AbhilashNagilla
Databricks Employee
Databricks Employee

The most likely reason is that system.ai grants EXECUTE to all users by default, so you probably hold effective EXECUTE inherited from the schema even without an explicit grant on any model, which is the privilege the API requires. USE CATALOG and USE SCHEMA are parent usage privileges that do not by themselves grant model access. Two checks confirm whether inherited EXECUTE or catalog BROWSE returned the models.

  1. Print full_name and browse_only, then rerun with include_browse=False. The List Registered Models API says include_browse adds models the caller can access as selective metadata only, and browse_only=True marks a result returned through metadata-only BROWSE.

for model in w.registered_models.list(
    catalog_name="system",
    schema_name="ai",
    include_browse=True,
):
    print(model.full_name, model.browse_only)

The privileges reference separates that metadata discovery from EXECUTE, which loads a registered model for inference.

  1. Check effective permissions on the system.ai schema and on a returned model. The Get Effective Permissions API takes securable type SCHEMA for the schema and FUNCTION for the model, since registered models are a type of function. The schema check surfaces the default all-users EXECUTE that inherits to the models; the model check surfaces any direct grant. Databricks documents that all users have EXECUTE on system.ai by default, and administrators can revoke it and grant EXECUTE on selected models instead.

With the same caller and unchanged grants, a model still returned when include_browse=False came through the regular privilege-filtered path, which requires ownership or effective EXECUTE. A model that appears only with include_browse=True and reports browse_only=True came through BROWSE.

View solution in original post