{"title":"Databricks Genie One MCP: Does “Governed” Cover the Write Surface?","description":"The reviewed public record documents layered identity, provider-permission, and logging controls, but connector-specific approval, cancellation, rollback, and recovery rules remain unevenly specified. Genie One MCP’s documented tool surface is distinct from the separate SaaS connector write surface.","dataset_id":"spd:databricks-genie-one-mcp-does-governed-cover-the-write-surface-7bfaad9e","canonical_url":"https://superpowerdaily.com/research/databricks-genie-one-mcp-does-governed-cover-the-write-surface-7bfaad9e","version_url":"https://superpowerdaily.com/research/databricks-genie-one-mcp-does-governed-cover-the-write-surface-7bfaad9e/versions/v1","version":"v1","snapshot_hash":"7eb9e993289be4989162be4cf375d4f1e8cbca68e67f5d3123b6cc86527eb07c","date_created":"2026-09-28T16:02:06.823Z","date_modified":"2026-09-28T16:02:06.823Z","license":{"name":"Superpower Daily data reuse terms","url":"https://superpowerdaily.com/terms"},"license_url":"https://superpowerdaily.com/terms","temporal_coverage":"2026-09-22","coverage_note":"Bounded to eight supplied official Databricks documentation and API-reference pages. The assessment covers public documentation available by the stated cutoff, not provider-native recovery features, undisclosed implementations, or future orchestration paths.","measurement_technique":["Evidence-matrix plan: separate the Genie One MCP analytics tools from native Genie One connections and separate system.ai SaaS MCP services before assessing write controls.","For each connector, classify explicitly documented actions as search/read, draft, create, edit, update, or send; treat unlisted actions as unspecified rather than unavailable.","Map documented controls by action class: external-client identity, Unity Catalog privileges, individual provider authentication, OAuth scope or GitHub App permissions, approval, logging, token lifecycle, cancellation, and recovery.","Control ledger: Google Workspace supports search/read, Gmail drafts, calendar-event creation, and creation of Drive documents, with Docs editing limited to connector-created Docs. Microsoft 365 supports search/read and Outlook drafts. Atlassian supports search and updates. Slack supports search and message sending, without connector editing or deletion after send. GitHub supports search and updates to file contents, issues, and pull requests.","Distinguish maximum provider authorization from documented exposed connector actions: requested OAuth grants or GitHub App permissions can exceed the narrower action descriptions.","Treat ASK as a general beta service-policy control: it pauses a call before execution, requires compatible external MCP clients, and reuses approval for an identical call within the documented one-hour cache window. The reviewed material does not map default approval requirements to each connector action.","Record logging separately from enforcement: Unity Gateway documentation describes audit and usage logging, while optional traces can include caller identity, serialized requests and responses, status, policy decisions, and failure classifications.","Preserve the evidence cutoff of September 22, 2026, 20:31 UTC; recovering the supplied evidence packet is not new collection or experimentation."],"methodology":["Evidence-matrix plan: separate the Genie One MCP analytics tools from native Genie One connections and separate system.ai SaaS MCP services before assessing write controls.","For each connector, classify explicitly documented actions as search/read, draft, create, edit, update, or send; treat unlisted actions as unspecified rather than unavailable.","Map documented controls by action class: external-client identity, Unity Catalog privileges, individual provider authentication, OAuth scope or GitHub App permissions, approval, logging, token lifecycle, cancellation, and recovery.","Control ledger: Google Workspace supports search/read, Gmail drafts, calendar-event creation, and creation of Drive documents, with Docs editing limited to connector-created Docs. Microsoft 365 supports search/read and Outlook drafts. Atlassian supports search and updates. Slack supports search and message sending, without connector editing or deletion after send. GitHub supports search and updates to file contents, issues, and pull requests.","Distinguish maximum provider authorization from documented exposed connector actions: requested OAuth grants or GitHub App permissions can exceed the narrower action descriptions.","Treat ASK as a general beta service-policy control: it pauses a call before execution, requires compatible external MCP clients, and reuses approval for an identical call within the documented one-hour cache window. The reviewed material does not map default approval requirements to each connector action.","Record logging separately from enforcement: Unity Gateway documentation describes audit and usage logging, while optional traces can include caller identity, serialized requests and responses, status, policy decisions, and failure classifications.","Preserve the evidence cutoff of September 22, 2026, 20:31 UTC; recovering the supplied evidence packet is not new collection or experimentation."],"metrics":[{"label":"Verified observations","value":"8","detail":"4 measured fields"},{"label":"Supported claims","value":"8","detail":"8 material findings"},{"label":"Cited sources","value":"8","detail":"8 primary or authoritative"},{"label":"Research score","value":"86","detail":"Automated topic and evidence score"}],"columns":[{"key":"entity","label":"Entity"},{"key":"metric","label":"Metric"},{"key":"value","label":"Value"},{"key":"unit","label":"Unit"},{"key":"observed","label":"Observed"},{"key":"source","label":"Source"},{"key":"transform","label":"Transform"}],"data":[{"unit":"hour","value":"An approved identical tool call is not prompted again within the documented cache window.","entity":"MCP Service ASK policy","metric":"approval reuse window","source":"https://docs.databricks.com/aws/en/data-governance/unity-catalog/service-policies/create-service-policy","observed":"2026-09-22","transform":null},{"unit":null,"value":"Search and update Jira and Confluence.","entity":"Atlassian","metric":"documented connector action surface","source":"https://docs.databricks.com/gcp/en/genie-one/external-sources","observed":"2026-09-22","transform":null},{"unit":null,"value":"Search and update repositories, issues and pull requests; writes are limited to file contents, issues and pull requests.","entity":"GitHub","metric":"documented connector action surface","source":"https://docs.databricks.com/gcp/en/genie-one/external-sources","observed":"2026-09-22","transform":null},{"unit":null,"value":"Drive: search/read; create Docs, Sheets and Slides; edit only Docs created through the connector. Gmail: search/read and draft, but not send or edit existing messages. Calendar: search/read and create events.","entity":"Google Workspace","metric":"documented connector action surface","source":"https://docs.databricks.com/gcp/en/genie-one/external-sources","observed":"2026-09-22","transform":null},{"unit":null,"value":"Search/read SharePoint, Teams, Outlook and Calendar; draft Outlook email but not send it.","entity":"Microsoft 365","metric":"documented connector action surface","source":"https://docs.databricks.com/gcp/en/genie-one/external-sources","observed":"2026-09-22","transform":null},{"unit":null,"value":"Search messages and channels and send messages; messages cannot be edited or deleted after sending through the connector.","entity":"Slack","metric":"documented connector action surface","source":"https://docs.databricks.com/gcp/en/genie-one/external-sources","observed":"2026-09-22","transform":null},{"unit":null,"value":"API returns access_token_expiration and, when applicable, refresh_token_expiration, plus provisioning state.","entity":"Per-user MCP credential","metric":"documented token-expiry observability","source":"https://docs.databricks.com/api/ai-gateway/v1/create-mcp-service-user-mapped-credential","observed":"2026-09-22","transform":null},{"unit":null,"value":"2025-11-25 or later","entity":"External MCP client","metric":"minimum protocol version for ASK approval","source":"https://docs.databricks.com/aws/en/data-governance/unity-catalog/service-policies/create-service-policy","observed":"2026-09-22","transform":null}],"sources":[{"url":"https://docs.databricks.com/aws/en/ai-gateway/unified-trace-table-reference","name":"Databricks","title":"docs.databricks.com","records":0},{"url":"https://docs.databricks.com/aws/en/data-governance/unity-catalog/service-policies/create-service-policy","name":"Databricks","title":"docs.databricks.com","records":2},{"url":"https://docs.databricks.com/gcp/en/genie-one/external-sources","name":"Databricks","title":"docs.databricks.com","records":5},{"url":"https://docs.databricks.com/aws/en/agents/mcp-tools/genie-mcp","name":"Databricks","title":"docs.databricks.com","records":0},{"url":"https://docs.databricks.com/aws/en/agents/mcp-tools/built-in-mcp-services","name":"Databricks","title":"docs.databricks.com","records":0},{"url":"https://docs.databricks.com/aws/en/agents/mcp-tools/managed-oauth","name":"Databricks","title":"docs.databricks.com","records":0},{"url":"https://docs.databricks.com/aws/en/ai-gateway/govern-mcp-service","name":"Databricks","title":"docs.databricks.com","records":0},{"url":"https://docs.databricks.com/api/ai-gateway/v1/create-mcp-service-user-mapped-credential","name":"Databricks","title":"Mcp Service | Databricks API Reference","records":1}],"provenance":{"publisher":"Superpower Daily","source_count":8,"source_urls":["https://docs.databricks.com/aws/en/ai-gateway/unified-trace-table-reference","https://docs.databricks.com/aws/en/data-governance/unity-catalog/service-policies/create-service-policy","https://docs.databricks.com/gcp/en/genie-one/external-sources","https://docs.databricks.com/aws/en/agents/mcp-tools/genie-mcp","https://docs.databricks.com/aws/en/agents/mcp-tools/built-in-mcp-services","https://docs.databricks.com/aws/en/agents/mcp-tools/managed-oauth","https://docs.databricks.com/aws/en/ai-gateway/govern-mcp-service","https://docs.databricks.com/api/ai-gateway/v1/create-mcp-service-user-mapped-credential"],"methodology":["Evidence-matrix plan: separate the Genie One MCP analytics tools from native Genie One connections and separate system.ai SaaS MCP services before assessing write controls.","For each connector, classify explicitly documented actions as search/read, draft, create, edit, update, or send; treat unlisted actions as unspecified rather than unavailable.","Map documented controls by action class: external-client identity, Unity Catalog privileges, individual provider authentication, OAuth scope or GitHub App permissions, approval, logging, token lifecycle, cancellation, and recovery.","Control ledger: Google Workspace supports search/read, Gmail drafts, calendar-event creation, and creation of Drive documents, with Docs editing limited to connector-created Docs. Microsoft 365 supports search/read and Outlook drafts. Atlassian supports search and updates. Slack supports search and message sending, without connector editing or deletion after send. GitHub supports search and updates to file contents, issues, and pull requests.","Distinguish maximum provider authorization from documented exposed connector actions: requested OAuth grants or GitHub App permissions can exceed the narrower action descriptions.","Treat ASK as a general beta service-policy control: it pauses a call before execution, requires compatible external MCP clients, and reuses approval for an identical call within the documented one-hour cache window. The reviewed material does not map default approval requirements to each connector action.","Record logging separately from enforcement: Unity Gateway documentation describes audit and usage logging, while optional traces can include caller identity, serialized requests and responses, status, policy decisions, and failure classifications.","Preserve the evidence cutoff of September 22, 2026, 20:31 UTC; recovering the supplied evidence packet is not new collection or experimentation."],"snapshot_hash":"7eb9e993289be4989162be4cf375d4f1e8cbca68e67f5d3123b6cc86527eb07c"},"distributions":{"csv":"https://superpowerdaily.com/api/research/databricks-genie-one-mcp-does-governed-cover-the-write-surface-7bfaad9e/versions/v1?format=csv","json":"https://superpowerdaily.com/api/research/databricks-genie-one-mcp-does-governed-cover-the-write-surface-7bfaad9e/versions/v1?format=json"}}