Fiddler needs three Databricks grants: CAN_MANAGE on the registered models, CAN_READ on the Feature Store tables if you use them, and CAN_USE on the clusters that run SHAP computation. For MLflow-based setups it needs read access to the Model Registry and to Experiment Tracking, plus write access if you want to export Fiddler metrics back to MLflow. On the auth side, personal access tokens are fine for development, but for production Fiddler recommends service principal OAuth (or Azure AD integration on Azure Databricks), since a personal token tied to one user breaks the integration when that person leaves or rotates their token.

Context: I am setting up the Fiddler Databricks integration and getting permission errors. Which Databricks permissions does Fiddler actually need?