The good news is that with Databricks, the answer exists within the data governance foundation you already have. The governance contract: Genie Agents run with the end user’s credentialsThe core architectural principle is simple: Genie Agents run with the end user’s credentials. If two documents need different readers, they need different volumes and different Genie Agents — plan the layout upfront. Be careful when surfacing Genie One or Genie Agents externally via MCP or API - you must handle identity carefully. To get started building your first governed Genie Agent, visit the Genie documentation and the ABAC policies documentation.