CertSafari
    Databricks Certified Data Analyst Associate· Lessons

    Domain 7 · Lesson 33/39

    Embedding Genie Spaces and External App Integrations

    Assign permissions via the UI and distribute Genie spaces using embedded links and external app integrations.

    9 min read
    2.56% of exam
    6 sources
    Published 3 Oct 2026
    Docs as of 30 Sep 2026

    What you will be able to do

    • Configure the workspace embedding policy and generate iframe embed code for a Genie space
    • Add a Genie space as a Databricks Apps resource and call it from app code
    • Pick the right authentication for Genie API integrations
    • Configure the Slack and Microsoft Teams Genie apps, including the agent pinned to a channel and message visibility

    1.Embedding a Genie space as an iframe

    Embedding puts a Genie space inside an internal portal or tool, so people can ask questions without going to Databricks. Two roles are involved, and the order matters. First, a workspace admin chooses where embedding is allowed. Then an author with CAN MANAGE generates the iframe code. CAN EDIT is enough to change the space, but it is not enough to embed it.

    The admin sets this up under Settings > Security > External access, in the Embed dashboards drop-down. The name is misleading: this one policy covers both dashboards and Genie spaces. There are three options. Allow permits any domain. Allow approved domains permits only the sites on a list the admin manages. Deny blocks embedding everywhere. Approved domains use Content Security Policy grammar, so *.databricks.com matches any subdomain but not another-databricks.com.

    Checkpoint 1 of 6· Put it in order

    Once the admin has allowed your domain, put the author's embedding steps in order

    1. 1.Paste the iframe code into your external website or application
    2. 2.Open the Genie space you want to embed
    3. 3.In the Share dialog, click Embed space
    4. 4.Copy the generated iframe code
    5. 5.Click Share
    Embed code with clipboard access, which lets users copy CSV results and conversation linkshtml
    <iframe src="<your-genie-space-url>" allow="clipboard-write" width="100%" height="600"></iframe>

    An embedded space is for asking questions only. Embedded users can send prompts but cannot change the configuration. They also need explicit access to the space and to its underlying data. Anyone not signed in to Databricks is asked to authenticate before they can use it.

    Checkpoint 2 of 6· Check yourself

    An author with CAN EDIT opens Share but cannot embed the space, even though the admin has allowed the portal's domain. What is missing?

    Sources12

    2.Adding a Genie space to a Databricks App

    A Databricks App doesn't use an iframe. You attach the space as an app resource: in the App resources section, click + Add resource > Genie Agent, pick a space, and choose a permission level for the app. Databricks then grants that level to the app's service principal. Access covers only that one space, and other spaces have to be added as separate resources. The levels match the Share dialog, and the docs write them in title case here.

    Permission levels you can grant an app on a Genie space resource
    LevelWhat the app's service principal can do
    Can viewRead the Genie Agent configuration and metadata
    Can runSubmit queries to the Genie Agent and receive responses
    Can editModify the Genie Agent configuration
    Can manageFull administrative access to the Genie Agent

    The two-credential rule applies to the app as well. Its service principal still needs USE CATALOG, USE SCHEMA and SELECT on the underlying tables and views. If you remove the resource later, the service principal loses access, but the space itself is not changed. At deploy time Databricks exposes the space ID as an environment variable, which you map in app.yaml using the resource key. The default key is genie-space.

    app.yaml mapping the Genie resource key to an environment variableyaml
    env:
      - name: GENIE_SPACE_ID
        valueFrom: genie-space # Use your custom resource key if different

    Checkpoint 3 of 6· Fill the gap

    Which SDK method opens a new Genie conversation with the first question?

    # Start a conversation with a natural language query
    response = w.genie. ? (
        space_id=space_id,
        content="What were our top-selling products last quarter?"
    )

    Checkpoint 4 of 6· Exam question

    An analyst who holds CAN RUN permission on a published Genie space opens the Share dialog and looks for the option to generate an embeddable iframe for the space, but the option is greyed out. What is the most likely cause?

    Sources3

    3.Custom integrations through the Genie API

    For your own chatbot or agent framework, the Genie API's Chat mode endpoints support stateful conversations with follow-up questions. You can call them over REST or through the Databricks SDKs, as in the app example above. Callers need the Databricks SQL entitlement and at least CAN USE on a pro or serverless warehouse. You can find a space ID with the List Genie Agents API or on the space's Settings tab.

    Checkpoint 5 of 6· Check yourself

    A nightly backend job with no user present posts Genie answers into a report. How should it authenticate to the Genie API?

    Sources4

    4.Genie in Slack and Microsoft Teams

    Both chat apps are in Public Preview, and an account admin has to enable them in the account console. A Slack workspace admin installs the Slack app, and a Microsoft 365 admin installs the Teams app from the Microsoft marketplace. By default, questions go to Genie One. A channel owner can pin a specific Genie space instead, which tells Genie One to send questions only to that space and gives more consistent answers for one use case. In Slack you run /databricks-genie config. In Teams you type config. If no space is pinned in Teams, the channel uses Genie One.

    Visibility can be set at three levels, and higher levels override lower ones. A workspace admin controls the workspace level through the Allow connection to collaboration platforms and Allow public messages in collaboration platforms settings. In Teams, turning off public messages makes every response private. Responses are public by default, and visualizations only appear in public messages.

    Checkpoint 6 of 6· Match them up

    Match each message-visibility level to who sets it

    Tap a term, then the definition that fits it.

    Sources56

    Exam traps

    Each one states something that sounds right. Open it to see what is actually true.

    1. 1.People using an embedded Genie space can adjust its instructions from inside the portal.Why is that wrong?

      An embedded space only accepts questions. Configuration changes are made in Databricks by users with CAN EDIT or higher.

      Covered in Embedding a Genie space as an iframe

    2. 2.Adding a Genie space as an app resource is all the app's service principal needs to return answers.Why is that wrong?

      The resource only grants permission on the space itself. The service principal also needs Unity Catalog privileges on the underlying data.

      Covered in Adding a Genie space to a Databricks App

    3. 3.Because Genie uses the asker's credentials, Slack channel members without data access cannot see the answer.Why is that wrong?

      Credentials decide what gets queried, not who can read the reply. A public response is visible to the whole channel unless visibility is set to private.

      Covered in Genie in Slack and Microsoft Teams

    Practise it for real

    Connect a Databricks App to a Genie space and ask it a question from Python

    1. 1.Edit your app. In App resources, click + Add resource > Genie Agent, select your space, choose Can run, and keep the default key genie-space.

      Why: Can run is the level that lets the app's service principal submit queries and receive responses.

      You should see: The space appears under the app's resources with Can run.

    2. 2.Grant the app's service principal USE CATALOG, USE SCHEMA and SELECT on the space's tables.

      Why: The space resource does not include data access. Genie still checks Unity Catalog as the caller.

      You should see: The service principal can read the tables the space uses.

    3. 3.Add the env block mapping GENIE_SPACE_ID to valueFrom: genie-space in app.yaml.

      Why: Databricks injects the space ID through the resource key, so you don't hard-code it.

      You should see: os.getenv("GENIE_SPACE_ID") returns the space ID after deployment.

    4. 4.Deploy the app and call w.genie.start_conversation_and_wait with a question. Then call create_message_and_wait with the returned conversation_id.

      Why: The first call opens a conversation, and the second sends a follow-up in the same conversation.

      You should see: Printed attachment text for both the first question and the follow-up.

    Stuck? Get a nudge

    If the call succeeds but returns no data, check the service principal's SELECT grants first.

    Sources

    Every claim above is drawn from one of these pages, quoted as it was written on the date shown.

    1. 1.
      “Workspace admins must define the allowed surfaces for embedding before authors can share a Genie Agent this way.”
      ↩︎ Embedding a Genie space as an iframe
      “This setting applies to both dashboards and Genie Agents.”
      ↩︎ Embedding a Genie space as an iframe
      “Allow approved domains: Dashboards and Genie Agents can only be embedded in sites that match the approved list.”
      ↩︎ Embedding a Genie space as an iframe
    2. 2.
      “Users who are not signed in to Databricks are prompted to authenticate before they can interact with the embedded agent.”
      ↩︎ Embedding a Genie space as an iframe
      “Embedded Genie Agent users can send prompts but cannot edit the agent configuration.”
      ↩︎ Exam trap 1
      “In the Share dialog, click Embed space.”
      ↩︎ Checkpoint
      “Agent author: Must have at least CAN MANAGE permission on the Genie Agent.”
      ↩︎ Checkpoint
    3. 3.
      “Databricks grants your app's service principal the specified permissions on the selected Genie Agent.”
      ↩︎ Adding a Genie space to a Databricks App
      “Access is scoped to the selected agent only.”
      ↩︎ Adding a Genie space to a Databricks App
      “When you remove a Genie Agent resource from an app, the app's service principal loses access to the agent.”
      ↩︎ Adding a Genie space to a Databricks App
      “This typically includes USE CATALOG, USE SCHEMA, and SELECT permissions on the relevant Unity Catalog tables and views.”
      ↩︎ Exam trap 2
    4. 4.
      “Integrate Genie Agents into your own chatbot, agent, or application with the Genie Agents API.”
      ↩︎ Custom integrations through the Genie API
      “Service principals must have permissions to access the required data and SQL warehouses.”
      ↩︎ Custom integrations through the Genie API
      “In situations where browser-based authentication is not possible, use a service principal to authenticate with the API.”
      ↩︎ Checkpoint
    5. 5.
      “pinning a specific Genie Agent directs Genie One to send the question to only that agent”
      ↩︎ Genie in Slack and Microsoft Teams
      “To keep a response visible only to the person who asked, set message visibility to private.”
      ↩︎ Exam trap 3
      “including members who do not have access to the underlying data”
      ↩︎ Prediction
      “Higher levels override lower levels”
      ↩︎ Checkpoint
    6. 6.
      “If no Genie Agent is pinned, the channel defaults to Genie One.”
      ↩︎ Genie in Slack and Microsoft Teams
      “When Allow public messages in collaboration platforms is off, all responses are private to the user who asked.”
      ↩︎ Genie in Slack and Microsoft Teams

    Spotted a mistake, or was something unclear? Tell us.