What you will be able to do
- Identify when a multi-agent Supervisor Agent fits a problem and what it can coordinate
- Apply the Supervisor Agent's permission model and limits
- Choose between Agent Bricks, a simpler design pattern, and a custom-coded agent
1.Supervisor Agent: one endpoint over many specialists
A single-purpose brick runs out of reach once a request crosses domains. An example is a question that needs both research reports and usage data. Supervisor Agent is the Agent Bricks answer. It builds a supervisor that delegates tasks to specialised subagents and tools, then combines their results into one response. The documented use cases are market analysis across research reports and usage data, answering questions about internal processes while automating a ticket backlog, and customer service across policy, FAQ and account questions. You must provide at least one subagent and can use at most 50 agents in one supervisor system. A Knowledge Assistant endpoint is one of the supported subagent types, so the bricks compose.
This is the key design consequence. Granting access to the supervisor is not enough, because each subagent type needs its own end-user permission.
| Subagent type | Required end user permission |
|---|---|
| Genie Agent | Access to the Genie Agent and its underlying Unity Catalog objects |
| Knowledge Assistant agent endpoint | CAN QUERY on the agent endpoint |
| Unity Catalog function | EXECUTE on the Unity Catalog function |
| AI Search index (Delta Sync indexes only) | USE CATALOG, USE SCHEMA, and SELECT on the AI Search index |
| Custom agent on Databricks Apps | CAN_USE on the Databricks app |
| Web search | No additional permissions; the user approves each invocation |
Two capabilities come built in. Every supervisor has a code execution tool that runs model-generated Python (the default), SQL or shell commands in a sandboxed serverless session, and you don't configure it. Web search always runs on the databricks-gpt-5 Foundation Model API, whatever model powers the supervisor. It needs databricks-gpt-5 in the workspace's system.ai allowlist and is unavailable in workspaces with the Enhanced Security and Compliance add-on.
Checkpoint 1 of 4· Check yourself
A supervisor is powered by a non-GPT model. The team adds the web search tool. Which model performs the web search?
Web search always runs on the Databricks-hosted databricks-gpt-5 Foundation Model API, so that model must be allowlisted in the workspace.
“Supervisor Agent uses the databricks-gpt-5 Foundation Model API for web search, regardless of the model that powers the supervisor.”Source: docs.databricks.com
Sources1
2.Building, tuning and sharing a supervisor
You can build a supervisor in the Agents UI. You can also build one with the Databricks SDK for Python, which is in Beta. With the SDK, the supervisor is an object with a display name, a description and instructions. Each subagent is attached as a Tool.
from databricks.sdk import WorkspaceClient
from databricks.sdk.service.supervisoragents import SupervisorAgent
w = WorkspaceClient()
supervisor_agent = SupervisorAgent(
display_name="<display-name>",
description="<description>",
instructions="<instructions>",
)
created = w.supervisor_agents.create_supervisor_agent(supervisor_agent=supervisor_agent)
print(created)Checkpoint 2 of 4· Fill the gap
Which SDK method attaches a Knowledge Assistant to an existing supervisor?
tool = Tool(
tool_type="knowledge_assistant",
description="<tool-description>",
knowledge_assistant=KnowledgeAssistant(
knowledge_assistant_id="<knowledge-assistant-id>",
),
)
created_tool = w.supervisor_agents. ? (
parent="supervisor-agents/<supervisor-agent-id>",
tool=tool,
tool_id="<tool-id>",
)Subagents are represented as tools, and create_tool adds one under the parent supervisor. update_tool only changes an existing tool's description.
Source: docs.databricks.comTo improve quality, you give feedback instead of writing code. In the Examples tab, add questions and task scenarios. Share the configuration page with experts, who need Can Manage on the supervisor plus access to each subagent, and have them attach Guidelines to questions. The supervisor is then retrained and optimised from the labeled data. People who only consume the endpoint get Can Query, which lets them call it from AI Playground or the API but not view or edit the agent.
The supervisor ends the conversation. Reviewers need permission on the subagents as well as on the supervisor, or they can't produce useful labels.
Sources1
3.Agent Bricks, a simpler pattern, or a custom agent?
Agent Bricks isn't the only option, and a multi-agent supervisor isn't the default. Databricks' design-pattern guidance says to start simple and add agentic behaviour only when you need it, because flexibility costs complexity and latency.
| Pattern | When to use | Main cost |
|---|---|---|
| LLM + prompt | Generic Q&A, quick short-term prototype | Minimal customization |
| Deterministic chain | Well-defined tasks, static pipelines such as basic RAG | Inflexible; requires code changes to adapt |
| Single-agent system | Moderate to complex queries in the same domain | Less predictable; guard against repeated or incorrect tool calls |
| Multi-agent system | Large or cross-functional domains with multiple expert agents | Complex to orchestrate; harder to trace and debug |
A supervisor earns its complexity when the work really is multi-domain. Signs of this are distinct skill areas, too many tools to fit in one agent's schema, or a need for agents to critique one another. The general risks don't go away: agents can bounce tasks between themselves without resolving them, so constraints and tracing still matter. When no brick fits, for example because you need a specific authoring library or control flow, build a custom agent in Python with LangGraph, LangChain, OpenAI, LlamaIndex or another library. This isn't an either/or choice. A custom agent deployed on Databricks Apps can itself be a supervisor subagent.
Checkpoint 3 of 4· Exam question
A finance team receives thousands of scanned vendor invoices as PDFs. They need to populate a Delta table with structured columns such as `invoice_number`, `vendor_name`, `invoice_date`, and `total_amount` for downstream reporting, and want to avoid writing custom parsing code for each vendor's invoice layout. Which Agent Bricks component best fits this requirement?
Correct answer: A — Information Extraction, which applies a user-defined schema over parsed invoice content and returns the requested structured fields for each document
- A. Information Extraction is purpose-built to pull structured fields from documents using a schema you define, so pointing it at the invoice content directly produces the invoice_number, vendor_name, invoice_date, and total_amount columns the finance team needs.
- B. Knowledge Assistant is designed for conversational question answering with citations, not for emitting structured rows of fields into a table, so it does not address the finance team's reporting need.
- C. Multi-Agent Supervisor coordinates multiple specialized subagents across different task domains, which is unnecessary overhead for a single, well-defined field-extraction task on one document type.
- D. Hand-written regular expressions tuned per vendor template is exactly the custom, per-layout parsing work the finance team wants to avoid, and it does not generalize well as new vendor formats appear.
Checkpoint 4 of 4· Check yourself
A retailer needs one assistant that answers product-documentation questions, queries sales data through a Genie Agent, and calls a returns-processing Unity Catalog function. Which choice best fits the guidance?
The request spans distinct specialised domains and tool types, which is the multi-agent case. Supervisor Agent coordinates exactly these subagent types.
“coordinates Genie Agents, agent endpoints, Unity Catalog functions, MCP servers, and custom agents to work together to complete complex tasks across different, specialized domains.”Source: docs.databricks.com
Exam traps
Each one states something that sounds right. Open it to see what is actually true.
1.A multi-agent supervisor is the best default design for any agent application.Why is that wrong?
The guidance is to start simple and move to multi-agent only for large or cross-functional domains. Multi-agent systems are harder to orchestrate, trace and debug.
Covered in Agent Bricks, a simpler pattern, or a custom agent?
2.Any AI Search index can be added to a supervisor as a subagent.Why is that wrong?
Supervisor Agent supports only Delta Sync indexes as AI Search index subagents.
Covered in Supervisor Agent: one endpoint over many specialists
3.Granting a user CAN QUERY on the supervisor endpoint gives them answers from every subagent.Why is that wrong?
The supervisor enforces each end user's own access, so users need explicit permission on each subagent and its data.
Covered in Supervisor Agent: one endpoint over many specialists
Sources
Every claim above is drawn from one of these pages, quoted as it was written on the date shown.
- 1.
“You cannot use more than 50 agents in a single supervisor system.”
↩︎ Supervisor Agent: one endpoint over many specialists“Every supervisor includes a code execution tool by default.”
↩︎ Supervisor Agent: one endpoint over many specialists“CAN QUERY on the agent endpoint.”
↩︎ Supervisor Agent: one endpoint over many specialists“Supervisor Agent will retrain and optimize the supervisor from the new data.”
↩︎ Building, tuning and sharing a supervisor“If the SME does not have access to any subagents, the supervisor will end the conversation.”
↩︎ Building, tuning and sharing a supervisor“Can Query: Allows querying the agent endpoint in AI Playground and through the API.”
↩︎ Building, tuning and sharing a supervisor“AI Search index subagents support only Delta Sync indexes.”
↩︎ Exam trap 2“The supervisor has built-in access controls, so that its end users only access the subagents and data they have access to.”
↩︎ Exam trap 3“the supervisor will redirect the conversation away from subagents the user cannot access.”
↩︎ Prediction“Supervisor Agent uses the databricks-gpt-5 Foundation Model API for web search, regardless of the model that powers the supervisor.”
↩︎ Checkpoint“coordinates Genie Agents, agent endpoints, Unity Catalog functions, MCP servers, and custom agents to work together to complete complex tasks across different, specialized domains.”
↩︎ Checkpoint - 2.
“You have so many tools that fitting them all into one agent's schema is impractical; each agent can own a subset.”
↩︎ Agent Bricks, a simpler pattern, or a custom agent?“Agents can bounce tasks indefinitely among themselves without resolution if not carefully constrained.”
↩︎ Agent Bricks, a simpler pattern, or a custom agent?“When building any AI-powered application, start simple.”
↩︎ Exam trap 1 - 3.
“Supports agents written with any authoring library, including LangGraph, LangChain, OpenAI, and LlamaIndex.”
↩︎ Agent Bricks, a simpler pattern, or a custom agent?