How I Built Agent-Based Security Reviews on Databricks
Databricks, Thursday, September 24th, 2026
A Databricks security engineer built an agent-based layer that automates routine security reviews while escalating high-risk cases to humans.
A Databricks team member describes building an agent-based review layer on Databricks to extend existing security review automation that had plateaued.
The system uses Unity Catalog to govern security standards, request data, evidence, and decisions, Databricks-hosted foundation models for classification and reasoning, and Lakeflow Jobs to orchestrate notebook-based workflows on serverless compute.
The goal was not to replace reviewers but to help the system understand requests, apply standards, ask for missing information, and recognize when a person needs to step in, freeing expert time for novel or high-risk architectures. The first version has since expanded to more of the review process.