Agent mode
Interactive, user-initiated multi-step agent mode of Databricks Genie Code. Agent mode plans a solution, retrieves relevant Databricks assets and context, generates and executes code, inspects outputs, adapts its approach, fixes errors automatically and can modify supported Databricks workspace objects, acting with the interacting user's permissions. Scheduled Genie Code tasks and the Genie Code task for Lakeflow Jobs are separate mechanisms and are excluded from this record.
Recorded characteristics
- Function
- Agent mode is the interactive multi-step mode of Genie Code. Databricks documents that it automates multi-step workflows: it plans solutions, retrieves relevant assets, generates and runs code, uses cell outputs to improve results and fixes errors automatically. The documented interaction pattern is: user prompt, then planning and context gathering, optional clarifying questions, selection of a tool or action, execution according to the current approval configuration, inspection of outputs, adaptation or error correction, and further steps toward the requested outcome. Databricks documents that a user can constrain a prompt to explanation-only behaviour (for example asking the agent to explain code without running anything), that the agent may present a step-by-step plan with Continue and Reject checkpoints, and that execution can be stopped. Supported surfaces carry their own documented boundaries and are not identical to one another. Notebooks and the SQL editor: create and edit cells, run cells and queries, read outputs, and perform exploratory data analysis, forecasting and machine-learning work. Lakeflow Pipelines Editor: edit SQL and Python pipeline source files, run pipeline updates and inspect the resulting pipeline data and outputs. AI/BI dashboards: create datasets, create and add visualisations, configure filters, add and organise pages, add supported widgets such as image widgets, and make further documented dashboard refinements. MLflow: Databricks documents read access to experiment traces, prompts, datasets, evaluation runs, scorers and labelling sessions for agent observability and evaluation work; write or modification behaviour on that surface is not publicly established. File editor and Genie Code command centre: only the functionality Databricks documents for those surfaces. Persistent actions therefore include modifying notebooks and creating cells, editing pipeline source files, running pipeline updates, creating and modifying dashboard objects, executing code, writing to tables the user is permitted to modify, and invoking referenced jobs and pipelines where documented. Generated code, queries and recommendations that are only displayed are suggestions, not actions; the distinction between suggestion and execution is maintained throughout this record. Scheduled Genie Code tasks, the Beta Genie Code task for Lakeflow Jobs, ordinary Genie Code chat mode, autocomplete, Quick Fix, Diagnose Error, standalone serverless code execution, the agentic code converter, Genie One, Genie Agents and data rooms, Databricks Apps, the Mosaic AI Agent Framework, custom agents and MCP or connector tool integrations are all outside this record.
- Data access
- Agent mode reads Databricks assets and context to plan and execute work. Databricks documents the context that may be sent to models as the user prompt, the code or query in the current cell or SQL editor tab, table and column names, descriptions and metadata, previous questions and conversational context, favourite or relevant tables where documented, and, specifically in Agent mode, cell outputs and data samples read from tables. Databricks states that the data sent respects the user's Unity Catalog permissions, so no data the user cannot access is sent; this is not the same as all data the user can access being sent, and no such claim is made here. On the write side, interactive Agent mode is explicitly not restricted to read-only SQL. Databricks documentation establishes three levels: it can execute read operations such as read-only queries; it can write to tables the user is permitted to modify (documented as writing to tables the user owns); and it can carry out explicitly requested destructive actions where the acting user has the necessary permissions, with documented examples of dropping a table the user named and deleting rows from a table being worked on. Databricks publishes no statement-level allow list, so no claim is made that every SQL DML or DDL form (INSERT, UPDATE, DELETE, MERGE, CREATE, ALTER, DROP) is individually supported. The verified boundary is: read operations, permitted table writes, and explicitly requested destructive actions, all constrained by the acting user's permissions.
- Actions
- Can take actions
- External actions
- No
- Human confirmation
- Conditional
- Permission basis
- User permissions
- Administrative control
- Documented controls: the account-level partner-powered AI setting and the workspace-level partner-powered AI setting, both of which Agent mode depends on; applicable Geo and cross-Geo processing and data-residency controls, Databricks treating AI assistive features as Designated Services; compliance-security-profile workspace behaviour, where partner-powered AI is off by default; Unity Catalog privileges over catalogs, schemas, tables, columns and other securables; workspace object permissions over notebooks, dashboards, pipelines and jobs; compute and SQL warehouse permissions; pipeline, job and dashboard permissions; the workspace previews page for adjacent preview-only functionality such as web search and the Genie Code task for Jobs; account-level Genie budgets with alert and block-usage thresholds administered through Unity Gateway using the databricks-product: genie tag at account, workspace, group and user level; and workspace-level and user-level instructions and skills where relevant. In addition, the per-chat approval mode is a user-facing setting rather than an administrative control. Databricks documents a future change to the partner-powered AI configuration control: the toggle is documented for removal on 1 November 2026, with existing values preserved and the setting remaining manageable through the Settings API thereafter. As of this record that removal has not occurred and the toggle is still documented as present; the change is recorded as announced and future-dated, and is one of the reasons the principal source is monitored. Agent-mode-specific audit logging behaviour is not publicly established.
- Default state
- Conditional
- Availability
- Databricks presents Agent mode as standard, current Genie Code functionality. Its documentation page carries no Beta or Public Preview label, and no explicit Agent-mode general-availability announcement or date was found in primary Databricks documentation; that absence is recorded here rather than an inferred GA date. Adjacent features carry their own distinct lifecycle labels which do not transfer to Agent mode: web search is Beta, Genie Ontology is Public Preview and the Genie Code task for Lakeflow Jobs is Beta. Availability depends on the partner-powered AI setting being enabled at both account and workspace level and on the workspace being in a supported region and Geo. If partner-powered AI is disabled, Genie Code remains available but without agentic capability, using a Databricks-hosted model. An exhaustive list of supported regions, and any cloud-by-cloud differences, are not established here.
- Licensing
- Databricks documents Genie usage as pay-as-you-go beyond a per-user free monthly allowance, with that pricing and billing treatment dated 8 July 2026, and consumption tracked and controlled through Unity Gateway budgets. Databricks separately documents free treatment for Genie One and Genie Agents for users through 31 January 2027, with service principals excluded; that separate allowance is not documented as applying to Genie Code Agent mode and is not claimed here.
- External model or provider
- Agent mode depends on partner-powered AI, and no single permanent model or provider is established. Databricks documents that, with partner-powered AI enabled, the provider and model infrastructure available to these features includes Azure OpenAI Service, OpenAI on Databricks and Anthropic on Databricks, and documents that Anthropic on Databricks uses Databricks-hosted endpoints. With partner-powered AI disabled, Agent mode is unavailable and Genie Code falls back to a Databricks-hosted model without agentic capability. No user-facing or admin-facing Agent-mode model picker is documented. Databricks states that partner providers serve these features through zero-data-retention endpoints and do not retain prompts or responses. Unresolved: an exhaustive supported-model list, a fixed default model, and any permanent provider assignment; provider and model behaviour is documented as plural and dynamic.
- Limitations and uncertainty
- Generated code, queries and outputs can be incorrect and require appropriate review before being relied on. Databricks states explicitly that Auto-approve is a productivity feature and not a security boundary, and that the classifier that decides which actions proceed automatically is best-effort and can approve or block incorrectly; Databricks factually recommends not using Auto-approve with production data or in shared workspaces. Explicitly requested destructive operations may execute when the acting user's permissions and the applicable approval behaviour allow, so Agent mode's destructive reach is real but permission constrained rather than unrestricted. The session or tab must remain active: Databricks documents that switching away from the tab can stop the agent. Agentic capability depends entirely on partner-powered AI availability. No exhaustive statement-level SQL allow list is published. Unresolved: an explicit lifecycle label or GA date for Agent mode; an exhaustive supported-model list; an exhaustive supported-region list; and Agent-mode-specific audit logging behaviour. MLflow-surface write behaviour is likewise not established.
Evidence
- Genie Code: Agent mode
Supports: Function · Actions · Data access · Human confirmation · Permission basis · Default state · Limitations · Availability · Primary source
Agent mode automates multi-step workflows: plans solutions, retrieves relevant assets, runs code, uses cell outputs to improve results and fixes errors automatically; plans expose Continue and Reject checkpoints and a prompt can be constrained to explanation only.
Documented actions include running code, editing notebooks, querying tables, writing to tables the user owns and running referenced jobs and pipelines.
Agent mode reads table data samples and cell outputs as context; SQL behaviour spans read operations, permitted table writes and explicitly requested destructive actions such as dropping a named table or deleting rows.
Tool actions request approval; modes are Ask every time, Allow in current chat, Always allow and Auto-approve, and the documented first-use default for a chat is Auto-approve, mediated by an AI classifier.
Agent mode acts within the interacting user's permissions and scope; the classifier blocks out-of-scope actions and risky scope escalation.
Agent mode requires partner-powered AI enabled at account and workspace level and a supported region; without it Genie Code remains available without agentic capability.
Auto-approve is explicitly described as not a security boundary, the classifier is best-effort, explicitly requested destructive actions may execute, and Databricks advises against Auto-approve for production data and shared workspaces.
The Agent mode page presents the feature as current Genie Code functionality with no Beta or Preview label and no GA announcement or date.
- Genie Code overview
Supports: Function · Primary source
Genie Code is the AI coding and data assistant in the Genie family, supported in notebooks, the SQL editor, the Lakeflow Pipelines Editor, AI/BI dashboards and MLflow.
- Genie Code features and capabilities
Supports: Function · Availability · Primary source
Features documentation distinguishes Agent mode from chat, autocomplete, Quick Fix, Diagnose Error, serverless execution and scheduled tasks.
Adjacent Genie Code features carry their own lifecycle labels distinct from Agent mode.
- Use Genie Code for data science
Supports: Actions · Function · Primary source
On the notebook surface the agent searches tables, creates and edits cells, runs cells and interprets outputs with user approval.
Documents exploratory data analysis, forecasting and machine-learning workflows performed through Genie Code in notebooks.
- Use Genie Code for pipeline development
Supports: Actions · Primary source
In the Lakeflow Pipelines Editor the agent edits SQL and Python pipeline source and runs pipeline updates with user approval.
- Use Genie Code for dashboard authoring
Supports: Actions · Primary source
On AI/BI dashboards the agent creates datasets and visualisations, configures filters, adds and organises pages and adds supported widgets.
- Genie Code for agent observability and evaluation (MLflow)
Supports: Data access · Primary source
MLflow usage documents read access to experiment traces, prompts, datasets, evaluation runs, scorers and labelling sessions; write behaviour on that surface is not established.
- Partner-powered AI features
Supports: Default state · Admin controls · External model · Availability · Primary source
Partner-powered AI is enabled by default for ordinary eligible workspaces and disabled by default for compliance-security-profile workspaces; Agent mode is unavailable when it is disabled.
Account-level and workspace-level partner-powered AI settings, Geo and data-residency handling, and the documented removal of the toggle on 1 November 2026 with values preserved and Settings API management thereafter.
With partner-powered AI enabled, providers include Azure OpenAI Service, OpenAI on Databricks and Anthropic on Databricks; with it disabled, Agent mode is unavailable.
Availability depends on supported regions and Geo handling for partner-powered AI features.
- Databricks AI assistive features: trust and safety
Supports: Data access · Human confirmation · External model · Permission basis · Primary source
Context sent to models includes the prompt, current code or query, table and column names and descriptions, previous questions, favourite tables and, in Agent mode, cell outputs and data samples; all constrained by the user's Unity Catalog permissions.
Agent mode can run notebook and SQL editor code after initial confirmation, which can be changed to current-chat or always-allow; other Genie Code modes do not run code on the user's behalf.
Partner providers serve these features through zero-data-retention endpoints and do not retain prompts or responses; Anthropic on Databricks uses Databricks-hosted endpoints.
Data sent to models respects the user's Unity Catalog permissions.
- Manage budgets and cost controls for Genie
Supports: Licensing · Admin controls · Primary source
Genie usage is pay-as-you-go beyond a per-user free monthly allowance, dated 8 July 2026, with Unity Gateway budgets at account, workspace, group and user level.
Genie budgets support alert and block-usage thresholds using the databricks-product: genie tag.
- Genie Code web search
Supports: External actions · Primary source
Web search is Beta and retrieval-only; no default state-changing action outside Databricks is documented for Agent mode.
- Genie Code scheduled tasks
Supports: General · Primary source
Boundary evidence: Genie Code scheduled tasks are a separate recurring mechanism with auto-approve always on, excluded from this record.
- Genie Code task for Lakeflow Jobs
Supports: General · Primary source
Boundary evidence: the Genie Code task for Lakeflow Jobs is a separate Beta, job-triggered, unattended capability, excluded from this record.