Skip to content

SYSTEM Cited by 3 sources

Databricks Genie One

Genie One is Databricks' data-smart AI coworker for business users — the natural-language analytics agent, powered by Genie Ontology, that answers data-intensive business questions, synthesizes across enterprise sources, and turns insights into follow-on work (documents, tasks, scheduled actions) both in Databricks and in third-party tools (Google Drive, Microsoft 365, Atlassian, Slack, GitHub, Glean). It is the product-branded surface of the Genie data-agent lineage; where "Genie" and "Genie Agents" name the underlying analytics agents, Genie One is the business-user cowork experience on top of them.

This page also documents Genie One MCP — the MCP server that exposes Genie One's governed conversational-analytics capability as a tool to any MCP-compatible external agent (first wiki disclosure 2026-09-22).

Genie One MCP: bringing governed context to any agent

The 2026-09-22 launch (sources/2026-09-22-databricks-genie-one-mcp-give-any-ai-agent-the-right-business-context) frames the problem as direct data access ≠ business context: connecting a general-purpose agent straight to structured/unstructured sources gives it access but not the shared, governed meaning it needs to answer reliably. Four failure modes of direct access (verbatim framing):

  • Accuracy — direct access doesn't tell the agent which sources, definitions, or SQL joins are approved.
  • Cost & latency — the agent must repeatedly inspect schemas, docs, and relationships, burning tokens and slowing responses.
  • Governance — direct connections make consistent per-user access enforcement in the end user's context hard.
  • Consistency — without shared context, each client/model/session can interpret definitions differently.

Genie One MCP's answer: expose one intent surface (a natural-language question) backed by Genie Ontology's approved definitions, trusted relationships, and authority ranking, with Unity Catalog permission enforcement carried through. This is a concrete instance of patterns/mcp-as-centralized-integration-proxy (one governed intent surface in front of the enterprise's analytics, consumed uniformly by every agent) and of concepts/governed-agent-data-access.

Named client integrations: ChatGPT Business, Claude Cowork, Microsoft Copilot Cowork, and coding agents including Claude Code (via the ug claude command against the workspace's Claude serving endpoint). Worked scenarios in the post: campaign-performance review (ChatGPT + governed attribution/campaign/spend/lead data), monthly business review (Claude Cowork + official forecast + approved margin definition), customer-retention review (Copilot + governed customer/usage/support/contract context).

The five-tool MCP contract

Genie One MCP interprets the business terminology, searches permitted enterprise data, generates and runs SQL, and returns a grounded answer with Databricks source links. It exposes five tools:

Tool Role
genie_ask Starts a response; returns conversation_id + response_id.
genie_poll_response Returns progress steps and, on completion, the answer with an Explore in Databricks deep link.
genie_get_query_result Returns the full result set when the truncated response is insufficient.
genie_cancel_response Stops an in-flight turn.
view_ask On clients that support MCP Apps, replaces genie_ask — renders an interactive panel with progress, visualizations, and Genie Ontology citations inline.

A warehouse_id _meta parameter pins execution to a specific SQL warehouse.

MCP Apps (the ext-apps extension) lets the server return an interactive view instead of plain text; clients without MCP Apps support automatically fall back to text-only results.

Identity and access control

Because agents query through Genie One rather than the underlying tables, Genie One determines which metrics users can access and how they're computed — so user identity must flow through the request.

  • On-behalf-of (OBO) is recommended. The external assistant passes the end user's OAuth token; Genie evaluates Unity Catalog privileges, row filters, and column masks in that user's context. "Two users can ask the same question in the same client and receive appropriately scoped answers without per-user prompt logic." Deep links open only assets the user can access (patterns/on-behalf-of-agent-authorization, concepts/attribute-based-access-control).
  • M2M flattens identity. Machine-to-machine service-principal auth is available for external-facing integrations but "represents every caller as one identity, removing per-user permission enforcement and potentially limiting personalization and memory."
  • External MCP connections are Unity Catalog objects governed through standard grants. The Access Genie everywhere guidance covers U2M / M2M / OBO patterns and their governance implications.

Management and monitoring

  • Managed MCP servers are listed under Agents > MCPs and visible in Unity Gateway (see systems/unity-ai-gateway). Genie chat events land in audit logs, SQL execution in Query History, consumption in billing system tables.
  • Tune Genie One in one place — the MCP server honors workspace instructions, certification, and Genie Agents curation configured in Databricks; "Don't attempt to steer Genie One from the client's system prompt."
  • Prefer the scoped Genie Agent MCP server at /api/2.0/mcp/genie/{genie_space_id} when a use case maps to one curated domain — a single read-only agent with its own instructions and trusted SQL, "easier to benchmark and to scope."
  • One OAuth application per client platform, minimum scope, token lifetimes matching identity policy (concepts/oauth-token-lifecycle).
  • Account for the 90-second SQL execution timeout and the workspace Genie QPM limit when sizing a rollout (Genie-Agent-routed questions count against QPM).
  • Validate governance by impersonation — ask the same question as members of different groups and confirm answers diverge as expected.

Genie One as an agent-observability surface (prior disclosure)

Genie One was already on the wiki as a diagnosis surface in the 2026-09-01 "How we eliminated $1M/year of wasted AI agent spend" post (sources/2026-09-01-databricks-how-we-eliminated-1-million-a-year-of-wasted-ai-agent-spend): pointed at Unity Gateway's unified OTel trace table of MCP tool calls, it answered — in plain English — which tool errors recur, how many turns each takes to recover, and what each costs. The 2026-09-22 disclosure is the mirror image: Genie One is not only a consumer of MCP traces, it is now exposed as an MCP tool to external agents.

What's not disclosed

  • No QPS / latency / adoption numbers (only the 90-second SQL timeout and the unspecified workspace QPM limit).
  • Ontology-internal mechanism (definition resolution, authority ranking, staleness bounds) — see systems/databricks-genie-ontology and the 2026-09-15 source; this launch is about the access surface.
  • The exact OBO token-exchange flow and downstream validation shape.
  • Whether/how the interactive MCP Apps view is cached or re-rendered per turn.

Seen in

Last updated · 766 distilled / 2,225 read