Dev.to Security πŸ” Cybersecurity πŸ‘ 0 πŸ“– 5 min read

Engineering Legal-Entity Isolation for Agentic FSI Systems Across Hong Kong and Singapore - Hong Kong Databricks FSI Community Day 2026

The Hong Kong Databricks FSI Community Day 2026 stands out as a highly unique, independent gathering happening directly within the Hong Kong Island waters. Operating away from typical convention centers, this exclusive,

The Hong Kong Databricks FSI Community Day 2026 stands out as a highly unique, independent gathering happening directly within the Hong Kong Island waters. Operating away from typical convention centers, this exclusive, invitation-only event takes place entirely aboard a private boat traveling along the local ferry route. The forum serves as a dedicated working exchange for professionals operating at the intersection of complex data streams, financial markets, risk modeling, and institutional oversight.

To maintain absolute psychological and operational safety for its attendees, the organizers have stripped away traditional corporate hierarchies and product pitches in favor of open, critical peer challenges. There are no speaker names, titles, or recording devices permitted on board, ensuring that all field briefings focus strictly on executable expertise rather than corporate branding. Over thirty distinct technical proposals detail real-world financial architectures, handling everything from cross-border liquidity management and real-time streaming calculation paths to data isolation between entities in Hong Kong and Singapore. This community-driven event remains entirely independent of Databricks corporation, functioning instead as a private, expert-led ecosystem for practitioners navigating the realities of fragmented regional market structures.

Event Page:
https://vertexmacro.com/events/databricks_community_day_2026/index.html

Group Page:
https://usergroups.databricks.com/hong-kong-databricks-fsi-group/

Topic:
Engineering Legal-Entity Isolation for Agentic FSI Systems Across Hong Kong and Singapore

Focus:
Distributed Systems Reliability and Advanced Observability

Speaker Background:
Institutional data and AI platform architect specializing in legal-entity isolation, distributed-systems reliability, observability, and zero-trust controls. The speaker designs governed agent platforms for Asian banks, trading firms, and insurers, translating regulatory boundaries into enforceable identities, runtime policies, network controls, evidence, and recovery procedures.

Description:
An international bank may store Hong Kong and Singapore data on one governed lakehouse, but Entity HK and Entity SG remain legally distinct. Shared infrastructure cannot become shared entitlement. An agent that analyzes Hong Kong liquidity must not retrieve Singapore client records, infer Singapore positions through metadata, or bypass restrictions during failover, debugging, caching, or tool execution. In Asia FSI, reliability therefore means preserving legal boundaries under normal operation and system failure.

This session presents a distributed control architecture for legal-entity-aware agents using Unity Catalog, governed tags, ABAC policies, row filters, column masks, service principals, Genie Agents, Genie Ontology, and approved Agent Bricks patterns. The three-level namespace provides an organizational foundation. Institutions may separate entities into catalogs or schemas, while shared tables carry explicit jurisdiction, legal-entity, confidentiality, residency, and purpose tags. The design does not rely on naming alone. Object privileges establish the base grant, and dynamic policies add restrictions according to identity, group membership, tags, and request context.

The identity plane registers a dedicated service principal for each deployed agent instance or bounded agent service. The Hong Kong liquidity agent belongs only to approved Hong Kong groups; the Singapore instance belongs only to Singapore groups. Separate identities are used for development, testing, production, retrieval, tool execution, and deployment automation. Human impersonation is prohibited. Credentials are short-lived, rotated, and prevented from crossing workspaces or regions without explicit approval.

At query time, Unity Catalog evaluates applicable ABAC policies and sends effective row filters and column masks to the Databricks Runtime. The runtime query planner enforces those restrictions over table scans. A Hong Kong principal can therefore receive only rows permitted by a legal-entity policy, while counterparty accounts, customer names, identifiers, and commercially sensitive fields are masked according to governed tags and authorized roles. Policies follow a fail-closed design when enforcement cannot be verified.

The proposal carefully distinguishes platform behavior from architectural shorthand. There is no separately documented product component called an β€œEntitlement Interceptor” that should be treated as a contract. The enforceable pattern is Unity Catalog policy evaluation followed by Databricks Runtime enforcement. Likewise, physical file skipping may improve performance, but the security guarantee comes from policy enforcement, not an assumption that unauthorized files were never touched by storage infrastructure.

Genie Ontology adds business meaning but never expands access. It maps terms such as legal entity, branch liquidity, counterparty concentration, restricted client, and cross-border exposure to certified metrics and authoritative sources. Ontology snippets are permission-aware, allowing a Hong Kong agent to use only context that its identity can access. Entity-specific vocabulary, metric definitions, and authoritative-source rules prevent an aggregate β€œAPAC liquidity” question from silently blending incompatible books.

Observability proves the boundary continuously. Every request records agent identity, caller, legal entity, model, agent version, SQL statement or tool, tables addressed, policy decision, row counts, masked columns, latency, denial, and response disposition. Distributed traces connect user request, agent planning, retrieval, SQL execution, model inference, and tool invocation without logging prohibited PII. Network telemetry verifies private paths, approved egress, DNS, TLS, route changes, and cross-region dependencies.

A failure scenario tests privilege drift during simultaneous Hong Kong and Singapore market stress. A deployment mistakenly assigns a Singapore group to an HK service principal. Preventive controls block production promotion because the entitlement graph differs from the approved manifest. A second experiment disables a policy dependency; fail-closed behavior denies access. A third causes regional failover; the recovery environment must reproduce identities, tags, grants, masks, and policy versions before traffic is accepted.

Clean Rooms address governed collaboration, not automatic internal aggregation. A no-trust clean room can let approved parties run mutually approved notebooks over shared assets without direct access to each other’s raw data. If group-level statistics require thresholding, output checking, aggregation restrictions, or differential privacy, those safeguards must be explicitly implemented and validated in the approved workload. Clean Rooms should not be described as automatically adding differential-privacy noise to every result.

Chaos engineering validates identity-service interruption, stale group membership, missing tags, policy-function failure, network partition, cache leakage, and regional recovery. Success requires correct denial, bounded recovery, immutable evidence, and no cross-entity disclosure. The result is a system whose observability explains not only whether an agent answered, but why it was legally permitted to answer.

Audience Takeaways:
Participants receive a legal-entity isolation architecture for Asian FSI agents, covering dedicated identities, Unity Catalog ABAC, row filters, column masks, Genie Ontology, Clean Rooms, zero-trust networking, entitlement observability, and chaos testing. They will learn how to preserve HK-SG separation during deployment, query execution, caching, tool use, and regional failover.

πŸ“° Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β€” full credit and traffic to the original publisher.