Research investigation R0922 / claim audit
Databricks Genie One MCP: Does “Governed” Cover the Write Surface?
The reviewed public record documents layered identity, provider-permission, and logging controls, but connector-specific approval, cancellation, rollback, and recovery rules remain unevenly specified. Genie One MCP’s documented tool surface is distinct from the separate SaaS connector write surface.
Snapshot only. There is not enough history to claim a trend yet.
Version ledger
Frozen public editions
Each edition preserves the records, method, sources, and downloads available at publication time.
Bounded to eight supplied official Databricks documentation and API-reference pages. The assessment covers public documentation available by the stated cutoff, not provider-native recovery features, undisclosed implementations, or future orchestration paths.
- Dataset ID
- spd:databricks-genie-one-mcp-does-governed-cover-the-write-surface-7bfaad9e
- Stable URL
- /research/databricks-genie-one-mcp-does-governed-cover-the-write-surface-7bfaad9e
- Version
- v1
- Coverage
- 2026-09-22
- Records
- 8
- Fields
- 7
- Updated
Measurement technique
How to read this report
- 01Evidence-matrix plan: separate the Genie One MCP analytics tools from native Genie One connections and separate system.ai SaaS MCP services before assessing write controls.
- 02For each connector, classify explicitly documented actions as search/read, draft, create, edit, update, or send; treat unlisted actions as unspecified rather than unavailable.
- 03Map documented controls by action class: external-client identity, Unity Catalog privileges, individual provider authentication, OAuth scope or GitHub App permissions, approval, logging, token lifecycle, cancellation, and recovery.
- 04Control ledger: Google Workspace supports search/read, Gmail drafts, calendar-event creation, and creation of Drive documents, with Docs editing limited to connector-created Docs. Microsoft 365 supports search/read and Outlook drafts. Atlassian supports search and updates. Slack supports search and message sending, without connector editing or deletion after send. GitHub supports search and updates to file contents, issues, and pull requests.
- 05Distinguish maximum provider authorization from documented exposed connector actions: requested OAuth grants or GitHub App permissions can exceed the narrower action descriptions.
- 06Treat ASK as a general beta service-policy control: it pauses a call before execution, requires compatible external MCP clients, and reuses approval for an identical call within the documented one-hour cache window. The reviewed material does not map default approval requirements to each connector action.
- 07Record logging separately from enforcement: Unity Gateway documentation describes audit and usage logging, while optional traces can include caller identity, serialized requests and responses, status, policy decisions, and failure classifications.
- 08Preserve the evidence cutoff of September 22, 2026, 20:31 UTC; recovering the supplied evidence packet is not new collection or experimentation.
Sources
Evidence
1 publisher supporting 8 records. Expand a publisher to inspect its cited pages.