Our Review Finds Databricks Has No Public Map for SaaS Write Approvals

A documentation review completed September 22 finds layered access controls and detailed traces around Genie One-related connectors, but not a connector-by-connector account of when writes pause for approval or how they can be reversed.

By 5 min read
Original researchDatabricks Genie One MCP: Does “Governed” Cover the Write Surface?

The reviewed public record documents layered identity, provider-permission, and logging controls, but connector-specific approval, cancellation, rollback, and recovery rules remain unevenly specified. Genie One MCP’s documented tool surface is distinct from the separate SaaS connector write surface.

Explore the full research
Our Review Finds Databricks Has No Public Map for SaaS Write Approvals
Superpower DailyOriginal research
Our Review Finds Databricks Has No Public Map for SaaS Write Approvals

Listen to this story

The audio brief

About 1:38
0:001:38
Read transcript
Databricks’ public documentation still doesn’t tell administrators, connector by connector, which workplace-software changes need human approval—or how to undo them. That’s the finding of a review completed September twenty-second. The gap matters because Genie One can do more than retrieve company information. Depending on the connection, it can draft Gmail, create calendar events and files, send Slack messages, or update GitHub and Atlassian records. Microsoft 365 is documented as draft-only. Those are different levels of real-world impact, not one uniform agent-writing capability. There’s an important boundary: Databricks documents its external MCP service for analytics tasks, such as asking questions of data and retrieving results. It does not automatically grant access to these separate software connectors. The platform also documents broad controls. Unity Gateway can allow, deny, or pause a call for approval. For external agents, that flow requires MCP protocol version dated November twenty-fifth, twenty twenty-five, or later. An identical approved call can be remembered for an hour. Databricks also describes detailed audit logs and traces. But the review found no public map tying approval defaults to each connector action, and no shared cancellation or rollback process. One specific limit: a Slack message can’t be edited or deleted through the connector after it’s sent. For other updates, recovery may depend on the provider or a customer’s own workflow. So the operational question remains: can teams verify approval behavior and a recovery path before enabling each specific write?

Story brief

3 key points

A bounded review through September 22 finds Databricks’ public materials do not provide a connector-level map of approval defaults or recovery paths for agent-initiated SaaS changes. Genie One exposes different write capabilities across Google Workspace, Microsoft 365, Atlassian, Slack, and GitHub, while Unity Gateway documents broad policy and audit controls. ASK approvals can pause calls and identical...

  1. 01

    Genie One’s external MCP service is documented for analytics workflows, not as an automatic gateway to SaaS write tools.

  2. 02

    Documented write surfaces vary: Slack can send messages; GitHub can update files, issues, and pull requests; Microsoft 365 is draft-only.

  3. 03

    Unity Gateway supports ALLOW, DENY, and ASK policies; external approval requires MCP protocol version 2025-11-25 or later.

A bounded review completed September 22 finds that Databricks’ public documentation does not provide a complete connector-by-connector specification for AI-agent writes into workplace software. Genie One-related connectors have different documented actions and layered authorization, while Unity Gateway offers detailed logging; default approval rules and a uniform cancellation or rollback path are not publicly mapped to each write action.

That is a material distinction for agents that can do more than retrieve company context. A draft email, a newly created calendar event, a Jira update, a Slack message, or a GitHub change can alter the systems where teams communicate and run work. General governance capabilities matter, but administrators also need to know what happens before and after a particular action executes.

The review separates analytics from connected applications

The review covers Databricks material available through September 22 for Google Workspace, Microsoft 365, Atlassian, Slack, and GitHub. It distinguishes the generally available Genie One MCP service from the connected SaaS services and native Genie One connections that can reach third-party applications.

That separation matters because the external Genie One server is documented as an analytics toolset. It can start a natural-language data question, poll for a response, retrieve query results, request cancellation of an in-flight response, and render an interactive view. Databricks documents Slack, GitHub, Atlassian, Google, and Microsoft 365 separately; a client connected only to system.ai.genie_one_mcp is not documented as automatically receiving their write tools.

Where the controls differ

The documented action surface is uneven by design. Google Workspace connections can search and read, draft Gmail messages, create calendar events, and create Google Docs, Sheets, and Slides. Editing is more limited: the connector can edit only Google Docs it created. Microsoft 365 is documented for search and Outlook drafts, not sending. Atlassian can search and update Jira and Confluence; Slack can search and send messages; GitHub can search and update file contents, issues, and pull requests.

The access boundaries

  • Calling an MCP service requires Unity Catalog EXECUTE privileges and access to its parent catalog and schema.
  • Users authenticate individually to connected providers, and their own provider permissions still restrict effective access.
  • OAuth scopes and GitHub App permissions define the maximum actions a connection can attempt, not a published list of every tool the connector exposes.

That final distinction makes consent screens an incomplete guide to connector behavior. Databricks’ managed OAuth reference lists Gmail modify access, Microsoft SharePoint read-write and Teams sending permissions, Slack canvas-write permission, and GitHub read-write permissions. Yet the Genie One connector page describes narrower exposed actions in several cases, including Gmail and Outlook drafting rather than sending. Provider authorization establishes an outer boundary; it does not establish the tool surface by itself.

Approval can pause a call, but defaults remain unclear

Unity Gateway service policies can return ALLOW, DENY, or ASK. ASK pauses a call before execution for human approval. For external agents, the MCP client must support protocol version 2025-11-25 or later, and approval for an identical call is cached for one hour. Databricks’ examples include blocking a GitHub push and requiring approval before repository deletion, demonstrating a policy model that can operate on individual tool calls.

The uncertainty is how that general mechanism applies to Databricks-managed SaaS services. Databricks says built-in services use platform-managed tools and built-in service policies, governed with grants rather than custom tool selection or policy functions. Its external-source documentation also says the gateway applies built-in policies and approval requirements. The reviewed pages do not identify which listed connector writes require approval by default.

Logs are detailed; recovery is connector-specific

Observability is the most fully described control layer. Unity Gateway records MCP activity in usage and audit tables, including call volume, errors, latency, control-plane changes, and invocations. With account-level trace logging enabled, the unified trace table can capture caller identity, tool names and arguments, serialized requests and responses, HTTP and JSON-RPC status, policy decisions, and failure classifications such as policy denial or upstream error.

What remains unspecified

The review found no uniform connector-level cancellation or rollback control in the bounded documentation. Genie One’s cancellation tool concerns an in-flight analytics response, not a SaaS write. Slack messages cannot be edited or deleted through the connector after sending. Gmail and Microsoft 365 email are draft-only in the documented Genie One experience, and Google Docs editing is limited to documents created through the connector. Recovery behavior for Atlassian and GitHub updates is not specified in the reviewed pages.

This is not evidence that recovery is impossible in a provider product or a customer workflow. It establishes a narrower point: the public documents reviewed here do not show one shared recovery model across these services. Teams considering agent-driven writes therefore need to evaluate the exposed action, the provider permissions behind it, any applicable approval setting, and what the destination system allows after the change is made.

Editorial analysis

Our Read

Databricks’ Genie One MCP launch positioned Unity Gateway as a common governance layer for outside AI agents. This review narrows the practical question that follows: central controls are not the same as a predictable operating rule for every action an agent can take in a work system. The most useful next evidence would be an action-level policy map for managed connectors, showing which exposed writes require approval and what recovery options apply after execution. That would make the gateway’s governance model easier to evaluate before organizations give agents authority beyond search and drafting.

Citation desk / original work

Cite this

Permanent attributionView citation
Finding 01

The public documentation separates Genie One MCP from the write-capable SaaS connector surface. Genie One MCP exposes analytics-oriented ask, poll, result-fetch, cancel, and view tools; Slack, GitHub, Atlassian, Google, and Microsoft connectors are separate system.ai MCP Services or native Genie One connections. An external client connected only to system.ai.genie_one_mcp is not documented as automatically receiving those connector write tools.

/posts/databricks-public-docs-leave-key-saas-write-controls-unspecified#finding-claim-1
Finding 02

Human approval is available as a general Beta service-policy outcome, but connector-by-connector confirmation is not uniformly specified. ASK pauses a call before execution, requires an external MCP client supporting protocol version 2025-11-25 or later, and caches approval for an identical call for one hour. Separately, Databricks says built-in SaaS services use platform-managed tools and policies and are governed with grants rather than custom tool selection or policy functions, leaving the exact default approval rule for each write action unresolved.

/posts/databricks-public-docs-leave-key-saas-write-controls-unspecified#finding-claim-5
Finding 03

The documented native action surface is uneven: Google Workspace supports search/read, drafts, creation, and limited editing; Microsoft 365 supports search/read and Outlook drafts; Atlassian supports search and updates; Slack supports search and sending messages; GitHub supports search and updates to file contents, issues, and pull requests.

/posts/databricks-public-docs-leave-key-saas-write-controls-unspecified#finding-claim-2

Sources

  1. docs.databricks.comdocs.databricks.com
  2. docs.databricks.comdocs.databricks.com
  3. docs.databricks.comdocs.databricks.com
  4. docs.databricks.comdocs.databricks.com
  5. docs.databricks.comdocs.databricks.com
  6. docs.databricks.comdocs.databricks.com
  7. docs.databricks.comdocs.databricks.com

Loading discussion...

YOUR READING SPACE

Notifications