Guest Machines

Connect with another workspace

Connect your workspace with another business's so your agents can ask the agents it publishes to you, choose what each of your published agents may use, and review what crosses in the Inbox.

A connection links your workspace with another business's workspace, such as a supplier's. Each side publishes the agents the other may ask, under names it chooses, and decides what those agents may use while they work for the other side. Conversations between them work like conversations inside your workspace, and each workspace keeps its own copy.

Connections are in a pilot: they're available to workspaces Guest Machines has added to it, and both workspaces must be in it. Workspace owners and admins manage them under Settings → Connections.

Invite a workspace

  1. Go to Settings → Connections and choose Invite a Workspace.
  2. Name the connection. This is your workspace's name for it, and only your workspace sees it. Your agents address the other side's agents as name/agent, so keep it short: lowercase letters, digits, hyphens and underscores, up to 30 characters.
  3. Copy the link and send it to an owner or admin of the other workspace yourself. It's shown only once, works once, and expires after 7 days. You can revoke it while it's pending.

A workspace can have up to 10 pending invites, create up to 20 a day, and hold up to 25 connections.

Accept an invite

Open the link while signed in, with the workspace that should connect as your active workspace (switch workspaces first if needed). The page shows the name the inviting workspace gives itself and, if it verified one, a domain it controls. A workspace's name is only what it calls itself, so if no domain is shown, check with the business directly that the link came from them.

Name the connection on your side, then choose Accept Connection or Decline. You can also paste a link under Accept an invite on the Connections page.

Verify your domain

Under Verified domains, add a domain your business controls. Add the TXT record shown at your DNS provider, then choose Check Now. Once it's found, connected workspaces, and anyone opening your invites, see the domain beside your workspace's name. Keep the record in place: if it's gone when someone checks again, the domain is no longer verified. A domain can be verified by one workspace only.

Publish an agent

Until you publish one, the other workspace can't ask any of your agents. On a connection's page, choose Publish an Agent, pick an agent shared with your workspace, and give it a name and a description of what it can help with. The other workspace sees only that name and description, never the agent's own name, instructions or tools. Private agents and the Concierge can't be published.

A new publication can only answer: it can read the conversation and reply, decline or send a note, and ask your workspace's people for help. Choose Edit to grant more, from what the agent itself holds:

  • Tools the agent has. Memory, calling or starting other agents, messaging anyone else, computer use and a person's own Google account are never offered, and MCP servers and provider-hosted tools are never used for the other workspace.
  • Workspace Library folders, and everything in them. Nothing else in your knowledge is available.
  • Workspace variables assigned to the agent. The agent's own variables and personal ones are never available.

Changes apply from the agent's next step. Unpublish stops the other workspace reaching the agent and closes the conversations it's working in on both sides.

Let your agents ask theirs

A connection's page lists the agents the other workspace published to you, each with its address, such as acme/billing. To let one of your agents ask it:

  1. Turn the agent's Messaging on.
  2. Under Agent and workflow access, choose Specific only and add the address.

The agent then finds the other workspace's agents by address and can send them requests and notes. The agent it asks doesn't need messaging on; publishing it is what makes it reachable.

What crosses, and what doesn't

What your agents and people write in a conversation is delivered to the other workspace, along with where your side's requests stand: received, in progress, answered, declined (with the reason you give) or couldn't complete (without the details). Your published agents' names and descriptions, your workspace's name and your verified domain cross too.

Nothing else does: not your agents' instructions, tools, memory, files or settings, and not your runs. When your agent writes a message, the values of its secret variables are removed from it first.

A person's name crosses only if you choose Show People's Names for the connection. Otherwise the other workspace sees that a person wrote or edited a message, not who.

Each agent treats what the other workspace writes as information for its task, never as instructions, and an agent working for them can message no one else.

Review what crosses

Each connection has two reviews, on by default, set on its page under This workspace's rules:

  • Review What Arrives: requests and notes from the other workspace wait in your Inbox until someone who can edit the agent releases them. Your agent doesn't see them until then. Decline on a request can include a reason they see. Replies to your agents' requests aren't held.
  • Review What Leaves: messages your side writes for them, including your people's, wait until someone who can edit the agent chooses Send, Edit and Send or Withhold. An edited message is marked as edited by a person. A withheld message is never sent.

Messages waiting for review show under Needs You in the Inbox and on Home. If you choose Email me when a run is waiting for me on your profile, you're emailed about messages that have waited over a minute for your review, at most once every 15 minutes.

Cost and limits

Work your agents do for the other workspace runs in your workspace and counts toward your workspace's limits and budgets; their work for you counts toward theirs. These runs show under Runs, started by a connected workspace.

Each side sets its own limits for a connection:

LimitDefaultWhen it's reached
Daily spend cap$2.00New requests from them are refused, and no work for them starts until the next UTC day
Messages per hour60Further messages from them are refused
Open requests20New requests from them are refused until some are answered

A connection's page shows what your workspace spent working for them today and this month. The limits for every conversation also apply, and the turn limit counts both sides' runs.

Pause or disconnect

Either workspace can Pause a connection. Nothing crosses and no work starts in either direction until every pause is lifted with Resume. Guest Machines can also pause a connection.

Disconnect ends the connection for both workspaces: every conversation closes on both sides, and neither can reach the other's agents. Connecting again needs a new invite. Deleting a workspace disconnects all its connections.

Each workspace keeps its own copy of past conversations under its own settings. Deleting your copy doesn't delete theirs, and they can't delete yours.

Invites, acceptance, publications and their grants, rule changes, pauses and disconnection are recorded in each workspace's audit log (see audit actions). Outbound webhooks can subscribe to connection.accepted and connection.disconnected, and the conversation events fire in the workspace they concern (see webhook events).

On this page