Walk into any modern engineering org and you’ll see a fragmented landscape: Claude Code on one screen, Codex on another, with Cursor and Copilot sprinkled across teams. Leadership’s instinct is often to force standardization, but that fights the tide of developer preference. A recent deep dive argues the goal shouldn’t be picking one tool, but rather adopting a 'bring your own agent, govern centrally' architecture. This pattern uses the Model Context Protocol (MCP) and Databricks’ AI Gateway to route every assistant through a single governance layer.

Solving the Context and Governance Gap

AI assistants often fail in enterprise settings due to two distinct problems: context and governance. A general model lacks specific knowledge of your company’s metrics or schemas, leading to hallucinations. Simultaneously, security teams worry about which models are being called, cost controls, and audit trails. The proposed solution decouples these issues: MCP provides the necessary business context, while a governed gateway enforces security and compliance rules without restricting tool choice.

How Databricks Genie and MCP Work Together

Databricks AI/BI Genie acts as the 'AI coworker,' supplying trusted business context layered on top of Unity Catalog. By exposing Genie’s governed context as an MCP server, any MCP-capable assistant can retrieve accurate definitions for terms like 'active customer' instead of guessing. This means you don’t need to migrate your entire team to a new agent to get secure data access. Instead, you equip the agents they already love with a governed tool to call for context.

Real-World Governance Checks

Testing this setup reveals that 'governed' isn’t just a buzzword. The system enforces per-user, per-model entitlements server-side, meaning an agent is refused immediately if it tries to call a model the user isn’t entitled to use. Furthermore, the MCP server is fail-closed; it refuses to run without a valid identity token. Reads are strictly permission-scoped to the user’s Unity Catalog grants, ensuring the agent can’t see data the human can’t. Human-in-the-loop safeguards are also default, showing SQL before execution and refusing to write to untrusted directories.

Implementation Paths for Teams

For teams with an existing fleet of agents, Databricks open-sourced the unity-gateway (the ug CLI). This tool points third-party agents like Claude Code, Codex, and Cursor at the Databricks AI Gateway, handling model discovery and budget tracking in one configure step. For those starting fresh, the first-party genie-code-cli ships gateway-native, minting short-lived tokens itself to avoid API keys sitting on laptops. Both paths funnel requests through the same shape: agent → governed gateway → MCP → Genie/Unity Catalog.

Key Takeaways

  • Tool Choice Matters: Developers stick with their preferred assistants (Claude, Cursor, etc.) while IT maintains control.
  • Server-Side Enforcement: Entitlements and permissions are checked at the gateway, not the client, preventing bypasses.
  • Fail-Closed Security: MCP servers refuse to start without valid identity tokens, ensuring no unauthorized access.
  • Auditability: Every call is attributable and permission-scoped, making it easier to sign off on AI workloads.

The Bottom Line

The winning enterprise pattern for AI coworkers isn’t forcing everyone to use the same tool; it’s giving developers choice while governing centrally. By leveraging MCP for context and a gateway for control, you turn a fragmented AI landscape into a secure, auditable asset.