Actors
Role List
| Role | Description | Main Actions |
|---|---|---|
| Viewer | Internal member who accesses the app through Databricks Apps | Selects a table, question type, and question, then reviews results as charts, grids, or heatmaps |
| Developer | Member responsible for implementing and deploying the app | Local development, regenerating types via npm run generate:client, deploying by pushing to main / stg / prd |
| Service principal | The identity the app uses to connect to Databricks (OAuth M2M) | Runs queries against the SQL Warehouse and lists Unity Catalog schemas and tables |
| GitHub Actions | External system that performs deployment | Authenticates to Databricks via OIDC, updates the Git folder, and runs databricks apps deploy |
No role branching inside the app
The application code contains no permission checks or role-based display branching. What a user can see is determined by the Unity Catalog grants held by the service principal and by Databricks Apps access control.
Role Diagram
graph TD
Viewer[Viewer]
Developer[Developer]
Actions[GitHub Actions]
App[Databricks Apps<br/>FastAPI + React SPA]
SP[Service principal]
Warehouse[(SQL Warehouse)]
UC[(Unity Catalog)]
Viewer --> App
Developer --> Actions --> App
App --> SP
SP --> Warehouse
SP --> UC