Databricks Context Engineer Associate Cheat Sheet
Recall context boundaries, retrieval diagnostics, memory lifecycles, tool authorization and recovery rules for Databricks agent scenarios.
For each scenario, trace task → caller → instructions → retrieved evidence → state → tool action → observed result. Find the first boundary where the required information or permission changes.
Keep context roles distinct
| Context source | Useful role | Check before relying on it |
|---|---|---|
| Application instructions | Define task rules and output contracts. | Are instructions compatible, prioritized and testable? |
| Current user request | Supplies the immediate objective and constraints. | Has a later correction replaced an earlier preference? |
| Retrieved records | Supply task evidence. | Are they current, authoritative, accessible and relevant? |
| Conversation history | Maintains continuity. | Does stale state override a current fact? |
| Persistent memory | Retains selected facts beyond one session. | Who owns the fact, how was it obtained and when should it expire? |
| Tool output | Reports an operation or observation. | What actually executed, under whose identity and with what result? |
A document may be approved as a factual source without being authorized to rewrite application instructions. A tool schema describes capability; it does not establish permission to execute it.
Diagnose retrieval in order
| Stage | Useful question |
|---|---|
| Source and ingestion | Does the authoritative, current record exist in the indexed data? |
| Eligibility | Do permissions, categories and filters admit the required record? |
| Candidate retrieval | Can the chosen lexical or embedding query retrieve it? |
| Ranking | Are eligible relevant candidates placed within the result budget? |
| Context assembly | Are the decisive fields and citations retained? |
| Response | Does the answer follow the supplied evidence and requested scope? |
Reranking cannot repair a record excluded before candidate retrieval. A larger result count can add distraction without restoring authority. Compare controlled replays before claiming that one changed setting caused a general improvement.
Read Genie and SQL evidence
Check which tables and instructions are actually attached, the effective caller’s data permissions, join keys and the grain of the result. A plausible total is not proof that joins avoided duplication. A benchmark helps measure behavior; its examples do not automatically become conversation context.
For an order-level fact joined to several line items, decide whether the requested measure belongs at the order or line level before summing. Preserve identifiers and units when comparing the answer with a tool result.
Separate memory from workflow state
| Need | What must be retained |
|---|---|
| Continue a conversation | Relevant messages and current context, with the session’s lifecycle. |
| Remember a verified preference | An attributable fact tied to the right user, with update and deletion behavior. |
| Resume a multi-step task | Completed steps, outputs, dependencies and the next permitted action. |
| Investigate an attempt | Trace and evaluation evidence; logging alone does not restore application state. |
Lakebase can support durable application state. Managed session and memory features have their own contracts; do not assume that deleting a conversation deletes every application-managed memory record. Treat a memory partition key as a retrieval boundary, not proof of authorization.
Inspect tool and MCP boundaries
Bind execution to the authenticated caller and the allowed operation. Check permissions at the service that executes the action. Discovery, a valid schema or a successful transport handshake does not prove that a business operation is permitted.
Distinguish registered services governed through AI Gateway from legacy direct MCP endpoints. Do not assume a control applies to an integration just because both use MCP. Use the endpoint and governance path stated in the scenario and verify current product details in the official references .
Compact without losing the task
Preserve active constraints, corrections, unresolved questions, source/version references and required output fields. Remove superseded or irrelevant material before compressing decisive evidence.
When a context window has a stated budget, include the reserved response allowance and every context component counted by the scenario. A summary that fits but omits the user’s deadline is not successful compaction. Test both task quality and resource use.
Resume agent work safely
A handoff needs an owner, task objective, required inputs, completion criteria and a usable output reference. A COMPLETE flag means only what its contract defines. Preserve dependencies rather than marking a blocked task complete to move the workflow forward.
For side-effecting operations, inspect persisted outcomes and the supplied idempotency contract before retrying. A timeout does not prove that nothing happened. Evaluate recovery and authorization alongside latency or token savings.