot; x=&quot;1035&quot; y=&quot;79&quot; text-anchor=&quot;middle&quot;&gt;foreign&lt;/text&gt;&lt;text class=&quot;t2&quot; x=&quot;1035&quot; y=&quot;94&quot; text-anchor=&quot;middle&quot;&gt;catalog&lt;/text&gt;&lt;/g&gt;
  &lt;text class=&quot;t2&quot; x=&quot;736&quot; y=&quot;128&quot;&gt;The engine reaches &lt;tspan font-style=&quot;italic&quot;&gt;through&lt;/tspan&gt; Horizon into tables&lt;/text&gt;
  &lt;text class=&quot;t2&quot; x=&quot;736&quot; y=&quot;143&quot;&gt;Horizon does not own.&lt;/text&gt;
  &lt;g class=&quot;bx f-amber&quot;&gt;&lt;rect x=&quot;736&quot; y=&quot;158&quot; width=&quot;336&quot; height=&quot;24&quot; rx=&quot;5&quot;/&gt;&lt;text class=&quot;t2&quot; x=&quot;748&quot; y=&quot;174&quot;&gt;Preview, 18 Aug 2026 &amp;mdash; thirteen days old at time of writing&lt;/text&gt;&lt;/g&gt;
  &lt;text class=&quot;t2i&quot; x=&quot;736&quot; y=&quot;200&quot;&gt;Horizon has moved from L2 owner to L3 broker.&lt;/text&gt;

  &lt;line class=&quot;axis&quot; x1=&quot;8&quot; y1=&quot;224&quot; x2=&quot;1072&quot; y2=&quot;224&quot;/&gt;
  &lt;text class=&quot;t2i&quot; x=&quot;8&quot; y=&quot;246&quot; fill=&quot;#8a8880&quot;&gt;All three are marketed under the same phrase. They have different maturities, different limitations, and in the third case a different architectural role.&lt;/text&gt;
  &lt;text class=&quot;t2i&quot; x=&quot;8&quot; y=&quot;264&quot; fill=&quot;#8a8880&quot;&gt;Ask which direction the use case needs before conceding or contesting the point.&lt;/text&gt;
&lt;/svg&gt;
&lt;/div&gt;

&lt;p&gt;The third panel is the one worth pausing on. A catalog that brokers access to tables it does not own has moved from layer two to layer three &amp;mdash; it has stopped being a metastore and started being an engine binding. If you have one word for both, you cannot see that happen.&lt;/p&gt;

&lt;h2&gt;The credential question&lt;/h2&gt;

&lt;p&gt;Here is the mechanism that every architecture diagram draws as a single arrow.&lt;/p&gt;

&lt;p&gt;When an external engine wants to read an Iceberg table, it asks the catalog to load it and signals that it can accept delegated storage access. The Iceberg REST specification defines this as an HTTP header, &lt;code&gt;X-Iceberg-Access-Delegation&lt;/code&gt;, with exactly two permitted values &amp;mdash; &lt;code&gt;vended-credentials&lt;/code&gt; and &lt;code&gt;remote-signing&lt;/code&gt;. The specification is careful to make it a request, not a demand: it is an &lt;q&gt;optional signal to the server that the client supports delegated access&lt;/q&gt;, and &lt;q&gt;the server may choose to supply access via any or none of the requested mechanisms.&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn32&quot; id=&quot;fr32&quot;&gt;32&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;What is striking is how little the specification says about what comes back. The &lt;code&gt;StorageCredential&lt;/code&gt; object has exactly two required fields: a &lt;code&gt;prefix&lt;/code&gt;, which &lt;q&gt;indicates a storage location prefix where the credential is relevant&lt;/q&gt;, and an untyped string map. &lt;b&gt;No credential type is mandated, no expiry field is defined, no lifetime semantics exist at all.&lt;/b&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn32&quot; id=&quot;fr32b&quot;&gt;32&lt;/a&gt;&lt;/sup&gt; Everything concrete is left to implementations, and they have filled the vacuum differently: Apache Polaris &lt;q&gt;calls AWS STS AssumeRole with an inline session policy scoped to the specific table locations and operations&lt;/q&gt; on S3, mints a user-delegation SAS on Azure, and downscopes an OAuth token on GCS.&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn33&quot; id=&quot;fr33&quot;&gt;33&lt;/a&gt;&lt;/sup&gt; Databricks documents a one-hour default expiry and a dedicated privilege that is deliberately excluded from &lt;code&gt;ALL PRIVILEGES&lt;/code&gt; &lt;q&gt;to avoid accidental exfiltration&lt;/q&gt;.&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn10&quot; id=&quot;fr10&quot;&gt;10&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;Now follow what happens to the user.&lt;/p&gt;

&lt;div class=&quot;wide scroll&quot;&gt;
&lt;svg class=&quot;diag&quot; viewBox=&quot;0 0 1080 340&quot; xmlns=&quot;http://www.w3.org/2000/svg&quot; role=&quot;img&quot;
  aria-label=&quot;A left-to-right flow showing the path of a credential. An analyst&apos;s identity reaches the engine, the engine calls the catalog&apos;s loadTable with the access delegation header, and the catalog scopes and mints a credential. A vertical dashed line marks the identity boundary: after this point the end user&apos;s identity is discarded and the object storage request carries the catalog&apos;s service role instead. The final step shows storage returning bytes with no policy evaluation possible. An annotation marks the catalog as the last point at which per-user policy can be evaluated.&quot;&gt;
  &lt;text class=&quot;lane&quot; x=&quot;8&quot; y=&quot;18&quot;&gt;The path of a vended credential &amp;mdash; and where per-user policy stops being evaluable&lt;/text&gt;

  &lt;g class=&quot;bx f-purp&quot;&gt;&lt;rect x=&quot;8&quot; y=&quot;40&quot; width=&quot;150&quot; height=&quot;58&quot; rx=&quot;7&quot;/&gt;
    &lt;text class=&quot;t1&quot; x=&quot;83&quot; y=&quot;62&quot; text-anchor=&quot;middle&quot;&gt;Analyst&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;83&quot; y=&quot;78&quot; text-anchor=&quot;middle&quot;&gt;authenticates via SSO&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;83&quot; y=&quot;92&quot; text-anchor=&quot;middle&quot;&gt;member of group X&lt;/text&gt;&lt;/g&gt;
  &lt;path d=&quot;M160 69 H 190&quot; stroke=&quot;#8a8880&quot; stroke-width=&quot;1.6&quot; fill=&quot;none&quot; marker-end=&quot;url(#a2)&quot;/&gt;
  &lt;defs&gt;&lt;marker id=&quot;a2&quot; markerWidth=&quot;9&quot; markerHeight=&quot;9&quot; refX=&quot;8&quot; refY=&quot;4.5&quot; orient=&quot;auto&quot;&gt;&lt;path d=&quot;M0,1 L8.5,4.5 L0,8 z&quot; fill=&quot;#8a8880&quot;/&gt;&lt;/marker&gt;
    &lt;marker id=&quot;a3&quot; markerWidth=&quot;9&quot; markerHeight=&quot;9&quot; refX=&quot;8&quot; refY=&quot;4.5&quot; orient=&quot;auto&quot;&gt;&lt;path d=&quot;M0,1 L8.5,4.5 L0,8 z&quot; fill=&quot;#993c1d&quot;/&gt;&lt;/marker&gt;&lt;/defs&gt;

  &lt;g class=&quot;bx f-blue&quot;&gt;&lt;rect x=&quot;194&quot; y=&quot;40&quot; width=&quot;160&quot; height=&quot;58&quot; rx=&quot;7&quot;/&gt;
    &lt;text class=&quot;t1&quot; x=&quot;274&quot; y=&quot;62&quot; text-anchor=&quot;middle&quot;&gt;External engine&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;274&quot; y=&quot;78&quot; text-anchor=&quot;middle&quot;&gt;Spark &amp;middot; Trino &amp;middot; DuckDB&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;274&quot; y=&quot;92&quot; text-anchor=&quot;middle&quot;&gt;carries a token per user+role&lt;/text&gt;&lt;/g&gt;
  &lt;path d=&quot;M356 69 H 386&quot; stroke=&quot;#8a8880&quot; stroke-width=&quot;1.6&quot; fill=&quot;none&quot; marker-end=&quot;url(#a2)&quot;/&gt;

  &lt;g class=&quot;bx f-teal&quot;&gt;&lt;rect x=&quot;390&quot; y=&quot;40&quot; width=&quot;180&quot; height=&quot;58&quot; rx=&quot;7&quot; stroke-width=&quot;2.2&quot;/&gt;
    &lt;text class=&quot;t1&quot; x=&quot;480&quot; y=&quot;60&quot; text-anchor=&quot;middle&quot;&gt;Catalog &amp;mdash; loadTable&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;480&quot; y=&quot;76&quot; text-anchor=&quot;middle&quot;&gt;checks the caller&apos;s rights,&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;480&quot; y=&quot;90&quot; text-anchor=&quot;middle&quot;&gt;scopes a prefix, mints a credential&lt;/text&gt;&lt;/g&gt;
  &lt;text class=&quot;t2i&quot; x=&quot;390&quot; y=&quot;118&quot; fill=&quot;#085041&quot;&gt;The last point at which the user&apos;s identity exists&lt;/text&gt;
  &lt;text class=&quot;t2i&quot; x=&quot;390&quot; y=&quot;132&quot; fill=&quot;#085041&quot;&gt;and per-user policy can still be evaluated.&lt;/text&gt;

  &lt;line x1=&quot;600&quot; y1=&quot;24&quot; x2=&quot;600&quot; y2=&quot;256&quot; stroke=&quot;#993c1d&quot; stroke-width=&quot;2&quot; stroke-dasharray=&quot;7 5&quot;/&gt;
  &lt;text class=&quot;t1&quot; x=&quot;608&quot; y=&quot;36&quot; fill=&quot;#993c1d&quot;&gt;IDENTITY BOUNDARY&lt;/text&gt;

  &lt;path d=&quot;M572 69 H 640&quot; stroke=&quot;#993c1d&quot; stroke-width=&quot;1.8&quot; fill=&quot;none&quot; marker-end=&quot;url(#a3)&quot;/&gt;
  &lt;g class=&quot;bx f-coral&quot;&gt;&lt;rect x=&quot;644&quot; y=&quot;40&quot; width=&quot;190&quot; height=&quot;58&quot; rx=&quot;7&quot;/&gt;
    &lt;text class=&quot;t1&quot; x=&quot;739&quot; y=&quot;60&quot; text-anchor=&quot;middle&quot;&gt;Credential in flight&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;739&quot; y=&quot;76&quot; text-anchor=&quot;middle&quot;&gt;STS session &amp;middot; SAS &amp;middot; OAuth token&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;739&quot; y=&quot;90&quot; text-anchor=&quot;middle&quot;&gt;scoped to a &lt;tspan font-style=&quot;italic&quot;&gt;path prefix&lt;/tspan&gt;, not a row or column&lt;/text&gt;&lt;/g&gt;
  &lt;path d=&quot;M836 69 H 866&quot; stroke=&quot;#993c1d&quot; stroke-width=&quot;1.8&quot; fill=&quot;none&quot; marker-end=&quot;url(#a3)&quot;/&gt;

  &lt;g class=&quot;bx f-gray&quot;&gt;&lt;rect x=&quot;870&quot; y=&quot;40&quot; width=&quot;202&quot; height=&quot;58&quot; rx=&quot;7&quot;/&gt;
    &lt;text class=&quot;t1&quot; x=&quot;971&quot; y=&quot;60&quot; text-anchor=&quot;middle&quot;&gt;Object storage&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;971&quot; y=&quot;76&quot; text-anchor=&quot;middle&quot;&gt;sees the catalog&apos;s service role&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;971&quot; y=&quot;90&quot; text-anchor=&quot;middle&quot;&gt;returns whole objects&lt;/text&gt;&lt;/g&gt;

  &lt;text class=&quot;t2&quot; x=&quot;608&quot; y=&quot;146&quot; fill=&quot;#712b13&quot;&gt;past this line the end user is discarded &amp;mdash; only the catalog&apos;s service identity continues&lt;/text&gt;
  &lt;g class=&quot;bx f-amber&quot;&gt;&lt;rect x=&quot;608&quot; y=&quot;158&quot; width=&quot;464&quot; height=&quot;88&quot; rx=&quot;8&quot;/&gt;
    &lt;text class=&quot;t1&quot; x=&quot;624&quot; y=&quot;180&quot;&gt;What storage cannot do, by construction&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;624&quot; y=&quot;198&quot;&gt;&amp;#8226; distinguish two users holding credentials vended from the same role&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;624&quot; y=&quot;214&quot;&gt;&amp;#8226; apply a column mask &amp;mdash; it serves files, not projections&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;624&quot; y=&quot;230&quot;&gt;&amp;#8226; apply a row filter &amp;mdash; the predicate was never sent to it&lt;/text&gt;&lt;/g&gt;

  &lt;g class=&quot;bx f-teal&quot;&gt;&lt;rect x=&quot;8&quot; y=&quot;158&quot; width=&quot;580&quot; height=&quot;88&quot; rx=&quot;8&quot;/&gt;
    &lt;text class=&quot;t1&quot; x=&quot;24&quot; y=&quot;180&quot;&gt;What the catalog can still do, before the boundary&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;24&quot; y=&quot;198&quot;&gt;&amp;#8226; refuse to vend at all &amp;mdash; Databricks excludes tables carrying masks or row filters&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;24&quot; y=&quot;214&quot;&gt;&amp;#8226; narrow the prefix &amp;mdash; table-level and coarser only; this is the whole granularity budget&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;24&quot; y=&quot;230&quot;&gt;&amp;#8226; decline delegation and keep the query &amp;mdash; the route both vendors actually took&lt;/text&gt;&lt;/g&gt;

  &lt;line class=&quot;axis&quot; x1=&quot;8&quot; y1=&quot;270&quot; x2=&quot;1072&quot; y2=&quot;270&quot;/&gt;
  &lt;text class=&quot;t2i&quot; x=&quot;8&quot; y=&quot;292&quot; fill=&quot;#8a8880&quot;&gt;The Iceberg REST specification defines no mechanism for propagating end-user identity to storage. Apache Polaris documents three IAM identities in the S3 vending flow; the end user is not one of them.&lt;/text&gt;
  &lt;text class=&quot;t2i&quot; x=&quot;8&quot; y=&quot;310&quot; fill=&quot;#8a8880&quot;&gt;Access delegation is a design choice with a granularity ceiling: a prefix. Everything finer has to be enforced somewhere the credential never reaches.&lt;/text&gt;
&lt;/svg&gt;
&lt;/div&gt;

&lt;h3&gt;The end user is not in the room&lt;/h3&gt;

&lt;p&gt;This is the finding that reorganises everything above it.&lt;/p&gt;

&lt;p&gt;Search the entire Iceberg REST OpenAPI specification for a mechanism to propagate end-user identity to storage and there is nothing &amp;mdash; no impersonation, no on-behalf-of, no principal forwarding. The only identity plumbing in the document belongs to the deprecated OAuth token-exchange endpoint and authenticates a client &lt;i&gt;to the catalog&lt;/i&gt;, never to the object store.&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn32&quot; id=&quot;fr32c&quot;&gt;32&lt;/a&gt;&lt;/sup&gt; Apache Polaris makes the consequence explicit and countable: &lt;q&gt;Three distinct IAM identities take part in the S3 credential-vending flow&lt;/q&gt;, and the end user is not among them. Polaris uses the caller&apos;s identity to decide &lt;i&gt;whether&lt;/i&gt; to vend and &lt;i&gt;how narrowly to scope the prefix&lt;/i&gt;, then &lt;q&gt;the client uses those credentials to talk to S3 and KMS directly.&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn35&quot; id=&quot;fr35&quot;&gt;35&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;

&lt;div class=&quot;pull&quot;&gt;&lt;b&gt;So the identity is spent, not carried.&lt;/b&gt; It is consumed at the catalog to make one authorisation decision, and the storage layer never learns who asked. Object storage cannot distinguish two analysts holding credentials vended from the same role &amp;mdash; which means per-user policy is not merely unenforced at that layer, it is &lt;b&gt;unevaluable&lt;/b&gt; there. And a credential&apos;s granularity ceiling is a path prefix. A column mask and a row filter are both finer than any prefix can express.&lt;/div&gt;

&lt;p&gt;None of this is a defect in the specification. It is a consequence of the thing that makes the specification valuable: direct engine-to-storage reads, with no proxy in the data path. You cannot have both that and enforcement in the same request.&lt;/p&gt;

&lt;h3&gt;What the project itself says&lt;/h3&gt;

&lt;p&gt;No primary source states the bypass in blunt terms. There is no sentence in the specification, the Iceberg documentation or the Polaris documentation saying &quot;vended credentials bypass column masking and row filtering.&quot; That absence is worth reporting honestly, and it is not the end of the matter, because the project has documented the underlying problem in its own words &amp;mdash; and more damningly than a blunt statement would.&lt;/p&gt;

&lt;p&gt;The active fine-grained-access-control proposal for the REST specification puts &lt;b&gt;every enforcement obligation on the client&lt;/b&gt;: the catalog returns restrictions, and &lt;q&gt;a reader must enforce projections on the columns it is actually reading.&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn37&quot; id=&quot;fr37&quot;&gt;37&lt;/a&gt;&lt;/sup&gt; It has been open and unmerged since 2026; two earlier attempts to place fine-grained access control in the specification were closed as not planned. On the project&apos;s development list the reasoning is stated plainly:&lt;/p&gt;

&lt;blockquote&gt;&quot;we are conflating trust with proof: proof is very hard and very expensive, and arguably unachievable&quot;&amp;hellip; &quot;Trust contract (out of spec): admin/catalog decides which clients are non-malicious and wired up to enforce.&quot;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn36&quot; id=&quot;fr36&quot;&gt;36&lt;/a&gt;&lt;/sup&gt;&lt;/blockquote&gt;

&lt;p&gt;And on identity, from the same discussion: &lt;q&gt;identity propagation across multi-tenant query engines is a real problem, but it&apos;s orthogonal to the spec.&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn36&quot; id=&quot;fr36b&quot;&gt;36&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;The honest reading is that the tension is not denied. It is &lt;b&gt;relocated&lt;/b&gt; &amp;mdash; reclassified from a specification problem into a deployment and trust problem, and moved out of scope. Which is a defensible engineering decision, and one that transfers the entire burden onto whoever operates the estate. If your governance model assumes the catalog enforces, and the catalog&apos;s own project says enforcement is a property of clients you have chosen to trust, those are different models.&lt;/p&gt;

&lt;p&gt;Worth knowing too: the alternative delegation mode, &lt;b&gt;remote signing&lt;/b&gt;, keeps the catalog in the path for every object request &amp;mdash; and the project&apos;s own contributors describe the cost as per-file round trips that &lt;q&gt;can cause server overwhelm for very huge tables&lt;/q&gt;, with a non-configurable fifteen-minute signature lifetime on AWS and GCS.&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn36&quot; id=&quot;fr36c&quot;&gt;36&lt;/a&gt;&lt;/sup&gt; The choice is not between safe and unsafe. It is between a proxy you must scale and a credential you must trust.&lt;/p&gt;

&lt;h3&gt;What each vendor actually does about it&lt;/h3&gt;

&lt;p&gt;All three had to resolve the same tension, and the convergence in their answers is the strongest evidence that the tension is structural rather than incidental.&lt;/p&gt;

&lt;div class=&quot;wide scroll&quot;&gt;
&lt;table&gt;
&lt;thead&gt;&lt;tr&gt;&lt;th style=&quot;width:14%&quot;&gt;Platform&lt;/th&gt;&lt;th style=&quot;width:29%&quot;&gt;Under vended credentials&lt;/th&gt;&lt;th style=&quot;width:29%&quot;&gt;When policy must be enforced&lt;/th&gt;&lt;th style=&quot;width:28%&quot;&gt;The cost of the resolution&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;&lt;b&gt;Databricks&lt;/b&gt;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Refuses outright.&lt;/b&gt; &lt;q&gt;You cannot use Iceberg REST catalog or Unity REST APIs to access tables with row filters or column masks.&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn11&quot; id=&quot;fr11&quot;&gt;11&lt;/a&gt;&lt;/sup&gt; Views and materialized views are excluded too.&lt;/td&gt;&lt;td&gt;&lt;b&gt;Stops vending and filters server-side.&lt;/b&gt; Cross-engine ABAC: &lt;q&gt;Databricks uses a specialized serverless compute layer to filter and return sanitized data to the external engine.&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn12&quot; id=&quot;fr12&quot;&gt;12&lt;/a&gt;&lt;/sup&gt;&lt;/td&gt;&lt;td&gt;Beta since 28 May 2026, and &lt;q&gt;Only reads are supported from external engines when fine-grained access controls (FGAC) are enforced.&lt;/q&gt; The engine no longer touches storage.&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;b&gt;Snowflake&lt;/b&gt;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Says so in a caption.&lt;/b&gt; The plain Iceberg-REST-plus-vended-credentials configuration example is headed, twice, &lt;q&gt;This code doesn&apos;t enforce data protection policies:&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn18&quot; id=&quot;fr18&quot;&gt;18&lt;/a&gt;&lt;/sup&gt;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Routes the query home.&lt;/b&gt; &lt;q&gt;The Spark connector supports querying tables that are protected by Snowflake policies by routing the query through Snowflake, which ensures efficient use of compute and consistent enforcement.&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn25&quot; id=&quot;fr25&quot;&gt;25&lt;/a&gt;&lt;/sup&gt;&lt;/td&gt;&lt;td&gt;One connector, one engine, three policy types; &lt;q&gt;Queries on tables that are protected with any other data policy result in an error.&lt;/q&gt; And no external writes to policy-protected tables at all.&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;b&gt;IBM&lt;/b&gt;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Documents nothing.&lt;/b&gt; Vending arrived in version 2.2.1 and is framed purely as key hygiene &amp;mdash; &lt;q&gt;without the need to manage long-lived access keys&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn39&quot; id=&quot;fr39b&quot;&gt;39&lt;/a&gt;&lt;/sup&gt; &amp;mdash; with no mention of Ranger, masking, filtering or policy on any vending page.&lt;/td&gt;&lt;td&gt;&lt;b&gt;Enforces inside the engine.&lt;/b&gt; Ranger service types govern &lt;q&gt;tables used by Presto engine&lt;/q&gt; and Spark respectively, via plugins; external Spark must load IBM&apos;s own extension into the session.&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn43&quot; id=&quot;fr43b&quot;&gt;43&lt;/a&gt;&lt;/sup&gt;&lt;/td&gt;&lt;td&gt;A cooperating-client model, not an enforcement boundary. And the interaction between vending and policy is undocumented in both directions.&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;

&lt;div class=&quot;caution&quot;&gt;&lt;b&gt;On that last cell, a word about my own employer.&lt;/b&gt; I searched IBM&apos;s documentation corpus in both directions: no vending page mentions Ranger, Knowledge Catalog, masking or filtering, and no policy page mentions vended credentials or the delegation header. IBM neither claims that policies still apply nor warns that they do not. &lt;b&gt;I am reporting a documented silence, not a documented answer&lt;/b&gt; &amp;mdash; the mechanism in the adjacent cell makes one outcome more plausible than the other, but IBM has not said so and I am not going to say it for them. If you are designing on watsonx.data, this is a question to put to IBM in writing rather than infer from an article.&lt;/div&gt;

&lt;p&gt;Two of the three converged on the identical resolution: &lt;b&gt;when fine-grained policy has to hold, stop vending credentials and bring the query back inside.&lt;/b&gt; Both accepted the same collateral damage — read-only, and a single engine or connector. Neither has demonstrated fine-grained enforcement co-existing with genuine direct-to-storage open-catalog access, because on the evidence above, nobody can.&lt;/p&gt;

&lt;h3&gt;One contradiction to be aware of before you quote anyone&lt;/h3&gt;

&lt;p&gt;Snowflake&apos;s own pages disagree about how far its enforcement reaches. The Horizon overview makes an engine-agnostic claim &amp;mdash; &lt;q&gt;Masking and row-access policies are enforced across any Iceberg REST Catalog-compatible engine&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn17&quot; id=&quot;fr17b&quot;&gt;17&lt;/a&gt;&lt;/sup&gt; &amp;mdash; while every operational page narrows it to Apache Spark with the Snowflake Spark connector, at specified minimum versions.&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn25&quot; id=&quot;fr25b&quot;&gt;25&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;What happens when Trino or DuckDB &amp;mdash; both listed as supported engines against the same endpoint &amp;mdash; reads a table carrying a masking policy? &lt;b&gt;The documentation does not say.&lt;/b&gt; I found no statement that the request is blocked and none that unmasked data is returned. A connector-based mechanism has no obvious path to a non-Spark engine, which makes one answer more likely, but that is inference and I am not going to publish it as fact. If your design depends on the answer, test it or get it in writing; do not take it from either the overview page or from me.&lt;/p&gt;

&lt;h3&gt;And the key custody question underneath&lt;/h3&gt;

&lt;p&gt;There is a matching pattern one layer down, and it is the same on both major platforms, which is what makes it worth noticing rather than dismissing as a product gap.&lt;/p&gt;

&lt;p&gt;&lt;b&gt;Open-format tables sit outside each vendor&apos;s strongest key-custody boundary.&lt;/b&gt; Databricks supports customer-managed keys for Unity Catalog, and the scope statement is explicit: &lt;q&gt;This feature only applies to catalogs backed by default storage. It doesn&apos;t apply to catalogs with external storage locations.&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn14&quot; id=&quot;fr14&quot;&gt;14&lt;/a&gt;&lt;/sup&gt; Snowflake&apos;s Tri-Secret Secure gives real custody &amp;mdash; &lt;q&gt;If the customer-managed key (CMK) in the composite master key hierarchy is revoked, your data can no longer be decrypted by Snowflake&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn28&quot; id=&quot;fr28&quot;&gt;28&lt;/a&gt;&lt;/sup&gt; &amp;mdash; but &lt;q&gt;Iceberg tables that use Snowflake storage support only server-side encryption (SSE). Customer-managed keys (CMK) are not supported, even if your account has Tri-Secret Secure enabled.&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn27&quot; id=&quot;fr27&quot;&gt;27&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;IBM deserves the same scrutiny and gets it. watsonx.data supports BYOK through Key Protect and KYOK through Hyper Protect Crypto Services at provision time &amp;mdash; but read the scope: &lt;q&gt;Backend object storage repositories for internal metadata and 10 GB limited trial bucket&lt;/q&gt;.&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn44&quot; id=&quot;fr44&quot;&gt;44&lt;/a&gt;&lt;/sup&gt; That is internal metadata and a trial bucket, not customer-registered data buckets. The frequently-quoted assurance that &lt;q&gt;KYOK provides technical assurance that IBM cannot access the customer keys&lt;/q&gt; is a statement in the &lt;i&gt;Hyper Protect&lt;/i&gt; documentation about HPCS&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn46&quot; id=&quot;fr46&quot;&gt;46&lt;/a&gt;&lt;/sup&gt; &amp;mdash; where the same table marks that assurance &lt;b&gt;No&lt;/b&gt; for BYOK &amp;mdash; and it does not appear anywhere in the watsonx.data corpus. Nor is HPCS available in most of the non-US regions watsonx.data lists.&lt;/p&gt;

&lt;div class=&quot;pull&quot;&gt;&lt;b&gt;The pattern is consistent across all three, and it is not a coincidence.&lt;/b&gt; Each vendor&apos;s strongest guarantees &amp;mdash; fine-grained policy, key custody &amp;mdash; are strongest exactly where it owns the whole path. Open the format, open the catalog, hand out a credential, and the guarantees thin out in proportion. That is the actual trade in &quot;open lakehouse&quot;, and it is almost never priced.&lt;/div&gt;

&lt;h2&gt;What to do with this&lt;/h2&gt;

&lt;p&gt;The six layers are not a scoring rubric and they produce no winner. They produce the ability to be specific about disagreement, which is the only durable thing in a market that ships something material every fortnight.&lt;/p&gt;

&lt;p&gt;When someone says a catalog is &quot;more open&quot;, the model forces the question &lt;i&gt;at which layer&lt;/i&gt; &amp;mdash; and the answer is almost always the waist, where all three have converged and the differences have largely evaporated. A conversation that stays at the waist is a conversation about a solved problem. That is precisely why so many of them stay there.&lt;/p&gt;

&lt;p&gt;Five questions worth more than any feature matrix:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;b&gt;Which layer is this claim about?&lt;/b&gt; If it cannot be placed, it cannot be checked.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Which direction of write?&lt;/b&gt; Outbound is GA since October 2025&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn22&quot; id=&quot;fr22&quot;&gt;22&lt;/a&gt;&lt;/sup&gt;, with Unity on Azure only from April 2026&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn23&quot; id=&quot;fr23&quot;&gt;23&lt;/a&gt;&lt;/sup&gt;; inbound read went GA in February and inbound write in May 2026&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn21&quot; id=&quot;fr21&quot;&gt;21&lt;/a&gt;&lt;/sup&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn19&quot; id=&quot;fr19&quot;&gt;19&lt;/a&gt;&lt;/sup&gt;, having been preview in March&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn20&quot; id=&quot;fr20&quot;&gt;20&lt;/a&gt;&lt;/sup&gt;; through-Horizon access is thirteen days old and in preview&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn24&quot; id=&quot;fr24&quot;&gt;24&lt;/a&gt;&lt;/sup&gt;. Three capabilities, one phrase.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Is the engine reading storage directly?&lt;/b&gt; If yes, the granularity ceiling is a path prefix and no mask or filter is in play, whatever the overview page says.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Where does the end user&apos;s identity stop?&lt;/b&gt; On the evidence here, at the catalog. Design as though everything past that point is one service principal, because it is.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;What is inside the key-custody boundary, and is your open-format data in it?&lt;/b&gt; On both major platforms, currently, it is not.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;One practical habit, learned expensively. Status in this market lives in dated release notes, not on feature pages &amp;mdash; several Snowflake feature pages carry no GA or preview banner at all, so the page documenting a capability cannot tell you whether it is generally available.&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn18&quot; id=&quot;fr18b&quot;&gt;18&lt;/a&gt;&lt;/sup&gt; Databricks publishes monthly platform notes with explicit GA language and dates&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn4&quot; id=&quot;fr4&quot;&gt;4&lt;/a&gt;&lt;/sup&gt;, and those are the citable artefact. Put an expiry on a claim rather than a date of writing: anything preview-tier deserves re-checking at four weeks, anything GA at a quarter.&lt;/p&gt;

&lt;p&gt;Including this article.&lt;/p&gt;

&lt;div class=&quot;pull&quot;&gt;&lt;b&gt;Part two, &lt;i&gt;Authoring Is Not Enforcing&lt;/i&gt;&lt;/b&gt;, looks at the layer this one leaves alone: the enterprise governance catalog &amp;mdash; Collibra, Alation, Informatica, Microsoft Purview and IBM&apos;s own Knowledge Catalog. Where it sits on the model, what it can and cannot enforce, why none of them speaks the protocol at the waist, and what the seam between authoring and enforcement actually costs to operate. It ends by joining its argument to this one, and the join is the part I would read first if I were reading them in reverse.&lt;/div&gt;

&lt;hr class=&quot;sep&quot;&gt;

&lt;h2 id=&quot;notes&quot;&gt;Notes&lt;/h2&gt;
&lt;p class=&quot;cap&quot; style=&quot;margin-bottom:14px&quot;&gt;Every source below was retrieved on &lt;b&gt;31 August 2026&lt;/b&gt;. Vendor engineering blogs and press releases are marked as such and used for wording, never for feature status. Where IBM&apos;s published documentation site refused automated retrieval, IBM&apos;s own documentation source repository was used instead and the provenance is flagged. Entries marked &lt;i&gt;consulted&lt;/i&gt; support a statement without being quoted.&lt;/p&gt;

&lt;ol class=&quot;notes&quot;&gt;
&lt;li id=&quot;fn1&quot;&gt;Databricks, &lt;i&gt;Platform release notes &amp;mdash; May 2026&lt;/i&gt;: managed Iceberg, foreign Iceberg and Iceberg v3 generally available, 21 May 2026; also the 28 May entry for cross-engine ABAC. &lt;a href=&quot;https://docs.databricks.com/aws/en/release-notes/product/2026/may&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;docs.databricks.com&lt;/a&gt; &lt;a href=&quot;#fr1&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn2&quot;&gt;Databricks, &lt;i&gt;External access to Iceberg&lt;/i&gt; &amp;mdash; the Iceberg REST implementation, the read/write matrix, and &lt;q&gt;Credential vending on Foreign Iceberg tables is not supported.&lt;/q&gt; Last updated 3 August 2026. &lt;a href=&quot;https://docs.databricks.com/aws/en/external-access/iceberg&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;docs.databricks.com&lt;/a&gt; &lt;a href=&quot;#fr2&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn3&quot;&gt;Databricks, &lt;i&gt;Catalog federation&lt;/i&gt;: &lt;q&gt;Internal Hive metastores allow reads and writes&lt;/q&gt; &amp;mdash; the sole exception to read-only foreign catalogs. &lt;a href=&quot;https://docs.databricks.com/aws/en/query-federation/catalog-federation&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;docs.databricks.com&lt;/a&gt; &lt;a href=&quot;#fr3&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn4&quot;&gt;Databricks, &lt;i&gt;Platform release notes &amp;mdash; April 2026&lt;/i&gt;: ABAC GA 28 April, governed tags GA 2 April, Data Classification GA 20 April. &lt;a href=&quot;https://docs.databricks.com/aws/en/release-notes/product/2026/april&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;docs.databricks.com&lt;/a&gt; &lt;a href=&quot;#fr4&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn5&quot;&gt;Databricks, &lt;i&gt;Platform release notes &amp;mdash; June 2026&lt;/i&gt;: external lineage GA; &lt;q&gt;Following the release of open-source OpenSharing, Delta Sharing is now OpenSharing.&lt;/q&gt; &lt;a href=&quot;https://docs.databricks.com/aws/en/release-notes/product/2026/june&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;docs.databricks.com&lt;/a&gt; &lt;a href=&quot;#fr5&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn6&quot;&gt;Databricks, &lt;i&gt;Platform release notes &amp;mdash; August 2026&lt;/i&gt;: RBAC GA 19 Aug; managed Iceberg sharing GA 14 Aug; three ABAC extensions 11, 17 and 21 Aug; Pages Beta 12 Aug. &lt;a href=&quot;https://docs.databricks.com/aws/en/release-notes/product/2026/august&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;docs.databricks.com&lt;/a&gt; &lt;a href=&quot;#fr6&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn7&quot;&gt;Databricks, &lt;i&gt;Unity Catalog semantics&lt;/i&gt; and &lt;i&gt;Pages&lt;/i&gt;: &lt;q&gt;A Page is a governed, authoritative definition of a business concept&lt;/q&gt;. &lt;a href=&quot;https://docs.databricks.com/aws/en/business-semantics/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;business-semantics&lt;/a&gt; &amp;middot; &lt;a href=&quot;https://docs.databricks.com/aws/en/uc-semantics/pages&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Pages&lt;/a&gt; &lt;a href=&quot;#fr7&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn8&quot;&gt;Unity Catalog OSS: &lt;q&gt;Unity Catalog is currently a sandbox project with LF AI and Data Foundation (part of the Linux Foundation).&lt;/q&gt; &lt;a href=&quot;https://github.com/unitycatalog/unitycatalog&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;github.com/unitycatalog&lt;/a&gt; &lt;a href=&quot;#fr8&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn9&quot;&gt;Databricks, &lt;i&gt;Data classification&lt;/i&gt;: &lt;q&gt;Databricks Data Classification uses an agent to automatically classify and tag tables in your catalog.&lt;/q&gt; &lt;a href=&quot;https://docs.databricks.com/aws/en/data-governance/unity-catalog/data-classification&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;docs.databricks.com&lt;/a&gt; &lt;a href=&quot;#fr9&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn10&quot;&gt;Databricks, &lt;i&gt;Credential vending&lt;/i&gt;: &lt;q&gt;Issued credentials allow direct access to the cloud storage location, scoped to the relevant path.&lt;/q&gt;; &lt;q&gt;The default expiration time is one hour.&lt;/q&gt;; and &lt;q&gt;To avoid accidental exfiltration, ALL PRIVILEGES does not include the EXTERNAL USE SCHEMA privilege&lt;/q&gt;. Whether the expiry is configurable is not documented on this page. &lt;a href=&quot;https://docs.databricks.com/aws/en/external-access/credential-vending&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;docs.databricks.com&lt;/a&gt; &lt;a href=&quot;#fr10&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn11&quot;&gt;Databricks, &lt;i&gt;Filters and masks&lt;/i&gt;: &lt;q&gt;You cannot use Iceberg REST catalog or Unity REST APIs to access tables with row filters or column masks.&lt;/q&gt; and &lt;q&gt;Path-based access to files in tables with policies is not supported.&lt;/q&gt; &lt;a href=&quot;https://docs.databricks.com/aws/en/data-governance/unity-catalog/filters-and-masks/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;docs.databricks.com&lt;/a&gt; &lt;a href=&quot;#fr11&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn12&quot;&gt;Databricks, &lt;i&gt;Cross-engine ABAC&lt;/i&gt; (Beta): &lt;q&gt;Databricks uses a specialized serverless compute layer to filter and return sanitized data to the external engine.&lt;/q&gt; and &lt;q&gt;Only reads are supported from external engines when fine-grained access controls (FGAC) are enforced.&lt;/q&gt; Note the tension with note 11, which still states the flat prohibition. &lt;a href=&quot;https://docs.databricks.com/aws/en/external-access/cross-engine-abac&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;docs.databricks.com&lt;/a&gt; &lt;a href=&quot;#fr12&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn13&quot;&gt;Databricks, &lt;i&gt;Storage credentials&lt;/i&gt;: &lt;q&gt;A storage credential represents an authentication and authorization mechanism for accessing data stored on your cloud tenant.&lt;/q&gt; &amp;mdash; the service identity behind vending. &lt;a href=&quot;https://docs.databricks.com/aws/en/connect/unity-catalog/cloud-storage/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;docs.databricks.com&lt;/a&gt; &lt;i&gt;&amp;mdash; consulted&lt;/i&gt;&lt;/li&gt;
&lt;li id=&quot;fn14&quot;&gt;Databricks, &lt;i&gt;Customer-managed keys for Unity Catalog&lt;/i&gt;: &lt;q&gt;This feature only applies to catalogs backed by default storage. It doesn&apos;t apply to catalogs with external storage locations.&lt;/q&gt; and, on revocation, &lt;q&gt;After you disable the key, Databricks can no longer decrypt data in catalogs using this CMK configuration.&lt;/q&gt; &lt;a href=&quot;https://docs.databricks.com/aws/en/security/keys/cmek-unity-catalog&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;docs.databricks.com&lt;/a&gt; &amp;middot; &lt;a href=&quot;https://docs.databricks.com/aws/en/security/keys/customer-managed-keys&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;CMK overview&lt;/a&gt; &lt;a href=&quot;#fr14&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn15&quot;&gt;Databricks, &lt;i&gt;SCIM provisioning&lt;/i&gt; &amp;mdash; account-level SCIM from the identity provider; workspace-level SCIM is legacy. &lt;a href=&quot;https://docs.databricks.com/aws/en/admin/users-groups/scim/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;docs.databricks.com&lt;/a&gt; &lt;i&gt;&amp;mdash; consulted&lt;/i&gt;&lt;/li&gt;
&lt;li id=&quot;fn16&quot;&gt;Snowflake, &lt;i&gt;Open Catalog overview&lt;/i&gt;: &lt;q&gt;Snowflake Open Catalog is a managed service for Apache Polaris&amp;trade;&lt;/q&gt;; &lt;q&gt;Customers who haven&apos;t previously created a Snowflake Open Catalog account can&apos;t sign up for their first Open Catalog account.&lt;/q&gt; &lt;a href=&quot;https://docs.snowflake.com/en/user-guide/opencatalog/overview&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;docs.snowflake.com&lt;/a&gt; &lt;a href=&quot;#fr16&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn17&quot;&gt;Snowflake, &lt;i&gt;Horizon Catalog&lt;/i&gt; &amp;mdash; the engine-agnostic enforcement claim: &lt;q&gt;Masking and row-access policies are enforced across any Iceberg REST Catalog-compatible engine.&lt;/q&gt; &lt;a href=&quot;https://docs.snowflake.com/en/user-guide/snowflake-horizon&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;docs.snowflake.com&lt;/a&gt; &lt;a href=&quot;#fr17&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn18&quot;&gt;Snowflake, &lt;i&gt;Access Snowflake-managed Iceberg tables using an external query engine through Horizon Catalog&lt;/i&gt; &amp;mdash; the vended-credentials configuration, captioned twice &lt;q&gt;This code doesn&apos;t enforce data protection policies:&lt;/q&gt;; the restriction list including &lt;q&gt;Writing to tables that have fine-grained access control policies or tags isn&apos;t supported.&lt;/q&gt;; and the per-user-and-role token model, &lt;q&gt;You need to obtain an access token for each user — service or human — and role&lt;/q&gt;. This page carries no GA or preview banner. &lt;a href=&quot;https://docs.snowflake.com/en/user-guide/tables-iceberg-access-using-external-query-engine-snowflake-horizon&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;docs.snowflake.com&lt;/a&gt; &lt;a href=&quot;#fr18&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn19&quot;&gt;Snowflake, release note 26 May 2026 &amp;mdash; inbound external write GA. &lt;a href=&quot;https://docs.snowflake.com/en/release-notes/2026/other/2026-05-26-tables-iceberg-query-using-external-query-engine-snowflake-horizon-writes-ga&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;docs.snowflake.com&lt;/a&gt; &lt;a href=&quot;#fr19&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn20&quot;&gt;Snowflake, release note 16 March 2026 &amp;mdash; inbound write, Preview. &lt;a href=&quot;https://docs.snowflake.com/en/release-notes/2026/other/2026-03-16-tables-iceberg-query-using-external-query-engine-snowflake-horizon-writes-feature&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;docs.snowflake.com&lt;/a&gt; &lt;a href=&quot;#fr20&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn21&quot;&gt;Snowflake, release note 6 February 2026 &amp;mdash; inbound read, GA. &lt;a href=&quot;https://docs.snowflake.com/en/release-notes/2026/other/2026-02-06-tables-iceberg-query-using-external-query-engine-snowflake-horizon-ga&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;docs.snowflake.com&lt;/a&gt; &lt;a href=&quot;#fr21&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn22&quot;&gt;Snowflake, release note 17 October 2025 &amp;mdash; externally managed Iceberg writes and catalog-linked databases, GA. &lt;a href=&quot;https://docs.snowflake.com/en/release-notes/2025/other/2025-10-17-iceberg-external-writes-cld-ga&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;docs.snowflake.com&lt;/a&gt; &lt;a href=&quot;#fr22&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn23&quot;&gt;Snowflake, release note 6 April 2026 &amp;mdash; Iceberg write support for Azure Unity Catalog, GA. &lt;a href=&quot;https://docs.snowflake.com/en/release-notes/2026/other/2026-04-06-iceberg-write-support-azure-unity-catalog&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;docs.snowflake.com&lt;/a&gt; &lt;a href=&quot;#fr23&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn24&quot;&gt;Snowflake, release note 18 August 2026, Preview: &lt;q&gt;You can now use the Horizon Iceberg REST Catalog (IRC) API to access externally managed Apache Iceberg&amp;trade; tables in a catalog-linked database from external engines such as Apache Spark&amp;trade;, Trino, DuckDB, or PyIceberg.&lt;/q&gt; &lt;a href=&quot;https://docs.snowflake.com/en/release-notes/2026/other/2026-08-18-externally-managed-iceberg-tables-horizon-irc-preview&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;docs.snowflake.com&lt;/a&gt; &lt;a href=&quot;#fr24&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn25&quot;&gt;Snowflake, &lt;i&gt;Enforce access policies when querying with an external engine through Horizon Catalog&lt;/i&gt;: &lt;q&gt;The Spark connector supports querying tables that are protected by Snowflake policies by routing the query through Snowflake, which ensures efficient use of compute and consistent enforcement.&lt;/q&gt; and &lt;q&gt;Queries on tables that are protected with any other data policy result in an error.&lt;/q&gt; Scoped throughout to Apache Spark at specified minimum versions. &lt;a href=&quot;https://docs.snowflake.com/en/user-guide/tables-iceberg-query-using-external-query-engine-snowflake-horizon-enforce-access-policies&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;docs.snowflake.com&lt;/a&gt; &lt;a href=&quot;#fr25&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn26&quot;&gt;Snowflake, release note 27 January 2026 &amp;mdash; enforce data protection policies when querying Iceberg tables from Apache Spark. &lt;a href=&quot;https://docs.snowflake.com/en/release-notes/2026/other/2026-01-27-iceberg-enforce-access-policies-on-tables-queried-from-apache-spark&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;docs.snowflake.com&lt;/a&gt; &lt;i&gt;&amp;mdash; consulted&lt;/i&gt;&lt;/li&gt;
&lt;li id=&quot;fn27&quot;&gt;Snowflake, &lt;i&gt;Iceberg tables on Snowflake storage&lt;/i&gt;: &lt;q&gt;Iceberg tables that use Snowflake storage support only server-side encryption (SSE). Customer-managed keys (CMK) are not supported, even if your account has Tri-Secret Secure enabled.&lt;/q&gt; &lt;a href=&quot;https://docs.snowflake.com/en/user-guide/tables-iceberg-internal-storage&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;docs.snowflake.com&lt;/a&gt; &lt;a href=&quot;#fr27&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn28&quot;&gt;Snowflake, &lt;i&gt;Tri-Secret Secure&lt;/i&gt;: &lt;q&gt;If the customer-managed key (CMK) in the composite master key hierarchy is revoked, your data can no longer be decrypted by Snowflake.&lt;/q&gt; Neither this page nor the encryption-management page mentions Iceberg or external volumes. &lt;a href=&quot;https://docs.snowflake.com/en/user-guide/security-encryption-tss&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;docs.snowflake.com&lt;/a&gt; &lt;a href=&quot;#fr28&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn29&quot;&gt;Snowflake Engineering, &lt;i&gt;Apache Polaris: The End of Data Vendor Lock-In&lt;/i&gt;, 9 April 2026. &lt;a href=&quot;https://www.snowflake.com/en/blog/engineering/apache-polaris-iceberg-rest-catalog/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;snowflake.com&lt;/a&gt; &lt;i&gt;&amp;mdash; vendor engineering blog&lt;/i&gt; &lt;a href=&quot;#fr29&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn30&quot;&gt;Snowflake, release note 2 March 2026 &amp;mdash; querying semantic views in standard SQL, GA. &lt;a href=&quot;https://docs.snowflake.com/en/release-notes/2026/other/2026-03-02-semantic-views-standard-sql&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;docs.snowflake.com&lt;/a&gt; &lt;a href=&quot;#fr30&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn31&quot;&gt;Apache Polaris, &lt;i&gt;Apache Polaris Graduates to Top Level Project!&lt;/i&gt;, 19 February 2026. &lt;a href=&quot;https://polaris.apache.org/blog/2026/02/19/apache-polaris-graduates-to-top-level-project/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;polaris.apache.org&lt;/a&gt; &amp;middot; foundation announcement 5 March 2026: &lt;a href=&quot;https://news.apache.org/foundation/entry/the-apache-software-foundation-graduates-two-open-source-projects-from-incubator&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;news.apache.org&lt;/a&gt; &lt;a href=&quot;#fr31&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn32&quot;&gt;Apache Iceberg, &lt;i&gt;REST Catalog OpenAPI specification&lt;/i&gt;, &lt;code&gt;main&lt;/code&gt; branch &amp;mdash; the &lt;code&gt;X-Iceberg-Access-Delegation&lt;/code&gt; parameter (&lt;q&gt;Optional signal to the server that the client supports delegated access&amp;hellip;&lt;/q&gt;, &lt;q&gt;The server may choose to supply access via any or none of the requested mechanisms.&lt;/q&gt;), the &lt;code&gt;StorageCredential&lt;/code&gt; schema (&lt;q&gt;Indicates a storage location prefix where the credential is relevant.&lt;/q&gt;), the &lt;code&gt;/sign&lt;/code&gt; endpoint, and the deprecation of the built-in token endpoint. The specification defines no credential type, no expiry field, and no end-user identity propagation. &lt;a href=&quot;https://raw.githubusercontent.com/apache/iceberg/main/open-api/rest-catalog-open-api.yaml&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;github.com/apache/iceberg&lt;/a&gt; &lt;a href=&quot;#fr32&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn33&quot;&gt;Apache Polaris 1.7.0, &lt;i&gt;Vended credentials&lt;/i&gt;: &lt;q&gt;Polaris calls AWS STS AssumeRole with an inline session policy scoped to the specific table locations and operations (read, list, write) the caller is authorized to perform.&lt;/q&gt; &lt;a href=&quot;https://polaris.apache.org/releases/1.7.0/vended-credentials/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;polaris.apache.org&lt;/a&gt; &lt;a href=&quot;#fr33&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn34&quot;&gt;Apache Polaris 1.7.0, &lt;i&gt;Access control&lt;/i&gt; &amp;mdash; the privilege model, in which &lt;code&gt;TABLE_READ_DATA&lt;/code&gt; &lt;q&gt;Enables reading data from the table by receiving short-lived read-only storage credentials from the catalog&lt;/q&gt;: reading and receiving credentials are the same grant, and the vocabulary bottoms out at the table. &lt;a href=&quot;https://polaris.apache.org/releases/1.7.0/managing-security/access-control/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;polaris.apache.org&lt;/a&gt; &lt;i&gt;&amp;mdash; consulted&lt;/i&gt;&lt;/li&gt;
&lt;li id=&quot;fn35&quot;&gt;Apache Polaris 1.7.0, &lt;i&gt;Configuring AWS S3&lt;/i&gt;: &lt;q&gt;Three distinct IAM identities take part in the S3 credential-vending flow.&lt;/q&gt; and &lt;q&gt;the client uses those credentials to talk to S3 and KMS directly&lt;/q&gt;. &lt;a href=&quot;https://polaris.apache.org/releases/1.7.0/configuration/configuring-polaris-for-production/configuring-aws-s3-cloud-storage-specific/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;polaris.apache.org&lt;/a&gt; &lt;a href=&quot;#fr35&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn36&quot;&gt;Apache Iceberg developer list, fine-grained access control and read restrictions, 2026: &lt;q&gt;we are conflating trust with proof: proof is very hard and very expensive, and arguably unachievable&lt;/q&gt;; &lt;q&gt;Trust contract (out of spec): admin/catalog decides which clients are non-malicious and wired up to enforce.&lt;/q&gt;; &lt;q&gt;identity propagation across multi-tenant query engines is a real problem, but it&apos;s orthogonal to the spec&lt;/q&gt;. On remote signing: &lt;q&gt;one of the concerns of the current remote signing was that it was requested was per file and it can cause server overwhelm for very huge tables&lt;/q&gt;. &lt;a href=&quot;https://lists.apache.org/thread/9qrcgoq0lmwszqhwr6yx7jd55ohwbt9l&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;lists.apache.org&lt;/a&gt; &amp;middot; &lt;a href=&quot;https://lists.apache.org/thread/4fxylxkfj0ngp0ksfysgkhn8s6o9x4n5&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;remote-signing thread&lt;/a&gt; &lt;i&gt;&amp;mdash; official project mailing list; discussion, not ratified specification&lt;/i&gt; &lt;a href=&quot;#fr36&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn37&quot;&gt;Apache Iceberg, pull request 13879 &amp;mdash; read restrictions for the REST specification, open and unmerged: &lt;q&gt;A reader must enforce projections on the columns it is actually reading.&lt;/q&gt; Quoted from the raw diff. Two earlier attempts, issues 10909 and 14187, were closed as not planned. &lt;a href=&quot;https://patch-diff.githubusercontent.com/raw/apache/iceberg/pull/13879.diff&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;patch-diff.githubusercontent.com&lt;/a&gt; &lt;a href=&quot;#fr37&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn38&quot;&gt;Apache Polaris 1.7.0, &lt;i&gt;External identity providers&lt;/i&gt;: &lt;q&gt;Apache Polaris supports authentication via external identity providers (IdPs) using OpenID Connect (OIDC)&lt;/q&gt; &amp;mdash; note this is an implementation choice; the specification defines no SSO or OIDC integration. &lt;a href=&quot;https://polaris.apache.org/releases/1.7.0/managing-security/external-idp/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;polaris.apache.org&lt;/a&gt; &lt;i&gt;&amp;mdash; consulted&lt;/i&gt;&lt;/li&gt;
&lt;li id=&quot;fn39&quot;&gt;IBM, &lt;i&gt;Release notes for watsonx.data&lt;/i&gt;: MDS replaces the Hive Metastore from version 2.1; and at 2.2.1, &lt;q&gt;The Metadata Service (MDS) in watsonx.data now supports issuing vended credentials through the Iceberg and Unity REST APIs.&lt;/q&gt;, framed as &lt;q&gt;without the need to manage long-lived access keys&lt;/q&gt;. &lt;a href=&quot;https://raw.githubusercontent.com/ibm-cloud-docs/watsonxdata/master/release.md&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;IBM documentation source repository&lt;/a&gt; &lt;i&gt;&amp;mdash; ibm.com/docs refuses automated retrieval; this is IBM&apos;s own docs source, repository HEAD dated 26 May 2026&lt;/i&gt; &lt;a href=&quot;#fr39&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn40&quot;&gt;IBM, &lt;i&gt;Unity Catalog REST API and Iceberg REST Catalog API&lt;/i&gt;: &lt;q&gt;Metadata Service implements selected APIs from the Iceberg REST Catalog and Unity Catalog Open API spec.&lt;/q&gt;; &lt;q&gt;X-Iceberg-Access-Delegation is supported for vended-credentials.&lt;/q&gt;; unsupported features include &lt;q&gt;Multi-level namespace creation&lt;/q&gt;; and &lt;q&gt;Presto cannot query views created using the Iceberg REST catalog API due to encoding incompatibility.&lt;/q&gt; &lt;a href=&quot;https://raw.githubusercontent.com/ibm-cloud-docs/watsonxdata/master/iceberg_unity_cat_api.md&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;IBM documentation source repository&lt;/a&gt; &lt;a href=&quot;#fr40&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn41&quot;&gt;IBM, &lt;i&gt;MDS Iceberg REST Catalog and Unity Catalog API&lt;/i&gt; specification &amp;mdash; the &lt;code&gt;temporary-table-credentials&lt;/code&gt; and &lt;code&gt;temporary-path-credentials&lt;/code&gt; endpoints, whose response carries &lt;code&gt;aws_temp_credentials&lt;/code&gt;, &lt;code&gt;azure_user_delegation_sas&lt;/code&gt;, &lt;code&gt;gcp_oauth_token&lt;/code&gt; and &lt;code&gt;expiration_time&lt;/code&gt;. No credential lifetime is documented as an input. &lt;a href=&quot;https://cloud.ibm.com/apidocs/watsonxdata-mds&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;cloud.ibm.com/apidocs&lt;/a&gt; &lt;i&gt;&amp;mdash; consulted&lt;/i&gt;&lt;/li&gt;
&lt;li id=&quot;fn42&quot;&gt;IBM, &lt;i&gt;Integrating Apache Ranger&lt;/i&gt;: &lt;q&gt;You can only integrate with one of the following policy engines starting with watsonx.data version 2.1.&lt;/q&gt; &amp;mdash; Apache Ranger or IBM Knowledge Catalog. The Knowledge Catalog page states its own scope: &lt;q&gt;You can define IKC governance policies for Presto (C++), and Presto (Java) engines.&lt;/q&gt; &lt;a href=&quot;https://raw.githubusercontent.com/ibm-cloud-docs/watsonxdata/master/wxd_ranger.md&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Ranger page&lt;/a&gt; &amp;middot; &lt;a href=&quot;https://raw.githubusercontent.com/ibm-cloud-docs/watsonxdata/master/ikc_integration.md&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Knowledge Catalog page&lt;/a&gt; &lt;i&gt;&amp;mdash; IBM documentation source repository&lt;/i&gt; &lt;a href=&quot;#fr42&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn43&quot;&gt;IBM, Ranger service types: &lt;q&gt;Create resource policies in this Ranger service type to enforce security on catalogs(Iceberg, Hive and Hudi), buckets, schemas and tables used by Presto engine in watsonx.data.&lt;/q&gt;, with the equivalent &lt;code&gt;Hadoop SQL&lt;/code&gt; type for Spark; and for external Spark, &lt;q&gt;add authz.IBMSparkACExtension to spark.sql.extensions&lt;/q&gt; &amp;mdash; a cooperating-client model. &lt;a href=&quot;https://raw.githubusercontent.com/ibm-cloud-docs/watsonxdata/master/wxd_ranger.md&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Ranger service types&lt;/a&gt; &amp;middot; &lt;a href=&quot;https://raw.githubusercontent.com/ibm-cloud-docs/watsonxdata/master/spark-extnsn-extnl.md&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;external Spark extension&lt;/a&gt; &lt;a href=&quot;#fr43&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn44&quot;&gt;IBM, &lt;i&gt;Data security&lt;/i&gt;: &lt;q&gt;Backend object storage repositories for internal metadata and 10 GB limited trial bucket are encrypted by using AES-256. Customer Bring-your-own-key (BYOK) via Key Protect and Keep-your-own-key(KYOK)via Hyper Protect Crypto(HPCS) are supported at provision time&lt;/q&gt; &amp;mdash; quoted verbatim, spacing included. The regional tables list HPCS as unavailable in Frankfurt, London, Tokyo and Sydney. &lt;a href=&quot;https://raw.githubusercontent.com/ibm-cloud-docs/watsonxdata/master/data_security.md&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;IBM documentation source repository&lt;/a&gt; &lt;a href=&quot;#fr44&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn45&quot;&gt;IBM, &lt;i&gt;Registering Amazon S3 storage&lt;/i&gt;: &lt;q&gt;The Role ARN is used to generate temporary credentials with permissions defined by the role&apos;s access policies.&lt;/q&gt; &amp;mdash; the vended credential carries the role&apos;s permissions, not the caller&apos;s. &lt;a href=&quot;https://raw.githubusercontent.com/ibm-cloud-docs/watsonxdata/master/amazons_storage.md&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;IBM documentation source repository&lt;/a&gt; &lt;i&gt;&amp;mdash; consulted&lt;/i&gt;&lt;/li&gt;
&lt;li id=&quot;fn46&quot;&gt;IBM, &lt;i&gt;Hyper Protect Crypto Services FAQ&lt;/i&gt;: &lt;q&gt;In addition to the BYOK capabilities, KYOK provides technical assurance that IBM cannot access the customer keys.&lt;/q&gt; The same page&apos;s comparison table marks technical assurance &lt;b&gt;No&lt;/b&gt; for BYOK and &lt;b&gt;Yes&lt;/b&gt; for KYOK. This statement is about HPCS and does not appear in the watsonx.data documentation. &lt;a href=&quot;https://raw.githubusercontent.com/ibm-cloud-docs/hs-crypto/master/FAQs-general.md&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;IBM documentation source repository&lt;/a&gt; &lt;a href=&quot;#fr46&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn47&quot;&gt;IBM Cloud Global Catalog API, live query, 31 August 2026 &amp;mdash; watsonx BI carries &lt;code&gt;geo_tags [&apos;us-south&apos;]&lt;/code&gt;. &lt;a href=&quot;https://globalcatalog.cloud.ibm.com/api/v1?q=watsonx&amp;amp;limit=200&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;globalcatalog.cloud.ibm.com&lt;/a&gt; &lt;a href=&quot;#fr47&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p class=&quot;cap&quot; style=&quot;margin-top:18px&quot;&gt;&lt;b&gt;Stated limits.&lt;/b&gt; Three things in this article rest on absence rather than statement, and are marked as such in the text: that no primary Iceberg source declares the vending bypass in plain terms; that IBM documents no interaction between credential vending and its policy engines; and that no source settles what a non-Spark engine receives when it reads a policy-protected Snowflake table. IBM findings were retrieved from IBM&apos;s own documentation source repository because &lt;code&gt;ibm.com/docs&lt;/code&gt; refuses automated retrieval; that repository&apos;s HEAD is dated 26 May 2026, so anything IBM published since would not appear here. Corrections are welcome and will be applied with the date attached.&lt;/p&gt;

&lt;div class=&quot;foot&quot;&gt;
&lt;p&gt;&lt;b&gt;David Leconte&lt;/b&gt; is a Customer Success Engineer in the Data &amp;amp; AI team at IBM France, covering Horizon Customers. He writes about lakehouse architecture, retrieval systems and the parts of data engineering that resist being tidied up. Corrections and correspondence: &lt;a href=&quot;https://www.linkedin.com/in/davidleconte&quot; rel=&quot;me noopener&quot; target=&quot;_blank&quot;&gt;linkedin.com/in/davidleconte&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Part two: &lt;a href=&quot;/articles/authoring-is-not-enforcing/&quot;&gt;&lt;i&gt;Authoring Is Not Enforcing&lt;/i&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Disclaimer.&lt;/b&gt; The postings on this site are my own and do not necessarily represent IBM&amp;rsquo;s positions, strategies or opinions. This article reflects the author&amp;rsquo;s own analysis and is not an IBM publication.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Trademarks.&lt;/b&gt; IBM, watsonx and watsonx.data are trademarks or registered trademarks of International Business Machines Corporation. Databricks and Unity Catalog are trademarks or registered trademarks of Databricks, Inc. Snowflake and Snowflake Horizon are trademarks or registered trademarks of Snowflake Inc. Collibra is a trademark or registered trademark of Collibra NV. Apache, Apache Iceberg, Apache Polaris, Apache Ranger and Apache Spark are trademarks or registered trademarks of the Apache Software Foundation. All other marks are the property of their respective owners. Their use here is nominative and descriptive; no affiliation, sponsorship or endorsement is implied.&lt;/p&gt;
&lt;p&gt;&amp;copy; 2026 David Leconte. All rights reserved. Quotations from third-party documentation remain the property of their publishers and are reproduced, in short form and with attribution, for the purposes of analysis, criticism and commentary.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;/&quot;&gt;All articles&lt;/a&gt; &amp;middot; &lt;a href=&quot;/rss.xml&quot;&gt;RSS&lt;/a&gt; &amp;middot; &lt;a href=&quot;/mentions-legales/&quot;&gt;Mentions l&amp;eacute;gales&lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;/div&gt;</content:encoded><author>David Leconte</author></item><item><title>Authoring Is Not Enforcing</title><link>https://blog.datartist.win/articles/authoring-is-not-enforcing/</link><guid isPermaLink="true">https://blog.datartist.win/articles/authoring-is-not-enforcing/</guid><description>Enterprise governance catalogs author policy; platforms enforce it. What Collibra and IBM Knowledge Catalog can and cannot do after the lakehouse catalogs absorbed the primitives, why neither speaks the Iceberg REST protocol, and what the compilation seam costs to operate.</description><pubDate>Mon, 31 Aug 2026 09:00:00 GMT</pubDate><content:encoded>&lt;div class=&quot;wrap&quot;&gt;
&lt;div class=&quot;col&quot;&gt;

&lt;p class=&quot;eyebrow&quot;&gt;Lakehouse architecture &amp;middot; Part two of two&lt;/p&gt;
&lt;h1&gt;Authoring Is Not Enforcing&lt;/h1&gt;
&lt;p class=&quot;dek&quot;&gt;The lakehouse catalogs have absorbed the glossary, the classification, the lineage and the marketplace. So what is an enterprise governance catalog for now &amp;mdash; and why does none of them speak the one protocol the market converged on? Collibra and IBM&apos;s Knowledge Catalog, held to the same test.&lt;/p&gt;
&lt;p class=&quot;byline&quot;&gt;David Leconte &amp;middot; 31 August 2026 &amp;middot; 15 min read&lt;/p&gt;

&lt;div class=&quot;disclosure&quot;&gt;&lt;b&gt;Disclosure, and it matters more here than in part one.&lt;/b&gt; I work at IBM France, as a Customer Success Engineer in the Data &amp;amp; AI team for Horizon Customers. IBM sells a product in the category this article assesses &amp;mdash; watsonx.data intelligence, formerly IBM Knowledge Catalog &amp;mdash; and it competes directly with Collibra, which is the other product assessed. Writing a critical piece about a competitor while employed by a rival would be worthless, so I have done the only thing that makes it worth reading: &lt;b&gt;every test applied to Collibra is applied to IBM&apos;s product in the same section&lt;/b&gt;, and on the criterion that matters most, IBM comes out narrower. Sources are primary and dated 31 August 2026. This is not an IBM publication. The postings on this site are my own and do not necessarily represent IBM&amp;rsquo;s positions, strategies or opinions.&lt;/div&gt;

&lt;p class=&quot;lead&quot;&gt;Part one of this pair, &lt;i&gt;Six Things Called Catalog, One Credential Underneath&lt;/i&gt;, ended at a waist: table truth in the lakehouse has converged on the Iceberg REST catalog, and everything above it &amp;mdash; governance, semantics, distribution &amp;mdash; has not converged on anything at all.&lt;/p&gt;

&lt;p&gt;This article is about the products that live in that unconverged band and have done for a decade. Collibra, Alation, Atlan, Informatica, Microsoft Purview, IBM&apos;s Knowledge Catalog. The category has a positioning problem that nobody in it enjoys discussing, and it comes down to one sentence.&lt;/p&gt;

&lt;p&gt;&lt;b&gt;An enterprise governance catalog is an L4/L5 product with no presence at L2 and no enforcement engine of its own.&lt;/b&gt; Everything else follows from those two facts, including the things it is genuinely good at.&lt;/p&gt;

&lt;h2&gt;What &quot;enforcement&quot; means when you do not own the engine&lt;/h2&gt;

&lt;p&gt;Start with the mechanism, because the marketing word covers two different things.&lt;/p&gt;

&lt;p&gt;Collibra can enforce policy on exactly four platforms, through two separate products, and in every case by &lt;b&gt;pushing policy into the platform&apos;s native engine&lt;/b&gt;. Collibra Protect &lt;q&gt;supports the following data sources: AWS Lake Formation, BigQuery, Databricks, Snowflake&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn1&quot; id=&quot;fr1&quot;&gt;1&lt;/a&gt;&lt;/sup&gt;, and its own documentation describes the mechanism as Edge capabilities &lt;q&gt;translating the representation to actions toward the data source provider using their technology.&lt;/q&gt; On Databricks the output is a native object: &lt;q&gt;Data access standards created in Protect result in column-based policies on Databricks.&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn2&quot; id=&quot;fr2&quot;&gt;2&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;The newer Collibra Data Access &amp;mdash; which appears to be the productised form of the Raito acquisition, though no Collibra document says so&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn13&quot; id=&quot;fr13&quot;&gt;13&lt;/a&gt;&lt;/sup&gt; &amp;mdash; covers BigQuery, Databricks and Snowflake plus Entra ID and Okta, and unlike Protect it reads existing native grants as well as writing them.&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn4&quot; id=&quot;fr4&quot;&gt;4&lt;/a&gt;&lt;/sup&gt; Collibra warns that the two must not overlap: &lt;q&gt;To prevent policy drift and inconsistent security, do not manage the same data sources with Data Access and Protect at the same time.&lt;/q&gt; Note the seam that leaves: Data Access does not cover Lake Formation, so a Lake Formation customer cannot move to the newer product.&lt;/p&gt;

&lt;p&gt;Three documented limitations shape the operating model rather than the feature list, and they are the ones to raise in a design review:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;b&gt;It cannot reconcile with reality.&lt;/b&gt; &lt;q&gt;Protect can&apos;t import or synchronize policies created directly in the data source. Synchronization is one-way: you must define your policies (standards and rules) in Collibra.&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn3&quot; id=&quot;fr3&quot;&gt;3&lt;/a&gt;&lt;/sup&gt; Anything an engineer sets natively is invisible to it.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;It does not revoke access, it removes masks.&lt;/b&gt; &lt;q&gt;Although Protect removes any masking or row filtering, users can still access the data until they manually revoke the access in Databricks or Snowflake.&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn3&quot; id=&quot;fr3b&quot;&gt;3&lt;/a&gt;&lt;/sup&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Effect lags intent.&lt;/b&gt; Synchronisation runs hourly by default. Policy change and policy effect are separated by a window, and nothing in the authoring product tells you when the window closed.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;The same test, applied to IBM&lt;/h2&gt;

&lt;p&gt;Now the part that makes the rest worth reading.&lt;/p&gt;

&lt;p&gt;IBM&apos;s watsonx.data intelligence &amp;mdash; the product formerly and still widely called IBM Knowledge Catalog &amp;mdash; occupies the same slot in the model. Held to the same criterion, &lt;b&gt;its enforcement reach is narrower than Collibra&apos;s, and it is not close.&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;Take the two documented scopes and put them side by side, because that is the only comparison the evidence actually supports. Collibra states its own: &lt;q&gt;Protect supports the following data sources: AWS Lake Formation, BigQuery, Databricks, Snowflake.&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn1&quot; id=&quot;fr1b&quot;&gt;1&lt;/a&gt;&lt;/sup&gt; IBM states its own: &lt;q&gt;You can define IKC governance policies for Presto (C++), and Presto (Java) engines.&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn15&quot; id=&quot;fr15&quot;&gt;15&lt;/a&gt;&lt;/sup&gt; Four platforms on one side; two engines inside one IBM product on the other. &lt;b&gt;Both sentences are the vendor&apos;s own, unhedged, and that is the whole comparison&lt;/b&gt; &amp;mdash; four platforms against two engines.&lt;/p&gt;

&lt;div class=&quot;caution&quot;&gt;&lt;b&gt;What I could not establish, stated before I draw any conclusion from it.&lt;/b&gt; I did not find an IBM statement that Knowledge Catalog pushes policy into Snowflake, Databricks, BigQuery or Lake Formation native engines &amp;mdash; but I also did not find an IBM statement denying it, and the page where such a thing would live, IBM&apos;s data-protection-rules enforcement topic, &lt;b&gt;refused automated retrieval on every attempt, including on the day of publication&lt;/b&gt;. So the honest form of the claim is narrower than the one I would like to make: &lt;b&gt;IBM documents a narrower enforcement scope than Collibra documents.&lt;/b&gt; Whether IBM enforces more than it documents, I do not know, and neither does anyone reading only the documentation.&lt;/div&gt;

&lt;p&gt;The connector asymmetry sharpens it. IBM&apos;s metadata harvest reaches the major non-IBM platforms &amp;mdash; Snowflake, Databricks, BigQuery, Redshift, Teradata, SAP. But the connector list that carries &lt;i&gt;governance&lt;/i&gt; into watsonx.data is eleven sources long and contains none of those four: &lt;q&gt;IBM Knowledge Catalog - watsonx.data integration supports the following connectors for governance:&lt;/q&gt; Hive, Iceberg, Hudi, Delta Lake, Oracle, PostgreSQL, MySQL, SQL Server, Db2, Teradata, MongoDB.&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn15&quot; id=&quot;fr15b&quot;&gt;15&lt;/a&gt;&lt;/sup&gt; &lt;b&gt;Breadth of cataloguing is not breadth of control&lt;/b&gt;, and the gap between the two lists is where that distinction lives.&lt;/p&gt;

&lt;div class=&quot;caution&quot;&gt;&lt;b&gt;And IBM&apos;s own governance product covers fewer of IBM&apos;s own engines than the Apache alternative does.&lt;/b&gt; A watsonx.data instance integrates with &lt;q&gt;only one of the following policy engines&lt;/q&gt; &amp;mdash; Apache Ranger or IBM Knowledge Catalog.&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn16&quot; id=&quot;fr16&quot;&gt;16&lt;/a&gt;&lt;/sup&gt; Ranger&apos;s service types cover Presto &lt;i&gt;and&lt;/i&gt; Spark, including external Spark via an extension. Knowledge Catalog is documented for the two Presto engines only. Choosing IBM&apos;s governance catalog over the open-source policy engine costs you Spark enforcement. That is a real trade and IBM does not, as far as I can find, publish it as a comparison table.&lt;/div&gt;

&lt;div class=&quot;wide scroll&quot;&gt;
&lt;svg class=&quot;diag&quot; viewBox=&quot;0 0 1080 400&quot; xmlns=&quot;http://www.w3.org/2000/svg&quot; role=&quot;img&quot;
  aria-label=&quot;Two side-by-side funnels comparing Collibra and IBM watsonx.data intelligence. Each begins with a wide band of metadata reach across dozens of sources, then narrows sharply to a much smaller enforcement reach: four platforms for Collibra, and two Presto engines inside watsonx.data for IBM. A band beneath states that neither product enforces anything itself; both push policy into, or run inside, an engine owned by someone else.&quot;&gt;
  &lt;text class=&quot;lane&quot; x=&quot;8&quot; y=&quot;18&quot;&gt;Metadata reach against enforcement reach &amp;mdash; both narrow sharply, at different points&lt;/text&gt;

  &lt;text class=&quot;el&quot; x=&quot;8&quot; y=&quot;32&quot;&gt;COLLIBRA&lt;/text&gt;
  &lt;g class=&quot;bx f-amber&quot;&gt;&lt;rect x=&quot;8&quot; y=&quot;40&quot; width=&quot;524&quot; height=&quot;58&quot; rx=&quot;7&quot;/&gt;
    &lt;text class=&quot;t1&quot; x=&quot;24&quot; y=&quot;60&quot;&gt;Metadata reach &amp;mdash; wide&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;24&quot; y=&quot;76&quot;&gt;several dozen certified sources over JDBC and Edge: Snowflake, Databricks,&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;24&quot; y=&quot;90&quot;&gt;BigQuery, Redshift, Teradata, Dremio, Denodo, Presto, Starburst, Trino, SAP HANA&lt;/text&gt;&lt;/g&gt;
  &lt;g stroke=&quot;#8a8880&quot; stroke-width=&quot;1.1&quot; fill=&quot;none&quot; opacity=&quot;.8&quot;&gt;
    &lt;path d=&quot;M60 98 L160 176&quot;/&gt;&lt;path d=&quot;M480 98 L380 176&quot;/&gt;&lt;/g&gt;
  &lt;g class=&quot;bx f-coral&quot;&gt;&lt;rect x=&quot;160&quot; y=&quot;176&quot; width=&quot;220&quot; height=&quot;76&quot; rx=&quot;7&quot; stroke-width=&quot;2&quot;/&gt;
    &lt;text class=&quot;t1&quot; x=&quot;270&quot; y=&quot;196&quot; text-anchor=&quot;middle&quot;&gt;Enforcement reach&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;270&quot; y=&quot;212&quot; text-anchor=&quot;middle&quot;&gt;four platforms:&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;270&quot; y=&quot;226&quot; text-anchor=&quot;middle&quot;&gt;Lake Formation &amp;middot; BigQuery&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;270&quot; y=&quot;240&quot; text-anchor=&quot;middle&quot;&gt;Databricks &amp;middot; Snowflake&lt;/text&gt;&lt;/g&gt;
  &lt;text class=&quot;t2i&quot; x=&quot;24&quot; y=&quot;272&quot; fill=&quot;#8a8880&quot;&gt;Split across two products that Collibra says must not manage the same source.&lt;/text&gt;
  &lt;text class=&quot;t2i&quot; x=&quot;24&quot; y=&quot;288&quot; fill=&quot;#8a8880&quot;&gt;Protect is one-way: it cannot import a policy set natively in the platform.&lt;/text&gt;

  &lt;line x1=&quot;540&quot; y1=&quot;28&quot; x2=&quot;540&quot; y2=&quot;300&quot; stroke=&quot;#c9c6bd&quot; stroke-width=&quot;1&quot;/&gt;

  &lt;text class=&quot;el&quot; x=&quot;548&quot; y=&quot;32&quot;&gt;IBM WATSONX.DATA INTELLIGENCE&lt;/text&gt;
  &lt;g class=&quot;bx f-amber&quot;&gt;&lt;rect x=&quot;548&quot; y=&quot;40&quot; width=&quot;524&quot; height=&quot;58&quot; rx=&quot;7&quot;/&gt;
    &lt;text class=&quot;t1&quot; x=&quot;564&quot; y=&quot;60&quot;&gt;Metadata reach &amp;mdash; also wide&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;564&quot; y=&quot;76&quot;&gt;reaches the major platforms &amp;mdash; Snowflake, Databricks, BigQuery, Redshift,&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;564&quot; y=&quot;90&quot;&gt;Teradata, SAP, Db2 for z/OS &amp;mdash; plus thirty-two lineage configurations&lt;/text&gt;&lt;/g&gt;
  &lt;g stroke=&quot;#8a8880&quot; stroke-width=&quot;1.1&quot; fill=&quot;none&quot; opacity=&quot;.8&quot;&gt;
    &lt;path d=&quot;M600 98 L700 176&quot;/&gt;&lt;path d=&quot;M1020 98 L920 176&quot;/&gt;&lt;/g&gt;
  &lt;g class=&quot;bx f-coral&quot;&gt;&lt;rect x=&quot;700&quot; y=&quot;176&quot; width=&quot;220&quot; height=&quot;76&quot; rx=&quot;7&quot; stroke-width=&quot;2&quot;/&gt;
    &lt;text class=&quot;t1&quot; x=&quot;810&quot; y=&quot;196&quot; text-anchor=&quot;middle&quot;&gt;Enforcement reach&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;810&quot; y=&quot;212&quot; text-anchor=&quot;middle&quot;&gt;two engines:&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;810&quot; y=&quot;226&quot; text-anchor=&quot;middle&quot;&gt;Presto (Java) and Presto (C++)&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;810&quot; y=&quot;240&quot; text-anchor=&quot;middle&quot;&gt;inside watsonx.data&lt;/text&gt;&lt;/g&gt;
  &lt;text class=&quot;t2i&quot; x=&quot;564&quot; y=&quot;272&quot; fill=&quot;#8a8880&quot;&gt;The governance connector list is eleven sources, and contains none of the four&lt;/text&gt;
  &lt;text class=&quot;t2i&quot; x=&quot;564&quot; y=&quot;288&quot; fill=&quot;#8a8880&quot;&gt;cloud warehouses the metadata side reaches.&lt;/text&gt;

  &lt;g class=&quot;bx f-teal&quot;&gt;&lt;rect x=&quot;8&quot; y=&quot;312&quot; width=&quot;1064&quot; height=&quot;72&quot; rx=&quot;8&quot;/&gt;
    &lt;text class=&quot;t1&quot; x=&quot;26&quot; y=&quot;334&quot;&gt;What the two have in common, and it is the point&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;26&quot; y=&quot;352&quot;&gt;Neither enforces anything itself. Collibra compiles policy into a platform&amp;#39;s native engine; IBM&amp;#39;s runs inside IBM&amp;#39;s own query engines. In both cases the&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;26&quot; y=&quot;368&quot;&gt;object that finally stops a query belongs to somebody else, and the governance catalog&amp;#39;s reach ends where its ability to write that object ends.&lt;/text&gt;&lt;/g&gt;
&lt;/svg&gt;
&lt;p class=&quot;cap&quot;&gt;Two vendors, the same shape. The gap between the wide band and the narrow one is where &quot;we govern your data estate&quot; quietly becomes &quot;we catalogue your data estate&quot;.&lt;/p&gt;
&lt;/div&gt;

&lt;p&gt;Two more findings that belong in the same paragraph as the Collibra limitations, for symmetry. IBM documents its own enforcement defects, and they are not cosmetic: &lt;q&gt;Attempt to download protected data assets is allowed&lt;/q&gt;, and &lt;q&gt;Masked data might be profiled when the data source is IBM watsonx.data.&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn17&quot; id=&quot;fr17&quot;&gt;17&lt;/a&gt;&lt;/sup&gt; And IBM&apos;s own API documentation uses the verb the whole category should be using: the Knowledge Catalog APIs let you &lt;q&gt;define data protection rules&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn18&quot; id=&quot;fr18&quot;&gt;18&lt;/a&gt;&lt;/sup&gt;. Define. Not enforce.&lt;/p&gt;

&lt;h2&gt;Nobody in this category speaks the protocol at the waist&lt;/h2&gt;

&lt;p&gt;Here is the structural point, and it applies to both products equally.&lt;/p&gt;

&lt;p&gt;L2 converged on the Iceberg REST catalog. &lt;b&gt;Collibra has no Iceberg REST catalog integration and no Apache Polaris integration.&lt;/b&gt; Across its current product documentation and both 2026 release-note sets, the only appearance of Iceberg is as a value of a Snowflake attribute &amp;mdash; the table type shown as &lt;q&gt;&apos;Dynamic Table,&apos; &apos;Hybrid Table,&apos; &apos;Iceberg Table,&apos; or &apos;Base Table.&apos;&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn5&quot; id=&quot;fr5&quot;&gt;5&lt;/a&gt;&lt;/sup&gt; Collibra can record that a Snowflake table happens to be Iceberg. It cannot talk to an Iceberg catalog.&lt;/p&gt;

&lt;p&gt;Its integration surface is overwhelmingly JDBC metadata harvest&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn6&quot; id=&quot;fr6&quot;&gt;6&lt;/a&gt;&lt;/sup&gt; &amp;mdash; even AWS Lake Formation is reached through Amazon Athena&apos;s JDBC driver rather than a Lake Formation API&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn7&quot; id=&quot;fr7&quot;&gt;7&lt;/a&gt;&lt;/sup&gt; &amp;mdash; with outbound push on exactly two platforms: Unity Catalog, which &lt;q&gt;supports both inbound and outbound (in preview) metadata flows&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn8&quot; id=&quot;fr8&quot;&gt;8&lt;/a&gt;&lt;/sup&gt; and is gated behind a support request, carrying tags only; and Google Knowledge Catalog, where outbound went GA.&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn9&quot; id=&quot;fr9&quot;&gt;9&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;

&lt;p&gt;&lt;b&gt;IBM is in the identical structural position, and sounds as though it is not.&lt;/b&gt; IBM markets deep Iceberg, Unity and Polaris adjacency &amp;mdash; but that capability belongs to the watsonx.data &lt;i&gt;lakehouse query engine&lt;/i&gt;, which is a different product from the governance catalog. The Metadata Service &lt;q&gt;implements selected APIs from the Iceberg REST Catalog and Unity Catalog Open API spec&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn19&quot; id=&quot;fr19&quot;&gt;19&lt;/a&gt;&lt;/sup&gt;, and the federation to Snowflake Open Catalog and Unity Catalog is engine-level, done by Presto and Spark for query purposes.&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn20&quot; id=&quot;fr20&quot;&gt;20&lt;/a&gt;&lt;/sup&gt; The governance layer reaches that estate through a connection configured with a hostname, a port and an engine ID. It sees tables through a connector surface, exactly like Collibra does.&lt;/p&gt;

&lt;div class=&quot;caution&quot;&gt;&lt;b&gt;What this costs in practice.&lt;/b&gt; In an Iceberg-first estate, the governance catalog sees your tables &lt;i&gt;through a platform&lt;/i&gt;, never through the catalog. Register the same Iceberg tables with two engines and you get two unrelated asset sets, because the harvest has no notion of the shared catalog identity underneath. The lakehouse&apos;s central promise &amp;mdash; one table, many engines &amp;mdash; is the thing this ingestion model structurally cannot represent.&lt;/div&gt;

&lt;h2&gt;The Apache Ranger problem&lt;/h2&gt;

&lt;p&gt;For anyone running on-premises, this is the sharpest gap in the category, and it cuts both ways.&lt;/p&gt;

&lt;p&gt;Ranger is the enforcement engine of most Hadoop-descended and Trino-based estates, and of watsonx.data whenever Ranger rather than Knowledge Catalog is elected. &lt;b&gt;There is no Collibra-built Apache Ranger integration.&lt;/b&gt; No Ranger page exists in Collibra&apos;s product documentation. The route that does exist is a third-party partner listing whose own terms state that &lt;q&gt;Your Master Agreement with Collibra for the Collibra Service DOES NOT apply to your use of the Partner Offerings.&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn10&quot; id=&quot;fr10&quot;&gt;10&lt;/a&gt;&lt;/sup&gt; The same partner supplies the Trino and Starburst equivalent. Neither listing shows a version or a supported Collibra release.&lt;/p&gt;

&lt;p&gt;There is a matching lineage asymmetry on both sides, and it is almost comic. Collibra ingests metadata from Trino, Presto and Starburst &amp;mdash; all three are on its certified connector list&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn12&quot; id=&quot;fr12&quot;&gt;12&lt;/a&gt;&lt;/sup&gt; &amp;mdash; but none of the three appears among the seventeen SQL dialects it parses for technical lineage.&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn11&quot; id=&quot;fr11&quot;&gt;11&lt;/a&gt;&lt;/sup&gt; And IBM&apos;s lineage configurations, which run to thirty-two sources including Informatica, SSIS, Talend, SAS and Db2 for z/OS, &lt;b&gt;do not include Trino or Presto either&lt;/b&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn21&quot; id=&quot;fr21&quot;&gt;21&lt;/a&gt;&lt;/sup&gt; &amp;mdash; Presto being the engine IBM&apos;s own lakehouse runs on. That second finding is weaker evidence than the first: it comes from the documentation site&apos;s navigation, corroborated in two separate collections, because the authoritative table refused retrieval. Collibra&apos;s gap is quoted from a dated page; IBM&apos;s is inferred from an index. Two governance catalogs, neither of which parses lineage for the query engine at the centre of the architecture they are governing.&lt;/p&gt;

&lt;p&gt;One counterweight worth recording, because it is the only real bridge in either direction: IBM&apos;s Common Policy Gateway is an extensibility point, and a release note names Collibra as a candidate engine &amp;mdash; &lt;q&gt;a downloadable plugin, enabling seamless integration with any policy engine (for example, IBM Knowledge Catalog, Apache Ranger, Collibra)&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn22&quot; id=&quot;fr22&quot;&gt;22&lt;/a&gt;&lt;/sup&gt;. But the gateway&apos;s own topic page narrows the list to two, and the plugin is something the customer writes. It is a socket, not a shipped integration.&lt;/p&gt;

&lt;h2&gt;The seam&lt;/h2&gt;

&lt;p&gt;Everything above collapses into one operating principle, and it is the sentence I would put on the wall of any team running an enterprise catalog next to a lakehouse.&lt;/p&gt;

&lt;div class=&quot;pull&quot;&gt;&lt;b&gt;Policy is authored once in the governance catalog and &lt;i&gt;compiled&lt;/i&gt; into the platform&apos;s own enforcement engine. It does not travel by itself.&lt;/b&gt; Everything that matters operationally &amp;mdash; drift, latency between intent and effect, what happens when someone edits natively, what happens when the sync fails &amp;mdash; lives in that compilation step, and it appears in neither product&apos;s feature list.&lt;/div&gt;

&lt;div class=&quot;wide scroll&quot;&gt;
&lt;svg class=&quot;diag&quot; viewBox=&quot;0 0 1080 420&quot; xmlns=&quot;http://www.w3.org/2000/svg&quot; role=&quot;img&quot;
  aria-label=&quot;A left-to-right diagram. On the left, the authoring plane of a governance catalog holds policy standards, classifications and glossary terms. In the middle, a compiler box translates them. On the right, the enforcement plane holds native engine objects: Unity Catalog policies, Snowflake masking and row access policies, and Apache Ranger conditions. Below the compiler, four annotated failure points are shown: latency, drift, vocabulary loss and silent failure. A note states that the compiler is a scheduled job, not a protocol, and that nothing in the specification governs this step.&quot;&gt;
  &lt;text class=&quot;lane&quot; x=&quot;8&quot; y=&quot;18&quot;&gt;Authoring plane&lt;/text&gt;
  &lt;text class=&quot;lane&quot; x=&quot;392&quot; y=&quot;18&quot;&gt;The seam&lt;/text&gt;
  &lt;text class=&quot;lane&quot; x=&quot;742&quot; y=&quot;18&quot;&gt;Enforcement plane &amp;mdash; where the query is stopped&lt;/text&gt;

  &lt;g class=&quot;bx f-amber&quot;&gt;&lt;rect x=&quot;8&quot; y=&quot;30&quot; width=&quot;330&quot; height=&quot;150&quot; rx=&quot;8&quot;/&gt;
    &lt;text class=&quot;t1&quot; x=&quot;26&quot; y=&quot;52&quot;&gt;Governance catalog&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;26&quot; y=&quot;70&quot;&gt;policy standards and rules&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;26&quot; y=&quot;86&quot;&gt;data classes and classifications&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;26&quot; y=&quot;102&quot;&gt;business glossary terms&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;26&quot; y=&quot;118&quot;&gt;stewardship, ownership, certification&lt;/text&gt;
    &lt;text class=&quot;t2i&quot; x=&quot;26&quot; y=&quot;142&quot;&gt;expresses intent, in its own vocabulary&lt;/text&gt;
    &lt;text class=&quot;t2i&quot; x=&quot;26&quot; y=&quot;158&quot;&gt;enforces nothing anywhere&lt;/text&gt;&lt;/g&gt;

  &lt;path d=&quot;M340 100 H 382&quot; stroke=&quot;#8a8880&quot; stroke-width=&quot;2&quot; fill=&quot;none&quot; marker-end=&quot;url(#s1)&quot;/&gt;
  &lt;defs&gt;&lt;marker id=&quot;s1&quot; markerWidth=&quot;9&quot; markerHeight=&quot;9&quot; refX=&quot;8&quot; refY=&quot;4.5&quot; orient=&quot;auto&quot;&gt;&lt;path d=&quot;M0,1 L8.5,4.5 L0,8 z&quot; fill=&quot;#8a8880&quot;/&gt;&lt;/marker&gt;
    &lt;marker id=&quot;s2&quot; markerWidth=&quot;9&quot; markerHeight=&quot;9&quot; refX=&quot;8&quot; refY=&quot;4.5&quot; orient=&quot;auto&quot;&gt;&lt;path d=&quot;M0,1 L8.5,4.5 L0,8 z&quot; fill=&quot;#0f6e56&quot;/&gt;&lt;/marker&gt;&lt;/defs&gt;

  &lt;g class=&quot;bx f-coral&quot;&gt;&lt;rect x=&quot;386&quot; y=&quot;30&quot; width=&quot;286&quot; height=&quot;150&quot; rx=&quot;8&quot; stroke-width=&quot;2.4&quot;/&gt;
    &lt;text class=&quot;t1&quot; x=&quot;404&quot; y=&quot;52&quot;&gt;The compiler&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;404&quot; y=&quot;70&quot;&gt;a scheduled job, or an agent, that&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;404&quot; y=&quot;86&quot;&gt;translates intent into the target&apos;s&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;404&quot; y=&quot;102&quot;&gt;own policy objects&lt;/text&gt;
    &lt;text class=&quot;t2i&quot; x=&quot;404&quot; y=&quot;126&quot;&gt;no specification governs this step&lt;/text&gt;
    &lt;text class=&quot;t2i&quot; x=&quot;404&quot; y=&quot;142&quot;&gt;no standard defines its vocabulary&lt;/text&gt;
    &lt;text class=&quot;t2i&quot; x=&quot;404&quot; y=&quot;158&quot;&gt;it is bespoke per platform, by construction&lt;/text&gt;&lt;/g&gt;

  &lt;path d=&quot;M674 100 H 716&quot; stroke=&quot;#0f6e56&quot; stroke-width=&quot;2&quot; fill=&quot;none&quot; marker-end=&quot;url(#s2)&quot;/&gt;

  &lt;g class=&quot;bx f-teal&quot;&gt;&lt;rect x=&quot;720&quot; y=&quot;30&quot; width=&quot;352&quot; height=&quot;150&quot; rx=&quot;8&quot;/&gt;
    &lt;text class=&quot;t1&quot; x=&quot;738&quot; y=&quot;52&quot;&gt;Native engine objects&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;738&quot; y=&quot;70&quot;&gt;Unity Catalog column-based policies&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;738&quot; y=&quot;86&quot;&gt;Snowflake masking and row-access policies&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;738&quot; y=&quot;102&quot;&gt;Apache Ranger conditions&lt;/text&gt;
    &lt;text class=&quot;t2i&quot; x=&quot;738&quot; y=&quot;126&quot;&gt;the only place a query is actually stopped&lt;/text&gt;
    &lt;text class=&quot;t2i&quot; x=&quot;738&quot; y=&quot;142&quot;&gt;and the only vocabulary that is authoritative&lt;/text&gt;
    &lt;text class=&quot;t2i&quot; x=&quot;738&quot; y=&quot;158&quot;&gt;once compilation has happened&lt;/text&gt;&lt;/g&gt;

  &lt;text class=&quot;t1&quot; x=&quot;8&quot; y=&quot;212&quot; fill=&quot;#993c1d&quot;&gt;Four things that go wrong here, and none of them raises an alarm in the authoring product&lt;/text&gt;

  &lt;g class=&quot;bx f-gray&quot;&gt;&lt;rect x=&quot;8&quot; y=&quot;222&quot; width=&quot;258&quot; height=&quot;98&quot; rx=&quot;7&quot;/&gt;
    &lt;text class=&quot;t1&quot; x=&quot;24&quot; y=&quot;244&quot;&gt;1 &amp;middot; Latency&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;24&quot; y=&quot;262&quot;&gt;Synchronisation runs on a schedule&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;24&quot; y=&quot;278&quot;&gt;&amp;mdash; hourly by default in Collibra Protect.&lt;/text&gt;
    &lt;text class=&quot;t2i&quot; x=&quot;24&quot; y=&quot;300&quot;&gt;Intent and effect are separated by a&lt;/text&gt;
    &lt;text class=&quot;t2i&quot; x=&quot;24&quot; y=&quot;314&quot;&gt;window nobody is watching.&lt;/text&gt;&lt;/g&gt;

  &lt;g class=&quot;bx f-gray&quot;&gt;&lt;rect x=&quot;278&quot; y=&quot;222&quot; width=&quot;258&quot; height=&quot;98&quot; rx=&quot;7&quot;/&gt;
    &lt;text class=&quot;t1&quot; x=&quot;294&quot; y=&quot;244&quot;&gt;2 &amp;middot; Drift&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;294&quot; y=&quot;262&quot;&gt;One-way compilation cannot see what&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;294&quot; y=&quot;278&quot;&gt;an engineer changed natively.&lt;/text&gt;
    &lt;text class=&quot;t2i&quot; x=&quot;294&quot; y=&quot;300&quot;&gt;The catalog keeps reporting the policy&lt;/text&gt;
    &lt;text class=&quot;t2i&quot; x=&quot;294&quot; y=&quot;314&quot;&gt;it authored, not the one in force.&lt;/text&gt;&lt;/g&gt;

  &lt;g class=&quot;bx f-gray&quot;&gt;&lt;rect x=&quot;548&quot; y=&quot;222&quot; width=&quot;258&quot; height=&quot;98&quot; rx=&quot;7&quot;/&gt;
    &lt;text class=&quot;t1&quot; x=&quot;564&quot; y=&quot;244&quot;&gt;3 &amp;middot; Vocabulary loss&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;564&quot; y=&quot;262&quot;&gt;Whatever the target cannot express is&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;564&quot; y=&quot;278&quot;&gt;dropped or approximated in translation.&lt;/text&gt;
    &lt;text class=&quot;t2i&quot; x=&quot;564&quot; y=&quot;300&quot;&gt;Two platforms, two policy models,&lt;/text&gt;
    &lt;text class=&quot;t2i&quot; x=&quot;564&quot; y=&quot;314&quot;&gt;two different residues.&lt;/text&gt;&lt;/g&gt;

  &lt;g class=&quot;bx f-gray&quot;&gt;&lt;rect x=&quot;818&quot; y=&quot;222&quot; width=&quot;254&quot; height=&quot;98&quot; rx=&quot;7&quot;/&gt;
    &lt;text class=&quot;t1&quot; x=&quot;834&quot; y=&quot;244&quot;&gt;4 &amp;middot; Silent failure&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;834&quot; y=&quot;262&quot;&gt;If the compiler stops, the last-compiled&lt;/text&gt;
    &lt;text class=&quot;t2&quot; x=&quot;834&quot; y=&quot;278&quot;&gt;policy stays in force and looks correct.&lt;/text&gt;
    &lt;text class=&quot;t2i&quot; x=&quot;834&quot; y=&quot;300&quot;&gt;Nothing degrades. Nothing errors.&lt;/text&gt;
    &lt;text class=&quot;t2i&quot; x=&quot;834&quot; y=&quot;314&quot;&gt;The estate simply stops updating.&lt;/text&gt;&lt;/g&gt;

  &lt;rect x=&quot;8&quot; y=&quot;338&quot; width=&quot;1064&quot; height=&quot;58&quot; rx=&quot;7&quot; fill=&quot;none&quot; stroke=&quot;#185fa5&quot; stroke-width=&quot;1.6&quot; stroke-dasharray=&quot;6 4&quot;/&gt;
  &lt;text class=&quot;t1&quot; x=&quot;26&quot; y=&quot;358&quot; fill=&quot;#185fa5&quot;&gt;The question to put to any design in this shape&lt;/text&gt;
  &lt;text class=&quot;t2&quot; x=&quot;26&quot; y=&quot;373&quot; fill=&quot;#0c447c&quot;&gt;Where is policy authored, where is it enforced, what compiles the first into the second, how often &amp;mdash; and how do you find out when it stops?&lt;/text&gt;
  &lt;text class=&quot;t2&quot; x=&quot;26&quot; y=&quot;388&quot; fill=&quot;#0c447c&quot;&gt;A design that cannot answer the last one has not been designed, it has been assembled.&lt;/text&gt;
&lt;/svg&gt;
&lt;/div&gt;

&lt;p&gt;Read the four boxes again and notice what they have in common: &lt;b&gt;none of them is a feature gap&lt;/b&gt;. They are properties of the arrangement. You would get all four from a perfectly implemented product on both ends, because the arrangement puts a translation step between the place where intent is expressed and the place where it binds.&lt;/p&gt;

&lt;p&gt;Which is why the useful questions in a vendor evaluation are not about the catalog&apos;s feature matrix at all. They are: what is the compilation interval, is it one-way or reconciling, what does the target refuse to express, and what monitors the compiler.&lt;/p&gt;

&lt;h2&gt;The overlap, and why the positioning changed&lt;/h2&gt;

&lt;p&gt;Five years ago the division of labour was clean. Metastores were dumb; the enterprise catalog held the glossary, the classifications, the lineage, the quality scores and the stewardship workflow. That division no longer holds on any of the three platforms.&lt;/p&gt;

&lt;div class=&quot;wide scroll&quot;&gt;
&lt;table&gt;
&lt;thead&gt;&lt;tr&gt;&lt;th style=&quot;width:17%&quot;&gt;Capability&lt;/th&gt;&lt;th style=&quot;width:21%&quot;&gt;Unity Catalog&lt;/th&gt;&lt;th style=&quot;width:21%&quot;&gt;Snowflake Horizon&lt;/th&gt;&lt;th style=&quot;width:20%&quot;&gt;IBM estate&lt;/th&gt;&lt;th style=&quot;width:21%&quot;&gt;Still differentiated above?&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;&lt;b&gt;Business glossary&lt;/b&gt;&lt;/td&gt;&lt;td&gt;Pages, Beta &amp;mdash; governed definitions of business concepts&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn23&quot; id=&quot;fr23&quot;&gt;23&lt;/a&gt;&lt;/sup&gt;&lt;/td&gt;&lt;td&gt;Semantic Views and Horizon context&lt;/td&gt;&lt;td&gt;Knowledge Catalog glossary&lt;/td&gt;&lt;td&gt;&lt;b&gt;Only across estates.&lt;/b&gt; Within one platform, no.&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;b&gt;Classification&lt;/b&gt;&lt;/td&gt;&lt;td&gt;Native, agent-driven, GA&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn24&quot; id=&quot;fr24&quot;&gt;24&lt;/a&gt;&lt;/sup&gt;&lt;/td&gt;&lt;td&gt;&lt;q&gt;Automatically discover and classify columns&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn25&quot; id=&quot;fr25&quot;&gt;25&lt;/a&gt;&lt;/sup&gt;&lt;/td&gt;&lt;td&gt;Native classes and profiling&lt;/td&gt;&lt;td&gt;No.&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;b&gt;Lineage&lt;/b&gt;&lt;/td&gt;&lt;td&gt;Computed natively; Collibra reads it from system tables rather than parsing&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn11&quot; id=&quot;fr11b&quot;&gt;11&lt;/a&gt;&lt;/sup&gt;&lt;/td&gt;&lt;td&gt;Column-level, plus OpenLineage feeds&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn25&quot; id=&quot;fr25b&quot;&gt;25&lt;/a&gt;&lt;/sup&gt;&lt;/td&gt;&lt;td&gt;Dedicated lineage engine &amp;mdash; but not for Presto&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn21&quot; id=&quot;fr21b&quot;&gt;21&lt;/a&gt;&lt;/sup&gt;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Only for the seams&lt;/b&gt; &amp;mdash; dbt, BI tools, cross-platform hops.&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;b&gt;Data quality&lt;/b&gt;&lt;/td&gt;&lt;td&gt;Expectations and monitors&lt;/td&gt;&lt;td&gt;Native&lt;/td&gt;&lt;td&gt;Native rules and scoring&lt;/td&gt;&lt;td&gt;Contested.&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;b&gt;Marketplace&lt;/b&gt;&lt;/td&gt;&lt;td&gt;Databricks Marketplace&lt;/td&gt;&lt;td&gt;&lt;q&gt;Internal Marketplace: Discover and share governed data products across teams without copying data.&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn25&quot; id=&quot;fr25c&quot;&gt;25&lt;/a&gt;&lt;/sup&gt;&lt;/td&gt;&lt;td&gt;Data Product Hub&lt;/td&gt;&lt;td&gt;&lt;b&gt;Only across estates.&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;b&gt;Enforcement&lt;/b&gt;&lt;/td&gt;&lt;td&gt;Native, in the query path&lt;/td&gt;&lt;td&gt;Native, in the query path&lt;/td&gt;&lt;td&gt;Ranger or Knowledge Catalog, in the query path&lt;/td&gt;&lt;td&gt;&lt;b&gt;Never&lt;/b&gt; &amp;mdash; the category delegates by construction.&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;

&lt;p&gt;Collibra&apos;s own positioning concedes the shift, and the verb is the tell. Announcing its Databricks partner award in June 2026, the company wrote that Unity Catalog &lt;q&gt;gives Databricks customers a powerful governance foundation for data and AI assets across the Lakehouse&lt;/q&gt; and that &lt;q&gt;Collibra complements that foundation, enriching Unity Catalog with the broader enterprise context layer.&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn14&quot; id=&quot;fr14&quot;&gt;14&lt;/a&gt;&lt;/sup&gt; Complements. Enriches. Not governs.&lt;/p&gt;

&lt;p&gt;IBM does the same thing in its own documentation, and more revealingly, because it is technical prose rather than a press release. IBM describes &lt;q&gt;Snowflake Open Catalog is a unified governance solution for Apache Iceberg tables in Snowflake&lt;/q&gt; and Unity Catalog as &lt;q&gt;a unified governance solution for data and AI assets in Databricks&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn20&quot; id=&quot;fr20b&quot;&gt;20&lt;/a&gt;&lt;/sup&gt; &amp;mdash; in the course of documenting how to federate to them. IBM is calling its competitors&apos; catalogs governance solutions while positioning its own governance catalog above the same estate.&lt;/p&gt;

&lt;p&gt;This is not a decline story. It is a change of job. But it is worth naming, because a great many architecture diagrams still show the enterprise catalog sitting on top as though it were the control plane, and it is not one.&lt;/p&gt;

&lt;h2&gt;What the layer is genuinely for&lt;/h2&gt;

&lt;p&gt;Four things survive the encroachment, and they are the four to buy for:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Federation across estates nobody owns.&lt;/b&gt; A bank with Snowflake in one division, Databricks in another, Teradata and a mainframe underneath, and an on-premises lakehouse for the regulated core has no native catalog that spans them. Collibra&apos;s certified connector list runs to several dozen sources including Dremio, Denodo, Starburst, SAP HANA and Netezza&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn12&quot; id=&quot;fr12b&quot;&gt;12&lt;/a&gt;&lt;/sup&gt;; IBM&apos;s lineage configurations reach Informatica PowerCenter, SSIS, Talend, SAS and Db2 for z/OS.&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn21&quot; id=&quot;fr21c&quot;&gt;21&lt;/a&gt;&lt;/sup&gt; No platform catalog offers that breadth, and it is not close to being replicated.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Stewardship as a workflow, not a field.&lt;/b&gt; Ownership, approval chains, certification, deprecation &amp;mdash; the human process that keeps a definition true. Native catalogs give you an owner attribute; they do not give you the process behind it.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Regulatory assessment and AI inventory.&lt;/b&gt; Collibra&apos;s AI Command Center, which replaced its previous AI Governance product in May 2026, is a registry with risk assessments, sign-offs and a trust score&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn26&quot; id=&quot;fr26&quot;&gt;26&lt;/a&gt;&lt;/sup&gt;. Governance-as-documentation rather than runtime control &amp;mdash; which is exactly what an EU AI Act file needs and exactly what a query engine cannot produce.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;A metadata interface for agents.&lt;/b&gt; The Collibra MCP server is documented and its OAuth support reached GA in June 2026: an assistant can &lt;q&gt;discover data assets, explore lineage, search the Business Glossary&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn27&quot; id=&quot;fr27&quot;&gt;27&lt;/a&gt;&lt;/sup&gt;. Being the cross-platform context an agent queries is a defensible position, whatever one thinks of the category.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;One deployment caveat that decides sovereign designs&lt;/h2&gt;

&lt;p&gt;Collibra is not SaaS-only: Collibra Platform Self-Hosted is actively developed, and air-gapped installation is documented, with FIPS mode mandatory in that mode.&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn28&quot; id=&quot;fr28&quot;&gt;28&lt;/a&gt;&lt;/sup&gt; But the self-hosted product is materially reduced, and the published Edge capability list for it covers ingestion, profiling, classification, sampling, synchronisation and the data-quality connector &amp;mdash; &lt;b&gt;with neither Protect nor Data Access on it&lt;/b&gt;.&lt;/p&gt;

&lt;p&gt;I want to be careful. I could not find a page stating in words that policy enforcement is unavailable on self-hosted Collibra; the capability list omits it, which is strong but indirect. &lt;b&gt;Treat &quot;air-gapped Collibra cannot push policy&quot; as a well-supported inference to verify with the vendor, not as a documented fact.&lt;/b&gt; If it holds, it decides any sovereign design: you get the authoring plane and you do not get the compilation step.&lt;/p&gt;

&lt;p&gt;For data-residency reviews, one more: technical lineage on the SaaS path is processed by Collibra-operated regional cloud services &amp;mdash; &lt;q&gt;Collibra Data Lineage service instances are cloud-hosted endpoints that process and store technical lineage metadata.&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn29&quot; id=&quot;fr29&quot;&gt;29&lt;/a&gt;&lt;/sup&gt; Metadata leaves the network, not data. A self-hosted air-gapped lineage package exists, so this is a SaaS-path constraint rather than an absolute one.&lt;/p&gt;

&lt;h2&gt;The standard that does not exist&lt;/h2&gt;

&lt;p&gt;Which brings the two articles together.&lt;/p&gt;

&lt;p&gt;At the waist, the market has a contract. An engine written against the Iceberg REST specification reads tables owned by any of the three platforms, and that convergence happened in about two years. Above the waist there is nothing of the kind. &lt;b&gt;There is no interchange standard for policy.&lt;/b&gt; OpenLineage covers lineage. The Open Data Contract Standard covers data products. Apache Ossie &amp;mdash; the Open Semantic Interchange, renamed on entering the Apache Incubator in July 2026&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn30&quot; id=&quot;fr30&quot;&gt;30&lt;/a&gt;&lt;/sup&gt; &amp;mdash; is attempting semantics. Nothing covers a masking rule.&lt;/p&gt;

&lt;p&gt;That absence is the whole explanation for this article. It is why enforcement is a per-platform push-down rather than a protocol. It is why the compilation step is bespoke, unmonitored and invisible to both ends. It is why Collibra reaches four platforms and IBM reaches its own Presto engines, rather than both reaching everything that speaks a common contract. And it is why the category&apos;s honest self-description has shifted from &lt;i&gt;governs&lt;/i&gt; to &lt;i&gt;complements&lt;/i&gt;.&lt;/p&gt;

&lt;p&gt;The Iceberg project has looked at putting fine-grained access control into the REST specification twice, and closed both attempts as not planned. The current proposal puts the enforcement obligation on the client &amp;mdash; &lt;q&gt;a reader must enforce projections on the columns it is actually reading&lt;/q&gt;&lt;sup class=&quot;fn&quot;&gt;&lt;a href=&quot;#fn31&quot; id=&quot;fr31&quot;&gt;31&lt;/a&gt;&lt;/sup&gt; &amp;mdash; and the reasoning on the project&apos;s own list is that proof is unaffordable, so trust will have to do. That is a coherent position. It also means the layer above the waist is not going to converge by protocol any time soon.&lt;/p&gt;

&lt;p&gt;And here the two halves of this pair meet, which is the thing I did not see until both were written. Part one ended on a credential: to let an engine read the bytes, the catalog hands out a storage token scoped to a path prefix and carrying nobody&apos;s identity, at which point a column mask and a row filter become not merely unenforced but &lt;i&gt;unevaluable&lt;/i&gt;. This article ends on an absence: above the waist there is no interchange contract for policy at all. &lt;b&gt;They are the same fact seen from two ends.&lt;/b&gt; Below the waist, openness was bought by handing out a credential that fine-grained policy cannot survive. Above it, no standard emerged to carry that policy across perimeters &amp;mdash; because the layer that would have had to transport it is precisely the layer the open protocol declined to model. The lakehouse got one contract, and it got it at the exact altitude where governance stops being expressible.&lt;/p&gt;

&lt;div class=&quot;pull&quot;&gt;&lt;b&gt;So the practical answer to &quot;do we still need an enterprise governance catalog?&quot; is: yes, and for narrower reasons than the category advertises.&lt;/b&gt; Not because it governs the lakehouse &amp;mdash; it does not, and the platform does. Because it is the only thing that spans estates nobody owns, holds the human process around a definition, and produces the documentation a regulator asks for. Buy it for federation, stewardship and evidence. Do not buy it as a control plane, and do not draw it as one.&lt;/div&gt;

&lt;p&gt;And whichever product you pick, the question that decides whether the design works is the same one, and neither vendor&apos;s feature matrix answers it: &lt;b&gt;what compiles authored intent into enforced policy, how often, and how do you find out when it stops?&lt;/b&gt;&lt;/p&gt;

&lt;hr class=&quot;sep&quot;&gt;

&lt;h2 id=&quot;notes&quot;&gt;Notes&lt;/h2&gt;
&lt;p class=&quot;cap&quot; style=&quot;margin-bottom:14px&quot;&gt;Every source below was retrieved on &lt;b&gt;31 August 2026&lt;/b&gt;. Press releases and product marketing pages are marked as such and cited only for positioning, never for feature status. Where IBM&apos;s published documentation site refused automated retrieval, IBM&apos;s own documentation source repository was used and the provenance is flagged; where a finding rests on a page&apos;s navigation rather than its body text, that is flagged too.&lt;/p&gt;

&lt;ol class=&quot;notes&quot;&gt;
&lt;li id=&quot;fn1&quot;&gt;Collibra, &lt;i&gt;About Collibra Protect&lt;/i&gt;: &lt;q&gt;Protect supports the following data sources: AWS Lake Formation, BigQuery, Databricks, Snowflake.&lt;/q&gt;; and on mechanism, Edge capabilities &lt;q&gt;translating the representation to actions toward the data source provider using their technology.&lt;/q&gt; Dated 30 June 2026. &lt;a href=&quot;https://productresources.collibra.com/docs/collibra/latest/Content/Protect/to_collibra-protect.htm&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;productresources.collibra.com&lt;/a&gt; &lt;a href=&quot;#fr1&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn2&quot;&gt;Collibra, &lt;i&gt;Databricks policies in Protect&lt;/i&gt;: &lt;q&gt;Data access standards created in Protect result in column-based policies on Databricks. Column-based policies are applied directly to the columns on Databricks.&lt;/q&gt; Dated 4 May 2026. &lt;a href=&quot;https://productresources.collibra.com/docs/collibra/latest/Content/Protect/co_databricks-policies.htm&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;productresources.collibra.com&lt;/a&gt; &lt;a href=&quot;#fr2&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn3&quot;&gt;Collibra, &lt;i&gt;Protect FAQ&lt;/i&gt;: &lt;q&gt;Protect can&apos;t import or synchronize policies created directly in the data source. Synchronization is one-way&lt;/q&gt;; &lt;q&gt;Although Protect removes any masking or row filtering, users can still access the data until they manually revoke the access in Databricks or Snowflake.&lt;/q&gt;; hourly synchronisation by default. Dated 26 June 2026. &lt;a href=&quot;https://productresources.collibra.com/docs/collibra/latest/Content/Protect/ref_protect-faq.htm&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;productresources.collibra.com&lt;/a&gt; &lt;a href=&quot;#fr3&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn4&quot;&gt;Collibra, &lt;i&gt;Data Access&lt;/i&gt;: &lt;q&gt;These access controls are automatically enforced in your underlying data sources&lt;/q&gt;; supported sources &lt;q&gt;BigQuery, Databricks, Snowflake&lt;/q&gt; plus Entra ID and Okta; &lt;q&gt;Both inbound and outbound&lt;/q&gt;; and &lt;q&gt;To prevent policy drift and inconsistent security, do not manage the same data sources with Data Access and Protect at the same time.&lt;/q&gt; Dated 11 August 2026. &lt;a href=&quot;https://productresources.collibra.com/docs/collibra/latest/Content/DataAccess/co_data-access.htm&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;productresources.collibra.com&lt;/a&gt; &lt;a href=&quot;#fr4&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn5&quot;&gt;Collibra, &lt;i&gt;Release notes 2026.05 and 2026.06&lt;/i&gt; &amp;mdash; the Snowflake table-type attribute (&lt;q&gt;&apos;Dynamic Table,&apos; &apos;Hybrid Table,&apos; &apos;Iceberg Table,&apos; or &apos;Base Table.&apos;&lt;/q&gt;), Semantic Views ingestion reaching GA, and the Unity Catalog outbound gate: &lt;q&gt;This feature is in public preview and not enabled by default. Contact Collibra Support to activate it for your instance.&lt;/q&gt; &lt;a href=&quot;https://productresources.collibra.com/docs/collibra/latest/Content/ReleaseNotes/Archive/ref_release-202606.htm&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;2026.06&lt;/a&gt; &amp;middot; &lt;a href=&quot;https://productresources.collibra.com/docs/collibra/latest/Content/ReleaseNotes/Archive/ref_release-202605.htm&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;2026.05&lt;/a&gt; &lt;a href=&quot;#fr5&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn6&quot;&gt;Collibra, &lt;i&gt;Register and integrate data sources&lt;/i&gt; &amp;mdash; the canonical integration list. Dated 16 July 2026. &lt;a href=&quot;https://productresources.collibra.com/docs/collibra/latest/Content/Catalog/to_register-integrate.htm&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;productresources.collibra.com&lt;/a&gt; &lt;a href=&quot;#fr6&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn7&quot;&gt;Collibra, &lt;i&gt;Install Protect&lt;/i&gt;: &lt;q&gt;Ingest data from AWS Lake Formation: Download the JDBC driver for Amazon Athena.&lt;/q&gt; &lt;a href=&quot;https://productresources.collibra.com/docs/collibra/latest/Content/Protect/ta_install-protect.htm&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;productresources.collibra.com&lt;/a&gt; &lt;a href=&quot;#fr7&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn8&quot;&gt;Collibra, &lt;i&gt;Databricks Unity Catalog integration methods&lt;/i&gt;: &lt;q&gt;The integration supports both inbound and outbound (in preview) metadata flows to keep your catalog in sync with Databricks Unity Catalog.&lt;/q&gt; Dated 21 August 2026. &lt;a href=&quot;https://productresources.collibra.com/docs/collibra/latest/Content/Catalog/Databricks/co_databricks-methods.htm&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;productresources.collibra.com&lt;/a&gt; &lt;a href=&quot;#fr8&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn9&quot;&gt;Collibra, &lt;i&gt;Google Knowledge Catalog ingestion&lt;/i&gt;: &lt;q&gt;It supports both inbound and outbound metadata flows&lt;/q&gt;; and the scope limit, &lt;q&gt;The Knowledge Catalog integration ingests metadata only; it does not create technical lineage.&lt;/q&gt; Dated 12 August 2026. &lt;a href=&quot;https://productresources.collibra.com/docs/collibra/latest/Content/Catalog/GCS/Dataplex/co_about-dataplex-catalog-ingestion.htm&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;productresources.collibra.com&lt;/a&gt; &lt;a href=&quot;#fr9&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn10&quot;&gt;Collibra Marketplace, &lt;i&gt;Lorang &amp;mdash; Data access control for Apache Ranger&lt;/i&gt;, a third-party Partner Offering: &lt;q&gt;Partners create, own and are responsible for their Partner Offerings&amp;hellip; Your Master Agreement with Collibra for the Collibra Service DOES NOT apply to your use of the Partner Offerings.&lt;/q&gt; The same partner lists a Trino/Starburst equivalent. Neither shows a version or supported Collibra release. &lt;a href=&quot;https://marketplace.collibra.com/listings/lorang-data-access-control-apache-ranger/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;marketplace.collibra.com&lt;/a&gt; &lt;a href=&quot;#fr10&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn11&quot;&gt;Collibra, &lt;i&gt;Technical lineage &amp;mdash; supported data sources&lt;/i&gt;. Seventeen JDBC SQL dialects listed; Trino, Presto and Starburst appear on none of the lineage tables. Databricks lineage is read from &lt;q&gt;the lineage system tables&lt;/q&gt; rather than parsed. Also records that &lt;q&gt;The CLI lineage harvester reached its end of life on July 31, 2026.&lt;/q&gt; Dated 29 July 2026. &lt;a href=&quot;https://productresources.collibra.com/docs/collibra/latest/Content/CollibraDataLineage/TechnicalLineage/ref_technical-lineage-supported-data-sources.htm&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;productresources.collibra.com&lt;/a&gt; &lt;a href=&quot;#fr11&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn12&quot;&gt;Collibra, &lt;i&gt;Supported data sources for Edge&lt;/i&gt; &amp;mdash; the certified connector list, including Presto, Starburst, Trino, Dremio, Denodo, SAP HANA and Netezza alongside the cloud warehouses. &lt;a href=&quot;https://productresources.collibra.com/docs/catalog-connectors/Content/Resources/Snippets/CatalogSnippets/CatalogConnectors/_all-data-sources/selector/ref_supported-data-sources-edge.htm&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;productresources.collibra.com&lt;/a&gt; &lt;a href=&quot;#fr12&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn13&quot;&gt;Collibra, press release, &lt;i&gt;Acquisition of Raito&lt;/i&gt;, 5 June 2025. Attributing Collibra Data Access to this acquisition is an inference from timing and scope match; no Collibra documentation names Raito as its origin. &lt;a href=&quot;https://www.collibra.com/company/newsroom/press-releases/collibra-announces-acquisition-of-raito-and-advancements-in-unified-governance-for-data-and-ai&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;collibra.com&lt;/a&gt; &lt;i&gt;&amp;mdash; vendor press release&lt;/i&gt; &lt;a href=&quot;#fr13&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn14&quot;&gt;Collibra, press release, &lt;i&gt;Collibra named Databricks Governance Partner of the Year&lt;/i&gt;, 16 June 2026: &lt;q&gt;Collibra complements that foundation, enriching Unity Catalog with the broader enterprise context layer.&lt;/q&gt; &lt;a href=&quot;https://www.collibra.com/company/newsroom/press-releases/collibra-named-databricks-governance-partner-of-the-year&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;collibra.com&lt;/a&gt; &lt;i&gt;&amp;mdash; vendor press release, cited for positioning&lt;/i&gt; &lt;a href=&quot;#fr14&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn15&quot;&gt;IBM, &lt;i&gt;Integrating IBM Knowledge Catalog with watsonx.data&lt;/i&gt;: &lt;q&gt;You can define IKC governance policies for Presto (C++), and Presto (Java) engines.&lt;/q&gt; and &lt;q&gt;IBM Knowledge Catalog - watsonx.data integration supports the following connectors for governance:&lt;/q&gt; followed by Hive, Iceberg, Hudi, Delta Lake, Oracle, PostgreSQL, MySQL, SQL Server, Db2, Teradata, MongoDB. &lt;a href=&quot;https://raw.githubusercontent.com/ibm-cloud-docs/watsonxdata/master/ikc_integration.md&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;IBM documentation source repository&lt;/a&gt; &lt;i&gt;&amp;mdash; ibm.com/docs refuses automated retrieval; repository HEAD dated 26 May 2026&lt;/i&gt; &lt;a href=&quot;#fr15&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn16&quot;&gt;IBM, &lt;i&gt;Integrating Apache Ranger&lt;/i&gt;: &lt;q&gt;You can only integrate with one of the following policy engines starting with watsonx.data version 2.1.&lt;/q&gt;; Ranger service types cover &lt;q&gt;tables used by Presto engine in watsonx.data&lt;/q&gt; and, via &lt;code&gt;Hadoop SQL&lt;/code&gt;, the Spark engine. &lt;a href=&quot;https://raw.githubusercontent.com/ibm-cloud-docs/watsonxdata/master/wxd_ranger.md&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;IBM documentation source repository&lt;/a&gt; &lt;a href=&quot;#fr16&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn17&quot;&gt;IBM, &lt;i&gt;Known issues and limitations&lt;/i&gt; for IBM Knowledge Catalog and watsonx.data intelligence: &lt;q&gt;Attempt to download protected data assets is allowed&lt;/q&gt;; &lt;q&gt;Masked data might be profiled when the data source is IBM watsonx.data&lt;/q&gt;. The page opens &lt;q&gt;The following known issues and limitations apply to IBM Knowledge Catalog and to watsonx.data intelligence.&lt;/q&gt; &lt;a href=&quot;https://www.ibm.com/docs/SSNFH6_5.4.x/wsj/catalog/known-issues-wkcop.html&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;ibm.com/docs&lt;/a&gt; &lt;i&gt;&amp;mdash; re-retrieved and both quotations re-confirmed verbatim on 31 August 2026&lt;/i&gt; &lt;a href=&quot;#fr17&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn18&quot;&gt;IBM, &lt;i&gt;IBM Knowledge Catalog as a Service API&lt;/i&gt;: &lt;q&gt;You can use the IBM Knowledge Catalog as a Service APIs to establish business vocabulary, import and enrich data assets, analyze data quality, define data protection rules, and more.&lt;/q&gt; &lt;a href=&quot;https://cloud.ibm.com/apidocs/knowledge-catalog&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;cloud.ibm.com/apidocs&lt;/a&gt; &lt;a href=&quot;#fr18&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn19&quot;&gt;IBM, &lt;i&gt;Unity Catalog REST API and Iceberg REST Catalog API&lt;/i&gt;: &lt;q&gt;Metadata Service implements selected APIs from the Iceberg REST Catalog and Unity Catalog Open API spec.&lt;/q&gt; &lt;a href=&quot;https://raw.githubusercontent.com/ibm-cloud-docs/watsonxdata/master/iceberg_unity_cat_api.md&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;IBM documentation source repository&lt;/a&gt; &lt;a href=&quot;#fr19&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn20&quot;&gt;IBM, federation pages: &lt;q&gt;Snowflake Open Catalog is a unified governance solution for Apache Iceberg tables in Snowflake.&lt;/q&gt; and &lt;q&gt;Databricks Unity Catalog is a unified governance solution for data and AI assets in Databricks.&lt;/q&gt; &amp;mdash; with federation performed by the Presto and Spark engines through the Iceberg REST Catalog API. &lt;a href=&quot;https://raw.githubusercontent.com/ibm-cloud-docs/watsonxdata/master/data_stream_snowflake1.md&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Snowflake page&lt;/a&gt; &amp;middot; &lt;a href=&quot;https://raw.githubusercontent.com/ibm-cloud-docs/watsonxdata/master/data_stream_databricks1.md&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Databricks page&lt;/a&gt; &lt;i&gt;&amp;mdash; IBM documentation source repository&lt;/i&gt; &lt;a href=&quot;#fr20&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn21&quot;&gt;IBM, watsonx.data intelligence lineage configurations &amp;mdash; thirty-two source-specific entries including Snowflake, Teradata, Informatica PowerCenter, SSIS, Talend, SAS, four BI tools, OpenLineage and Db2 for z/OS; Databricks appears only as &quot;Microsoft Azure Databricks&quot;; Trino and Presto appear on none of them. &lt;a href=&quot;https://www.ibm.com/docs/en/watsonx/wdi/saas&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;ibm.com/docs&lt;/a&gt; &lt;i&gt;&amp;mdash; this finding comes from the documentation site&apos;s navigation, corroborated independently in a second collection; the authoritative table page refused retrieval, so it is weaker evidence than the quoted material elsewhere in these notes&lt;/i&gt; &lt;a href=&quot;#fr21&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn22&quot;&gt;IBM, &lt;i&gt;Release notes for watsonx.data&lt;/i&gt;: &lt;q&gt;A new lightweight CPG is now available as a downloadable plugin, enabling seamless integration with any policy engine (for example, IBM Knowledge Catalog, Apache Ranger, Collibra).&lt;/q&gt; The Common Policy Gateway topic page narrows the named list to two engines and the plugin is customer-written. &lt;a href=&quot;https://raw.githubusercontent.com/ibm-cloud-docs/watsonxdata/master/release.md&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;IBM documentation source repository&lt;/a&gt; &amp;middot; &lt;a href=&quot;https://raw.githubusercontent.com/ibm-cloud-docs/watsonxdata/master/cpg_plugin.md&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;gateway plugin page&lt;/a&gt; &lt;a href=&quot;#fr22&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn23&quot;&gt;Databricks, &lt;i&gt;Pages&lt;/i&gt;: &lt;q&gt;A Page is a governed, authoritative definition of a business concept&lt;/q&gt; &amp;mdash; Beta. &lt;a href=&quot;https://docs.databricks.com/aws/en/uc-semantics/pages&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;docs.databricks.com&lt;/a&gt; &lt;a href=&quot;#fr23&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn24&quot;&gt;Databricks, &lt;i&gt;Data classification&lt;/i&gt;: &lt;q&gt;Databricks Data Classification uses an agent to automatically classify and tag tables in your catalog.&lt;/q&gt; &lt;a href=&quot;https://docs.databricks.com/aws/en/data-governance/unity-catalog/data-classification&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;docs.databricks.com&lt;/a&gt; &lt;a href=&quot;#fr24&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn25&quot;&gt;Snowflake, &lt;i&gt;Horizon Catalog&lt;/i&gt;: &lt;q&gt;Automatically discover and classify columns.&lt;/q&gt;; &lt;q&gt;Column-level lineage across Snowflake, external databases, BI tools, and OpenLineage feeds.&lt;/q&gt;; &lt;q&gt;Internal Marketplace: Discover and share governed data products across teams without copying data.&lt;/q&gt; &lt;a href=&quot;https://docs.snowflake.com/en/user-guide/snowflake-horizon&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;docs.snowflake.com&lt;/a&gt; &lt;a href=&quot;#fr25&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn26&quot;&gt;Collibra, &lt;i&gt;AI Command Center&lt;/i&gt;: &lt;q&gt;AI Command Center helps you to monitor and manage your AI landscape from a centralized dashboard.&lt;/q&gt;; it &lt;q&gt;replaces the fragmented product pages of AI Governance&lt;/q&gt;. Dated 3 August 2026. &lt;a href=&quot;https://productresources.collibra.com/docs/collibra/latest/Content/AICommandCenter/co_aicc-about.htm&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;productresources.collibra.com&lt;/a&gt; &lt;a href=&quot;#fr26&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn27&quot;&gt;Collibra, &lt;i&gt;Model Context Protocol&lt;/i&gt;: &lt;q&gt;The Collibra MCP server connects your AI assistant to governed metadata and business context in Collibra. Through it, an assistant can discover data assets, explore lineage, search the Business Glossary.&lt;/q&gt; Dated 26 June 2026; OAuth support GA per release notes 2026.06. &lt;a href=&quot;https://productresources.collibra.com/docs/collibra/latest/Content/ModelContextProtocol/co_mcp.htm&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;productresources.collibra.com&lt;/a&gt; &lt;a href=&quot;#fr27&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn28&quot;&gt;Collibra Platform Self-Hosted, &lt;i&gt;Extend Edge capabilities&lt;/i&gt;: &lt;q&gt;The Zarf package method is only supported if you have an Air-gapped Collibra Platform and environment.&lt;/q&gt;; &lt;q&gt;For Air-gapped environments, FIPS mode is mandatory&lt;/q&gt;. This page carries the Edge capability list on which neither Protect nor Data Access appears &amp;mdash; the basis for the inference stated in the text. &lt;a href=&quot;https://productresources.collibra.com/docs/cpsh/latest/Content/Installation/CPSH/ta_cpsh-edge-extend-cap.htm&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;productresources.collibra.com&lt;/a&gt; &amp;middot; &lt;a href=&quot;https://productresources.collibra.com/docs/cpsh/latest/Content/Installation/CPSH/co_cpsh-getting-started.htm&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;self-hosted overview&lt;/a&gt; &lt;a href=&quot;#fr28&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn29&quot;&gt;Collibra, &lt;i&gt;Data Lineage service instances&lt;/i&gt;: &lt;q&gt;Collibra Data Lineage service instances are cloud-hosted endpoints that process and store technical lineage metadata.&lt;/q&gt; Eleven regional endpoints. Dated 1 April 2026. &lt;a href=&quot;https://productresources.collibra.com/docs/collibra/latest/Content/CollibraDataLineage/TechnicalLineage/InstallationAndConfiguration/LineageHarvestingApp/co_collibra-data-lineage-servers.htm&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;productresources.collibra.com&lt;/a&gt; &lt;a href=&quot;#fr29&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn30&quot;&gt;Snowflake, 8 July 2026: &lt;q&gt;The project has been accepted into the Apache Incubator under a new name: Apache Ossie (Incubating)&lt;/q&gt; &amp;mdash; the Open Semantic Interchange rename. &lt;a href=&quot;https://www.snowflake.com/en/blog/apache-ossie-open-semantic-interchange-incubator/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;snowflake.com&lt;/a&gt; &lt;a href=&quot;#fr30&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;li id=&quot;fn31&quot;&gt;Apache Iceberg, pull request 13879 &amp;mdash; read restrictions for the REST specification, open and unmerged: &lt;q&gt;A reader must enforce projections on the columns it is actually reading.&lt;/q&gt; Two earlier attempts, issues 10909 and 14187, were closed as not planned. &lt;a href=&quot;https://patch-diff.githubusercontent.com/raw/apache/iceberg/pull/13879.diff&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;patch-diff.githubusercontent.com&lt;/a&gt; &lt;a href=&quot;#fr31&quot; class=&quot;bk&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p class=&quot;cap&quot; style=&quot;margin-top:18px&quot;&gt;&lt;b&gt;Stated limits.&lt;/b&gt; Three claims rest on absence rather than statement and are marked as inferences in the text: that policy enforcement is unavailable on self-hosted Collibra; that neither Collibra nor IBM&apos;s governance catalog has an Iceberg REST or Apache Polaris integration; and that IBM does not push policy into non-IBM native engines. Each rests on a full read of the reachable product documentation, but absence cannot prove a page does not exist. Separately, a Snowflake&amp;ndash;Collibra bi-directional integration was announced in June 2026 with no corresponding documentation or release-note entry, so it should be read as &lt;b&gt;announced, not shipped&lt;/b&gt;. IBM&apos;s published documentation site refuses automated retrieval, so IBM findings come from its own documentation source repository, whose HEAD is dated 26 May 2026. Corrections are welcome and will be applied with the date attached.&lt;/p&gt;

&lt;div class=&quot;foot&quot;&gt;
&lt;p&gt;&lt;b&gt;David Leconte&lt;/b&gt; is a Customer Success Engineer in the Data &amp;amp; AI team at IBM France, covering Horizon Customers. He writes about lakehouse architecture, retrieval systems and the parts of data engineering that resist being tidied up. Corrections and correspondence: &lt;a href=&quot;https://www.linkedin.com/in/davidleconte&quot; rel=&quot;me noopener&quot; target=&quot;_blank&quot;&gt;linkedin.com/in/davidleconte&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Part one: &lt;a href=&quot;/articles/six-things-called-catalog/&quot;&gt;&lt;i&gt;Six Things Called Catalog, One Credential Underneath&lt;/i&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Disclaimer.&lt;/b&gt; The postings on this site are my own and do not necessarily represent IBM&amp;rsquo;s positions, strategies or opinions. This article reflects the author&amp;rsquo;s own analysis and is not an IBM publication.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Trademarks.&lt;/b&gt; IBM, watsonx and watsonx.data are trademarks or registered trademarks of International Business Machines Corporation. Databricks and Unity Catalog are trademarks or registered trademarks of Databricks, Inc. Snowflake and Snowflake Horizon are trademarks or registered trademarks of Snowflake Inc. Collibra is a trademark or registered trademark of Collibra NV. Apache, Apache Iceberg, Apache Polaris, Apache Ranger and Apache Spark are trademarks or registered trademarks of the Apache Software Foundation. All other marks are the property of their respective owners. Their use here is nominative and descriptive; no affiliation, sponsorship or endorsement is implied.&lt;/p&gt;
&lt;p&gt;&amp;copy; 2026 David Leconte. All rights reserved. Quotations from third-party documentation remain the property of their publishers and are reproduced, in short form and with attribution, for the purposes of analysis, criticism and commentary.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;/&quot;&gt;All articles&lt;/a&gt; &amp;middot; &lt;a href=&quot;/rss.xml&quot;&gt;RSS&lt;/a&gt; &amp;middot; &lt;a href=&quot;/mentions-legales/&quot;&gt;Mentions l&amp;eacute;gales&lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;

&lt;/div&gt;
&lt;/div&gt;</content:encoded><author>David Leconte</author></item></channel></rss>