A data analyst needs to share a dashboard with stakeholders who do not have access to the underlying Databricks workspace. Which feature should the analyst use to enable this access?
Trap 1: Export the dashboard as a PDF and email it directly.
Exporting to PDF is a manual process that lacks real-time data updates. Stakeholders would need a new file every time the underlying data changes. This approach is prone to errors, versioning issues, and does not provide the interactive capabilities required for modern data-driven decision-making within a controlled Databricks framework.
Trap 2: Provide credentials to a service account.
Sharing credentials violates fundamental security principles and Databricks compliance policies. Each user should access resources through their own identity, typically managed via SSO or SCIM. Using shared service accounts obscures audit logs, makes accountability impossible, and introduces significant risks regarding unauthorized data access or accidental modification of production assets.
Trap 3: Grant full workspace access to the stakeholders.
Granting full workspace access is a severe security risk and violates the principle of least privilege. Stakeholders only require dashboard viewing capabilities, not the ability to edit notebooks, create clusters, or access underlying storage files. Workspace access should be restricted to users who actively develop or perform complex administrative data tasks.
- A
Export the dashboard as a PDF and email it directly.
Why it fails: Exporting to PDF is a manual process that lacks real-time data updates. Stakeholders would need a new file every time the underlying data changes. This approach is prone to errors, versioning issues, and does not provide the interactive capabilities required for modern data-driven decision-making within a controlled Databricks framework.
- B
Provide credentials to a service account.
Why it fails: Sharing credentials violates fundamental security principles and Databricks compliance policies. Each user should access resources through their own identity, typically managed via SSO or SCIM. Using shared service accounts obscures audit logs, makes accountability impossible, and introduces significant risks regarding unauthorized data access or accidental modification of production assets.
- C
Configure the dashboard for 'Share with public' or specific external guest access.
Databricks provides specific sharing configurations for dashboards that allow external access. This feature leverages the platform's authentication and authorization framework to ensure that only designated recipients can view the dashboard. It centralizes control, allows for permission management, and ensures that the data presentation remains secure while meeting the needs of external stakeholders.
- D
Grant full workspace access to the stakeholders.
Why it fails: Granting full workspace access is a severe security risk and violates the principle of least privilege. Stakeholders only require dashboard viewing capabilities, not the ability to edit notebooks, create clusters, or access underlying storage files. Workspace access should be restricted to users who actively develop or perform complex administrative data tasks.