Databricks Governance for AWS

Databricks on AWS,
governed by default

Move from periodic reviews to continuous policy enforcement for cost, access, and reliability controls across every AWS Databricks workspace.

Where AWS Databricks Governance Breaks Down

Workspaces scale. Controls don't.

Idle clusters burn budget around the clock. Permissions drift across workspaces unchecked. Tags go missing and secrets get mishandled, with no automated way to catch it.

Kostavo closes the gap.

Continuous scans detect policy drift across compute, access, tags, networking, and secrets. Findings route to the right owners automatically, with notify, fix, or remove actions that match the risk.

How Kostavo Enforces Policy Automatically

Continuous Policy Scanning

Kostavo scans compute, permissions, networking, tags, and secrets on a schedule, surfacing non-compliant resources before they become incidents.

  • Scheduled scans across all workspaces
  • Findings mapped to policy profiles
  • Owner and admin notifications

Notify, Fix, or Remove

Pick the right response for each policy. Alert workspace admins, auto-remediate configuration drift, or remove disallowed resources.

  • Notify for visibility and triage
  • Fix for controlled auto-remediation
  • Remove for high-risk configurations

Open findings across clusters, warehouses, and permissions: severity, owner context, and recency.

What Gets Enforced

  • Compute governance: Cluster sizing, autotermination, runtime versions, idle detection, and instance pool usage
  • Access governance: Open permissions, entitlement drift, service principal hygiene, and token expiry
  • Cost hygiene: Missing cost tags, abandoned resources, and warehouse auto-stop enforcement
  • Security & ops: Secret handling, network exposure, configuration baselines, and reliability settings

How It Works

1

Connect Your AWS Databricks Workspaces

Add workspaces to Kostavo and assign policy profiles aligned to your environment and workload types.

2

Policies Scan Continuously

Kostavo runs checks on a schedule and routes findings to resource owners and workspace admins through your notification channels.

3

Enforce by Risk Level

Use notify, fix, or remove per policy, balancing automation with human control based on risk.

Govern AWS Databricks Without the Spreadsheets

First workspace connected in minutes, first findings on the same day.

Start Free Trial