Keep app access reviews connected to Drive sharing changes
Use a new Drive share as a prompt to review and update access on the Databricks app covered by your policy.
Trigger
File Shared (Permissions Added)
Triggers when new sharing permissions are granted to a file or folder. Uses Drive's `changes.list` endpoint with inline `permissions` in the `fields` mask so each change carries the file's current permission set provider-atomically. We diff that against `seen_permission_keys` to identify newly added grants. Drive page tokens are the primary cursor; if Drive rejects a stored token, the trigger raises `PollingTriggerError` without clearing state rather than silently re-baselining and dropping events. Limitation: truly ephemeral permissions (added and revoked between two polls without any other file modification in between) are not detected. Drive Activity API would catch those but requires an additional OAuth scope and a different payload contract.
Action
Update Databricks App Permissions
Tool to incrementally update permissions for a Databricks app. Use when you need to modify specific permissions without replacing the entire permission set. This PATCH operation updates only the specified permissions, preserving existing permissions not included in the request. For replacing all permissions, use SetPermissions instead.
Why this helps
Changes to shared project files can signal an access change that still needs review in Databricks.
- Bring new sharing changes into an app access review.
- Use incremental permission updates that preserve permissions not included in the update.
- Keep the Databricks app and access policy explicit.
Setup
Build it in a few focused steps.
- 1Connect Google Drive and Databricks once in the Notis portal.
- 2Create an automation in Automations, New Automation, and give it a name.
- 3In one instruction, identify the Databricks app and state the policy for deciding whether and how new Drive sharing should change its permissions.
- 4Pick the Google Drive File Shared trigger and choose where run reports should go.
- 5Test with one real sharing change and inspect the app permissions afterward.
Questions about this workflow
Does a Drive share automatically grant Databricks app access?
Only if your instruction and access policy say it should. Provide a reliable identity mapping and the Databricks app to review; the Drive event alone may not provide either.
Will existing Databricks app permissions be replaced?
This workflow uses Update Databricks App Permissions, an incremental update that preserves permissions not included in the update.
When this happens · Trigger
Do this · Action
Supported Triggers and Actions
Notis builds workflows that link Google Drive to Databricks. A trigger fires from one place; an action lands in another.
Google Drive triggers
Databricks actions
Recurring trigger
Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.
Add Member to Security Group
Tool to add a user or group as a member to a Databricks security group. Use when you need to grant group membership for access control.
Webhook trigger
Notis starts this workflow when an external tool or custom backend sends an HTTP request.
Delete Custom LLM Agent
Tool to delete a Custom LLM agent created through Agent Bricks. Use when you need to remove a custom LLM and all associated data. This operation is irreversible and deletes all data including temporary transformations, model checkpoints, and internal metadata.
Comment Added (Docs/Sheets/Slides)
Triggers when a new comment is added to Google Docs, Sheets, or Slides.
Create Databricks App
Tool to create a new Databricks app with specified configuration. Use when you need to create apps hosted on Databricks serverless platform to deploy secure data and AI applications. The app name must be unique within the workspace, contain only lowercase alphanumeric characters and hyphens, and cannot be changed after creation.
File Created
Triggers when a new file is created in Google Drive.
Delete Databricks App
Tool to delete a Databricks app from the workspace. Use when you need to remove an app and its associated service principal. When an app is deleted, Databricks automatically deletes the provisioned service principal.
File Deleted or Trashed
Triggers when a file is moved to trash or permanently deleted in Drive.
Deploy Databricks App
Tool to create a deployment for a Databricks app. Use when you need to deploy an app with source code from a workspace path. The deployment process provisions compute resources and uploads the source code. Deployments can be in states: IN_PROGRESS, SUCCEEDED, FAILED, or CANCELLED.
File Shared (Permissions Added)
Triggers when new sharing permissions are granted to a file or folder. Uses Drive's `changes.list` endpoint with inline `permissions` in the `fields` mask so each change carries the file's current permission set provider-atomically. We diff that against `seen_permission_keys` to identify newly added grants. Drive page tokens are the primary cursor; if Drive rejects a stored token, the trigger raises `PollingTriggerError` without clearing state rather than silently re-baselining and dropping events. Limitation: truly ephemeral permissions (added and revoked between two polls without any other file modification in between) are not detected. Drive Activity API would catch those but requires an additional OAuth scope and a different payload contract.
Get Databricks App Details
Tool to retrieve details about a specific Databricks app by name. Use when you need to get comprehensive information about an app including configuration, deployment status, compute resources, and metadata.
File Updated
Triggers when a file's metadata or content changes in Google Drive.
Get Databricks App Permission Levels
Tool to retrieve available permission levels for a Databricks app. Use when you need to understand what permission levels can be assigned to users or groups for a specific app. Returns permission levels like CAN_USE and CAN_MANAGE with their descriptions.
Google Drive Changes
Triggers when changes are detected in a Google Drive.
Get Databricks App Permissions
Tool to retrieve permissions for a Databricks app. Use when you need to check who has access to an app and their permission levels. Returns the access control list including inherited permissions from parent or root objects.
Connect any two apps with Notis in the middle.
Google Drive and Databricks, or any other combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Databricks.