Databricks is changing how principals get workspace entitlements. After this change, you grant entitlements explicitly when adding a principal to a workspace instead of relying on inheritance from the users system group. Workspace administrators can opt in starting June 15, 2026, and the new behavior is enforced for all workspaces on September 14, 2026.
This change enables you to add principals at any access level, including consumer-only users, without them automatically inheriting authoring privileges.
What's changing
Every workspace has two system groups: users, which includes all principals granted access to the workspace, and admins, which includes the workspace administrators. Today, every principal added to a workspace inherits the entitlements granted to users. By default, these are:
- Workspace access — create and use notebooks, jobs, pipelines, apps, and more.
- Databricks SQL access — create and use dashboards, Genie Agents, alerts, and more.
After the change:
- The
users group will have no entitlements. The admins group will have all workspace entitlements. Both groups' entitlements are locked.
- New principals must be granted entitlements explicitly when added to a workspace.
users and admins cannot be nested as members of other groups. …