What you will be able to do
- Explain how a Genie space uses the author's embedded warehouse credentials together with each user's own Unity Catalog permissions
- Choose the right Genie permission level (CAN VIEW, CAN RUN, CAN EDIT, CAN MANAGE) for a given user
- Share a Genie space from the Share dialog with users, groups, or all account users, and hand out a copy link
Key concept
Two-credential access model — A Genie space reaches the SQL warehouse with the compute credentials its author embedded, but every query reads data as the person asking, under that person's own Unity Catalog permissions. Sharing a space lets someone ask questions. It does not let them see data they could not already read.
1.What sharing a Genie space actually grants
The current Databricks documentation calls these objects Genie Agents. The exam guide still says Genie spaces, and the docs confirm the two names mean the same thing. This lesson uses "Genie space" except where it quotes the docs.
Before you give anyone access, you need to know what that access unlocks. Building a space takes a lot of permissions: the Databricks SQL entitlement, CAN USE on a pro or serverless SQL warehouse, SELECT on the data, and at least CAN EDIT on the space. The person who creates a space becomes its owner automatically, with the highest permission level.
A Genie space uses two separate credentials. For compute, the author's credentials are embedded in the space, so everyone who uses it can reach the warehouse without their own warehouse grant. For data, Genie checks Unity Catalog as the individual user every time. If a business user asks about a table they cannot SELECT from, the share does not get around that.
This is why distributing a space is usually two jobs. You grant the space permission in the Share dialog, and you separately make sure the audience has the Unity Catalog privileges on the tables behind it. Granting those data privileges usually takes elevated permissions, often held by an administrator, so plan for it before you send out a link.
Checkpoint 1 of 5· Check yourself
A business user asks a question in a shared Genie space. Whose credentials does the generated SQL use to reach the SQL warehouse?
Compute access uses the author's embedded credentials, so end users need no warehouse permissions. Data access is still evaluated as the end user.
“Compute access to the SQL warehouse uses the embedded credentials of the author who configured the warehouse”Source: docs.databricks.com
Sources1
2.The four Genie permission levels
The Share dialog offers four levels. They follow the usual Databricks access-control pattern, but on a Genie space the two lowest levels behave the same. The table below lists what each level allows.
| Ability | CAN VIEW | CAN RUN | CAN EDIT | CAN MANAGE |
|---|---|---|---|---|
| Ask questions in the Genie Agent | ✓ | ✓ | ✓ | ✓ |
| Provide response feedback | ✓ | ✓ | ✓ | ✓ |
| Add or edit instructions | ✓ | ✓ | ||
| Add or remove included tables | ✓ | ✓ | ||
| Monitor a space | ✓ | |||
| Modify permissions | ✓ | |||
| View other users' conversations | ✓ | |||
| Delete space | ✓ |
The table gives you three tiers. Consumers get CAN VIEW or CAN RUN, which lets them ask questions, leave feedback and upload files to a conversation. Curators get CAN EDIT, which lets them change instructions, sample questions and tables. Owners get CAN MANAGE, the only level that can monitor the space, change who has access, delete it, or read other people's conversations.
Checkpoint 2 of 5· Check yourself
A data analyst needs to adjust a space's instructions and add a table. They should not be able to change who has access. What is the lowest level that works?
Editing instructions and included tables starts at CAN EDIT. Modifying permissions needs CAN MANAGE, so CAN EDIT meets the requirement without giving extra access.
“At least CAN EDIT permissions on the Genie Agent.”Source: docs.databricks.com
Checkpoint 3 of 5· Exam question
A data analyst on the Marketing team has been granted SELECT privileges on every Unity Catalog table and view curated inside a Genie space, but has not been added to the space's Share dialog. When the analyst tries to open the space and ask a question, what happens?
Correct answer: B — The analyst is blocked from querying, because Genie enforces both an explicit CAN VIEW or CAN RUN grant on the space itself and SELECT privileges on the underlying data.
- A. SELECT privileges on the curated tables are necessary but not sufficient. Genie also requires the user to hold an explicit permission grant on the space itself, so table-level access alone does not open the space.
- B. Correct. Genie access is layered: the user needs an explicit CAN VIEW or CAN RUN grant on the space through the Share dialog, and separately needs SELECT on the underlying Unity Catalog objects the space queries.
- C. Warehouse compute for a Genie space runs under the embedded credentials of the space's author, not the querying user's own warehouse permission, so this is not the reason access would be blocked.
- D. Unity Catalog SELECT privileges have no automatic relationship to Genie space permission tiers, and there is no mechanism that escalates a data grant into a CAN EDIT request.
3.Sharing from the UI: folders, the Share dialog and copy links
You can give access in the UI in two ways. The first is the folder. A new space is saved to your user folder, and like other workspace objects it picks up the permissions of the folder that contains it. Putting a space in a shared team folder is a quick way to give the whole team access.
The second is the Share dialog, which gives you direct control. You can name individual users or groups, or choose all account users, and give each one a permission level.
Checkpoint 4 of 5· Put it in order
Put the steps for sharing a Genie space with a specific group in order
- 1.Set the appropriate permission level for each entry
- 2.Enter the users or groups to share with
- 3.Open the Genie space and click Share
- 4.Click Add
In the Share dialog you enter the principals, click Add, and then set their permission levels.
“Then, click Add and set appropriate permission levels.”Source: docs.databricks.com
When you share with individual users or small groups, Databricks sends them an email notification. To share with everyone, open Share, select All account users, and pick a level.
The link is the simplest way to distribute a space. At the bottom of the Share dialog, Copy link gives you a URL you can paste into chat, email or a wiki. A link does not grant access on its own. Only people who already have permission can open it and ask questions.
They cannot use it. The docs say privileged users, meaning those with permission, can open the link in a new tab and ask questions. Anyone else first needs a share entry or folder permission.
Checkpoint 5 of 5· Exam question
The BI team wants to embed a Genie space directly inside an internal customer-support console hosted at https://support.acme.internal, so agents can ask questions without leaving that tool. Before the Genie space author can generate a working embed, what must a workspace admin configure first?
Correct answer: A — In Settings > Security > External access, set the embed dashboards policy to Allow approved domains and add the support console's domain to the approved list.
- A. Correct. Workspace admins control embedding policy under Settings > Security > External access, and an author cannot successfully embed a space in an external domain until that domain is allowed or explicitly approved there.
- B. CAN MANAGE on the space controls who can administer or share that specific Genie space, but it does not control which external domains are permitted to host an embedded iframe.
- C. Creating a new catalog and migrating tables changes data organization, not embedding permissions, and is unrelated to whether a domain is allowed to embed the space.
- D. Photon is a query execution engine setting that affects performance, not whether an external domain is authorized to embed a Genie space.
Sources1
Exam traps
Each one states something that sounds right. Open it to see what is actually true.
1.CAN RUN gives users more on a Genie space than CAN VIEW, because CAN RUN is the level that lets them run queries.Why is that wrong?
On a Genie space the two levels are the same. Both can ask questions, give feedback and upload files. Neither can edit the space.
Covered in The four Genie permission levels
2.Sharing a Genie space lets the recipient see every table in it, because the author's credentials run the queries.Why is that wrong?
The embedded author credentials cover only warehouse compute. Data reads are always checked against the user's own Unity Catalog permissions.
Covered in What sharing a Genie space actually grants
Sources
Every claim above is drawn from one of these pages, quoted as it was written on the date shown.
- 1.
“Genie Agents were formerly known as Genie Spaces.”
↩︎ What sharing a Genie space actually grants“Genie Agent creators automatically have CAN MANAGE permissions on agents they create.”
↩︎ What sharing a Genie space actually grants“Your compute credentials are embedded into the Genie Agent to provide warehouse access for all users.”
↩︎ What sharing a Genie space actually grants“share with at a given permission level: CAN MANAGE, CAN EDIT, CAN RUN, and CAN VIEW.”
↩︎ The four Genie permission levels“Like other workspace objects, they inherit permissions from their enclosing folder.”
↩︎ Sharing from the UI: folders, the Share dialog and copy links“Use the Copy link button at the bottom of the Share dialog to get a shareable link to the Genie Agent.”
↩︎ Sharing from the UI: folders, the Share dialog and copy links“Privileged users can click the link to open the Genie Agent in a new tab and ask questions.”
↩︎ Sharing from the UI: folders, the Share dialog and copy links“Individual users and members of small groups receive an email notification confirming that the agent has been shared.”
↩︎ Sharing from the UI: folders, the Share dialog and copy links“Data access is always evaluated using each end user's own Unity Catalog permissions.”
↩︎ Key concept“Data access is always evaluated using each end user's own Unity Catalog permissions.”
↩︎ Exam trap 2“so end users do not need warehouse permissions”
↩︎ Prediction“Compute access to the SQL warehouse uses the embedded credentials of the author who configured the warehouse”
↩︎ Checkpoint“At least CAN EDIT permissions on the Genie Agent.”
↩︎ Checkpoint“Then, click Add and set appropriate permission levels.”
↩︎ Checkpoint - 2.
“For a Genie Agent, CAN VIEW and CAN RUN grant the same abilities.”
↩︎ The four Genie permission levels“For a Genie Agent, CAN VIEW and CAN RUN grant the same abilities.”
↩︎ Exam trap 1