Every MCP tool in the SCOPE compliance index, grouped by server — risk posture, regulatory exposure, and the tools that warrant tighter governance.
1 critical 2 high 2 med · 5 tools · 1 SoD-flagged
regimes APPICCPACOSOGDPRISO_27001LGPDNIST_CSFPIPEDAPIPLPOPIASOC2SOXUK_GDPR
Tools needing tighter control (4 of 5)
databricks.databricks_sql critical conf mediumhuman approval
Runs AI-generated SQL with read and write access, creating or altering data pipelines and tables anywhere the connected identity's warehouse privileges reach.
databricks.genie_one high conf mediumOBO
Answers natural-language questions by searching across all Genie Spaces and Unity Catalog data, potentially surfacing PII or confidential business figures in the response.
databricks.ai_search high conf mediumOBO
Queries AI Search (Vector Search) indexes to retrieve documents, which may include personal data or proprietary content embedded in the corpus.
databricks.unity_catalog_functions medium conf lowaudit
Executes predefined Unity Catalog functions exposed as SQL tools; effect and data exposure depend entirely on each function's definition.
All other tools (1)
databricks.genie_space medium conf mediumaudit
Runs natural-language queries against a single configured Genie Space, returning grounded answers that can include the space's underlying business data.