<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Prevent Access to AI Functions Execution in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/prevent-access-to-ai-functions-execution/m-p/140192#M4531</link>
    <description>&lt;P&gt;As a workspace Admin, I want to prevent unexpected API costs from unrestricted usage of AI Functions (AI_QUERY() etc.), how can we control that only a particular group-users can execute AI Functions ?&lt;/P&gt;&lt;P&gt;I understand the function execution cost can be viewed from &lt;A href="https://docs.databricks.com/aws/en/large-language-models/ai-functions#-view-costs-for-ai-function-workloads," target="_blank"&gt;https://docs.databricks.com/aws/en/large-language-models/ai-functions#-view-costs-for-ai-function-workloads,&lt;/A&gt;&amp;nbsp;but perhaps it will be too late &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Best Practice and guidelines pls.&lt;/P&gt;</description>
    <pubDate>Mon, 24 Nov 2025 14:05:59 GMT</pubDate>
    <dc:creator>Raman_Unifeye</dc:creator>
    <dc:date>2025-11-24T14:05:59Z</dc:date>
    <item>
      <title>Prevent Access to AI Functions Execution</title>
      <link>https://community.databricks.com/t5/administration-architecture/prevent-access-to-ai-functions-execution/m-p/140192#M4531</link>
      <description>&lt;P&gt;As a workspace Admin, I want to prevent unexpected API costs from unrestricted usage of AI Functions (AI_QUERY() etc.), how can we control that only a particular group-users can execute AI Functions ?&lt;/P&gt;&lt;P&gt;I understand the function execution cost can be viewed from &lt;A href="https://docs.databricks.com/aws/en/large-language-models/ai-functions#-view-costs-for-ai-function-workloads," target="_blank"&gt;https://docs.databricks.com/aws/en/large-language-models/ai-functions#-view-costs-for-ai-function-workloads,&lt;/A&gt;&amp;nbsp;but perhaps it will be too late &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Best Practice and guidelines pls.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Nov 2025 14:05:59 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/prevent-access-to-ai-functions-execution/m-p/140192#M4531</guid>
      <dc:creator>Raman_Unifeye</dc:creator>
      <dc:date>2025-11-24T14:05:59Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent Access to AI Functions Execution</title>
      <link>https://community.databricks.com/t5/administration-architecture/prevent-access-to-ai-functions-execution/m-p/140215#M4532</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/179607"&gt;@Raman_Unifeye&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;For PT (Provisioned Throughput) endpoints, on the UI, you will have an option to edit "Permissions" and set a specific User/Group that can query them. You will have to assign that group "Can Query" permission. By Default all Admins will have access to this.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screenshot 2025-11-24 at 11.28.41 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/21929i85F132085E88B89C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2025-11-24 at 11.28.41 PM.png" alt="Screenshot 2025-11-24 at 11.28.41 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Thanks,&lt;BR /&gt;Yashwanth&lt;/P&gt;</description>
      <pubDate>Mon, 24 Nov 2025 18:00:27 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/prevent-access-to-ai-functions-execution/m-p/140215#M4532</guid>
      <dc:creator>iyashk-DB</dc:creator>
      <dc:date>2025-11-24T18:00:27Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent Access to AI Functions Execution</title>
      <link>https://community.databricks.com/t5/administration-architecture/prevent-access-to-ai-functions-execution/m-p/140239#M4537</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/112558"&gt;@iyashk-DB&lt;/a&gt;&amp;nbsp;- can you pls elaborate on it. I am looking to turn it off for all of Databricks AI Functions usage -&amp;nbsp;&lt;A href="https://docs.databricks.com/aws/en/large-language-models/ai-functions#-task-specific-ai-functions" target="_blank"&gt;https://docs.databricks.com/aws/en/large-language-models/ai-functions#-task-specific-ai-functions&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Nov 2025 22:24:05 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/prevent-access-to-ai-functions-execution/m-p/140239#M4537</guid>
      <dc:creator>Raman_Unifeye</dc:creator>
      <dc:date>2025-11-24T22:24:05Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent Access to AI Functions Execution</title>
      <link>https://community.databricks.com/t5/administration-architecture/prevent-access-to-ai-functions-execution/m-p/140263#M4540</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/179607"&gt;@Raman_Unifeye&lt;/a&gt;&amp;nbsp;, you will be disabling access to the endpionts that will be used inside the ai_query() function. It is not something like disabling the function, but managing the endpoint's access to the Users/groups who can and cannot query them.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Nov 2025 07:38:52 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/prevent-access-to-ai-functions-execution/m-p/140263#M4540</guid>
      <dc:creator>iyashk-DB</dc:creator>
      <dc:date>2025-11-25T07:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent Access to AI Functions Execution</title>
      <link>https://community.databricks.com/t5/administration-architecture/prevent-access-to-ai-functions-execution/m-p/140294#M4542</link>
      <description>&lt;P&gt;ok, so it has to be done at individual end-point and function level&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":unamused_face:"&gt;😒&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Nov 2025 10:32:31 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/prevent-access-to-ai-functions-execution/m-p/140294#M4542</guid>
      <dc:creator>Raman_Unifeye</dc:creator>
      <dc:date>2025-11-25T10:32:31Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent Access to AI Functions Execution</title>
      <link>https://community.databricks.com/t5/administration-architecture/prevent-access-to-ai-functions-execution/m-p/140307#M4543</link>
      <description>&lt;P&gt;Nothing at the function level, but yes this has to be done to each endpoint&lt;/P&gt;</description>
      <pubDate>Tue, 25 Nov 2025 12:33:48 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/prevent-access-to-ai-functions-execution/m-p/140307#M4543</guid>
      <dc:creator>iyashk-DB</dc:creator>
      <dc:date>2025-11-25T12:33:48Z</dc:date>
    </item>
  </channel>
</rss>

