Research investigation R0922 / claim audit

Databricks Genie One MCP: Does “Governed” Cover the Write Surface?

The reviewed public record documents layered identity, provider-permission, and logging controls, but connector-specific approval, cancellation, rollback, and recovery rules remain unevenly specified. Genie One MCP’s documented tool surface is distinct from the separate SaaS connector write surface.

Current public editionv1Sep 28, 2026
Verified observations
8

4 measured fields

Supported claims
8

8 material findings

Cited sources
8

8 primary or authoritative

Research score
86

Automated topic and evidence score

Interactive figureDatabricks Genie One MCP: Does “Governed” Cover...
CSV JSON
Data status1 verified record across 1 period

Snapshot only. There is not enough history to claim a trend yet.

Verified observationHover or focus any mark for exact valuesLast updated Sep 28, 2026

Version ledger

Frozen public editions

Each edition preserves the records, method, sources, and downloads available at publication time.

  1. v1 / latestSep 28, 20268 records / 8 sources

    Initial public snapshot with 8 records and 8 cited sources.

Coverage note

Bounded to eight supplied official Databricks documentation and API-reference pages. The assessment covers public documentation available by the stated cutoff, not provider-native recovery features, undisclosed implementations, or future orchestration paths.

Dataset ID
spd:databricks-genie-one-mcp-does-governed-cover-the-write-surface-7bfaad9e
Stable URL
/research/databricks-genie-one-mcp-does-governed-cover-the-write-surface-7bfaad9e
Version
v1
Coverage
2026-09-22
Records
8
Fields
7
Updated

Read the data

The records behind the figure

CSV JSON
Databricks Genie One MCP: Does “Governed” Cover the Write Surface? data records
EntityMetricValueUnitObservedSourceTransform
MCP Service ASK policyapproval reuse windowAn approved identical tool call is not prompted again within the documented cache window.hour2026-09-22https://docs.databricks.com/aws/en/data-governance/unity-catalog/service-policies/create-service-policy—
Atlassiandocumented connector action surfaceSearch and update Jira and Confluence.—2026-09-22https://docs.databricks.com/gcp/en/genie-one/external-sources—
GitHubdocumented connector action surfaceSearch and update repositories, issues and pull requests; writes are limited to file contents, issues and pull requests.—2026-09-22https://docs.databricks.com/gcp/en/genie-one/external-sources—
Google Workspacedocumented connector action surfaceDrive: search/read; create Docs, Sheets and Slides; edit only Docs created through the connector. Gmail: search/read and draft, but not send or edit existing messages. Calendar: search/read and create events.—2026-09-22https://docs.databricks.com/gcp/en/genie-one/external-sources—
Microsoft 365documented connector action surfaceSearch/read SharePoint, Teams, Outlook and Calendar; draft Outlook email but not send it.—2026-09-22https://docs.databricks.com/gcp/en/genie-one/external-sources—
Slackdocumented connector action surfaceSearch messages and channels and send messages; messages cannot be edited or deleted after sending through the connector.—2026-09-22https://docs.databricks.com/gcp/en/genie-one/external-sources—
Per-user MCP credentialdocumented token-expiry observabilityAPI returns access_token_expiration and, when applicable, refresh_token_expiration, plus provisioning state.—2026-09-22https://docs.databricks.com/api/ai-gateway/v1/create-mcp-service-user-mapped-credential—
External MCP clientminimum protocol version for ASK approval2025-11-25 or later—2026-09-22https://docs.databricks.com/aws/en/data-governance/unity-catalog/service-policies/create-service-policy—

Measurement technique

How to read this report

  1. 01Evidence-matrix plan: separate the Genie One MCP analytics tools from native Genie One connections and separate system.ai SaaS MCP services before assessing write controls.
  2. 02For each connector, classify explicitly documented actions as search/read, draft, create, edit, update, or send; treat unlisted actions as unspecified rather than unavailable.
  3. 03Map documented controls by action class: external-client identity, Unity Catalog privileges, individual provider authentication, OAuth scope or GitHub App permissions, approval, logging, token lifecycle, cancellation, and recovery.
  4. 04Control ledger: Google Workspace supports search/read, Gmail drafts, calendar-event creation, and creation of Drive documents, with Docs editing limited to connector-created Docs. Microsoft 365 supports search/read and Outlook drafts. Atlassian supports search and updates. Slack supports search and message sending, without connector editing or deletion after send. GitHub supports search and updates to file contents, issues, and pull requests.
  5. 05Distinguish maximum provider authorization from documented exposed connector actions: requested OAuth grants or GitHub App permissions can exceed the narrower action descriptions.
  6. 06Treat ASK as a general beta service-policy control: it pauses a call before execution, requires compatible external MCP clients, and reuses approval for an identical call within the documented one-hour cache window. The reviewed material does not map default approval requirements to each connector action.
  7. 07Record logging separately from enforcement: Unity Gateway documentation describes audit and usage logging, while optional traces can include caller identity, serialized requests and responses, status, policy decisions, and failure classifications.
  8. 08Preserve the evidence cutoff of September 22, 2026, 20:31 UTC; recovering the supplied evidence packet is not new collection or experimentation.
Next report / 01AI Model Economics Index All research reports
YOUR READING SPACE

Notifications