Guest Machines

Use Google Workspace

Connect your Google account, decide exactly what each agent may do with it, and run Google work in chats, private automations and triggers.

Agents can work with the Google Docs, Sheets and Slides files you select, with your Gmail, and with your Google calendars. A connection belongs to you. It is used only by your own agents and only for what you grant them, and nobody else in the workspace can use it or see what it produces.

For what Guest Machines reads, keeps and shares when you connect Google, see the privacy policy.

Before you start

A workspace owner or admin turns on Enable Google Workspace for Members in Settings → Google Workspace. While it is off, members can't connect accounts and agents can't use Google tools.

Turning it off stops new Google actions for every member at once, including runs already in progress. Accounts stay connected, so turning it back on restores access without asking members to approve anything again.

Connect your account

  1. Open Settings → Google Workspace and choose Connect Google. To connect another account later, choose Add Another Account.
  2. Sign in to Google and approve access.
  3. Choose what Guest Machines may use:
    • Files. Choose Select Files, then Open Google Picker, and pick the Docs, Sheets and Slides agents may work with. Only the files you pick are connected; picking a folder never grants access to what is inside it. New files and copies an agent creates are saved in your My Drive.
    • Gmail. Reading, drafts and sending are separate permissions: Allow Gmail Reading, Allow Gmail Drafts and Allow Gmail Sending. Each one explains what it covers and asks you to confirm. Reading covers your whole mailbox except spam and trash. Sending alone doesn't let an agent read your mail.
    • Calendar. Event details, availability and changes are separate permissions: Allow Calendar Event Reading, Allow Calendar Availability and Allow Calendar Changes. Then choose Select Calendars, pick up to 50 calendars and choose Save Calendar Selection. Availability shows only when you are busy, without titles, descriptions, locations or guests.

Connecting an account, selecting a file or selecting a calendar gives no agent access on its own. You grant access per agent in the next step.

Each Google app has its own switch on the account's card. Turning an app off stops every agent from using it while keeping your Google permission and your agents' saved permissions. Runs already in progress need a replan to use it again after you turn it back on.

Give an agent access

You grant access per agent and per account, and only to agents you own. Being a workspace admin never grants access to another person's Google account.

  1. On the agent's Tools page, assign the Google tools the agent needs, as you would any other tool.
  2. On the account's card in Settings → Google Workspace, under Agent permissions, choose the agent. The same controls appear on the agent's Tools page.
  3. Select the operations the agent may perform and what it may use them on:
    • Files: All Selected Files or individual files. Add Outputs Created in This Task to let a task keep working on files it creates.
    • Calendars: Allow Event Operations on or Read Availability on each selected calendar.
    • Gmail: Allow This Agent to Use This Gmail Account. Add Allow Run Files as Gmail Attachments to let the agent attach files from its own run, up to a size limit you confirm.
  4. Choose Save Permissions. Remove Agent Access withdraws everything the agent was granted on that account.

Every operation you grant starts with Approve Each Use turned on, so the agent asks you each time. Clearing it lets the agent use that operation without asking. Sending email and changing calendar events always need your approval, whatever you choose here.

Runs already in progress keep the permissions they started with. Replan a run to give it operations you added.

Approve emails and calendar changes

Before an agent sends an email, saves a draft that attaches run files, or creates, changes or cancels a calendar event, the run pauses as Awaiting approval. The request shows exactly what will happen: the recipients, message and attached files for an email; the event, its guests and whether Google will notify them for a calendar change. Approve or deny it from the run or its chat. Consequential actions also ask you to type a confirmation.

Only you can approve actions on your own Google account, and only while signed in to Guest Machines in your browser. Workspace admins, other members and API keys can't approve them for you. An approval covers exactly what you reviewed; if the agent changes the message or the event, it asks again. An approved calendar change expires if it isn't made within 15 minutes.

If Guest Machines can't confirm that an email was delivered, check Gmail before letting the agent send it again.

Run Google work while you're away

A private automation uses your Google permissions when nobody is at the keyboard. There are four kinds:

  • Private schedule. In Schedules, create a schedule and turn on Private Google Schedule.
  • Private webhook. In Inbound Webhooks, create a webhook and turn on Private Google Webhook. Anyone with its URL can send events, but an event can't change the Google account, add permissions, skip your approvals or send results anywhere else. Keep the URL secret, and rotate it from the webhook's card if it leaks.
  • Private API task. In Settings → Apps and API Access → API Keys, choose Manage Private Google API Tasks, then New API Task. The task, its fixed input, the agent and one of your API keys are set when you create it. Anyone holding that key can start that exact task, up to the hourly limit you choose, and read its results. See start an approved private Google task.
  • Google trigger. Starts an agent when a calendar changes or new mail arrives. See start an agent from calendar changes or new mail.

They all follow the same rules:

  • The agent must be your own, not on a team and without computer control, and its Google permissions must have Allow Private Automated Work turned on. Teams and pipelines can't use your Google access.
  • A new private automation starts turned off. Choose Review and Turn On to check the task, the agent, its Google permissions and the limits for each run, then turn it on. Editing it, or changing the agent or its Google permissions, turns it off until you review it again.
  • Runs happen one at a time. A run waiting for your approval holds the next one.
  • Only you can see its task, results, approval requests and files.
  • Its runs can't share results through other tools, control a computer or hand work to another agent. Emails and calendar changes still wait for your approval.
  • Turning it off or deleting it stops any further Google actions. Events, changes and messages already waiting to start stay queued while it is off, and deleting it discards them.

Start an agent from calendar changes or new mail

Open Triggers → Google Triggers:

  • New Calendar Trigger runs an agent when events on one of your selected calendars are added, changed or cancelled. You choose the account, the calendar and which kinds of change count. The agent needs permission to read event details on that calendar.
  • New Gmail Trigger runs an agent when new mail arrives carrying at least one label you choose (Inbox by default), optionally only from the senders or domains you list. The agent needs permission to read that Gmail account.

Google triggers follow the private automation rules above. Each new message and each calendar change starts one run, and runs happen one at a time; repeated edits to an event that is still waiting are combined. A run is told which event or message it is about, and the agent reads it with its own permission. Email and event content is treated as information for the task, never as instructions: it can't change the account, add permissions or skip your approvals.

A trigger reacts only to what happens while it is on. Spam, trash, drafts, chats and mail your account sends never start a Gmail trigger, so the agent's own emails can't start it again, and calendar changes made by trigger runs don't start calendar triggers. A sender filter only decides which mail is relevant. From addresses can be forged, so a matching sender grants nothing.

The trigger's card shows how it is watching. Watching for changes and Watching for new mail mean Google tells Guest Machines as things happen; otherwise the card says how often it checks instead. The card also shows how many changes or messages are waiting to start. When more arrive than its queue holds, the rest wait and are added as earlier runs start.

Recover what a trigger missed

Occasionally Google can't tell Guest Machines what changed since a trigger last checked, for example after a long interruption. Because changes may have been missed, the trigger pauses and its card explains why. Review it and turn it back on. The card then offers Recover Missed Changes for a calendar trigger or Recover Missed Mail for a Gmail trigger.

Choose where the recovery starts, from the time changes may first have been missed until you turned the trigger back on, going back no more than six days. The trigger looks for what happened in that period and runs once for each change or message it hasn't already run for, oldest first. Nothing runs until the search finishes. If it finds more than one recovery can handle, nothing runs and you can try again with a later start.

  • A calendar recovery reports each event once, with its overall change since the start you chose.
  • A Gmail recovery matches messages by the labels they have now and your sender filter.

Time you kept the trigger turned off yourself is never recovered. Choose Dismiss if you don't need to recover.

Turn access off

  • Turn an app off on the account's card to stop agents from using it while keeping everything else.
  • Choose Remove Access next to a connected file to stop agents from using it. The file itself doesn't change.
  • Turn off or delete a private automation to stop its further Google actions.
  • Choose Disconnect Google to remove an account. Every agent loses access immediately and your file and calendar selections are cleared. Past runs and their results are kept as usual.

None of these can undo an action Guest Machines already carried out in Google, such as an email that was sent.

For workspace admins

Admins decide whether Google Workspace is available in the workspace, but never get access to a member's Google account. Admins can see that members' private automations exist, in Members' private schedules, Members' private webhooks, Members' Calendar triggers, Members' Gmail triggers and Other members' private API tasks, and can stop or delete them. They can't see their tasks, Google permissions or results, and only the owner can turn one back on.

On this page