Skip to content
Notis

Keep app access reviews connected to Drive sharing changes

Use a new Drive share as a prompt to review and update access on the Databricks app covered by your policy.

Trigger

File Shared (Permissions Added)

Triggers when new sharing permissions are granted to a file or folder. Uses Drive's `changes.list` endpoint with inline `permissions` in the `fields` mask so each change carries the file's current permission set provider-atomically. We diff that against `seen_permission_keys` to identify newly added grants. Drive page tokens are the primary cursor; if Drive rejects a stored token, the trigger raises `PollingTriggerError` without clearing state rather than silently re-baselining and dropping events. Limitation: truly ephemeral permissions (added and revoked between two polls without any other file modification in between) are not detected. Drive Activity API would catch those but requires an additional OAuth scope and a different payload contract.

Action

Update Databricks App Permissions

Tool to incrementally update permissions for a Databricks app. Use when you need to modify specific permissions without replacing the entire permission set. This PATCH operation updates only the specified permissions, preserving existing permissions not included in the request. For replacing all permissions, use SetPermissions instead.

Why this helps

Changes to shared project files can signal an access change that still needs review in Databricks.

  • Bring new sharing changes into an app access review.
  • Use incremental permission updates that preserve permissions not included in the update.
  • Keep the Databricks app and access policy explicit.

Setup

Build it in a few focused steps.

  • 1Connect Google Drive and Databricks once in the Notis portal.
  • 2Create an automation in Automations, New Automation, and give it a name.
  • 3In one instruction, identify the Databricks app and state the policy for deciding whether and how new Drive sharing should change its permissions.
  • 4Pick the Google Drive File Shared trigger and choose where run reports should go.
  • 5Test with one real sharing change and inspect the app permissions afterward.

Questions about this workflow

Does a Drive share automatically grant Databricks app access?

Only if your instruction and access policy say it should. Provide a reliable identity mapping and the Databricks app to review; the Drive event alone may not provide either.

Will existing Databricks app permissions be replaced?

This workflow uses Update Databricks App Permissions, an incremental update that preserves permissions not included in the update.

When this happens · Trigger

Do this · Action

Supported Triggers and Actions

Notis builds workflows that link Google Drive to Databricks. A trigger fires from one place; an action lands in another.

Google Drive triggers

Databricks actions

Recurring trigger

Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.

TriggerScheduled

Add Member to Security Group

Tool to add a user or group as a member to a Databricks security group. Use when you need to grant group membership for access control.

ActionInstant

Webhook trigger

Notis starts this workflow when an external tool or custom backend sends an HTTP request.

TriggerInstant

Delete Custom LLM Agent

Tool to delete a Custom LLM agent created through Agent Bricks. Use when you need to remove a custom LLM and all associated data. This operation is irreversible and deletes all data including temporary transformations, model checkpoints, and internal metadata.

ActionInstant

Comment Added (Docs/Sheets/Slides)

Triggers when a new comment is added to Google Docs, Sheets, or Slides.

TriggerPolling

Create Databricks App

Tool to create a new Databricks app with specified configuration. Use when you need to create apps hosted on Databricks serverless platform to deploy secure data and AI applications. The app name must be unique within the workspace, contain only lowercase alphanumeric characters and hyphens, and cannot be changed after creation.

ActionInstant

File Created

Triggers when a new file is created in Google Drive.

TriggerPolling

Delete Databricks App

Tool to delete a Databricks app from the workspace. Use when you need to remove an app and its associated service principal. When an app is deleted, Databricks automatically deletes the provisioned service principal.

ActionInstant

File Deleted or Trashed

Triggers when a file is moved to trash or permanently deleted in Drive.

TriggerPolling

Deploy Databricks App

Tool to create a deployment for a Databricks app. Use when you need to deploy an app with source code from a workspace path. The deployment process provisions compute resources and uploads the source code. Deployments can be in states: IN_PROGRESS, SUCCEEDED, FAILED, or CANCELLED.

ActionInstant

File Shared (Permissions Added)

Triggers when new sharing permissions are granted to a file or folder. Uses Drive's `changes.list` endpoint with inline `permissions` in the `fields` mask so each change carries the file's current permission set provider-atomically. We diff that against `seen_permission_keys` to identify newly added grants. Drive page tokens are the primary cursor; if Drive rejects a stored token, the trigger raises `PollingTriggerError` without clearing state rather than silently re-baselining and dropping events. Limitation: truly ephemeral permissions (added and revoked between two polls without any other file modification in between) are not detected. Drive Activity API would catch those but requires an additional OAuth scope and a different payload contract.

TriggerPolling

Get Databricks App Details

Tool to retrieve details about a specific Databricks app by name. Use when you need to get comprehensive information about an app including configuration, deployment status, compute resources, and metadata.

ActionInstant

File Updated

Triggers when a file's metadata or content changes in Google Drive.

TriggerPolling

Get Databricks App Permission Levels

Tool to retrieve available permission levels for a Databricks app. Use when you need to understand what permission levels can be assigned to users or groups for a specific app. Returns permission levels like CAN_USE and CAN_MANAGE with their descriptions.

ActionInstant

Google Drive Changes

Triggers when changes are detected in a Google Drive.

TriggerPolling

Get Databricks App Permissions

Tool to retrieve permissions for a Databricks app. Use when you need to check who has access to an app and their permission levels. Returns the access control list including inherited permissions from parent or root objects.

ActionInstant

Connect any two apps with Notis in the middle.

Google Drive and Databricks, or any other combination from 1,000+ integrations.

When this happens · Trigger

Do this · Action

Save your first hour today.

7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Databricks.