Whitepapers & Guides
One LLM. Millions of users. Zero policy drift.

How JetBlue deployed production Generative AI on its data estate with one control layer across data security posture, data access governance, and AI-layer policy enforcement — anchored on Databricks Unity Catalog, Azure AD identity, and the Theom control layer.
The challenge: production GenAI on regulated aviation data
JetBlue runs one of the most sophisticated data stacks in the airline industry — Azure-centered, with a Databricks lakehouse serving every line of business, from Commercial and Operations Data Science to AI & ML Engineering and Business Intelligence, all reporting directly to the CTO. Adopting Generative AI on top of that estate ran into a problem JetBlue’s own data leadership was explicit about:
Data governance is the biggest obstacle to deploying generative AI and machine learning in any organization.
Sai Ravuru — Senior Manager, Data Science & Analytics, JetBlue — Databricks blog, June 2023
That obstacle resolved into three concrete sub-problems: access at the data layer, where hundreds of thousands of users, policies, and data objects left no way to manually govern who an LLM-backed application could retrieve documents for on a user’s behalf; regulatory load, where aviation data carries Federal Air Regulations and other obligations and GenAI multiplies the surface area where those rules must be enforced; and multi-model economics, where training a separate model per business function would have been operationally untenable.
What JetBlue got in the first 90 days
- GenAI shipped to production. BlueBot moved from prototype to enterprise service on production data — not a sanitized copy.
- One model, many roles. Finance, operations, crew, and customer service share a single LLM and pipeline. Theom enforces what each role can retrieve — no per-team model fine-tuning required.
- 50+ data-layer findings in 90 days. Surfaced and remediated issues including service-account impersonation, over-permissioned analytics access, sensitive-join policy violations, and unauthorized cross-environment data movement.
- Continuous access recertification. Replaces manual, point-in-time access reviews with continuous evaluation across the data estate — a material reduction in audit preparation effort.
- No identity-based data exposure. No identity-based or policy-violation data exposure incidents detected in BlueBot production since Theom deployment.
- One control layer over the existing stack. Theom operates over the Azure + Databricks lakehouse without forcing a re-platforming. Unity Catalog ACLs, Azure AD identity, and the Dolly + Azure OpenAI retrieval path stay where they are; Theom adds posture, governance, and AI-layer enforcement on top.
JetBlue’s integration of Databricks Unity Catalog and Theom’s access governance platform marks a significant advancement in aviation technology, specifically in deploying generative AI. The combination of Unity Catalog and Theom fortifies data security, ensuring compliance and data integrity, making JetBlue a model for AI application in aviation.
Databricks — Data + AI use cases blog, August 2024


