Templates
Three bundled Databricks App templates — Governed Analytics Copilot, Lakebase Stateful RAG Agent, and Data Engineering Agent — with least-privilege grants and mock testing.
Fabric Agents bundles three Databricks workload templates. Each scaffolds a complete Fabric Harness project with a databricks.yml asset bundle, agent definitions, skills, a least-privilege GRANTS.md checklist, and an .env.example that references environment variables only — no secrets are ever written to disk.
| Template | Workload | Mock mode | Runtime |
|---|---|---|---|
governed-analytics-copilot | Genie-first analytics with approval gates | ✅ Yes (no credentials needed) | Databricks App |
lakebase-rag-agent | Vector Search RAG with Lakebase memory | ❌ Live-only | Temporal worker + Databricks App |
data-engineering-agent | Lakeflow pipelines, SQL diagnostics, cost reporting | ❌ Live-only | Temporal worker + Databricks App |
Scaffold any of them with:
fabric-cli databricks init --template <template-name>Governed Analytics Copilot (lead demo)
The Governed Analytics Copilot scaffolds a Genie-first analyst agent with sensitive-catalog approval gates, SQL fallback, cost attribution, and least-privilege role guidance.
One-command scaffold
fabric-cli databricks init --template governed-analytics-copilotThis creates a project with:
databricks.yml— Databricks App bundle (env-var references only)fabric.config.ts— Harness config targetingdatabricks-app.fabricharness/agents/analyst.ts— Governed analyst agent.fabricharness/skills/governed-analytics/SKILL.md— Skill instructions.fabricharness/roles/governed-analyst.md— Role guidanceGRANTS.md— Least-privilege grant checklisttest/analyst.test.ts— Mock test suite
Mock happy path (no credentials)
fabric-cli databricks run --mock --question "What tables are in main?"Validates agent structure, tool registration (sql, tables, table-info), and mock responses without touching a live workspace.
Preview deploy (no side effects)
fabric-cli databricks deploy --target databricks-app --preview --mockPrints the deployment plan using mock data. Safe to run in CI or during code review.
Live gate
Set the live gate to enable real workspace calls:
export FABRIC_DATABRICKS_TEST=1Then run live commands with credentials:
export DATABRICKS_HOST="https://adb-1234567890.0.cloud.databricks.com"
export DATABRICKS_TOKEN="dapi..."
export DATABRICKS_CATALOG="main"
export DATABRICKS_SCHEMA="default"
export DATABRICKS_MODEL_ENDPOINT="databricks-gpt-oss-120b"
export FABRIC_COST_CENTER="analytics"
export SENSITIVE_CATALOGS="pii,sensitive,restricted"
export CATALOG_DENYLIST="system,information_schema"
fabric-cli databricks run --question "What tables are in main?"
fabric-cli databricks deploy --target databricks-appSensitive-catalog approval flow
The copilot gates access to sensitive catalogs via a human-in-the-loop approval step:
- The agent receives a question referencing a sensitive catalog (e.g.,
pii). - It checks the
SENSITIVE_CATALOGSenvironment variable. - If matched, the agent pauses and requests explicit approval in the chat UI.
- The reviewer approves or denies; the action is fully audit-logged.
Lakebase Stateful RAG Agent
The Lakebase Stateful RAG Agent combines Lakebase (managed Postgres) conversation memory, Vector Search for RAG retrieval, and Mosaic AI Model Serving for responses. It runs on a Temporal worker for durable, replayable sessions and is ideal for knowledge-base Q&A over governed Unity Catalog assets.
Note: This template is live-only — it has no mock mode. It requires a real workspace with a Vector Search index and (optionally) a Lakebase instance.
One-command scaffold
fabric-cli databricks init --template lakebase-rag-agentThis creates a project with:
databricks.yml— bundle manifest with Vector Search and Lakebase referencesfabric.config.ts— Harness config targetingdatabricks-app.fabricharness/agents/support-agent.ts— RAG agent with durable memory.fabricharness/skills/rag/SKILL.md— Skill instructions (retrieval, citations, MLflow tracing).fabricharness/roles/rag-engineer.md— Role guidanceGRANTS.md— Least-privilege grant checklist
Live configuration
The agent authenticates with a service principal (M2M OAuth) and requires the Vector Search index details:
export FABRIC_DATABRICKS_TEST=1
export DATABRICKS_HOST="https://adb-1234567890.0.cloud.databricks.com"
export DATABRICKS_CLIENT_ID="<service-principal-id>"
export DATABRICKS_CLIENT_SECRET="<service-principal-secret>"
export DATABRICKS_VS_INDEX="main.default.support_tickets_index"
export DATABRICKS_VS_TEXT_COLUMN="chunk"
export DATABRICKS_VS_ID_COLUMN="id"
# Optional: Lakebase durable memory
export LAKEBASE_HOST="<lakebase-host>"
export LAKEBASE_USER="<lakebase-user>"
fabric-cli databricks run --question "Find docs about OAuth setup"
fabric-cli databricks deploy --target databricks-appRequired grants (RAG-specific)
-- Vector Search: SELECT on the backing Delta table + warehouse access
GRANT SELECT ON TABLE main.default.support_tickets TO `fabric-agent-sp`;
GRANT USE ON WAREHOUSE `sql-warehouse-id` TO `fabric-agent-sp`;
-- Lakebase memory table (the only place MODIFY is granted)
GRANT SELECT, MODIFY ON TABLE lakebase.memory TO `fabric-agent-sp`;
-- Model serving endpoint
GRANT CAN QUERY ON MODEL SERVING ENDPOINT `databricks-gpt-oss-120b` TO `fabric-agent-sp`;Data Engineering Agent
The Data Engineering Agent inspects Unity Catalog tables, runs safe SQL diagnostics, starts and monitors Lakeflow pipelines, triggers Jobs, and reports DBU/cost impact through System Tables. Pipeline start/stop actions route through a data-steward approval gate. It runs on a Temporal worker.
Note: This template is live-only — it has no mock mode. It requires a real workspace with a SQL warehouse.
One-command scaffold
fabric-cli databricks init --template data-engineering-agentThis creates a project with:
databricks.yml— bundle manifest with catalog, pipeline, and job referencesfabric.config.ts— Harness config targetingdatabricks-app.fabricharness/agents/dataeng-agent.ts— Data engineering agent.fabricharness/skills/data-engineering/SKILL.md— Skill instructions.fabricharness/roles/data-engineer.md— Role guidanceGRANTS.md— Least-privilege grant checklist
Live configuration
export FABRIC_DATABRICKS_TEST=1
export DATABRICKS_HOST="https://adb-1234567890.0.cloud.databricks.com"
export DATABRICKS_CLIENT_ID="<service-principal-id>"
export DATABRICKS_CLIENT_SECRET="<service-principal-secret>"
export DATABRICKS_WAREHOUSE_ID="sql-warehouse-id"
export FABRIC_COST_CENTER="data-engineering"
fabric-cli databricks run --question "Show pipeline status for bronze-ingest"
fabric-cli databricks deploy --target databricks-appRequired grants (data engineering-specific)
-- Catalog read access
GRANT USE CATALOG ON CATALOG main TO `fabric-agent-sp`;
GRANT USE SCHEMA ON SCHEMA main.default TO `fabric-agent-sp`;
GRANT SELECT ON SCHEMA main.default TO `fabric-agent-sp`;
-- SQL warehouse
GRANT CAN USE ON SQL WAREHOUSE `sql-warehouse-id` TO `fabric-agent-sp`;
-- Pipeline and job monitoring (workspace-level)
-- CAN VIEW on jobs and pipelines is set in the workspace UI
-- System Tables for cost reporting (read-only)
GRANT SELECT ON TABLE system.billing.usage TO `fabric-agent-sp`;Related
- Harness bridge — the commands behind
init,run,build, anddeploy - Discovery & health — how scaffolds get pre-filled with workspace metadata
- Troubleshooting — common errors and fixes
Discovery & health
Discover catalogs, schemas, tables, warehouses, clusters, and jobs from chat, and validate your Databricks source with live health tests.
Harness bridge
Scaffold, mock-run, build, and deploy Databricks projects with fabric-cli databricks — a secure bridge to the Fabric Harness CLI (fh).