<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Permission Denied for Genie Auto-Generated Service Principal on SQL Endpoint in Playground in Generative AI</title>
    <link>https://community.databricks.com/t5/generative-ai/permission-denied-for-genie-auto-generated-service-principal-on/m-p/120189#M906</link>
    <description>&lt;P&gt;Hi community,&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.databricks.com/aws/en/generative-ai/agent-framework/multi-agent-genie?scid=701Vp000004h4c4IAA&amp;amp;utm_medium=programmatic&amp;amp;utm_source=google&amp;amp;utm_campaign=22507112156&amp;amp;utm_adgroup=&amp;amp;utm_content=summit&amp;amp;utm_offer=dataaisummit&amp;amp;utm_ad=&amp;amp;utm_term=&amp;amp;gad_source=1&amp;amp;gad_campaignid=22507113074&amp;amp;gbraid=0AAAAABYBeAjJBK6Yps_hSSp9sIzsxssUG&amp;amp;gclid=EAIaIQobChMI9-Lhwfi0jQMVXQCtBh3fuDyzEAAYASAAEgLm_PD_BwE" target="_blank"&gt;Use Genie in multi-agent systems | Databricks Documentation&lt;/A&gt;&lt;BR /&gt;I’ve developed a &lt;STRONG&gt;multi-agent Genie&lt;/STRONG&gt; in Databricks and integrated it with &lt;STRONG&gt;vector indexes&lt;/STRONG&gt;. The setup works fine during model logging and prediction. The system successfully registers models to &lt;STRONG&gt;Model Serving&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;However, when I interact with the Genie using the &lt;STRONG&gt;Playground UI&lt;/STRONG&gt;, I receive the following error:&lt;/P&gt;&lt;P&gt;&lt;FONT color="#993366"&gt;&lt;U&gt;PermissionDenied: 2654507c-3f21-48f6-87f6-2e5ef2ac5c75 is not authorized to use or monitor this SQL Endpoint. Please contact your administrator.&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#993366"&gt;&lt;U&gt;Config: host=&lt;A href="https://dbc-3a822fc8-adcc.cloud.databricks.com" target="_blank" rel="noopener"&gt;https://dbc-3a822fc8-adcc.cloud.databricks.com&lt;/A&gt;, auth_type=model-serving&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#993366"&gt;&lt;U&gt;During task with name 'Genie' and id&lt;/U&gt; 'f039979b-69b5-0353-3070-24c8427faeef'&lt;BR /&gt;&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;H3&gt;What I’ve Observed:&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;The Genie automatically generates a &lt;STRONG&gt;service principal&lt;/STRONG&gt; when integrated with multiple agents.&lt;/LI&gt;&lt;LI&gt;This principal queries or interacts with a SQL Endpoint to query the tables.&lt;/LI&gt;&lt;LI&gt;Unfortunately, I cannot &lt;STRONG&gt;manually assign permissions&lt;/STRONG&gt; to this service principal.&lt;/LI&gt;&lt;LI&gt;It does not show up under typical service principal listings or user management.&lt;/LI&gt;&lt;LI&gt;As a result, &lt;STRONG&gt;any queries from the Playground fail with permission errors&lt;/STRONG&gt;.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Any help or insight would be appreciated. I'm happy to provide more details if needed!&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Karthik k&lt;/P&gt;&lt;P&gt;#genie #multiagent #model-serving #sql-endpoint #playground #permissions #service-principal #unity-catalog #databricks&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 26 May 2025 08:28:17 GMT</pubDate>
    <dc:creator>Karthik_Karanm</dc:creator>
    <dc:date>2025-05-26T08:28:17Z</dc:date>
    <item>
      <title>Permission Denied for Genie Auto-Generated Service Principal on SQL Endpoint in Playground</title>
      <link>https://community.databricks.com/t5/generative-ai/permission-denied-for-genie-auto-generated-service-principal-on/m-p/120189#M906</link>
      <description>&lt;P&gt;Hi community,&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.databricks.com/aws/en/generative-ai/agent-framework/multi-agent-genie?scid=701Vp000004h4c4IAA&amp;amp;utm_medium=programmatic&amp;amp;utm_source=google&amp;amp;utm_campaign=22507112156&amp;amp;utm_adgroup=&amp;amp;utm_content=summit&amp;amp;utm_offer=dataaisummit&amp;amp;utm_ad=&amp;amp;utm_term=&amp;amp;gad_source=1&amp;amp;gad_campaignid=22507113074&amp;amp;gbraid=0AAAAABYBeAjJBK6Yps_hSSp9sIzsxssUG&amp;amp;gclid=EAIaIQobChMI9-Lhwfi0jQMVXQCtBh3fuDyzEAAYASAAEgLm_PD_BwE" target="_blank"&gt;Use Genie in multi-agent systems | Databricks Documentation&lt;/A&gt;&lt;BR /&gt;I’ve developed a &lt;STRONG&gt;multi-agent Genie&lt;/STRONG&gt; in Databricks and integrated it with &lt;STRONG&gt;vector indexes&lt;/STRONG&gt;. The setup works fine during model logging and prediction. The system successfully registers models to &lt;STRONG&gt;Model Serving&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;However, when I interact with the Genie using the &lt;STRONG&gt;Playground UI&lt;/STRONG&gt;, I receive the following error:&lt;/P&gt;&lt;P&gt;&lt;FONT color="#993366"&gt;&lt;U&gt;PermissionDenied: 2654507c-3f21-48f6-87f6-2e5ef2ac5c75 is not authorized to use or monitor this SQL Endpoint. Please contact your administrator.&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#993366"&gt;&lt;U&gt;Config: host=&lt;A href="https://dbc-3a822fc8-adcc.cloud.databricks.com" target="_blank" rel="noopener"&gt;https://dbc-3a822fc8-adcc.cloud.databricks.com&lt;/A&gt;, auth_type=model-serving&lt;/U&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#993366"&gt;&lt;U&gt;During task with name 'Genie' and id&lt;/U&gt; 'f039979b-69b5-0353-3070-24c8427faeef'&lt;BR /&gt;&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;H3&gt;What I’ve Observed:&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;The Genie automatically generates a &lt;STRONG&gt;service principal&lt;/STRONG&gt; when integrated with multiple agents.&lt;/LI&gt;&lt;LI&gt;This principal queries or interacts with a SQL Endpoint to query the tables.&lt;/LI&gt;&lt;LI&gt;Unfortunately, I cannot &lt;STRONG&gt;manually assign permissions&lt;/STRONG&gt; to this service principal.&lt;/LI&gt;&lt;LI&gt;It does not show up under typical service principal listings or user management.&lt;/LI&gt;&lt;LI&gt;As a result, &lt;STRONG&gt;any queries from the Playground fail with permission errors&lt;/STRONG&gt;.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Any help or insight would be appreciated. I'm happy to provide more details if needed!&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Karthik k&lt;/P&gt;&lt;P&gt;#genie #multiagent #model-serving #sql-endpoint #playground #permissions #service-principal #unity-catalog #databricks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 May 2025 08:28:17 GMT</pubDate>
      <guid>https://community.databricks.com/t5/generative-ai/permission-denied-for-genie-auto-generated-service-principal-on/m-p/120189#M906</guid>
      <dc:creator>Karthik_Karanm</dc:creator>
      <dc:date>2025-05-26T08:28:17Z</dc:date>
    </item>
    <item>
      <title>Re: Permission Denied for Genie Auto-Generated Service Principal on SQL Endpoint in Playground</title>
      <link>https://community.databricks.com/t5/generative-ai/permission-denied-for-genie-auto-generated-service-principal-on/m-p/135778#M1264</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi&amp;nbsp;&lt;A target="_blank" rel="noopener"&gt;@Karthik_Karanm&lt;/A&gt;&amp;nbsp;- Can you ensure to add the Genie in the resources as mentioned in the TODO of the cell.&lt;/SPAN&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;To enable automatic authentication, specify the dependent Databricks resources when calling mlflow.pyfunc.log_model().

TODO: If your Unity Catalog tool queries a vector search index or leverages external functions, you need to include the dependent vector search index and UC connection objects, respectively, as resources. See docs (AWS | Azure).

TODO: Add the SQL Warehouse or tables powering your Genie space to enable passthrough authentication. (AWS | Azure). If your genie space uses "embedded credentials" then you do not have to add this.&lt;/LI-CODE&gt;
&lt;P&gt;As an example, this is what I did -&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV&gt;&lt;LI-CODE lang="python"&gt;resources = [
DatabricksServingEndpoint(endpoint_name=LLM_ENDPOINT_NAME),
DatabricksGenieSpace(genie_space_id=GENIE_SPACE_ID),
]&lt;/LI-CODE&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dkushari_0-1761174939220.png" style="width: 400px;"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/20972i85E3C181C03B6A27/image-size/medium?v=v2&amp;amp;px=400" role="button" title="dkushari_0-1761174939220.png" alt="dkushari_0-1761174939220.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Oct 2025 23:18:27 GMT</pubDate>
      <guid>https://community.databricks.com/t5/generative-ai/permission-denied-for-genie-auto-generated-service-principal-on/m-p/135778#M1264</guid>
      <dc:creator>dkushari</dc:creator>
      <dc:date>2025-10-22T23:18:27Z</dc:date>
    </item>
  </channel>
</rss>

