Bunny Honey ClubBunny Honey/blog
Work with us
← back to indexblog / ai / gemini-agent-workspace-small-business
● AI

Gemini Agent Gets Its Own Email. Who Can Write to It?

Google's Gemini agent can get its own Workspace account and email address. Before you hire one, check what it inherits and who can reach it.

AH
Arthur HofFounder, Bunny Honey Club AI
publishedOct 10, 2026
read6 min
Gemini Agent Gets Its Own Email. Who Can Write to It?

On Thursday, Google announced an AI coworker that gets its own Workspace account, its own calendar and its own email address on your domain. The Gemini agent is built to sit in your company directory next to the people. If you run a small b

On Thursday, Google announced an AI coworker that gets its own Workspace account, its own calendar and its own email address on your domain.

The Gemini agent is built to sit in your company directory next to the people. If you run a small business on Google Workspace, one day someone will offer you one. Here is what to check before you say yes.

Google's Gemini agent gets a mailbox, a calendar and a Drive

At Gemini at Work 2026 on October 8, Google Cloud introduced the Gemini agent as "your new single, universal agent for work." You give it objectives, not instructions. It plans the job, uses tools, and comes back with something finished.

Inside Workspace, Google describes three ways it works. One is a personal agent that already knows your calendar and your team. One proactively suggests tasks you could hand over. The third is the interesting one: a coworker agent.

You describe a role, and Gemini creates the agent. Google says the agent "receives its own Workspace account, including an email address, calendar, Drive, and presence in your company directory." Your team adds it to a Chat space or @mentions it in a document comment, and its edits show up under its own name in version history.

1separate Workspace account per coworker agent: email, calendar, Drive, directory entry (Google)
2model families Google names behind the agent today: Gemini and Claude (Google)
Hours or dayshow long Google says multi-step agent jobs can keep running (Google)
0plan names or prices in Google's announcement post (checked October 10)

That last number matters if you are a small business. Google's post is written for large organizations, with banks, utilities and airlines as the customer stories.

Google gave the agent the login we told you to give your task

On Tuesday we wrote about ChatGPT's team tasks, which run under a shared team service account. Our advice there was blunt: give each job its own login, so the damage stops at that account's edge.

Google built that advice into the product. A coworker agent acts under its own identity, not yours. Google says every action is written to an audit trail "attributed to the agent rather than to a person."

That is the right design. An agent running as the owner's inbox is the version that goes wrong in the worst way, because nobody can tell the owner's actions from the agent's.

Credit where it is due: for a small team, that default is safer than a shared team login.

It does not finish the job, though. A clean identity says who acted. It does not say how much that identity was allowed to touch.

Its identity is clean, but its reach is whatever you already shared

Here is the sentence to read twice.

A coworker agent acts under its own identity rather than yours, and it sees only what you share with it. Access follows the sharing and membership your team already uses, and no outside connector holds your data.

— Google Cloud Blog, Gemini at Work 2026, October 8

"Only what you share with it" sounds tight. The second sentence is the real one. Access follows the sharing and membership your team already uses.

So the agent does not arrive with a blank slate. It arrives with whatever your Drive already says about who can see what. Think about your own Drive after five years of a small team. The folder someone shared with the whole company in 2022 and never narrowed. The shared drive where every employee is a member because it was easier. The payroll spreadsheet in a folder that was only meant to be temporary.

Put an agent into a Chat space that has that membership, and the agent can reach what that space can reach.

This is our opinion, not a finding from Google. We have not tested the product, because nobody outside the preview has. But the mechanism is stated in Google's own words, and it is the same mechanism that made the Gemini connectors for HubSpot and QuickBooks a permissions question rather than a feature question in September.

An email address means strangers can write to it

A mailbox is a door. Google's own example shows what walks through it.

Ask Gemini to set up a meeting with your regional event leads, and Google says it "starts an email thread to coordinate a time that works, even with external participants." TechCrunch's launch report adds that users can reach the agent by tagging it, emailing it, sharing with it, or adding it to a group chat.

An agent that reads email from outside your company, and holds access to your documents, is exactly the setup our prompt injection piece warns about. A stranger writes a message that is also an instruction. The agent reads the message because reading is its job.

I did not find, in Google's announcement, how the agent treats mail from senders outside your domain. Google does describe an Agent Gateway that enforces policies you write once, such as "agents may not open documents classified Need to Know." That is a real control. It is also an administrator's console, built for a security team, and a ten-person company usually has none.

So ask the question before the invite: can people outside our domain email this agent, and what can it do when they do?

The audit trail points at the agent, and accountability still points at you

An audit trail attributed to the agent is useful. It lets you reconstruct what happened.

It does not move the responsibility. If the agent sends a client a wrong price, the client does not complain to an agent. They complain to you.

Google also says Gemini can spin up temporary, job-specific sub-agents, each with its own identity, that work in parallel or in sequence for hours or days. Each one is another identity in your logs. One agent is a hire. A roster is a department, and a small business rarely has anyone to run a department. Google's tasks inbox, which TechCrunch says shows the agent's thinking, delegation and progress, only helps if a named human opens it.

One more thing Google does not answer. It says the agent picks the model per job across Gemini and Claude. That is sensible for cost. It is also a question about where your documents go for each job. Ask your Workspace admin, or whoever is running the preview, before you load client files.

A role description beats a prompt when you set one up

The product asks you to describe a role. Most owners will type one line. Write a paragraph instead.

Here is how we would set up a first coworker agent, with the caveat that we are working from Google's description and not from hands-on time:

  1. Write the job description. What it owns, what it reports to whom, and a list of things it never touches. Payroll, contracts, client bank details.
  2. Give it its own folder. Do not add it to your existing spaces. Create one shared folder for its work and put only that folder in front of it.
  3. Start with suggestions. Comment on a document or draft a reply. Do not let it send anything for the first month.
  4. Keep it off client threads. Internal requests first. Outside email only after you have read a month of what it did.
  5. Name an owner. One person opens the tasks inbox for ten minutes every Friday. No owner, no agent.

None of this is exotic. It is the same discipline you would apply to a new hire on their first week, which is the whole point of giving it a login and a desk.

Where the do-it-yourself version stops and a build starts

If you only want an agent to draft a recurring report from one folder, wait for your invite and try it yourself. It is a fine place to learn, and the first month will teach you more than this article can.

If the job touches clients, money or contracts, the folder cleanup and the role are the project. The agent is the easy part. Most of the work is deciding what it should never see, setting the approval step, and checking that the answer survives a Tuesday when someone shares the wrong link.

That is what we build. The role, the permissions, the approval gates and a log a person reads. See our automation work, or tell us the job and we will tell you honestly whether it needs us. The same logic applies to any always-on agent, which is why we wrote the rules to set first for ChatGPT's always-on dots.

— share
— keep reading

Three more from the log.