Thanks v-ksheldon
This looks like a solution that would solve problems for us, but i'm struggling to see how it works in practice.
OneLake security & read/write roles make sense to me. What i'm missing is how the restricted SG can use notebooks etc where they need to.
As your post illustrates I think - giving Contributor Workspace Role gives access to everything, so they can't have that.
I think what i'm missing is how the developer even finds the lakehouse - is the Lakehouse shared with a specific configuration? How do they see the tables they are allowed to work with and the schema they are allowed to work from?
I managed to give them no workspace role at all, share the Lakehouse directly with Execute Apache Spark permissions, but they then can't create a notebook in the workspace?