What you will be able to do
- Configure the workspace embedding policy and generate iframe embed code for a Genie space
- Add a Genie space as a Databricks Apps resource and call it from app code
- Pick the right authentication for Genie API integrations
- Configure the Slack and Microsoft Teams Genie apps, including the agent pinned to a channel and message visibility
1.Embedding a Genie space as an iframe
Embedding puts a Genie space inside an internal portal or tool, so people can ask questions without going to Databricks. Two roles are involved, and the order matters. First, a workspace admin chooses where embedding is allowed. Then an author with CAN MANAGE generates the iframe code. CAN EDIT is enough to change the space, but it is not enough to embed it.
The admin sets this up under Settings > Security > External access, in the Embed dashboards drop-down. The name is misleading: this one policy covers both dashboards and Genie spaces. There are three options. Allow permits any domain. Allow approved domains permits only the sites on a list the admin manages. Deny blocks embedding everywhere. Approved domains use Content Security Policy grammar, so *.databricks.com matches any subdomain but not another-databricks.com.
Checkpoint 1 of 6· Put it in order
Once the admin has allowed your domain, put the author's embedding steps in order
- 1.Paste the iframe code into your external website or application
- 2.Open the Genie space you want to embed
- 3.In the Share dialog, click Embed space
- 4.Copy the generated iframe code
- 5.Click Share
The embed code is generated in the same Share dialog you use for permissions, through its Embed space option.
“In the Share dialog, click Embed space.”Source: docs.databricks.com
<iframe src="<your-genie-space-url>" allow="clipboard-write" width="100%" height="600"></iframe>An embedded space is for asking questions only. Embedded users can send prompts but cannot change the configuration. They also need explicit access to the space and to its underlying data. Anyone not signed in to Databricks is asked to authenticate before they can use it.
Checkpoint 2 of 6· Check yourself
An author with CAN EDIT opens Share but cannot embed the space, even though the admin has allowed the portal's domain. What is missing?
Embedding needs at least CAN MANAGE. Clipboard access only turns on extra features, and an approved-domains policy is a valid setup.
“Agent author: Must have at least CAN MANAGE permission on the Genie Agent.”Source: docs.databricks.com
2.Adding a Genie space to a Databricks App
A Databricks App doesn't use an iframe. You attach the space as an app resource: in the App resources section, click + Add resource > Genie Agent, pick a space, and choose a permission level for the app. Databricks then grants that level to the app's service principal. Access covers only that one space, and other spaces have to be added as separate resources. The levels match the Share dialog, and the docs write them in title case here.
| Level | What the app's service principal can do |
|---|---|
| Can view | Read the Genie Agent configuration and metadata |
| Can run | Submit queries to the Genie Agent and receive responses |
| Can edit | Modify the Genie Agent configuration |
| Can manage | Full administrative access to the Genie Agent |
The two-credential rule applies to the app as well. Its service principal still needs USE CATALOG, USE SCHEMA and SELECT on the underlying tables and views. If you remove the resource later, the service principal loses access, but the space itself is not changed. At deploy time Databricks exposes the space ID as an environment variable, which you map in app.yaml using the resource key. The default key is genie-space.
env:
- name: GENIE_SPACE_ID
valueFrom: genie-space # Use your custom resource key if differentCheckpoint 3 of 6· Fill the gap
Which SDK method opens a new Genie conversation with the first question?
# Start a conversation with a natural language query
response = w.genie. ? (
space_id=space_id,
content="What were our top-selling products last quarter?"
)start_conversation_and_wait opens the conversation. create_message_and_wait is used afterwards for follow-up questions and needs a conversation_id.
Source: docs.databricks.comCheckpoint 4 of 6· Exam question
An analyst who holds CAN RUN permission on a published Genie space opens the Share dialog and looks for the option to generate an embeddable iframe for the space, but the option is greyed out. What is the most likely cause?
Correct answer: A — Generating embed code for a Genie space requires at least CAN MANAGE permission on that specific space, and CAN RUN alone does not unlock it.
- A. Correct. Generating an embeddable iframe is gated behind CAN MANAGE on the space, so a user with only CAN RUN can ask questions but will not see the embed-generation control unlocked.
- B. Account admins are not the only ones who can generate embed code; any user holding CAN MANAGE on the specific space can do so, without needing account-wide admin rights.
- C. There is no documented per-workspace cap on how many Genie spaces can be embedded, so a limit being reached is not the explanation for the control being unavailable.
- D. Embed generation is not tied to whether the backing warehouse is serverless or classic; warehouse type does not determine whether the Share dialog's embed option is enabled.
Sources3
3.Custom integrations through the Genie API
For your own chatbot or agent framework, the Genie API's Chat mode endpoints support stateful conversations with follow-up questions. You can call them over REST or through the Databricks SDKs, as in the app example above. Callers need the Databricks SQL entitlement and at least CAN USE on a pro or serverless warehouse. You can find a space ID with the List Genie Agents API or on the space's Settings tab.
Checkpoint 5 of 6· Check yourself
A nightly backend job with no user present posts Genie answers into a report. How should it authenticate to the Genie API?
Use U2M when a browser user is present. A headless job uses a service principal, and that principal needs its own data and warehouse permissions.
“In situations where browser-based authentication is not possible, use a service principal to authenticate with the API.”Source: docs.databricks.com
Sources4
4.Genie in Slack and Microsoft Teams
Both chat apps are in Public Preview, and an account admin has to enable them in the account console. A Slack workspace admin installs the Slack app, and a Microsoft 365 admin installs the Teams app from the Microsoft marketplace. By default, questions go to Genie One. A channel owner can pin a specific Genie space instead, which tells Genie One to send questions only to that space and gives more consistent answers for one use case. In Slack you run /databricks-genie config. In Teams you type config. If no space is pinned in Teams, the channel uses Genie One.
Visibility can be set at three levels, and higher levels override lower ones. A workspace admin controls the workspace level through the Allow connection to collaboration platforms and Allow public messages in collaboration platforms settings. In Teams, turning off public messages makes every response private. Responses are public by default, and visualizations only appear in public messages.
Checkpoint 6 of 6· Match them up
Match each message-visibility level to who sets it
Tap a term, then the definition that fits it.
Workspace settings override channel settings, and channel settings override personal ones.
“Higher levels override lower levels”Source: docs.databricks.com
Exam traps
Each one states something that sounds right. Open it to see what is actually true.
1.People using an embedded Genie space can adjust its instructions from inside the portal.Why is that wrong?
An embedded space only accepts questions. Configuration changes are made in Databricks by users with CAN EDIT or higher.
Covered in Embedding a Genie space as an iframe
2.Adding a Genie space as an app resource is all the app's service principal needs to return answers.Why is that wrong?
The resource only grants permission on the space itself. The service principal also needs Unity Catalog privileges on the underlying data.
Covered in Adding a Genie space to a Databricks App
3.Because Genie uses the asker's credentials, Slack channel members without data access cannot see the answer.Why is that wrong?
Credentials decide what gets queried, not who can read the reply. A public response is visible to the whole channel unless visibility is set to private.
Covered in Genie in Slack and Microsoft Teams
Practise it for real
Connect a Databricks App to a Genie space and ask it a question from Python
1.Edit your app. In App resources, click + Add resource > Genie Agent, select your space, choose Can run, and keep the default key genie-space.
Why: Can run is the level that lets the app's service principal submit queries and receive responses.
You should see: The space appears under the app's resources with Can run.
2.Grant the app's service principal USE CATALOG, USE SCHEMA and SELECT on the space's tables.
Why: The space resource does not include data access. Genie still checks Unity Catalog as the caller.
You should see: The service principal can read the tables the space uses.
3.Add the env block mapping GENIE_SPACE_ID to valueFrom: genie-space in app.yaml.
Why: Databricks injects the space ID through the resource key, so you don't hard-code it.
You should see: os.getenv("GENIE_SPACE_ID") returns the space ID after deployment.
4.Deploy the app and call w.genie.start_conversation_and_wait with a question. Then call create_message_and_wait with the returned conversation_id.
Why: The first call opens a conversation, and the second sends a follow-up in the same conversation.
You should see: Printed attachment text for both the first question and the follow-up.
Stuck? Get a nudge
If the call succeeds but returns no data, check the service principal's SELECT grants first.
Sources
Every claim above is drawn from one of these pages, quoted as it was written on the date shown.
- 1.https://docs.databricks.com/aws/en/ai-bi/admin/embedOfficial docs
“Workspace admins must define the allowed surfaces for embedding before authors can share a Genie Agent this way.”
↩︎ Embedding a Genie space as an iframe“This setting applies to both dashboards and Genie Agents.”
↩︎ Embedding a Genie space as an iframe“Allow approved domains: Dashboards and Genie Agents can only be embedded in sites that match the approved list.”
↩︎ Embedding a Genie space as an iframe - 2.
“Users who are not signed in to Databricks are prompted to authenticate before they can interact with the embedded agent.”
↩︎ Embedding a Genie space as an iframe“Embedded Genie Agent users can send prompts but cannot edit the agent configuration.”
↩︎ Exam trap 1“In the Share dialog, click Embed space.”
↩︎ Checkpoint“Agent author: Must have at least CAN MANAGE permission on the Genie Agent.”
↩︎ Checkpoint - 3.
“Databricks grants your app's service principal the specified permissions on the selected Genie Agent.”
↩︎ Adding a Genie space to a Databricks App“Access is scoped to the selected agent only.”
↩︎ Adding a Genie space to a Databricks App“When you remove a Genie Agent resource from an app, the app's service principal loses access to the agent.”
↩︎ Adding a Genie space to a Databricks App“This typically includes USE CATALOG, USE SCHEMA, and SELECT permissions on the relevant Unity Catalog tables and views.”
↩︎ Exam trap 2 - 4.
“Integrate Genie Agents into your own chatbot, agent, or application with the Genie Agents API.”
↩︎ Custom integrations through the Genie API“Service principals must have permissions to access the required data and SQL warehouses.”
↩︎ Custom integrations through the Genie API“In situations where browser-based authentication is not possible, use a service principal to authenticate with the API.”
↩︎ Checkpoint - 5.
“pinning a specific Genie Agent directs Genie One to send the question to only that agent”
↩︎ Genie in Slack and Microsoft Teams“To keep a response visible only to the person who asked, set message visibility to private.”
↩︎ Exam trap 3“including members who do not have access to the underlying data”
↩︎ Prediction“Higher levels override lower levels”
↩︎ Checkpoint - 6.
“If no Genie Agent is pinned, the channel defaults to Genie One.”
↩︎ Genie in Slack and Microsoft Teams“When Allow public messages in collaboration platforms is off, all responses are private to the user who asked.”
↩︎ Genie in Slack and Microsoft Teams