Notă
Accesul la această pagină necesită autorizare. Puteți încerca să vă conectați sau să modificați directoarele.
Accesul la această pagină necesită autorizare. Puteți încerca să modificați directoarele.
In this tutorial, you govern a coding agent's access to GitHub using Unity Catalog and AI Gateway. Suppose your team uses a coding agent such as Claude Code or Cursor to read repositories and pull requests, but you want to block write operations and audit every tool call.
You use the system.ai.github MCP Service that Azure Databricks provides, so you don't host or register an MCP server or create a Unity Catalog connection. You attach a built-in service policy to block write operations, grant your team access, connect a coding agent, and confirm that every tool call is logged.
Prerequisites
A workspace enabled for Unity Catalog. See Get started with Unity Catalog.
The Unity Gateway beta features enabled for your account. An account admin can enable them from the account console Previews page. See Manage Azure Databricks previews.
The following privileges on the built-in service
system.ai.github:MANAGE, to attach a service policy.EXECUTE, to invoke the service and to grant access to others.
To use the REST API in Step 1, authenticate the Azure Databricks CLI to your workspace.
If your workspace uses a restricted serverless network policy, an account admin must allow the destinations required by the GitHub MCP Service.
Find the required domains
To find the required domains, connect your agent in Step 3 and try a read-only GitHub tool. If the network policy blocks the call, the error names the denied domain (
Access to <fqdn> is denied because of serverless network policy). An account admin can add that domain to Allowed domains in the network policy and retry.If the call still fails, check the outbound network denial logs after another test call. Replace
<workspace-id>with your workspace ID. Thesystem.accessschema must be enabled to query the table.SELECT event_time, destination FROM system.access.outbound_network WHERE workspace_id = '<workspace-id>' AND destination_type = 'DNS' AND access_type = 'DROP' AND event_time >= current_timestamp() - INTERVAL 15 MINUTES ORDER BY event_time DESC;The table doesn't identify the MCP Service, so compare
event_timewith the test call. Denial logs can take time to appear. Add any required domains to Allowed domains and retry until the read-only tool succeeds. See Outbound network access events for more about these records.
Step 1: Block write operations with a built-in policy
Attach the built-in GitHub service policy and enable Disallow writes. This blocks tools that create, modify, or delete data on GitHub while allowing read-only tools. The policy is platform-managed, so you don't need to write a policy function.
UI
- In the workspace sidebar, click AI Gateway.
- On the MCPs tab, select
system.ai.github. - Open the Policies tab, then click New policy.
- Enter a policy name, such as
block_github_writes. - Under Guardrail type, select GitHub.
- Select Disallow writes, then click Create policy.
REST API
The API policy uses the system.ai.github_policy handler with disallow_writes set to true:
databricks api patch \
"/api/2.1/unity-catalog/mcp-services/system.ai.github?update_mask=config.service_policies" \
--json '{
"config": {
"service_policies": [
{
"name": "block_github_writes",
"policy_type": "POLICY_TYPE_BUILTIN",
"handler": "system.ai.github_policy",
"options": { "disallow_writes": "true" }
}
]
}
}'
The PATCH replaces the service's policy list. If the service already has policies, include them in service_policies so they remain attached.
With the policy attached, a tools/call for a write tool is rejected, including tools that create pull requests. To allow selected write tools while blocking destructive operations, create a custom service policy instead. For more about the available services and policy controls, see Databricks-provided MCP Services and Service policies.
Step 2: Share the MCP Service with your team
Users need EXECUTE on the MCP Service, plus USE CATALOG and USE SCHEMA on system and system.ai. To grant your developer team EXECUTE from the UI:
- In the AI Gateway, go to the MCPs tab and select the MCP Service to share, such as
system.ai.github. - Go to the Permissions tab.
- Click Grant.
- Select the principal to allow to invoke the MCP Service, such as
dev_team, select the EXECUTE privilege, and click Grant. See Grant access to an MCP Service for more about service permissions.
Note
To grant access on an MCP Service in system.ai, a metastore admin must first grant themselves MANAGE on the system.ai schema.
Check for existing grants on system.ai before treating this as team-only access. A broad schema-level EXECUTE grant can let other users invoke the service even after you grant dev_team access. To replace the default schema grant with policies for approved MCP Services, see Govern models and MCPs with GRANT policies. That change affects other executable objects in system.ai as well.
Step 3: Connect your coding agent
Install an MCP-capable coding agent if you don't already have one. Use the Unity Gateway CLI (ug) to configure the gateway connection and launch the agent on your device. For example, ug claude opens Claude Code with that configuration. To configure a client yourself, follow the manual setup below.
If
ugisn't installed, install it and check the version. You need Python 3.12 or later anduv. See the coding agent quickstart for installation details.uv tool install git+https://github.com/databricks/unity-gateway ug --versionConfigure your coding agent for your workspace and sign in when prompted. If your device is already configured, skip this step.
ug configure --workspace https://<workspace-hostname>Add the GitHub MCP Service to your configured agents. If your admin's published configuration already added it, skip this step.
ug mcp add --names system.ai.githubConfirm that the service appears in your configured connections:
ug mcp listLaunch or restart your agent to use the service. For example, launch Claude Code:
ug claudeIn Claude Code, enter
/mcpto check the connection status. For other launch commands and MCP setup options, see Add tools and skills and the ug CLI reference.
For manual setup, follow Connect MCPs to AI assistants and coding agents for Claude Code, Cursor, and other clients. Use this MCP endpoint for the built-in service:
https://<workspace-url>/ai-gateway/mcp-services/system.ai.github
For invocation examples, including the OpenAI Agents SDK, see Invoke the MCP Service.
Step 4: Confirm activity is governed and logged
Verify that governance is working from both ends:
Policy enforcement: From the agent, a read-only tool succeeds, while a write tool, such as one that creates a pull request, is rejected with a policy error.
Usage logging: Query the usage system table to confirm calls are recorded:
SELECT service_name, mcp_metadata.tool_name AS tool_name, status_code, COUNT(*) AS calls FROM system.ai_gateway.usage WHERE service_type = 'MCP_SERVICE' AND service_name = 'system.ai.github' GROUP BY service_name, mcp_metadata.tool_name, status_code ORDER BY calls DESC;
For more about monitoring, see Monitor usage and activity.