Databricks · Genie Code

Agent mode

Interactive, user-initiated multi-step agent mode of Databricks Genie Code. Agent mode plans a solution, retrieves relevant Databricks assets and context, generates and executes code, inspects outputs, adapts its approach, fixes errors automatically and can modify supported Databricks workspace objects, acting with the interacting user's permissions. Scheduled Genie Code tasks and the Genie Code task for Lakeflow Jobs are separate mechanisms and are excluded from this record.

Recorded characteristics

Function
Agent mode is the interactive multi-step mode of Genie Code. Databricks documents that it automates multi-step workflows: it plans solutions, retrieves relevant assets, generates and runs code, uses cell outputs to improve results and fixes errors automatically. The documented interaction pattern is: user prompt, then planning and context gathering, optional clarifying questions, selection of a tool or action, execution according to the current approval configuration, inspection of outputs, adaptation or error correction, and further steps toward the requested outcome. Databricks documents that a user can constrain a prompt to explanation-only behaviour (for example asking the agent to explain code without running anything), that the agent may present a step-by-step plan with Continue and Reject checkpoints, and that execution can be stopped. Supported surfaces carry their own documented boundaries and are not identical to one another. Notebooks and the SQL editor: create and edit cells, run cells and queries, read outputs, and perform exploratory data analysis, forecasting and machine-learning work. Lakeflow Pipelines Editor: edit SQL and Python pipeline source files, run pipeline updates and inspect the resulting pipeline data and outputs. AI/BI dashboards: create datasets, create and add visualisations, configure filters, add and organise pages, add supported widgets such as image widgets, and make further documented dashboard refinements. MLflow: Databricks documents read access to experiment traces, prompts, datasets, evaluation runs, scorers and labelling sessions for agent observability and evaluation work; write or modification behaviour on that surface is not publicly established. File editor and Genie Code command centre: only the functionality Databricks documents for those surfaces. Persistent actions therefore include modifying notebooks and creating cells, editing pipeline source files, running pipeline updates, creating and modifying dashboard objects, executing code, writing to tables the user is permitted to modify, and invoking referenced jobs and pipelines where documented. Generated code, queries and recommendations that are only displayed are suggestions, not actions; the distinction between suggestion and execution is maintained throughout this record. Scheduled Genie Code tasks, the Beta Genie Code task for Lakeflow Jobs, ordinary Genie Code chat mode, autocomplete, Quick Fix, Diagnose Error, standalone serverless code execution, the agentic code converter, Genie One, Genie Agents and data rooms, Databricks Apps, the Mosaic AI Agent Framework, custom agents and MCP or connector tool integrations are all outside this record.
Data access
Agent mode reads Databricks assets and context to plan and execute work. Databricks documents the context that may be sent to models as the user prompt, the code or query in the current cell or SQL editor tab, table and column names, descriptions and metadata, previous questions and conversational context, favourite or relevant tables where documented, and, specifically in Agent mode, cell outputs and data samples read from tables. Databricks states that the data sent respects the user's Unity Catalog permissions, so no data the user cannot access is sent; this is not the same as all data the user can access being sent, and no such claim is made here. On the write side, interactive Agent mode is explicitly not restricted to read-only SQL. Databricks documentation establishes three levels: it can execute read operations such as read-only queries; it can write to tables the user is permitted to modify (documented as writing to tables the user owns); and it can carry out explicitly requested destructive actions where the acting user has the necessary permissions, with documented examples of dropping a table the user named and deleting rows from a table being worked on. Databricks publishes no statement-level allow list, so no claim is made that every SQL DML or DDL form (INSERT, UPDATE, DELETE, MERGE, CREATE, ALTER, DROP) is individually supported. The verified boundary is: read operations, permitted table writes, and explicitly requested destructive actions, all constrained by the acting user's permissions.
Actions
Can take actions
External actions
No
Human confirmation
Conditional
Permission basis
User permissions
Administrative control
Documented controls: the account-level partner-powered AI setting and the workspace-level partner-powered AI setting, both of which Agent mode depends on; applicable Geo and cross-Geo processing and data-residency controls, Databricks treating AI assistive features as Designated Services; compliance-security-profile workspace behaviour, where partner-powered AI is off by default; Unity Catalog privileges over catalogs, schemas, tables, columns and other securables; workspace object permissions over notebooks, dashboards, pipelines and jobs; compute and SQL warehouse permissions; pipeline, job and dashboard permissions; the workspace previews page for adjacent preview-only functionality such as web search and the Genie Code task for Jobs; account-level Genie budgets with alert and block-usage thresholds administered through Unity Gateway using the databricks-product: genie tag at account, workspace, group and user level; and workspace-level and user-level instructions and skills where relevant. In addition, the per-chat approval mode is a user-facing setting rather than an administrative control. Databricks documents a future change to the partner-powered AI configuration control: the toggle is documented for removal on 1 November 2026, with existing values preserved and the setting remaining manageable through the Settings API thereafter. As of this record that removal has not occurred and the toggle is still documented as present; the change is recorded as announced and future-dated, and is one of the reasons the principal source is monitored. Agent-mode-specific audit logging behaviour is not publicly established.
Default state
Conditional
Availability
Databricks presents Agent mode as standard, current Genie Code functionality. Its documentation page carries no Beta or Public Preview label, and no explicit Agent-mode general-availability announcement or date was found in primary Databricks documentation; that absence is recorded here rather than an inferred GA date. Adjacent features carry their own distinct lifecycle labels which do not transfer to Agent mode: web search is Beta, Genie Ontology is Public Preview and the Genie Code task for Lakeflow Jobs is Beta. Availability depends on the partner-powered AI setting being enabled at both account and workspace level and on the workspace being in a supported region and Geo. If partner-powered AI is disabled, Genie Code remains available but without agentic capability, using a Databricks-hosted model. An exhaustive list of supported regions, and any cloud-by-cloud differences, are not established here.
Licensing
Databricks documents Genie usage as pay-as-you-go beyond a per-user free monthly allowance, with that pricing and billing treatment dated 8 July 2026, and consumption tracked and controlled through Unity Gateway budgets. Databricks separately documents free treatment for Genie One and Genie Agents for users through 31 January 2027, with service principals excluded; that separate allowance is not documented as applying to Genie Code Agent mode and is not claimed here.
External model or provider
Agent mode depends on partner-powered AI, and no single permanent model or provider is established. Databricks documents that, with partner-powered AI enabled, the provider and model infrastructure available to these features includes Azure OpenAI Service, OpenAI on Databricks and Anthropic on Databricks, and documents that Anthropic on Databricks uses Databricks-hosted endpoints. With partner-powered AI disabled, Agent mode is unavailable and Genie Code falls back to a Databricks-hosted model without agentic capability. No user-facing or admin-facing Agent-mode model picker is documented. Databricks states that partner providers serve these features through zero-data-retention endpoints and do not retain prompts or responses. Unresolved: an exhaustive supported-model list, a fixed default model, and any permanent provider assignment; provider and model behaviour is documented as plural and dynamic.
Limitations and uncertainty
Generated code, queries and outputs can be incorrect and require appropriate review before being relied on. Databricks states explicitly that Auto-approve is a productivity feature and not a security boundary, and that the classifier that decides which actions proceed automatically is best-effort and can approve or block incorrectly; Databricks factually recommends not using Auto-approve with production data or in shared workspaces. Explicitly requested destructive operations may execute when the acting user's permissions and the applicable approval behaviour allow, so Agent mode's destructive reach is real but permission constrained rather than unrestricted. The session or tab must remain active: Databricks documents that switching away from the tab can stop the agent. Agentic capability depends entirely on partner-powered AI availability. No exhaustive statement-level SQL allow list is published. Unresolved: an explicit lifecycle label or GA date for Agent mode; an exhaustive supported-model list; an exhaustive supported-region list; and Agent-mode-specific audit logging behaviour. MLflow-surface write behaviour is likewise not established.

Evidence