Read your lakehouse for context, change apps and catalog access with approval
Connect Databricks and Luumen can look up apps, deployments, Unity Catalog objects, credentials, and permission assignments while you work. Ask who has access to an app, or what an external location points at, and get an answer from the workspace itself. Changes like deploying an app or editing permissions are previewed first and, by default, held for your approval.
410 tools: 164 read, 246 write. Reads answer instantly. Writes require approval by default. Everything is logged.
ReadGet Databricks App DetailsRetrieve details about a specific Databricks app by name.
ReadGet Databricks App Permission LevelsRetrieve available permission levels for a Databricks app.
ReadGet Databricks App PermissionsRetrieve permissions for a Databricks app.
ReadGet App Update StatusRetrieves the current update status of a Databricks app.
ReadGet Catalog Artifact AllowlistRetrieve artifact allowlist configuration for a specified artifact type in Unity Catalog.
ReadGet Catalog DetailsRetrieve details of a specific catalog in Unity Catalog.
ReadGet Catalog ConnectionRetrieve detailed information about a specific Unity Catalog connection.
ReadGet Catalog CredentialRetrieve detailed information about a specific Unity Catalog credential.
ReadGenerate Temporary Service CredentialGenerate temporary credentials from a service credential with admin access.
ReadValidate Catalog CredentialValidate a Unity Catalog credential for external access.
ReadGet Entity Tag AssignmentRetrieve a specific tag assignment for a Unity Catalog entity by tag key.
ReadGet External Location DetailsRetrieve details of a specific Unity Catalog external location.
ReadGet Catalog GrantsGet permissions (grants) for a securable in Unity Catalog without inherited permissions.
ReadGet Effective Catalog PermissionsGet effective permissions for a securable in Unity Catalog, including inherited permissions from parent securables.
ReadGet Current Metastore AssignmentRetrieve the current metastore assignment for the workspace being accessed.
ReadGet Metastore DetailsRetrieves comprehensive details about a Unity Catalog metastore by its unique ID.
ReadGet Metastore SummaryRetrieve summary information about the metastore associated with the current workspace.
ReadGet Model VersionRetrieve detailed information about a specific version of a registered model in Unity Catalog.
ReadGet Quality MonitorRetrieve quality monitor configuration for a Unity Catalog table.
ReadList Quality Monitor RefreshesRetrieve the refresh history for a quality monitor on a Unity Catalog table.
ReadGet Registered ModelRetrieve detailed information about a registered model in Unity Catalog.
ReadGet Resource Quota InformationRetrieve usage information for a Unity Catalog resource quota defined by a child-parent pair.
ReadGet Access Request DestinationsRetrieve access request destinations for a Unity Catalog securable.
ReadGet Catalog SchemaRetrieve details of a specific schema from Unity Catalog metastore.
ReadGet Storage CredentialRetrieve storage credential details from Unity Catalog metastore by name.
ReadValidate Storage CredentialValidate a storage credential configuration for Unity Catalog.
ReadCheck Table ExistsCheck if a table exists in Unity Catalog metastore.
ReadGet Catalog Table DetailsRetrieve comprehensive metadata about a table from Unity Catalog metastore.
ReadGenerate Temporary Path CredentialsGenerate short-lived, scoped temporary credentials for accessing external storage locations registered in Unity Catalog.
ReadGet Catalog Volume DetailsRetrieve detailed information about a specific Unity Catalog volume.
ReadGet Clean Room AssetRetrieve detailed information about a specific asset within a Databricks Clean Room.
ReadGet Compute Cluster PolicyRetrieve detailed information about a specific cluster policy by its ID.
ReadGet Compute Cluster Policy Permission LevelsRetrieve available permission levels for a Databricks cluster policy.
ReadGet Compute Cluster Policy PermissionsRetrieve permissions for a Databricks cluster policy.
ReadGet Compute Cluster Permission LevelsRetrieve available permission levels for a Databricks compute cluster.
ReadList Compute Cluster Node TypesList all supported Spark node types available for cluster launch in the workspace region.
ReadList Compute Cluster Availability ZonesList availability zones where Databricks clusters can be created.
ReadList Compute Cluster Spark VersionsList all available Databricks Runtime Spark versions for cluster creation.
ReadGet Global Init ScriptRetrieve complete details of a global initialization script in Databricks workspace.
ReadGet Instance Pool DetailsRetrieve detailed information about a Databricks instance pool by its ID.
ReadGet Instance Pool PermissionsRetrieve permissions for a Databricks instance pool.
ReadGet Instance Pool Permission LevelsRetrieve available permission levels for a Databricks instance pool.
ReadGet Cluster Policy ComplianceRetrieve policy compliance status for a specific cluster.
ReadGet Compute Policy FamiliesRetrieve information for a policy family by identifier and optional version.
ReadGet Genie MessageRetrieve details of a specific message from a Genie conversation.
ReadGet Genie Message Attachment Query ResultRetrieve SQL query results from a Genie message attachment.
ReadGet Genie Message Query ResultRetrieve SQL query execution results for a Genie message (up to 5000 rows).
ReadGet Genie Space DetailsRetrieve detailed information about a specific Databricks Genie space by ID.
ReadList Genie ConversationsRetrieve all existing conversation threads within a Genie space.
ReadList Genie Conversation MessagesRetrieve all messages from a specific conversation thread in a Genie space.
ReadList Genie SpacesRetrieve all Genie spaces in the workspace that the authenticated user has access to.
ReadGet Published Dashboard Token InfoRetrieves authorization information needed to generate a downscoped OAuth token for embedding a published Lakeview dashboard for external viewers.
ReadGet Lakeview Dashboard DetailsRetrieve details about a draft AI/BI Lakeview dashboard from the workspace.
ReadGet Published Lakeview DashboardRetrieve the current published version of a Lakeview dashboard.
ReadGet Lakeview Dashboard ScheduleRetrieve a specific schedule for a Databricks AI/BI Lakeview dashboard.
ReadFind Database Instance By UIDFind a database instance by its unique identifier (UID).
ReadGet Database InstanceRetrieves detailed information about a Databricks Lakebase (managed PostgreSQL) database instance by name.
ReadList DBFS Directory ContentsList the contents of a directory or get details of a file in DBFS.
ReadGet DBFS File StatusGet the information of a file or directory in DBFS.
ReadRead DBFS File ContentsRead the contents of a file from DBFS.
ReadGet All Library StatusesRetrieve status of all libraries across all Databricks clusters.
ReadGet Cluster InformationRetrieve comprehensive metadata and configuration details for a Databricks cluster by its unique identifier.
ReadGet User by IDRetrieve information for a specific user in Databricks workspace by their ID.
ReadGet IAM Account Group V2Retrieve a specific group resource by its unique identifier from a Databricks account using SCIM v2 protocol.
ReadGet Current User InformationRetrieve details about the currently authenticated user or service principal making the API request.
ReadGet Workspace IAM Group V2Retrieve details of a specific group by ID from Databricks workspace using SCIM v2 protocol.
ReadGet IAM PermissionsRetrieve IAM permissions for a Databricks workspace object.
ReadGet IAM Permission LevelsRetrieve available permission levels for a Databricks workspace object.
ReadGet IAM Service Principal V2Retrieve details of a specific service principal by ID from Databricks workspace using SCIM v2 protocol.
ReadGet Workspace Access DetailRetrieves workspace access details for a specific principal (user, service principal, or group) in Databricks.
ReadList Job Compliance for PolicyRetrieve policy compliance status of all jobs using a given cluster policy.
ReadGet Job Run By IDRetrieve metadata of a single Databricks job run by ID.
ReadGet Databricks Job DetailsRetrieve detailed information about a single Databricks job.
ReadGet Job Permission LevelsRetrieve available permission levels for a Databricks job.
ReadGet Job Policy ComplianceRetrieve policy compliance status for a specific job.
ReadList Unity CatalogsRetrieve a list of all catalogs in the Unity Catalog metastore.
ReadList ClustersList all pinned, active, and recently terminated Databricks clusters.
ReadList Workspace GroupsList all groups in the Databricks workspace using SCIM v2 protocol.
ReadList Instance PoolsRetrieve a list of all active instance pools in the Databricks workspace with their statistics and configuration.
ReadList All Databricks Jobs (API 2.0)List all jobs in the Databricks workspace using API 2.0.
ReadList Members of a Security GroupRetrieve all members (users and nested groups) of a Databricks security group.
ReadList Model Serving EndpointsLists all model serving endpoints in the Databricks workspace.
ReadList Delta Live Tables PipelinesList Delta Live Tables pipelines in the workspace.
ReadList ReposList Git repos that the calling user has Manage permissions on.
ReadList Databricks Job RunsList Databricks job runs in descending order by start time.
ReadList Catalog SchemasRetrieve all schemas in a specified catalog from Unity Catalog.
ReadList SecretsList all secret keys stored in a Databricks secret scope.
ReadList Secret ScopesList all secret scopes available in the Databricks workspace.
ReadList SQL WarehousesList all SQL warehouses in the Databricks workspace.
ReadList Catalog TablesList all tables in a Unity Catalog schema with pagination support.
ReadList TokensList all valid personal access tokens (PATs) for a user-workspace pair.
ReadList UsersList all users in a Databricks workspace using SCIM 2.0 protocol.
ReadList Vector Search EndpointsList all vector search endpoints in the Databricks workspace.
ReadGet Marketplace Consumer ListingRetrieve a published listing from Databricks Marketplace that consumer has access to.
ReadGet Marketplace Consumer ProviderRetrieve information about a specific provider in the Databricks Marketplace with visible listings.
ReadGet Marketplace Provider ListingRetrieve a specific marketplace provider listing by its identifier.
ReadBatch Get Marketplace Consumer ListingsRetrieve multiple published marketplace listings by their IDs in a single API call.
ReadGet Marketplace Consumer Personalization RequestsRetrieve personalization requests for a specific marketplace listing.
ReadBatch Get Marketplace Consumer ProvidersRetrieve multiple marketplace provider details in a single batch API call.
ReadGet Provider Analytics DashboardRetrieve provider analytics dashboard information for monitoring consumer usage metrics.
ReadGet Latest Provider Analytics Dashboard VersionRetrieve the latest logical version of the provider analytics dashboard template.
ReadGet ML Experiment By NameRetrieve MLflow experiment metadata by name.
ReadGet ML ExperimentRetrieve metadata for an MLflow experiment by ID.
ReadGet Logged ModelFetch logged model metadata by unique ID.
ReadGet ML Experiment Permission LevelsRetrieve available permission levels for a Databricks ML experiment.
ReadGet ML Experiment PermissionsRetrieve permissions for an MLflow experiment.
ReadGet MLflow RunRetrieve complete information about a specific MLflow run including metadata, metrics, parameters, tags, inputs, and outputs.
ReadSearch Logged ModelsSearch for logged models in MLflow experiments based on various criteria.
ReadGet ML Feature TagRetrieve a specific tag from a feature in a feature table in ML Feature Store.
ReadGet ML Model Registry Permission LevelsRetrieves the list of available permission levels that can be assigned to users or groups for a Databricks ML registered model.
ReadGet Pipeline PermissionsRetrieve permissions for a Databricks Delta Live Tables pipeline.
ReadGet Pipeline Permission LevelsRetrieve available permission levels for a Databricks Delta Live Tables pipeline.
ReadList Pipeline UpdatesRetrieve a paginated list of updates for a Databricks Delta Live Tables pipeline.
ReadSearch MLflow ExperimentsSearch for MLflow experiments with filtering, ordering, and pagination support.
ReadSearch MLflow RunsSearch for MLflow runs with filtering, ordering, and pagination support.
ReadGet Serving Endpoint DetailsRetrieves comprehensive details about a specific Databricks serving endpoint by name.
ReadGet Serving Endpoint OpenAPI SpecRetrieve the OpenAPI 3.1.0 specification for a serving endpoint.
ReadGet Serving Endpoint Permission LevelsRetrieve available permission levels for a Databricks serving endpoint.
ReadGet Tag PolicyRetrieve a specific tag policy by its associated governed tag's key.
ReadQuery Vector Search IndexQuery vector search index to find similar vectors and return associated documents.
ReadGet Workspace Git CredentialsRetrieve Git credentials for authenticating with remote Git repositories in Databricks.
ReadList Workspace DirectoryList the contents of a directory in Databricks workspace.
ReadGet Workspace Repo Permission LevelsRetrieve available permission levels for a Databricks workspace repository.
ReadGet Secrets ACLRetrieve ACL details for a principal on a Databricks secret scope.
ReadGet Secret ValueGet a secret value from a Databricks secret scope.
ReadExport Workspace ObjectExport a workspace object (notebook, dashboard, or file) as file content or base64-encoded string.
ReadGet Workspace Object StatusRetrieve status and metadata for any workspace object including notebooks, directories, dashboards, and files.
WriteAdd Member to Security GroupAdd a user or group as a member to a Databricks security group. Approval by default
WriteDelete Custom LLM AgentDelete a Custom LLM agent created through Agent Bricks. Approval by default
WriteCreate Databricks AppCreate a new Databricks app with specified configuration. Approval by default
WriteDelete Databricks AppDelete a Databricks app from the workspace. Approval by default
WriteDeploy Databricks AppCreate a deployment for a Databricks app. Approval by default
WriteSet Databricks App PermissionsSet permissions for a Databricks app, replacing all existing permissions. Approval by default
WriteStart Databricks AppStart the last active deployment of a Databricks app. Approval by default
WriteStop Databricks AppStop the active deployment of a Databricks app. Approval by default
WriteUpdate Databricks AppUpdate an existing Databricks app configuration. Approval by default
WriteUpdate Databricks App PermissionsIncrementally update permissions for a Databricks app. Approval by default
WriteDelete CatalogDelete a catalog from Unity Catalog metastore. Approval by default
WriteCreate Catalog ConnectionCreate a new Unity Catalog connection to external data sources. Approval by default
WriteDelete Catalog ConnectionDelete a Unity Catalog connection to external data sources. Approval by default
WriteUpdate Catalog ConnectionUpdate an existing Unity Catalog connection configuration. Approval by default
WriteCreate Catalog CredentialCreate a new credential for Unity Catalog access to cloud services. Approval by default
WriteDelete Catalog CredentialDelete a Unity Catalog credential for cloud storage or service access. Approval by default
WriteUpdate Catalog CredentialUpdate an existing Unity Catalog credential with new properties. Approval by default
WriteCreate External LocationCreate a new Unity Catalog external location combining a cloud storage path with a storage credential. Approval by default
WriteDelete External LocationDelete an external location from Unity Catalog metastore. Approval by default
WriteUpdate External LocationUpdate an existing Unity Catalog external location properties. Approval by default
WriteUpdate External MetadataUpdate an external metadata object in Unity Catalog. Approval by default
WriteUpdate Catalog FunctionUpdate function owner in Unity Catalog. Approval by default
WriteUpdate Catalog GrantsUpdate permissions for Unity Catalog securables by adding or removing privileges for principals. Approval by default
WriteAssign Metastore to WorkspaceAssign a Unity Catalog metastore to a workspace. Approval by default
WriteCreate MetastoreCreate a new Unity Catalog metastore. Approval by default
WriteDelete MetastoreDelete a Unity Catalog metastore. Approval by default
WriteUnassign Metastore from WorkspaceUnassign a Unity Catalog metastore from a workspace. Approval by default
WriteUpdate MetastoreUpdate configuration settings for an existing Unity Catalog metastore. Approval by default
WriteUpdate Metastore AssignmentUpdate a metastore assignment for a workspace. Approval by default
WriteUpdate Model VersionUpdate a Unity Catalog model version. Approval by default
WriteBatch Create Access RequestsBatch create access requests for Unity Catalog permissions. Approval by default
WriteUpdate Access Request DestinationsUpdate access request notification destinations for Unity Catalog securables. Approval by default
WriteCreate Storage CredentialCreate a new storage credential in Unity Catalog for cloud data access. Approval by default
WriteDelete Storage CredentialDelete a storage credential from the Unity Catalog metastore. Approval by default
WriteUpdate Storage CredentialUpdate an existing storage credential in Unity Catalog. Approval by default
WriteDisable System SchemaDisable a system schema in Unity Catalog metastore. Approval by default
WriteEnable System SchemaEnable a system schema in Unity Catalog metastore. Approval by default
WriteDelete Catalog TableDelete a table from Unity Catalog. Approval by default
WriteUpdate Catalog TableUpdate Unity Catalog table properties. Approval by default
WriteUpdate Catalog Workspace BindingsUpdate workspace bindings for a Unity Catalog securable (catalog). Approval by default
WriteCreate Clean Room Auto-Approval RuleCreate a new auto-approval rule for a Databricks Clean Room. Approval by default
WriteCreate Clean RoomCreate a new Databricks Clean Room for secure data collaboration with specified collaborators. Approval by default
WriteCreate Compute Cluster PolicyCreate a new cluster policy with prescribed settings for controlling cluster creation. Approval by default
WriteDelete Compute Cluster PolicyDelete a cluster policy. Approval by default
WriteEdit Compute Cluster PolicyUpdate an existing Databricks cluster policy. Approval by default
WriteSet Compute Cluster Policy PermissionsSet permissions for a Databricks cluster policy, replacing all existing permissions. Approval by default
WriteUpdate Cluster Policy PermissionsIncrementally update permissions on a Databricks cluster policy. Approval by default
WritePermanently Delete Compute ClusterPermanently delete a Databricks compute cluster. Approval by default
WritePin Compute ClusterPin a Databricks compute cluster configuration. Approval by default
WriteStart Compute ClusterStart a terminated Databricks compute cluster asynchronously. Approval by default
WriteUnpin Compute ClusterUnpin a Databricks compute cluster configuration. Approval by default
WriteUpdate Compute ClusterPartially update a Databricks compute cluster configuration using field masks. Approval by default
WriteCreate Global Init ScriptCreate a new global initialization script in Databricks workspace. Approval by default
WriteDelete Global Init ScriptDelete a global initialization script from Databricks workspace. Approval by default
WriteUpdate Global Init ScriptUpdate a global initialization script in Databricks workspace. Approval by default
WriteCreate Compute Instance PoolCreate a new Databricks instance pool with specified configuration. Approval by default
WriteDelete Compute Instance PoolDelete a Databricks compute instance pool. Approval by default
WriteEdit Compute Instance PoolModify the configuration of an existing Databricks instance pool. Approval by default
WriteSet Compute Instance Pool PermissionsSet permissions for a Databricks instance pool, replacing all existing permissions. Approval by default
WriteUpdate Instance Pool PermissionsIncrementally update permissions on a Databricks instance pool. Approval by default
WriteAdd Compute Instance ProfileRegister an instance profile in Databricks for cluster launches. Approval by default
WriteEdit Compute Instance ProfileModify an existing AWS EC2 instance profile registered with Databricks. Approval by default
WriteRemove Compute Instance ProfileRemove an instance profile from Databricks. Approval by default
WriteEnforce Cluster Policy ComplianceUpdate a cluster to be compliant with the current version of its policy. Approval by default
WriteCreate Databricks ClusterCreate a new Databricks Spark cluster with specified configuration. Approval by default
WriteCreate Databricks JobCreates a new Databricks job with specified tasks, schedules, and notifications. Approval by default
WriteCreate Genie MessageCreate a message in a Genie conversation and get AI-generated responses. Approval by default
WriteCreate Genie SpaceCreate a new Genie space from a serialized payload for programmatic space management. Approval by default
WriteDelete Genie ConversationDelete a conversation from a Genie space programmatically. Approval by default
WriteDelete Genie Conversation MessageDelete a specific message from a Genie conversation. Approval by default
WriteExecute Message Attachment QueryExecute SQL query for an expired message attachment in a Genie space. Approval by default
WriteSend Genie Message FeedbackSend feedback for a Genie message. Approval by default
WriteStart Genie ConversationStart a new Genie conversation in a Databricks space for natural language data queries. Approval by default
WriteTrash Genie SpaceMove a Genie space to trash instead of permanently deleting it. Approval by default
WriteUpdate Genie SpaceUpdate an existing Genie space configuration. Approval by default
WriteCreate Lakeview DashboardCreate a new Lakeview dashboard in Databricks. Approval by default
WriteDelete Lakeview Dashboard ScheduleDelete a dashboard schedule from a Lakeview dashboard. Approval by default
WritePublish Lakeview DashboardPublish an AI/BI Lakeview dashboard making it accessible via public link. Approval by default
WriteTrash Lakeview DashboardMove a Lakeview dashboard to trash instead of permanently deleting it. Approval by default
WriteUnpublish Lakeview DashboardUnpublish an AI/BI Lakeview dashboard while preserving its draft version. Approval by default
WriteUpdate Lakeview DashboardUpdate a draft Lakeview dashboard configuration and metadata. Approval by default
WriteRegister Lakebase Database as CatalogRegister a Lakebase Postgres database as a Unity Catalog catalog in Databricks. Approval by default
WriteCreate Database InstanceCreates a new Lakebase Provisioned database instance in Databricks. Approval by default
WriteDelete Database InstanceDelete a Databricks Lakebase Postgres database instance. Approval by default
WriteDelete Synced Database TableDelete a synced table from Unity Catalog and stop data refreshes. Approval by default
WriteGenerate Database CredentialGenerate OAuth token for database instance authentication. Approval by default
WriteCreate Data Quality MonitorCreate a data quality monitor for a Unity Catalog Delta table. Approval by default
WriteDelete Databricks ClusterTerminate a Databricks Spark cluster asynchronously. Approval by default
WriteEdit Databricks ClusterEdit an existing Databricks cluster configuration. Approval by default
WriteAdd Block to DBFS StreamAppend a block of data to an open DBFS stream. Approval by default
WriteCreate DBFS File StreamOpen a stream to write to a DBFS file and returns a handle. Approval by default
WriteDelete DBFS File or DirectoryDelete a file or directory from DBFS. Approval by default
WriteMove DBFS File or DirectoryMove a file or directory from one location to another within DBFS. Approval by default
WriteUpdate IAM Account Access Control Rule SetUpdate account-level access control rule set for service principals, groups, or budget policies. Approval by default
WriteCreate IAM Group V2Create a new group in Databricks workspace using SCIM v2 protocol. Approval by default
WriteDelete IAM Group V2Delete a group from Databricks workspace using SCIM v2 protocol. Approval by default
WritePatch IAM Group V2Partially update a Databricks workspace group using SCIM 2.0 PATCH operations. Approval by default
WriteUpdate IAM Group V2Update an existing group in Databricks workspace using SCIM v2 protocol. Approval by default
WriteSet IAM PermissionsSet IAM permissions for a Databricks workspace object, replacing all existing permissions. Approval by default
WriteUpdate IAM PermissionsIncrementally update permissions on Databricks workspace objects including dashboards, jobs, clusters, warehouses, notebooks, and more. Approval by default
WriteMigrate PermissionsMigrate ACL permissions from workspace groups to account groups. Approval by default
WriteCreate IAM Service Principal V2Create a new service principal in Databricks workspace using SCIM v2 protocol. Approval by default
WriteDelete IAM Service Principal V2Delete a service principal from Databricks workspace using SCIM v2 protocol. Approval by default
WritePatch IAM Service Principal V2Partially update a service principal using SCIM 2.0 PATCH operations. Approval by default
WriteUpdate IAM Service Principal V2Update an existing service principal in Databricks workspace using SCIM v2 protocol. Approval by default
WriteCreate IAM User V2Create a new user in Databricks workspace using SCIM v2 protocol. Approval by default
WriteDelete IAM User V2Delete a user from Databricks workspace using SCIM v2 protocol. Approval by default
WritePatch IAM User V2Partially update a user using SCIM 2.0 PATCH operations. Approval by default
WriteUpdate IAM User V2Update a user in Databricks workspace using SCIM v2 protocol. Approval by default
WriteCancel All Databricks Job RunsCancel all active runs of a Databricks job asynchronously. Approval by default
WriteCancel Databricks Job RunCancel a Databricks job run asynchronously. Approval by default
WriteDelete Databricks Job RunDelete a non-active Databricks job run. Approval by default
WriteSet Databricks Job PermissionsSet permissions for a Databricks job, completely replacing all existing permissions. Approval by default
WriteCreate Marketplace Provider ListingCreate a new listing in Databricks Marketplace for data providers. Approval by default
WriteCreate Marketplace Consumer InstallationCreate a marketplace consumer installation for Databricks Marketplace listings. Approval by default
WriteDelete Marketplace Consumer InstallationUninstall a Databricks Marketplace installation. Approval by default
WriteUpdate Marketplace Consumer InstallationUpdate marketplace consumer installation fields and rotate tokens for marketplace listings. Approval by default
WriteCreate Provider Analytics DashboardCreate a provider analytics dashboard for monitoring Databricks Marketplace listing metrics. Approval by default
WriteDelete Listing From ExchangeRemove the association between a marketplace exchange and a listing. Approval by default
WriteCreate ML ExperimentCreate a new MLflow experiment for tracking machine learning runs and models. Approval by default
WriteCreate Logged ModelCreate a new logged model in MLflow that ties together model metadata, parameters, metrics, and artifacts. Approval by default
WriteCreate MLflow Experiment RunCreate a new MLflow run within an experiment for tracking machine learning execution. Approval by default
WriteDelete ML ExperimentDelete an MLflow experiment and associated metadata, runs, metrics, params, and tags. Approval by default
WriteDelete Logged ModelDelete a logged model from MLflow tracking. Approval by default
WriteDelete Logged Model TagDelete a tag from a logged model in MLflow. Approval by default
WriteDelete ML Experiment RunMark an MLflow run for deletion in ML experiments. Approval by default
WriteDelete ML Experiment RunsBulk delete runs in an ML experiment created before a specified timestamp. Approval by default
WriteDelete ML Experiment Run TagDelete a tag from an MLflow experiment run. Approval by default
WriteFinalize Logged ModelFinalize a logged model in MLflow by updating its status to READY or FAILED. Approval by default
WriteLog Batch MLflow DataLog a batch of metrics, parameters, and tags for an MLflow run in a single request. Approval by default
WriteLog MLflow Dataset InputsLog dataset inputs to an MLflow run for tracking data sources used during model development. Approval by default
WriteLog Logged Model ParametersLog parameters for a logged model in MLflow. Approval by default
WriteLog MLflow MetricLog a metric for an MLflow run with timestamp. Approval by default
WriteLog MLflow ModelLog a model artifact for an MLflow run (Experimental API). Approval by default
WriteLog MLflow Dataset OutputsLog dataset outputs from an MLflow run for tracking data generated during model development. Approval by default
WriteLog MLflow ParameterLog a parameter for an MLflow run as a key-value pair. Approval by default
WriteRestore ML ExperimentRestore a deleted MLflow experiment and its associated metadata, runs, metrics, params, and tags. Approval by default
WriteRestore ML Experiment RunRestore a deleted MLflow run and its associated metadata, runs, metrics, params, and tags. Approval by default
WriteRestore ML Experiment RunsBulk restore runs in an ML experiment that were deleted at or after a specified timestamp. Approval by default
WriteSet ML Experiment TagSet a tag on an MLflow experiment. Approval by default
WriteSet Logged Model TagsSet tags on a logged model in MLflow. Approval by default
WriteSet ML Experiment PermissionsSet permissions for an MLflow experiment, replacing all existing permissions. Approval by default
WriteSet MLflow Run TagSet a tag on an MLflow run. Approval by default
WriteUpdate ML ExperimentUpdate MLflow experiment metadata, primarily for renaming experiments. Approval by default
WriteUpdate ML Experiment PermissionsIncrementally update permissions for an MLflow experiment. Approval by default
WriteUpdate ML Experiment RunUpdate MLflow run metadata including status, end time, and run name. Approval by default
WriteDelete ML Feature Engineering Kafka ConfigDelete a Kafka configuration from ML Feature Engineering. Approval by default
WriteCreate ML Feature Store Online StoreCreate a Databricks Online Feature Store for real-time feature serving. Approval by default
WriteDelete ML Feature Store Online StoreDelete an online store from ML Feature Store. Approval by default
WriteCreate ML Forecasting ExperimentCreate a new AutoML forecasting experiment for time series prediction. Approval by default
WriteDelete ML Feature TagDelete a metadata tag from a specific feature column in a Databricks ML Feature Store table. Approval by default
WriteSet or Update ML Feature TagSet or update a tag on a feature in a feature table in ML Feature Store. Approval by default
WriteDelete OAuth2 Service Principal SecretDelete an OAuth secret from a service principal at the account level. Approval by default
WriteCreate OAuth Service Principal SecretCreate an OAuth secret for service principal authentication. Approval by default
WriteDelete Databricks PipelineDelete a Databricks Delta Live Tables pipeline permanently and stop any active updates. Approval by default
WriteUpdate Pipeline PermissionsIncrementally update permissions on a Databricks pipeline. Approval by default
WriteCreate Quality Monitor V2Create a quality monitor for Unity Catalog table. Approval by default
WriteCreate Provisioned Throughput EndpointCreate a provisioned throughput serving endpoint for AI models in Databricks. Approval by default
WriteDelete Serving EndpointDelete a model serving endpoint and all associated data. Approval by default
WriteUpdate Serving Endpoint AI GatewayUpdate AI Gateway configuration of a Databricks serving endpoint. Approval by default
WriteDelete AI/BI Dashboard Embedding Access PolicyDelete AI/BI dashboard embedding access policy, reverting to default. Approval by default
WriteUpdate AI/BI Dashboard Embedding Access PolicyUpdate AI/BI dashboard embedding workspace access policy at the workspace level. Approval by default
WriteDelete AI/BI Dashboard Embedding Approved DomainsDelete the list of approved domains for AI/BI dashboard embedding, reverting to default. Approval by default
WriteUpdate AI/BI Dashboard Embedding Approved DomainsUpdate the list of domains approved to host embedded AI/BI dashboards at the workspace level. Approval by default
WriteUpdate Automatic Cluster Update SettingUpdate workspace automatic cluster update configuration with etag-based concurrency control. Approval by default
WriteDelete Dashboard Email Subscriptions SettingDelete the dashboard email subscriptions setting, reverting to default value. Approval by default
WriteUpdate Dashboard Email Subscriptions SettingUpdate the Dashboard Email Subscriptions setting for the workspace with etag-based concurrency control. Approval by default
WriteDelete Default Namespace SettingDelete the default namespace setting for the workspace, removing the default catalog configuration. Approval by default
WriteUpdate Default Namespace SettingUpdate the default catalog namespace configuration for workspace queries with etag-based concurrency control. Approval by default
WriteDelete Default Warehouse ID SettingDelete the default warehouse ID setting for the workspace, reverting to default state. Approval by default
WriteUpdate Default Warehouse ID SettingUpdate the default SQL warehouse configuration for the workspace with etag-based concurrency control. Approval by default
WriteDelete Disable Legacy Access SettingDelete the disable legacy access workspace setting, re-enabling legacy features. Approval by default
WriteUpdate Disable Legacy Access SettingEnable the workspace disable legacy access setting with optional etag-based concurrency control. Approval by default
WriteDelete Disable Legacy DBFS SettingDelete the disable legacy DBFS workspace setting, reverting to default DBFS access behavior. Approval by default
WriteUpdate Disable Legacy DBFS SettingUpdate workspace disable legacy DBFS setting with etag-based concurrency control. Approval by default
WriteUpdate Enable Export NotebookUpdate workspace notebook and file export setting. Approval by default
WriteUpdate Enable Notebook Table ClipboardUpdate workspace setting for notebook table clipboard. Approval by default
WriteCreate IP Access ListCreate a new IP access list for workspace access control. Approval by default
WriteDelete LLM Proxy Partner Powered SettingDelete (revert to default) the partner-powered AI features workspace setting. Approval by default
WriteUpdate LLM Proxy Partner Powered SettingUpdates workspace-level setting that controls whether AI features are powered by partner-hosted models. Approval by default
WriteCreate Notification DestinationCreate a notification destination for alerts and jobs. Approval by default
WriteDelete Notification DestinationDelete a notification destination from the Databricks workspace. Approval by default
WriteUpdate Notification DestinationUpdate an existing notification destination configuration. Approval by default
WriteDelete Restrict Workspace Admins SettingDelete/revert the restrict workspace admins setting to its default state. Approval by default
WriteUpdate Restrict Workspace Admins SettingUpdate the restrict workspace admins setting with etag-based concurrency control. Approval by default
WriteDelete SQL Results Download SettingDelete SQL results download workspace setting, reverting to default state where users are permitted to download results. Approval by default
WriteUpdate SQL Results Download SettingUpdate workspace SQL results download setting controlling whether users can download results from SQL Editor and AI/BI Dashboards. Approval by default
WriteDelete Token via Token ManagementDelete a token specified by ID via token management. Approval by default
WriteSet Token Management PermissionsSet permissions for personal access token management, replacing all existing permissions. Approval by default
WriteUpdate Token Management PermissionsIncrementally update permissions for personal access token management. Approval by default
WriteCreate Personal Access TokenCreate a personal access token (PAT) for Databricks API authentication. Approval by default
WriteSet Workspace Configuration StatusSet workspace-level configuration settings for a Databricks workspace. Approval by default
WriteCreate Sharing ProviderCreate a new authentication provider in Unity Catalog for Delta Sharing. Approval by default
WriteUpdate Sharing ProviderUpdate an existing Delta Sharing authentication provider in Unity Catalog. Approval by default
WriteCreate Sharing RecipientCreate a Delta Sharing recipient in Unity Catalog metastore. Approval by default
WriteDelete Sharing RecipientDelete a Delta Sharing recipient from Unity Catalog metastore. Approval by default
WriteCreate ShareCreate a new share for data objects in Unity Catalog. Approval by default
WriteDelete ShareDelete a Unity Catalog share from the metastore. Approval by default
WriteUpdate ShareUpdate an existing share in Unity Catalog with changes to metadata or data objects. Approval by default
WriteCreate SQL AlertCreate a new Databricks SQL alert for query monitoring. Approval by default
WriteDelete SQL AlertDelete a Databricks SQL alert (soft delete to trash). Approval by default
WriteDelete Legacy SQL AlertPermanently delete a legacy SQL alert (permanent deletion). Approval by default
WriteUpdate SQL AlertUpdate an existing Databricks SQL alert using partial update with field mask. Approval by default
WriteDelete SQL DashboardDelete a legacy Databricks SQL dashboard by moving it to trash (soft delete). Approval by default
WriteCreate SQL QueryCreate a saved SQL query object in Databricks. Approval by default
WriteDelete SQL QueryDelete a Databricks SQL query (soft delete to trash). Approval by default
WriteCreate Legacy SQL QueryCreate a new SQL query definition using the legacy API. Approval by default
WriteUpdate SQL QueryUpdate a saved SQL query object in Databricks using partial field updates. Approval by default
WriteCreate SQL Query VisualizationCreate a new visualization for a Databricks SQL query. Approval by default
WriteUpdate SQL Query VisualizationUpdate an existing Databricks SQL query visualization using partial update with field mask. Approval by default
WriteCancel SQL Statement ExecutionCancel an executing SQL statement on a Databricks warehouse. Approval by default
WriteExecute SQL StatementExecute a SQL statement on a Databricks SQL warehouse. Approval by default
WriteDelete SQL WarehouseDeletes a SQL warehouse from the Databricks workspace. Approval by default
WriteEdit SQL WarehouseUpdate the configuration of an existing SQL warehouse. Approval by default
WriteSet SQL Warehouse PermissionsSet permissions for a Databricks SQL warehouse, replacing all existing permissions. Approval by default
WriteSet Workspace Warehouse ConfigConfigure workspace-level SQL warehouse settings shared by all SQL warehouses. Approval by default
WriteStart SQL WarehouseStart a stopped Databricks SQL warehouse asynchronously. Approval by default
WriteUpdate SQL Warehouse PermissionsIncrementally update permissions for a Databricks SQL warehouse. Approval by default
WriteSubmit One-Time RunSubmit a one-time run without creating a job. Approval by default
WriteCreate Tag PolicyCreate a new tag policy (governed tag) in Databricks with built-in rules for consistency and control. Approval by default
WriteDelete Tag PolicyDelete a tag policy by its key, making the tag ungoverned. Approval by default
WriteUpdate Tag PolicyUpdate an existing tag policy (governed tag) with specified fields. Approval by default
WriteUpdate Databricks Job By IDCompletely reset all settings for a Databricks job. Approval by default
WriteCreate Vector Search EndpointCreate a new vector search endpoint to host indexes in Databricks Mosaic AI Vector Search. Approval by default
WriteDelete Vector Search IndexDelete a vector search index from Databricks workspace. Approval by default
WriteUpsert Data Vector IndexUpsert (insert or update) data into a Direct Vector Access Index. Approval by default
WriteCreate Workspace Git CredentialsCreate Git credentials for authenticating with remote Git repositories in Databricks. Approval by default
WriteDelete Workspace Git CredentialsDelete Git credentials for remote repository authentication in Databricks. Approval by default
WriteUpdate Workspace Git CredentialsUpdate existing Git credentials for authenticating with remote Git repositories in Databricks. Approval by default
WriteCreate Workspace RepoCreate and optionally checkout a Databricks Repo linking a Git repository to the workspace. Approval by default
WriteDelete Workspace RepoDelete a Git repository from Databricks workspace. Approval by default
WriteSet Workspace Repo PermissionsSet permissions for a workspace repository, replacing all existing permissions. Approval by default
WriteUpdate Workspace RepoUpdate a workspace repo to a different branch or tag. Approval by default
WriteUpdate Workspace Repo PermissionsIncrementally update permissions on a Databricks workspace repository. Approval by default
WriteCreate Secret ScopeCreate a new secret scope in Databricks workspace. Approval by default
WriteDelete Secrets ACLDelete an access control list from a Databricks secret scope. Approval by default
WriteDelete Secret ScopeDelete a secret scope and all associated secrets and ACLs. Approval by default
WriteDelete Workspace SecretDelete a secret from a Databricks secret scope. Approval by default
WritePut Secrets ACLCreate or overwrite access control list for a principal on a Databricks secret scope. Approval by default
WritePut Secret in ScopeInsert or update a secret in a Databricks secret scope. Approval by default
WriteDelete Workspace ObjectPermanently delete a workspace object or directory. Approval by default
WriteImport Workspace ObjectImport a notebook or file into the Databricks workspace from base64-encoded content. Approval by default
WriteCreate Workspace DirectoryCreate a directory and necessary parent directories in the workspace. Approval by default
One prompt, start to finish
What a governed Databricks run looks like inside Luumen.
Questions
How does LuumenAI connect to Databricks?
Authorize once with API token. Luumen lists the scopes each action needs before you approve the connection, and credentials never appear in the chat.
Can LuumenAI change things in Databricks on its own?
Read actions answer immediately. Anything that writes — add member to security group, delete custom llm agent, create databricks app, delete databricks app, and more — is shown as a plan and requires approval by default, including the 75 actions classified as destructive. Administrators configure that per tool, so you decide exactly which actions can ever run unattended.
Who gets access to the integration?
You decide. Actions are granted per agent, skill, and team, and per environment — production is not staging. Read access can be broad while writes stay narrow.
Is there an audit trail?
Every call to Databricks — read or write, approved or declined — is recorded with the actor, the input, and the result, and can be linked to the ticket or change record.