Skip to content

Genie One MCP: Give any AI Agent the Right Business Context

Summary

Databricks' 2026-09-22 launch of Genie One MCP — an MCP server that exposes Genie One's governed conversational-analytics capability as a tool to any MCP-compatible AI agent (ChatGPT, Claude, Microsoft Copilot, Claude Code). The architectural thesis: direct data access is not business context — connecting an agent straight to structured/unstructured sources gives it access but not the shared, governed meaning it needs to answer reliably. Genie One MCP instead exposes one intent surface (a natural-language question) backed by Genie Ontology's approved definitions, trusted relationships, and authority ranking, with Unity Catalog permission enforcement carried through via on-behalf-of user identity. The post's substance beyond the launch framing is a concrete five-tool MCP contract, an identity/access-control section (OBO recommended, U2M/M2M tradeoffs), and management/monitoring operational guidance (90-second SQL timeout, workspace QPM limits, audit/query-history surfaces).

Key takeaways

  • Direct access ≠ business context. Wiring an agent directly to sources introduces four named failure modes: accuracy (the agent doesn't know which sources/definitions/joins are approved), cost & latency (repeated schema/doc/relationship inspection burns tokens and time), governance (per-user access is hard to enforce consistently across direct connections), and consistency (each client/model/session interprets definitions differently). Genie One MCP moves all four into one governed layer (concepts/governed-agent-data-access).

  • One context layer, many agents. Business meaning is defined once in Genie Ontology and made available across every approved agent. Genie One provides the native in-Databricks cowork surface; the Genie One MCP server extends the same ontology and the same permission enforcement to external assistants and coding agents.

  • Five-tool MCP contract. The server exposes genie_ask (starts a response, returns conversation_id + response_id), genie_poll_response (progress steps → final answer + an Explore in Databricks deep link), genie_get_query_result (full result set when the truncated answer isn't enough), genie_cancel_response (stops an in-flight turn), and — on clients that support MCP Apps — view_ask (replaces genie_ask, rendering an interactive panel with progress, visualizations, and ontology citations inline). A warehouse_id _meta parameter pins execution to a specific SQL warehouse.

  • On-behalf-of (OBO) is the recommended identity flow. Because agents query through Genie One rather than the underlying tables, user identity must flow through the request. The external assistant passes the end user's OAuth token; Genie evaluates Unity Catalog privileges, row filters, and column masks in that user's context. "Two users can ask the same question in the same client and receive appropriately scoped answers without per-user prompt logic" (patterns/on-behalf-of-agent-authorization, concepts/attribute-based-access-control).

  • M2M is available but flattens identity. Machine-to-machine service- principal auth works for external-facing integrations, but "represents every caller as one identity, removing per-user permission enforcement and potentially limiting personalization and memory." The Access Genie everywhere guidance covers U2M, M2M, and OBO tradeoffs; external MCP connections are Unity Catalog objects governed through standard grants.

  • MCP Apps returns an interactive view instead of plain text. Genie One MCP ships MCP Apps, an extension letting a server return a rendered interactive view (visuals, summary metrics, Genie Ontology citations) on clients that support it; clients without MCP Apps support degrade to text-only results.

  • Tune Genie One in one place, not from the client. Workspace instructions, certification, and Genie Agents curation configured in Databricks are honored by the MCP server — "Don't attempt to steer Genie One from the client's system prompt."

  • Prefer the scoped Genie Agent MCP server for a single curated domain. When a use case maps to one curated domain, the Genie Agent MCP server at /api/2.0/mcp/genie/{genie_space_id} exposes a single read-only agent with its own instructions and trusted SQL — "easier to benchmark and to scope" than the broader Genie One MCP surface.

Operational numbers / constraints

  • 90-second SQL execution timeout per question — must be accounted for when sizing a rollout.
  • Workspace Genie QPM (queries-per-minute) limit — questions routed to Genie Agents count against it.
  • One OAuth application per client platform, registered with minimum scope and token lifetimes matching the org's identity policy (concepts/oauth-token-lifecycle).
  • Managed MCP servers are listed under Agents > MCPs and are visible in Unity Gateway; Genie chat events appear in audit logs, SQL execution in Query History, consumption in billing system tables.
  • Validate governance by impersonation — ask the same question as members of different groups through the external client and confirm the answers diverge as expected (the same impersonation-testing discipline Databricks applies to Genie Agents grounding).

Systems / concepts / patterns extracted

Caveats

  • Tier-3 vendor launch post. Framing is product-announcement; but per the AGENTS.md borderline rule it is included because the architecture content (five-tool MCP contract, OBO/U2M/M2M identity model, MCP Apps, management/ monitoring operational constraints) is well above the 20% bar.
  • No scale numbers. No QPS, latency, or adoption figures are disclosed; the only hard numbers are the 90-second SQL timeout and the (unspecified) workspace QPM limit.
  • Mechanism-light on the ontology. How Genie Ontology resolves definitions, ranks authority, or bounds staleness is not disclosed here (see the 2026-09-15 Genie Ontology source for that framing); this post is about the access surface, not the ontology internals.
  • OBO downstream support required. OBO only enforces per-user permissions if the end user's OAuth token actually flows through — M2M integrations collapse to a single identity by design.

Source

Last updated · 766 distilled / 2,225 read