<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Failed to fetch tables for the space when using Genie MCP via Model Serving in Generative AI</title>
    <link>https://community.databricks.com/t5/generative-ai/failed-to-fetch-tables-for-the-space-when-using-genie-mcp-via/m-p/149904#M1651</link>
    <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I'm experiencing a specific permissions issue when using an AI agent that queries a Genie space via MCP (Model Context Protocol) within a Model Serving endpoint.&lt;BR /&gt;I developed an AI agent to query a Genie space to retrieve retail sales data for predictions. I own the catalog, schema, and Genie space.&lt;/P&gt;&lt;P&gt;When interacting with the agent via the Review app (Model Serving), any query that triggers a call to the Genie tool fails with the following error:&lt;BR /&gt;&lt;EM&gt;PERMISSION_DENIED: Unable to retrieve tables for the space. Please resolve these errors to continue: No access to the table 'fashion_retail.ppl_schema.silver_transactions'. Code: 42.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;What is the best practice for granting Unity Catalog permissions (USE CATALOG, USE SCHEMA, SELECT) to a system identity created from a Model Serving endpoint?&lt;/P&gt;&lt;P&gt;Any suggestions on how to properly configure the authorization chain between Model Serving -&amp;gt; MCP -&amp;gt; Genie -&amp;gt; Unity Catalog would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
    <pubDate>Thu, 05 Mar 2026 13:53:18 GMT</pubDate>
    <dc:creator>ilaria</dc:creator>
    <dc:date>2026-03-05T13:53:18Z</dc:date>
    <item>
      <title>Failed to fetch tables for the space when using Genie MCP via Model Serving</title>
      <link>https://community.databricks.com/t5/generative-ai/failed-to-fetch-tables-for-the-space-when-using-genie-mcp-via/m-p/149904#M1651</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I'm experiencing a specific permissions issue when using an AI agent that queries a Genie space via MCP (Model Context Protocol) within a Model Serving endpoint.&lt;BR /&gt;I developed an AI agent to query a Genie space to retrieve retail sales data for predictions. I own the catalog, schema, and Genie space.&lt;/P&gt;&lt;P&gt;When interacting with the agent via the Review app (Model Serving), any query that triggers a call to the Genie tool fails with the following error:&lt;BR /&gt;&lt;EM&gt;PERMISSION_DENIED: Unable to retrieve tables for the space. Please resolve these errors to continue: No access to the table 'fashion_retail.ppl_schema.silver_transactions'. Code: 42.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;What is the best practice for granting Unity Catalog permissions (USE CATALOG, USE SCHEMA, SELECT) to a system identity created from a Model Serving endpoint?&lt;/P&gt;&lt;P&gt;Any suggestions on how to properly configure the authorization chain between Model Serving -&amp;gt; MCP -&amp;gt; Genie -&amp;gt; Unity Catalog would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2026 13:53:18 GMT</pubDate>
      <guid>https://community.databricks.com/t5/generative-ai/failed-to-fetch-tables-for-the-space-when-using-genie-mcp-via/m-p/149904#M1651</guid>
      <dc:creator>ilaria</dc:creator>
      <dc:date>2026-03-05T13:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to fetch tables for the space when using Genie MCP via Model Serving</title>
      <link>https://community.databricks.com/t5/generative-ai/failed-to-fetch-tables-for-the-space-when-using-genie-mcp-via/m-p/150042#M1653</link>
      <description>&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/218739"&gt;@ilaria&lt;/a&gt;,&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;When you call a Genie space via MCP from a Model Serving endpoint, the queries against the table you have mentioned (fashion_retail.ppl_schema.silver_transactions) don’t run as you (the workspace user who owns the catalog/schema/space), but as the system identity/service principal associated with that serving endpoint. That identity must have its own Unity Catalog permissions.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="p8i6j01 paragraph"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;Here are some steps you can try...&lt;/FONT&gt;&lt;/P&gt;
&lt;H5 class="p8i6j01 paragraph"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;&lt;STRONG&gt;Check Genie space + app/endpoint permissions&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H5&gt;
&lt;P class="p8i6j01 paragraph"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;Make sure the endpoint’s identity has at least CAN RUN on the Genie space, not just you as a user. The Genie app/docs spell this out and also highlight that the app’s service principal needs UC privileges on the underlying tables:&lt;/FONT&gt;&lt;/P&gt;
&lt;UL class="p8i6j08 p8i6j02 lia-list-style-type-circle"&gt;
&lt;LI class="p8i6j0a"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;AWS: &lt;SPAN aria-expanded="false" aria-haspopup="dialog" data-base-ui-click-trigger=""&gt;&lt;A class="_1ibi0s3e5 markdown-link _1ibi0s376" href="https://docs.databricks.com/aws/en/dev-tools/databricks-apps/genie" rel="noreferrer" target="_blank"&gt;Add a Genie space resource to a Databricks app&lt;/A&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI class="p8i6j0a"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;Azure: &lt;SPAN aria-expanded="false" aria-haspopup="dialog" data-base-ui-click-trigger=""&gt;&lt;A class="_1ibi0s3e5 markdown-link _1ibi0s376" href="https://learn.microsoft.com/en-us/azure/databricks/dev-tools/databricks-apps/genie" rel="noreferrer" target="_blank"&gt;Add a Genie space resource to a Databricks app&lt;/A&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H5 class="p8i6j01 paragraph"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;&lt;STRONG&gt;Grant Unity Catalog privileges to the serving identity&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H5&gt;
&lt;P class="p8i6j01 paragraph"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;In addition to space‑level permissions, the Model Serving system identity (or associated service principal) must have at least:&lt;/FONT&gt;&lt;/P&gt;
&lt;DIV class="l8rrz21 _1ibi0s3dn" data-ui-element="code-block-container"&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;GRANT USE CATALOG ON CATALOG fashion_retail TO `&amp;lt;endpoint-sp-or-group&amp;gt;`;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;GRANT USE SCHEMA ON SCHEMA fashion_retail.ppl_schema TO `&amp;lt;endpoint-sp-or-group&amp;gt;`;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;GRANT SELECT ON TABLE fashion_retail.ppl_schema.silver_transactions TO `&amp;lt;endpoint-sp-or-group&amp;gt;`;&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV class="l8rrz23 _1ibi0s3d6 _1ibi0s332 _1ibi0s3do _1ibi0s3bm _1ibi0s3ce"&gt;
&lt;DIV class="lqznwq0"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;&lt;SPAN&gt;Replace &lt;/SPAN&gt;&amp;lt;endpoint-sp-or-group&amp;gt;&lt;SPAN&gt; with the actual principal that backs your Model Serving endpoint (often shown in the endpoint config or via your admin/team).&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV class="lqznwq0"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;If the above steps don't resolve,&amp;nbsp;test access using the same principal that backs the serving endpoint (for example, via a job or test notebook impersonating that SP). If a simple SELECT * FROM fashion_retail.ppl_schema.silver_transactions LIMIT 1 fails there with the same error, you’ve confirmed it’s purely a UC permissions issue.&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;FONT size="2" color="#FF6600"&gt;&amp;nbsp;If this answer resolves your question, could you mark it as “Accept as Solution”? That helps other users quickly find the correct fix.&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 06 Mar 2026 22:29:47 GMT</pubDate>
      <guid>https://community.databricks.com/t5/generative-ai/failed-to-fetch-tables-for-the-space-when-using-genie-mcp-via/m-p/150042#M1653</guid>
      <dc:creator>Ashwin_DSA</dc:creator>
      <dc:date>2026-03-06T22:29:47Z</dc:date>
    </item>
  </channel>
</rss>

