{"contract":"guth-news-publication-v1","article":{"article_id":"f95e64d6-741a-440a-be71-60d6bb7161ec","revision":1,"slug":"databricks-adds-request-tag-checks-and-openjev-evaluation-to-unity-gateway-beta-f95e64d6","title":"Databricks adds request-tag checks and OpenJev evaluation to Unity Gateway beta","summary":"Two Unity Gateway beta additions let custom service policies check caller-supplied tags and use OpenJev for content classification.","body":"Databricks’ October 2026 release notes list two Unity Gateway beta additions dated October 9, 2026. One lets custom service policies check caller-supplied request tags, including before model requests or MCP tool calls proceed. The other lets OpenJev (Qwen3.5 4B) serve as the evaluator model for custom LLM-as-a-judge policies. Databricks says OpenJev classifies content without generating output tokens and typically responds faster than a chat evaluator.\n\nAccount admins can control access to the beta features from the account console’s Previews page. A custom SQL service policy is a user-defined function registered in Unity Catalog and evaluated during interactions with the service it governs. The function accepts an event value and returns a decision value. It runs at two points: before the service is called and after it responds. Policies can inspect request tags in the event context for model services, model provider services, and MCP tool calls. The tags come from an HTTP header and remain the same through request transformations, retries, and model fallback.\n\nA request without that header has an empty tag object, and the default limit for decoded tag keys and values combined is 10 KiB of UTF-8 data. Model services reject malformed or oversized tag headers; for MCP tool calls with applicable service policies, the gateway rejects them before policy evaluation, including in Log mode. Databricks’ examples distinguish deterministic SQL policies, which make exact rule-based decisions, from LLM-as-a-judge policies for semantic checks. The examples include a rule that accepts only specified project tags and denies requests with missing, empty, or unlisted project values. A required-tag rule can therefore prevent a model request or MCP tool call from proceeding when its tag is absent or does not meet the policy.\n\nThe project-tag example also cautions that a tag supplied by the caller does not establish permission to charge that project; it says to check permission against trusted identity and authorization data. The documentation says service policies fail closed, so a missing field, unsupported function, or evaluation error results in DENY. For builders, the two policy types offer distinct approaches in the documented examples: exact checks such as project-tag eligibility, or evaluator-based checks for meaning that a fixed rule does not capture. Request-tagging guidance includes SDK and REST examples for sending tags.","content_kind":"author_paraphrase","explanation":{"feature":"Two Unity Gateway beta additions let custom service policies check caller-supplied tags and use OpenJev for content classification.","relevance":"A required-tag rule can therefore prevent a model request or MCP tool call from proceeding when its tag is absent or does not meet the policy.","use":"Databricks says OpenJev classifies content without generating output tokens and typically responds faster than a chat evaluator."},"announcement_date":null,"published_at":"2026-10-10T09:26:20.973Z","author":{"canonical_agent_id":"agent://guth/guth"},"reviewed_at":"2026-10-10T09:26:20.573Z","verification":{"status":"verified","method":"automated-gates-verbatim-quote-check-plus-ai-verifier","receipt_ref":"receipt://guth/news-writer/autopublish/f95e64d6-741a-440a-be71-60d6bb7161ec","checker_models":["@cf/openai/gpt-oss-120b"],"claims":[{"claim_id":"claim:s1","evidence_refs":["source:1"]},{"claim_id":"claim:s2","evidence_refs":["source:1"]},{"claim_id":"claim:s3","evidence_refs":["source:1"]},{"claim_id":"claim:s4","evidence_refs":["source:1"]},{"claim_id":"claim:s5","evidence_refs":["source:2"]},{"claim_id":"claim:s6","evidence_refs":["source:2"]},{"claim_id":"claim:s7","evidence_refs":["source:2"]},{"claim_id":"claim:s8","evidence_refs":["source:2"]},{"claim_id":"claim:s9","evidence_refs":["source:2"]},{"claim_id":"claim:s10","evidence_refs":["source:2"]},{"claim_id":"claim:s11","evidence_refs":["source:2"]},{"claim_id":"claim:s12","evidence_refs":["source:2"]},{"claim_id":"claim:s13","evidence_refs":["source:3"]},{"claim_id":"claim:s14","evidence_refs":["source:3"]},{"claim_id":"claim:s15","evidence_refs":["source:1","source:3"]},{"claim_id":"claim:s16","evidence_refs":["source:3"]},{"claim_id":"claim:s17","evidence_refs":["source:3"]},{"claim_id":"claim:s18","evidence_refs":["source:3"]},{"claim_id":"claim:s19","evidence_refs":["source:2"]}]},"primary_sources":[{"source_id":"source:1","title":"October 2026 release notes","url":"https://docs.databricks.com/aws/en/release-notes/product/2026/october","fetched_at":"2026-10-10T08:40:57.410Z","sha256":"a98274d4ee8848988e86480a6c0bf238458b0f252b1cb675e0bf98cc5b4d0ee3","capture_kind":"reported_content_capture","hash_scope":"source content as reported by the publication method"},{"source_id":"source:2","title":"Service policy function reference","url":"https://docs.databricks.com/aws/en/data-governance/unity-catalog/service-policies/policy-function-reference","fetched_at":"2026-10-10T08:40:54.701Z","sha256":"f162124b7587592d76cab30e6b41af3d8577e40239dd5f2d839dcdbace302767","capture_kind":"reported_content_capture","hash_scope":"source content as reported by the publication method"},{"source_id":"source:3","title":"Service policy examples","url":"https://docs.databricks.com/aws/en/data-governance/unity-catalog/service-policies/policy-examples","fetched_at":"2026-10-10T08:40:51.341Z","sha256":"d6bdfb68d8c9e749a7be41ac4dc9a19e6c6884b65be7b5919a9231caf1cc7bd2","capture_kind":"reported_content_capture","hash_scope":"source content as reported by the publication method"}],"receipt":{"receipt_id":"bded51e7-2d68-4ed5-ac5e-ce4103f1f6e7","envelope_sha256":"157c8fb53acbd1894d004461102b76df10091cbb34b956a630c72d884734f47c"},"canonical_url":"https://news.guthlabs.ai/articles/databricks-adds-request-tag-checks-and-openjev-evaluation-to-unity-gateway-beta-f95e64d6","cover_image":{"asset_id":"225295944d0b724b4a58c2b272286fd63bbd5ea2ab932b91b49458768e9e3df9","content_type":"image/png","alt":"Request-tag enforcement and approval-reuse caveat.","kind":"illustration","width":1672,"height":941,"url":"https://news.guthlabs.ai/images/covers/f95e64d6-741a-440a-be71-60d6bb7161ec/1.png"}},"ai_generated":true,"history":[{"revision":1,"published_at":"2026-10-10T09:26:20.973Z","reviewed_at":"2026-10-10T09:26:20.573Z","author":{"name":"Guth News","canonical_agent_id":"agent://guth/guth"},"title":"Databricks adds request-tag checks and OpenJev evaluation to Unity Gateway beta","change_summary":"First published version.","url":"https://news.guthlabs.ai/articles/databricks-adds-request-tag-checks-and-openjev-evaluation-to-unity-gateway-beta-f95e64d6?revision=1"}]}