FabricFabric
Databricks

Templates

Three bundled Databricks App templates — Governed Analytics Copilot, Lakebase Stateful RAG Agent, and Data Engineering Agent — with least-privilege grants and mock testing.

Fabric Agents bundles three Databricks workload templates. Each scaffolds a complete Fabric Harness project with a databricks.yml asset bundle, agent definitions, skills, a least-privilege GRANTS.md checklist, and an .env.example that references environment variables only — no secrets are ever written to disk.

TemplateWorkloadMock modeRuntime
governed-analytics-copilotGenie-first analytics with approval gates✅ Yes (no credentials needed)Databricks App
lakebase-rag-agentVector Search RAG with Lakebase memory❌ Live-onlyTemporal worker + Databricks App
data-engineering-agentLakeflow pipelines, SQL diagnostics, cost reporting❌ Live-onlyTemporal worker + Databricks App

Scaffold any of them with:

fabric-cli databricks init --template <template-name>

Governed Analytics Copilot (lead demo)

The Governed Analytics Copilot scaffolds a Genie-first analyst agent with sensitive-catalog approval gates, SQL fallback, cost attribution, and least-privilege role guidance.

One-command scaffold

fabric-cli databricks init --template governed-analytics-copilot

This creates a project with:

  • databricks.yml — Databricks App bundle (env-var references only)
  • fabric.config.ts — Harness config targeting databricks-app
  • .fabricharness/agents/analyst.ts — Governed analyst agent
  • .fabricharness/skills/governed-analytics/SKILL.md — Skill instructions
  • .fabricharness/roles/governed-analyst.md — Role guidance
  • GRANTS.md — Least-privilege grant checklist
  • test/analyst.test.ts — Mock test suite

Mock happy path (no credentials)

fabric-cli databricks run --mock --question "What tables are in main?"

Validates agent structure, tool registration (sql, tables, table-info), and mock responses without touching a live workspace.

Preview deploy (no side effects)

fabric-cli databricks deploy --target databricks-app --preview --mock

Prints the deployment plan using mock data. Safe to run in CI or during code review.

Live gate

Set the live gate to enable real workspace calls:

export FABRIC_DATABRICKS_TEST=1

Then run live commands with credentials:

export DATABRICKS_HOST="https://adb-1234567890.0.cloud.databricks.com"
export DATABRICKS_TOKEN="dapi..."
export DATABRICKS_CATALOG="main"
export DATABRICKS_SCHEMA="default"
export DATABRICKS_MODEL_ENDPOINT="databricks-gpt-oss-120b"
export FABRIC_COST_CENTER="analytics"
export SENSITIVE_CATALOGS="pii,sensitive,restricted"
export CATALOG_DENYLIST="system,information_schema"

fabric-cli databricks run --question "What tables are in main?"
fabric-cli databricks deploy --target databricks-app

Sensitive-catalog approval flow

The copilot gates access to sensitive catalogs via a human-in-the-loop approval step:

  1. The agent receives a question referencing a sensitive catalog (e.g., pii).
  2. It checks the SENSITIVE_CATALOGS environment variable.
  3. If matched, the agent pauses and requests explicit approval in the chat UI.
  4. The reviewer approves or denies; the action is fully audit-logged.

Lakebase Stateful RAG Agent

The Lakebase Stateful RAG Agent combines Lakebase (managed Postgres) conversation memory, Vector Search for RAG retrieval, and Mosaic AI Model Serving for responses. It runs on a Temporal worker for durable, replayable sessions and is ideal for knowledge-base Q&A over governed Unity Catalog assets.

Note: This template is live-only — it has no mock mode. It requires a real workspace with a Vector Search index and (optionally) a Lakebase instance.

One-command scaffold

fabric-cli databricks init --template lakebase-rag-agent

This creates a project with:

  • databricks.yml — bundle manifest with Vector Search and Lakebase references
  • fabric.config.ts — Harness config targeting databricks-app
  • .fabricharness/agents/support-agent.ts — RAG agent with durable memory
  • .fabricharness/skills/rag/SKILL.md — Skill instructions (retrieval, citations, MLflow tracing)
  • .fabricharness/roles/rag-engineer.md — Role guidance
  • GRANTS.md — Least-privilege grant checklist

Live configuration

The agent authenticates with a service principal (M2M OAuth) and requires the Vector Search index details:

export FABRIC_DATABRICKS_TEST=1
export DATABRICKS_HOST="https://adb-1234567890.0.cloud.databricks.com"
export DATABRICKS_CLIENT_ID="<service-principal-id>"
export DATABRICKS_CLIENT_SECRET="<service-principal-secret>"
export DATABRICKS_VS_INDEX="main.default.support_tickets_index"
export DATABRICKS_VS_TEXT_COLUMN="chunk"
export DATABRICKS_VS_ID_COLUMN="id"
# Optional: Lakebase durable memory
export LAKEBASE_HOST="<lakebase-host>"
export LAKEBASE_USER="<lakebase-user>"

fabric-cli databricks run --question "Find docs about OAuth setup"
fabric-cli databricks deploy --target databricks-app

Required grants (RAG-specific)

-- Vector Search: SELECT on the backing Delta table + warehouse access
GRANT SELECT ON TABLE main.default.support_tickets TO `fabric-agent-sp`;
GRANT USE ON WAREHOUSE `sql-warehouse-id` TO `fabric-agent-sp`;

-- Lakebase memory table (the only place MODIFY is granted)
GRANT SELECT, MODIFY ON TABLE lakebase.memory TO `fabric-agent-sp`;

-- Model serving endpoint
GRANT CAN QUERY ON MODEL SERVING ENDPOINT `databricks-gpt-oss-120b` TO `fabric-agent-sp`;

Data Engineering Agent

The Data Engineering Agent inspects Unity Catalog tables, runs safe SQL diagnostics, starts and monitors Lakeflow pipelines, triggers Jobs, and reports DBU/cost impact through System Tables. Pipeline start/stop actions route through a data-steward approval gate. It runs on a Temporal worker.

Note: This template is live-only — it has no mock mode. It requires a real workspace with a SQL warehouse.

One-command scaffold

fabric-cli databricks init --template data-engineering-agent

This creates a project with:

  • databricks.yml — bundle manifest with catalog, pipeline, and job references
  • fabric.config.ts — Harness config targeting databricks-app
  • .fabricharness/agents/dataeng-agent.ts — Data engineering agent
  • .fabricharness/skills/data-engineering/SKILL.md — Skill instructions
  • .fabricharness/roles/data-engineer.md — Role guidance
  • GRANTS.md — Least-privilege grant checklist

Live configuration

export FABRIC_DATABRICKS_TEST=1
export DATABRICKS_HOST="https://adb-1234567890.0.cloud.databricks.com"
export DATABRICKS_CLIENT_ID="<service-principal-id>"
export DATABRICKS_CLIENT_SECRET="<service-principal-secret>"
export DATABRICKS_WAREHOUSE_ID="sql-warehouse-id"
export FABRIC_COST_CENTER="data-engineering"

fabric-cli databricks run --question "Show pipeline status for bronze-ingest"
fabric-cli databricks deploy --target databricks-app

Required grants (data engineering-specific)

-- Catalog read access
GRANT USE CATALOG ON CATALOG main TO `fabric-agent-sp`;
GRANT USE SCHEMA  ON SCHEMA  main.default TO `fabric-agent-sp`;
GRANT SELECT      ON SCHEMA  main.default TO `fabric-agent-sp`;

-- SQL warehouse
GRANT CAN USE ON SQL WAREHOUSE `sql-warehouse-id` TO `fabric-agent-sp`;

-- Pipeline and job monitoring (workspace-level)
-- CAN VIEW on jobs and pipelines is set in the workspace UI

-- System Tables for cost reporting (read-only)
GRANT SELECT ON TABLE system.billing.usage TO `fabric-agent-sp`;

On this page