CertSafari
    Databricks Certified Data Analyst Associate· Lessons

    Domain 7 · Lesson 33/39

    Genie Space Permissions and Share Links

    Assign permissions via the UI and distribute Genie spaces using embedded links and external app integrations.

    8 min read
    2.56% of exam
    2 sources
    Published 3 Oct 2026
    Docs as of 30 Sep 2026

    What you will be able to do

    • Explain how a Genie space uses the author's embedded warehouse credentials together with each user's own Unity Catalog permissions
    • Choose the right Genie permission level (CAN VIEW, CAN RUN, CAN EDIT, CAN MANAGE) for a given user
    • Share a Genie space from the Share dialog with users, groups, or all account users, and hand out a copy link

    Key concept

    Two-credential access model — A Genie space reaches the SQL warehouse with the compute credentials its author embedded, but every query reads data as the person asking, under that person's own Unity Catalog permissions. Sharing a space lets someone ask questions. It does not let them see data they could not already read.

    1.What sharing a Genie space actually grants

    The current Databricks documentation calls these objects Genie Agents. The exam guide still says Genie spaces, and the docs confirm the two names mean the same thing. This lesson uses "Genie space" except where it quotes the docs.

    Before you give anyone access, you need to know what that access unlocks. Building a space takes a lot of permissions: the Databricks SQL entitlement, CAN USE on a pro or serverless SQL warehouse, SELECT on the data, and at least CAN EDIT on the space. The person who creates a space becomes its owner automatically, with the highest permission level.

    A Genie space uses two separate credentials. For compute, the author's credentials are embedded in the space, so everyone who uses it can reach the warehouse without their own warehouse grant. For data, Genie checks Unity Catalog as the individual user every time. If a business user asks about a table they cannot SELECT from, the share does not get around that.

    This is why distributing a space is usually two jobs. You grant the space permission in the Share dialog, and you separately make sure the audience has the Unity Catalog privileges on the tables behind it. Granting those data privileges usually takes elevated permissions, often held by an administrator, so plan for it before you send out a link.

    Checkpoint 1 of 5· Check yourself

    A business user asks a question in a shared Genie space. Whose credentials does the generated SQL use to reach the SQL warehouse?

    Sources1

    2.The four Genie permission levels

    The Share dialog offers four levels. They follow the usual Databricks access-control pattern, but on a Genie space the two lowest levels behave the same. The table below lists what each level allows.

    Abilities per Genie space permission level (from the Databricks ACL reference)
    AbilityCAN VIEWCAN RUNCAN EDITCAN MANAGE
    Ask questions in the Genie Agent✓✓✓✓
    Provide response feedback✓✓✓✓
    Add or edit instructions✓✓
    Add or remove included tables✓✓
    Monitor a space✓
    Modify permissions✓
    View other users' conversations✓
    Delete space✓

    The table gives you three tiers. Consumers get CAN VIEW or CAN RUN, which lets them ask questions, leave feedback and upload files to a conversation. Curators get CAN EDIT, which lets them change instructions, sample questions and tables. Owners get CAN MANAGE, the only level that can monitor the space, change who has access, delete it, or read other people's conversations.

    Checkpoint 2 of 5· Check yourself

    A data analyst needs to adjust a space's instructions and add a table. They should not be able to change who has access. What is the lowest level that works?

    Checkpoint 3 of 5· Exam question

    A data analyst on the Marketing team has been granted SELECT privileges on every Unity Catalog table and view curated inside a Genie space, but has not been added to the space's Share dialog. When the analyst tries to open the space and ask a question, what happens?

    Sources12

    3.Sharing from the UI: folders, the Share dialog and copy links

    You can give access in the UI in two ways. The first is the folder. A new space is saved to your user folder, and like other workspace objects it picks up the permissions of the folder that contains it. Putting a space in a shared team folder is a quick way to give the whole team access.

    The second is the Share dialog, which gives you direct control. You can name individual users or groups, or choose all account users, and give each one a permission level.

    Checkpoint 4 of 5· Put it in order

    Put the steps for sharing a Genie space with a specific group in order

    1. 1.Set the appropriate permission level for each entry
    2. 2.Enter the users or groups to share with
    3. 3.Open the Genie space and click Share
    4. 4.Click Add

    When you share with individual users or small groups, Databricks sends them an email notification. To share with everyone, open Share, select All account users, and pick a level.

    The link is the simplest way to distribute a space. At the bottom of the Share dialog, Copy link gives you a URL you can paste into chat, email or a wiki. A link does not grant access on its own. Only people who already have permission can open it and ask questions.

    Checkpoint 5 of 5· Exam question

    The BI team wants to embed a Genie space directly inside an internal customer-support console hosted at https://support.acme.internal, so agents can ask questions without leaving that tool. Before the Genie space author can generate a working embed, what must a workspace admin configure first?

    Sources1

    Exam traps

    Each one states something that sounds right. Open it to see what is actually true.

    1. 1.CAN RUN gives users more on a Genie space than CAN VIEW, because CAN RUN is the level that lets them run queries.Why is that wrong?

      On a Genie space the two levels are the same. Both can ask questions, give feedback and upload files. Neither can edit the space.

      Covered in The four Genie permission levels

    2. 2.Sharing a Genie space lets the recipient see every table in it, because the author's credentials run the queries.Why is that wrong?

      The embedded author credentials cover only warehouse compute. Data reads are always checked against the user's own Unity Catalog permissions.

      Covered in What sharing a Genie space actually grants

    Sources

    Every claim above is drawn from one of these pages, quoted as it was written on the date shown.

    1. 1.
      “Genie Agents were formerly known as Genie Spaces.”
      ↩︎ What sharing a Genie space actually grants
      “Genie Agent creators automatically have CAN MANAGE permissions on agents they create.”
      ↩︎ What sharing a Genie space actually grants
      “Your compute credentials are embedded into the Genie Agent to provide warehouse access for all users.”
      ↩︎ What sharing a Genie space actually grants
      “share with at a given permission level: CAN MANAGE, CAN EDIT, CAN RUN, and CAN VIEW.”
      ↩︎ The four Genie permission levels
      “Like other workspace objects, they inherit permissions from their enclosing folder.”
      ↩︎ Sharing from the UI: folders, the Share dialog and copy links
      “Use the Copy link button at the bottom of the Share dialog to get a shareable link to the Genie Agent.”
      ↩︎ Sharing from the UI: folders, the Share dialog and copy links
      “Privileged users can click the link to open the Genie Agent in a new tab and ask questions.”
      ↩︎ Sharing from the UI: folders, the Share dialog and copy links
      “Individual users and members of small groups receive an email notification confirming that the agent has been shared.”
      ↩︎ Sharing from the UI: folders, the Share dialog and copy links
      “Data access is always evaluated using each end user's own Unity Catalog permissions.”
      ↩︎ Key concept
      “Data access is always evaluated using each end user's own Unity Catalog permissions.”
      ↩︎ Exam trap 2
      “so end users do not need warehouse permissions”
      ↩︎ Prediction
      “Compute access to the SQL warehouse uses the embedded credentials of the author who configured the warehouse”
      ↩︎ Checkpoint
      “At least CAN EDIT permissions on the Genie Agent.”
      ↩︎ Checkpoint
      “Then, click Add and set appropriate permission levels.”
      ↩︎ Checkpoint
    2. 2.
      “For a Genie Agent, CAN VIEW and CAN RUN grant the same abilities.”
      ↩︎ The four Genie permission levels
      “For a Genie Agent, CAN VIEW and CAN RUN grant the same abilities.”
      ↩︎ Exam trap 1

    Continue to page 2 of 2

    Embedding Genie Spaces and External App Integrations

    Spotted a mistake, or was something unclear? Tell us.