TechFabricTechFabricHarness
Databricks

Databricks certification

Public certification status, tested capabilities, evidence scope, and limitations for TechFabric Harness on Databricks.

TechFabric Harness tests its Databricks integration in protected workspaces before making live-support claims. Certification binds the tested package, source commit, generated Databricks App, workspace profile, and redacted evidence into one retained record. A passing record applies only to that exact scope; it is not a blanket claim for every cloud, region, preview, or workspace configuration.

Certification record

  • Current npm package: @fabric-harness/databricks@7.1.1
  • Exact live-certified package: @fabric-harness/databricks@7.1.1
  • Certification date: September 4, 2026
  • Workspace profile: Azure Databricks, eastus2, OAuth machine-to-machine
  • Consumption checks: 21 of 21 required Tier R checks passed
  • Additional checks: 7 configured Tier O checks passed; 2 Tier O checks failed
  • Authoring checks: 10 of 10 required Tier A checks passed with an empty cleanup ledger
  • Source commit: bc56fa834a26e882953e4824796bd780a5b4efdb

What the public record shows

Exact-package results and limitations belong in the same view. The image below is a sanitized rendering of the machine-readable public record; the JSON evidence and protected run remain authoritative.

Databricks certification summary showing exact package Tier R, Tier A, optional checks, workspace scope, and unestablished claims
Certification evidence · @fabric-harness/databricks 7.1.1The public record keeps exact-package results and limitations together; it is not a blanket claim for every cloud, region, or preview.

Version 7.1.1 is the byte-identical npm package certified by the Tier R record. The protected publisher independently matched its tarball and generated App digests to the retained evidence before publishing. The focused Tier A workflow then downloaded that exact retained tarball and proved the governed authoring lifecycles against the same source commit and package digest.

The public record promotes 7.1.1 only after exact-commit Tier R, same-package Tier A, guarded publication, public package consumption, and tag verification all passed.

The repository version is the certified version

The version in this repository's packages/databricks manifest is 7.1.1 — the same version the machine-readable record certifies. There is no outstanding source candidate: the published version, the certified version, and the repository version are one package, and every live-support claim on this page belongs to that exact build and source commit. A future candidate appears in the record only as an explicitly uncertified entry until the complete protected evidence chain below promotes it — no part of that chain is assumed from a version bump.

Development builds may be published under the npm dev dist-tag for single-user evaluation. A development-tagged package is explicitly uncertified, does not move latest, does not advance this record, and must not be used to claim shared-user isolation or production readiness. Promoting that exact version to latest still requires the complete protected evidence above.

Tier R runs its 25-request concurrency burst in a fresh 60-second production rate-limit window. This keeps earlier correctness probes from consuming burst capacity while preserving the real 30-request prompt ceiling. Any failed burst request still fails certification, and retained load evidence aggregates non-secret failure categories such as admission_http_429 for diagnosis.

What the protected record proves

The current Tier R record passed:

  • workspace identity and OAuth machine-to-machine authentication;
  • Unity AI Gateway, Model Serving, SQL, and Unity Catalog allow-and-deny controls;
  • governed mutation approval, lineage, Volumes, Lakebase, and System Tables cost reconciliation;
  • RAG, Genie, and managed MCP invocation under on-behalf-of identity;
  • Databricks App health, Lakebase-backed stop/start recovery, hook-authored dynamic-agent continuity, cascade deletion, and burst-load bounds.

The certifying run executed in single-user workspace mode, so the two-user isolation probe was skipped rather than passed; see the capability status below for exactly what that does not cover.

The same 7.1.1 record also passed configured Tier O probes for MLflow ResponsesAgent, managed RAG evaluation, AI Search, Genie Agent Mode, Jobs, Lakeflow, and a classic notebook. Two Tier O probes failed in this run: Unity Catalog Agent Services registration was rejected by the workspace API, and Feature Serving did not resolve its configured records. Tier O failures are recorded visibly and do not block certification, but this record establishes nothing for those two surfaces.

The same-package Tier A record passed approval provenance plus create, verify, mutate, delete, and verify-delete lifecycles for serverless Jobs, Lakeflow, direct-vector AI Search, custom-model Serving, Unity Catalog administration under OBO, Workspace objects, secret references, and Genie Agents. Every lifecycle ended with cleanupRequired: false; the pre-run and post-run sweepers found no retained certification resources.

Capability status

Live-certified

  • Core consumption path: Required Tier R checks passed in the recorded Azure workspace.
  • Databricks App restart recovery: Durable state, stream offsets, approvals, and deletion behavior passed stop/start probes.

Beta and workspace-dependent

  • MLflow ResponsesAgent — passed Tier O: The Responses schema, stable streamed output item, inference tables, and secure App proxy path passed in the current run.
  • Genie Agent Mode — passed Tier O: Ordered output and a terminal SSE event passed in the current run.
  • Managed RAG evaluation — passed Tier O: The configured MLflow 3 evaluation job completed successfully against the governed golden set.

Not established by this record

  • Two-user App isolation, current run: The certifying run executed in single-user workspace mode, so the user-isolation checks were skipped rather than passed. This record says nothing about cross-user or cross-tenant protection; multi-user production deployments must treat that isolation as uncovered until a two-identity run retains passing evidence.
  • Two-user App isolation rolling claim: With no passing two-user probe in the current run, the separate 14-day rolling claim remains unestablished.
  • Unity Catalog Agent Services: The Tier O registration lifecycle probe failed in the current run, so this record establishes neither registration nor runtime invocation.
  • Feature Serving: The Tier O primary-key resolution probe failed in the current run.
  • Optional authoring variants: The current Tier A record does not establish classic-compute Jobs, Delta Sync indexes, provisioned-throughput Serving, or Genie Agent Mode authoring.
  • AWS and Google Cloud workspaces: This Azure record does not establish live behavior in another cloud or region.

Beta and workspace-dependent are textual status labels, not color-only indicators. Preview availability can differ by account, region, entitlement, and Databricks rollout.

A controlled single-user development or private evaluation can leave require_user_isolation disabled; that is the workflow default and does not require inventing a second user. A single-user certification can publish a changed Databricks package — the current 7.1.1 record is exactly that case — but it carries an explicit limitation: the certification makes no claim about cross-user or cross-tenant isolation, and multi-user production deployments should treat that isolation as uncovered. In the evidence record this appears as the user-isolation checks being skipped rather than passed, so the run makes no claim about cross-tenant protection. Certifying a shared or user-facing App's isolation behavior, and advancing the public two-user rolling claim, continue to require two distinct identities and retained isolation evidence.

How certification is evaluated

The reference Databricks App is an on-demand certification target. The protected live workflow deploys and starts it for the bounded certification window, uploads the redacted evidence, and stops its compute in an unconditional cleanup step. A cleanup failure fails the workflow rather than leaving the App silently active. Operators should not keep the reference App running between certifications.

Fabric uses three evidence tiers:

  • Tier R — production consumption and runtime behavior: Every required check must pass before publishing a changed Databricks package.
  • Tier A — protected resource-authoring lifecycles: Required for management claims; cleanup must complete without leaked resources.
  • Tier O — preview, SKU-specific, or optional integrations: Recorded visibly but non-blocking unless explicitly promoted for that run.

The release workflow validates the protected run, commit, package digest, generated App digest, restart evidence, required results, and evidence age before publishing. Direct local publication of the Databricks package fails closed. An independently versioned, non-Databricks release scope may publish only its explicit package allowlist without a Databricks run; it cannot include, tag, or publish the Databricks candidate. This prevents pending Databricks source from blocking an unrelated connector release without weakening the Databricks gate.

What customers should verify

Before production rollout, run the documented preflight and smoke tests in the target workspace. Confirm:

  • the intended cloud and region expose Databricks Apps, Lakebase, Model Serving, and required AI services;
  • the application and user principals have only the necessary workspace and Unity Catalog grants;
  • on-behalf-of scopes are consented and resolve the expected user;
  • private networking, egress, and SQL policies match the deployment;
  • restart recovery and tenant isolation pass using representative identities;
  • Beta capabilities are enabled for the target workspace before relying on them.

Use workspace compatibility for API and runtime requirements, authoring certification for resource-management coverage, and ResponsesAgent for that Beta surface's specific contract and evidence.

Evidence references

  • Tier R consumption run: 33909857317
  • Tier A authoring run: 33915517941
  • Machine-readable public status
  • Source and protected-run access
  • Certified package: @fabric-harness/databricks@7.1.1
  • Tier R evidence: dbx-cert-ca5de23e2502326192565582e6844c5ee423d0bcaf9d3ada19c96a608ae9743b
  • Tier A evidence: dbx-cert-abd5c9a21d0fe784a8ca44572a0d4955ee18494ce677d90fe9af1fe849abb722
  • Required results: 21 of 21 Tier R checks passed
  • Authoring results: 10 of 10 Tier A checks passed for the same package artifact