Connect a Genie Agent to external tools and sources

A Genie Agent can use Databricks-provided MCP (Model Context Protocol) connectors to pull context from and take actions in external tools and sources during an Agent mode conversation. An agent author attaches the connectors, and each user authenticates to them individually. Every tool call runs with the permissions of the user who asks the question.

Important

This feature is in Beta. To use it, a workspace admin must turn on Connect external tools in Genie Agents from the Previews page. See Manage Azure Databricks previews.

Note

Genie Agents were formerly known as Genie Spaces.

How MCP connectors work in a Genie Agent

MCP connectors let a Genie Agent combine its SQL and file analysis with the external applications your organization already uses. For example, a single conversation can analyze a sales table, pull related context from Google Drive, and draft a summary email. Azure Databricks governs every tool call through Unity Catalog and Unity Gateway. See Govern an MCP.

MCP tools fall into two categories:

  • Read-only tools (search, fetch, and list) run automatically.
  • Write tools (for example, sending a message or drafting an email) pause and ask the user to approve the action before it runs.

Genie Agents support the following Databricks-provided MCP connectors:

  • Google Drive: Search and create Google Docs, Sheets, and Slides; edit Docs it created.
  • Gmail: Search, read, and draft email.
  • Google Calendar: Search and create calendar events.
  • Microsoft 365: Search SharePoint, Teams, Outlook, and Calendar; draft Outlook email.
  • Atlassian: Search and update Jira and Confluence.
  • Glean (Beta): Search across your organization's connected apps using Glean.
  • Slack: Search Slack messages and channels, and send messages.
  • GitHub: Search and update repositories, issues, and pull requests.

Requirements

The following requirements apply to the agent and its users:

  • Both the Workspace access and Databricks SQL access entitlements for every user of the agent. Consumer-only, Databricks SQL-only, and account-only users can't use MCP tools. See Access entitlements.
  • An account in each connected external system for every user of the agent.

Add connectors to a Genie Agent

To attach connectors to a Genie Agent:

  1. Open your Genie Agent.
  2. Open the Sources tab, then click Add.
  3. Select one or more MCP Services.

To attach a connector, you need EXECUTE on the connector's MCP Service in Unity Catalog, plus USE CATALOG and USE SCHEMA on its parent catalog and schema. Connectors you don't have permission to run are unavailable. See Databricks-provided MCPs.

Configure tools

After you attach a connector, configure how the agent uses it:

  • Add a clear Description that explains how and when the agent should use the connector's tools. For example, you can instruct the agent on a required ticket-title format or tell it to look up a user's profile at the start of each conversation.
  • Enable or disable individual tools within a connector to scope which actions the agent can take.

Use MCP tools in a conversation

To use MCP tools in a Genie Agent:

  1. Open a Genie Agent that has MCP connectors attached.
  2. Turn on Agent mode in the chat box.
  3. Authenticate to the connector from the Configure panel. If the agent needs a connector you haven't authorized, or your authentication has expired, the agent prompts you to sign in.
  4. Send a prompt that uses the connector. When the agent calls a write tool, choose Allow once to approve the single action, Always allow in this chat to approve that tool for the rest of the conversation, or Reject to decline it.

To confirm a connector works, ask a question that requires it, for example "Search my Google Drive for the Q3 sales plan." The agent cites the external resource it used in its response.

Limitations

The following limitations apply:

  • MCP tools run only in Agent mode. They don't run in Chat mode.
  • Through the Agent mode APIs, only read tools work, and users can't authenticate to a connector. Complete authentication and write-tool approval in the UI.
  • For compliance guidance for connected applications, see External provider requirements.

The following sections describe limitations for specific connectors.

Google Drive

  • When authorizing Google Drive, you might see an Unverified app screen. Click Advanced and continue the authorization process.
  • Maximum file size is 25 MB.
  • Only native Google Workspace files (Docs, Sheets, Slides) are supported. PDFs, images, and other binary formats are not supported.
  • The connector can create Google Docs, Sheets, and Slides, and edit Google Docs it created. It can't edit Docs created outside the connector, or edit existing Sheets or Slides.
  • Reading a very large document can be slow.

Note

The use and transfer of raw or derived user data received from Google Workspace APIs will adhere to the Google API services User Data Policy, including the Limited Use requirements.

Gmail

  • The connector can search, read, and draft email, but it can't send email or edit existing messages.
  • The connector can't add Drive files as native Gmail attachments. As a workaround, include links to the files in the email body.

Microsoft 365

  • Includes SharePoint, Teams, Outlook, and Calendar.
  • The connector can draft Outlook email but can't send it.
  • Maximum file size is 25 MB for SharePoint files.
  • Supported SharePoint file types include built-in SharePoint documents, spreadsheets, and presentations, as well as common text-based formats such as .txt, .csv, .json, .md, and others. PDFs, images, and other binary formats are not supported.

Glean (Beta)

  • Glean is search-only. It can't read a document from a direct link.
  • A metastore admin must first configure the Glean tenant ID before non-admin users can use the connection. The admin can enter the tenant ID when first connecting to Glean.
  • To connect to a specific Glean MCP server, a metastore admin can optionally set the MCP server path (for example, /mcp/eng) when setting up the connection. Leave this field blank to use the default path (/mcp/default). Non-admin users cannot specify or change the Glean MCP server path.

Slack

  • The connector can't edit or delete a message after sending it.

GitHub

  • Writes are limited to file contents, issues, and pull requests.
  • By default, the Databricks GitHub MCP connector can access only public repositories. To give the connector read access to your private enterprise repositories, a GitHub organization admin must complete additional setup. See GitHub private repositories.
  • GitHub Enterprise Server (the self-hosted version of GitHub) is not supported.

Additional resources

See the following resources for related information: