The vector index inherits no permissions: data agents on Databricks, Fabric and Foundry

A vector index is a copy, and a copy inherits no permissions: the Databricks AI Search documentation states that row and column level permissions are not supported. The two routes an agent takes to the data — RAG and text-to-SQL —, where the access rule lives on each one, the Genie Agent's two credentials, and the metric layer that stops the number from changing.

Continue ReadingThe vector index inherits no permissions: data agents on Databricks, Fabric and Foundry

Network and security for AI workloads: a private endpoint closes the entrance, not the exit

A private endpoint controls ingress; it authenticates nobody and does not decide where the agent writes afterwards. The three boundaries of an AI workload — entrance, identity, and exit —, the three DNS zones Foundry requires, the roles that were renamed, and the egress control almost every project leaves open.

Continue ReadingNetwork and security for AI workloads: a private endpoint closes the entrance, not the exit

Guardrails and agent evaluation: what separates a demo from a production system

Guardrails contain at runtime; evaluation measures over time — and neither does the other's job. Content Safety, Prompt Shields, evaluators that see the tool call and not just the answer, red teaming with PyRIT, and the maturity signal that separates a demo from a system: a deployment blocked by a number.

Continue ReadingGuardrails and agent evaluation: what separates a demo from a production system

Federate, mirror, or ingest: the decision between Databricks and Fabric

Federating, mirroring, and ingesting are not synonyms — and in Fabric "mirroring" already means three different mechanisms. When to use Lakehouse Federation, when to mirror a catalog or a database into Microsoft Fabric, when to ingest with Lakeflow Connect, what is actually free, and why source permissions do not cross the OneLake boundary.

Continue ReadingFederate, mirror, or ingest: the decision between Databricks and Fabric

AI FinOps beyond caching: how to choose Batch, Model Router, PTU, and pay-as-you-go

Prompt caching solves reuse, but it does not decide when to run, how to buy capacity, or which model should answer. A practical framework for combining Batch, PTU, pay-as-you-go, and Model Router around cost per approved task.

Continue ReadingAI FinOps beyond caching: how to choose Batch, Model Router, PTU, and pay-as-you-go

Data ontology: the governed context that makes AI reason across Databricks and Fabric

The bottleneck of enterprise AI is not the model, it is governed business context. How Unity Catalog Metric Views, Genie Ontology and Fabric IQ form a single semantic layer over one copy of the data — with an FSI use case, cost model and roadmap.

Continue ReadingData ontology: the governed context that makes AI reason across Databricks and Fabric

Model Context Protocol (MCP): the standard that connects AI agents to tools and data

MCP has become the open standard for connecting AI agents to tools and data. What it is, what changed in detail in revision 2026-07-28 - stateless protocol, no sessions or initialize, subscriptions/listen, no SSE resumability, extensions and OAuth - with a migration checklist and how to host it on Azure.

Continue ReadingModel Context Protocol (MCP): the standard that connects AI agents to tools and data

Artificial Intelligence: a reflection on use, careers, security and how to put it to work for us

AI adoption stopped being a technology problem and became an operations and accountability problem. An executive guide to governance, the real dangers of AI, and the shift from application developer to AI engineer.

Continue ReadingArtificial Intelligence: a reflection on use, careers, security and how to put it to work for us