This official feed from the Google Workspace team provides essential information about new features and improvements for Google Workspace customers.


To help organizations elevate their security posture, we are introducing context-aware access (CAA) policies in the Admin console for Gemini Enterprise. Google Workspace administrators can select granular security attributes for Gemini Enterprise access, including device security and location settings that can be applied to personal and managed devices.

For example, an administrator can create a CAA policy that restricts access to Gemini Enterprise from specific geographic regions. Organizations can also reuse their existing policies that apply to Workspace apps by also applying them to Gemini Enterprise.



Context-Aware Access settings for Gemini Enterprise in Admin console

Getting started

  • Admins: Context-Aware Access for Gemini Enterprise can be configured at the organizational unit (OU) or group level. Visit the Help Center to learn more about Context-Aware Access, creating Context-Aware Access levels, and assigning Context-Aware Access levels to apps.
  • End users: If enabled by your admin, you can access Gemini Enterprise when authenticating using your Google sign-in. If your organization’s Context-Aware Access settings are not set to allow access, you may see a message letting you know that you cannot use Google sign-in to authenticate with Gemini Enterprise, or you may see remediation messages which will provide some options on how to unblock Gemini Enterprise.

Rollout pace

Availability

  • Enterprise: Enterprise Standard, and Plus
  • Education: Education Standard, and Plus
  • Other: Frontline Standard and Plus; Enterprise Essentials Plus; Cloud Identity Premium

Note: You will need to have purchased Gemini Enterprise to apply Context-Aware Access policies for your users.

Resources



Gemini-powered AI classification in Google Drive is now available in open beta.

By automating file identification and labeling across Drive, AI classification helps organizations enforce granular data loss prevention (DLP) policies at scale, establish retention rules, and utilize label metadata during audit investigations. This also becomes a critical aspect in elevating an organization’s security posture in the agentic era, preventing agentic workflows from accessing and acting autonomously on sensitive data. 

This feature leverages Gemini models to apply data classification labels to files in Google Drive. Previously, AI classification required admins to identify and manually label training files for the AI model to learn the types of data associated with each data classification level. With this new capability, Gemini models offer admins an alternative method for data classification that is faster and more efficient, eliminating the need for manual model training and replacing it with administrator-defined instructions.



In the Admin console, Gemini models interpret instructions, evaluate files, and apply appropriate data classification labels.


Administrators maintain full control of the Gemini-based data classification process. They select the label, provide Gemini with instructions, and scope the audience for the files being evaluated. For Gemini-labeled files, editors and owners of those files with the appropriate label permissions will have the opportunity to either review and accept, or modify the automatically-applied label. Audit logs capture when files are labeled, including any user acceptance or modification of a Gemini-applied label.



In the Admin console, once enabled, Workspace Admins can see metrics on the labels applied to files by Gemini.


Data classification is a critical activity for organizations that are conscious about data protection, compliance, and reporting. However, data classification can also be challenging to put into practice, particularly when it comes to accurately classifying files at scale. By using the new Gemini-based capabilities in AI classification for Drive, admins are able to achieve a higher degree of data classification accuracy at scale.

Rollout pace

Getting started

  • Admins: For customers on a supported product license, the option for configuring Gemini-based AI classification instructions will appear in the Workspace Admin Console under the Data Classification option in the Security section (Security > Access and data control > Data classification). Use our Help Center to learn more.
  • End users: There is no end user setting for this feature.

Availability

  • Enterprise: Enterprise Plus
  • Education: Google AI Pro for Education
  • Other Editions: Frontline Plus

Resources

Thumbnail

Workspace Studio enables users to boost their productivity with custom, no-code agentic automation. Today, we are adding a new set of enterprise security controls to enable additional collaboration use cases. These granular identity, data protection, observability, and governance controls provide admins with more confidence to safely enable and adopt agentic capabilities in their organization.

Built-in, enterprise security controls in Workspace Studio include:

  • Agent identities
  • Agent access management
  • Agent auditing and observability
  • Admin settings / human-in-the-loop (HiTL)
  • Runtime protections

Collaboration use cases

When Studio initially launched, it was only able to assist users in their tasks, such as drafting an email, not executing tasks autonomously, such as sending an email. Now, Studio supports cross-user collaboration through the introduction of several new steps with built-in guardrails.



Collaboration actions in Studio Flows

Agent identities: Automation with flows in Studio will continue to run with the user’s identity, but in a least-privileged way. This means that the flow will have the minimal set of privileges required to run, and not the full set of privileges the owner has. When the flow executes, it will do so with a unique, auditable identifier. Note: the least-privilege agent identity will apply to newly created flows only.  Existing flows will be supported in the future.

(Beta) Identity attribution: Admins, through a new setting, will be able to decide whether the actions taken by a flow show the owner's identity, or are attributed to the flow itself, with the owner information made visible.  This will default to “on”; meaning the actions by the flow will be attributed to the flow. Note: the agent identity attribution setting will apply to newly created flows only.  Existing flows will be supported in the future.

Flow represented as the owner's identity

Flow attributed as the flow’s name with owner’s information

Auditing and observability: Actions in Studio across configuration and execution events are recorded in Studio audit events. Additionally, audit events for actions, such as edits made to a file in Drive or emails sent in Gmail, will include flow context, such as a unique flow identifier and the owner’s information. Note: agent context in audit logs will apply to newly created flows only. Existing flows will be supported in the future.

Agent access management: In the admin console, an Agent access management dashboard gives admins the ability to suspend all flows or targeted OAuth scopes for individual flows, such as revoking Drive access. Additionally, the security investigation tool enables admins to transition directly from an audit event to the agent access management page, facilitating swift remediation during incident investigations. Note: after the rollout, newly created flows will be shown in Agent access management.  Existing flows will be supported in the future.



Agent access management dashboard


Admin settings & human-in-the-loop: Additional admin settings will support disabling specific step types for flows, disabling Gemini data access, enforcing end-user confirmation for steps that share data externally, and disabling webhook integrations.



Flow asking for human approval before it sends an email externally


Runtime protections: Additional data loss prevention (DLP) features for Gemini data access and Studio flows are available for added protection. Gemini DLP restricts Gemini’s ability to access Drive data based on content conditions and labels, with support for additional services coming soon. DLP for Studio will support restrictions on Studio flow execution, including blocking or enforcing end-user review, based on conditions of the sourced data, utilized data, and data visibility of the output.



Studio DLP

Rollout pace

Admin console settings

End-user visible features

(Beta) Identity attribution

Getting started

Availability

Available for Google Workspace*:

  • Business Starter,  Standard, and Plus
  • Enterprise Starter, Standard, and Plus
  • Education Fundamentals, Standard, and Plus

Also available to*:

  • Google AI Pro for Education
  • Google AI Ultra for Business

* Gemini DLP, and DLP for Studio are available only for Frontline Standard and Frontline Plus; Enterprise Standard and Enterprise Plus; Education Fundamentals, Education Standard, and Education Plus; Enterprise Essentials Plus

Administrators using Drive Inventory Reporting in Google BigQuery can now access granular external sharing fields designed to simplify complex permission structures. By automatically consolidating direct permissions, group memberships, and public links into clear signals, this update helps organizations easily identify external exposure across their Drive environments.

Administrators can now distinguish between human users, service accounts, and files published to the web, as well as cross-reference sharing attributes with existing Data Loss Prevention (DLP) metadata to prioritize remediation for high-risk data.

Getting started

  • Admins: This feature will be OFF by default and can be enabled via the "External sharing calculations" setting under Drive inventory report settings in the Google Admin console. Note that for organizations with large Google groups, enabling this calculation may extend processing time and impact report delivery schedules.

Rollout pace

Availability

  • Enterprise: Enterprise Standard, and Plus
  • Education: Education Standard, and Plus
  • Other Editions: Frontline Plus; Enterprise Essentials Plus; Cloud Identity Premium

Resources

Google Credential Provider for Windows (GCPW) has been updated to support FIDO2-compliant physical security keys as a second factor for authentication. This update helps organizations improve their security posture by enabling administrators to enforce 2-Step Verification (2SV) using hardware security keys at the Windows login screen. Additionally, users can now use passkeys from nearby Bluetooth-connected mobile devices for their second-factor authentication.


Getting started

Rollout pace

Availability

  • Available to all Google Workspace customers

Resources

Beginning today, the Gemini app adheres to your organization’s data regionalization requirements. As with Google Workspace, admins have the flexibility to configure controls for EU storage and processing, US storage and processing, or both, including granular settings down to the organizational unit (OU) level.


Data regions are critical for ensuring many customers can meet their own internal requirements, as well as other legal, regulatory, and data sovereignty requirements by controlling the geographical location of their data at rest. Expanding these controls to the Gemini app allows our customers to adopt Gemini broadly in their organization with confidence that their data is being processed and stored in the location they require. 

Getting started

Rollout pace

Availability

  • Enterprise: Enterprise Plus (provides in-region processing and storage capabilities)
  • Education: Education Plus and Education Standard (provides in-region storage capabilities only)
  • Other Editions: Frontline Plus (provides in-region processing and storage capabilities)

Resources

Earlier this year, we announced changes to Google Groups to enhance data security and privacy. The changes, which are rolling out now, include:

  • Stricter “internal” and “external” classifications for Groups
  • Clearer visual indicators for whether a group contains external members
  • Changes to how emails are shown within Google Groups
  • Additional settings granularity to control who can add external users (admins only, or admins and end users) 
  • Changes to how admins can add external users via Groups APIs

API changes

While we originally announced that admins would have to change the classification of a group before being able to add external members to Groups marked as internal, we’re updating that behavior to prevent issues with synced groups. When an admin attempts to add an external member to an internal group via the Cloud Identity or Admin SDK Directory API, or when they sync data from a third-party identity provider via API, the group settings will be automatically updated to allow admins to add external members.

Getting started

  • Admins: To ensure a smooth transition, existing groups will be automatically classified based on their current membership, so there will not be any changes in access. You can review and adjust these labels directly in the Admin console or via the Groups Settings API to match your organization's security needs.
  • End users: There is no action required for end users.

Rollout pace

Availability

  • Available to all Google Workspace customers

Resources

In Alert Center, we are expanding the existing “Super Admin password reset” alert into a broader Admin password reset alert. Previously, this rule only triggered alerts when a super admin’s password was changed. With this update, the alert will now cover password resets for all administrator roles within your organization.

This update provides admins with better visibility and control over the security of their organization's privileged accounts. Monitoring password changes for all admin roles provide a higher level of oversight to respond more quickly to potential account compromises or unauthorized changes.

This change aligns with security best practices by treating all administrative access with increased vigilance.

Getting started

  • Admins: This feature will be ON by default and automatically replaces the previous "Super Admin password reset" rule. No action is required to enable the new alert. If you had modified the recipient list for the previous rule, those settings will automatically carry over to the new rule.
  • End users: There is no end user setting or impact for this feature.

Rollout pace

Availability

  • Available to all Google Workspace customers

Resources

The Workspace Policy API provides a centralized, comprehensive view of your security settings, eliminating the need to navigate to numerous pages in the Admin console.

With our latest update, we are introducing mutate endpoints (Create, Update, Delete) alongside existing read-only capabilities (Get, List) for data loss prevention (DLP) rules and detectors. This allows super admins to programmatically manage and fully automate the entire lifecycle of their DLP policies, from initial creation to real-time activation and deactivation.

Note this is an API-only launch for capabilities currently supported in the Admin console.

About DLP

DLP lets Workspace admins control external file sharing to prevent sensitive information leaks. It scans files for violations, triggering incidents and protective actions like content blocking.

How DLP works:

  • Admins define rules for sensitive content across Drive, Gmail, Chat, and Chrome.
  • DLP scans content for DLP rule violations that trigger DLP incidents.
  • DLP enforces the rules you defined and violations trigger actions, such as alerts.
  • Admins are alerted for DLP rule violations.
Summary of capabilities supported by mutate endpoints for DLP

Getting started

  • Admins: You must be a super admin to use the Policy API. See our developer documentation to learn more about the Policy API. You can also use GAM, an open source tool for managing Workspace, which now supports the Policy API.
  • End users: This is an admin-only capability.

Rollout pace

Availability

  • Available to all Google Workspace customers and Workspace Individual subscribers

Resources

Data loss prevention (DLP) for Google Calendar is now generally available to protect sensitive information shared within event details. Previously available in beta, this feature allows you to create and apply data protection rules that scan calendar event titles, descriptions, and locations for sensitive content, such as credit card numbers or national identification numbers.

Key functionalities include:

  • Choice of actions: Admins can choose to audit when an event is saved with sensitive content, warn users about sensitive content in their event, or block event creation or updates if a DLP policy is violated.
  • Event details: DLP rules scan free-text fields in the event, including the event’s title, description, and location fields.
  • Owner-based policies: Rules are applied based on the organizational unit (OU) of the owner (event organizer on primary calendars or calendar owner on secondary calendars), consistent with other Workspace DLP configurations.
  • User notifications: With DLP policies for Calendar, users receive immediate feedback when sensitive data is detected. On the web, users see a pop-up notification explaining the issue. Admins can also customize this message with more specific details. If a meeting update is blocked on Android, iOS, or via the Calendar API, the user will receive an automated email notification explaining the policy violation and why changes to the meeting invite were not successful.

Getting started

  • Admins: The feature will be OFF by default and can be enabled at the organizational unit (OU) or group level. Visit the Help Center to learn more about DLP for Calendar.
  • End users: There is no end user setting for this feature.
DLP settings in the admin console to configure policies for sensitive data, including actions and alerts when creating Calendar events
An end user is prompted with a message asking them to remove sensitive information

Rollout pace

Availability

  • Enterprise: Enterprise Standard and Plus
  • Education: Education Fundamentals, Standard, and Plus
  • Other Editions: Enterprise Essentials; Frontline Standard and Plus

Resources

Data loss prevention (DLP) rules for non-Workspace file attachments and associated proximity conditions are now generally available. These new capabilities enable organizations to target files with specific parameters, such as blocking the sharing of sensitive file formats or identifying files that contain specific strings in their titles.

Using these new content conditions, admins can set up various DLP rules for added protection, such as:

  • File names: Block files containing text string “funkyword”
  • File extensions: Block .java files
  • File types: Block custom mime type such as application/custom_app
  • Proximity matching: Detect “routing number” in proximity of 100 characters of “account number”

Additional details

In addition to file-based conditions, administrators can utilize associated proximity conditions to identify sensitive information in the file. This feature allows for the detection of sensitive data that appears within a specified distance of other predefined data types, regular expressions, or word lists.

For example, a rule can be configured to trigger when a bank account number is found within 100 characters of a routing number. By identifying data in context, proximity matching helps administrators reduce false positives and more accurately secure financial information or proprietary content.

Key functionality in DLP rules for file attachments and associated proximity conditions include:

  • Ability to match against common or custom MIME types and system file categories
  • Support for scanning attachments in Gmail, Drive, and Chat to set rules across communication channels 
  • Granular distance settings for proximity matching, allowing admins to define a range of up to 1,000 characters between matched conditions

Getting started

  • Admins: When configuring DLP rules in the admin console, admins can locate the new content conditions of file extension, file name, and file type under content conditions. Admins can also select the option of proximity matching to set a maximum distance between two pieces of matched texts. Visit the Help Center to learn more.
  • End users: There is no end user setting for this feature.
Content conditions for DLP in the Admin console to configure policies for sensitive file attachments

Rollout pace

Availability

  • Enterprise: Enterprise Standard and Plus
  • Education: Education Fundamentals, Standard, and Plus
  • Other Editions: Enterprise Essentials; Frontline Standard and Plus

Resources

Previously, data transfers from corporate Google Workspace accounts to third-party apps were restricted. We’re now recalibrating these restrictions to allow for a "trusted ecosystem" between managed apps.

With this release, users are now able to maintain efficient workflows and securely move data between corporate Workspace accounts and other authorized, managed third-party applications without being blocked. For added data protection, this capability strictly prevents the transfer of that data to personal accounts within the same managed Google application or to unmanaged personal apps.

For example, a user is able to copy a client's email address from their corporate Gmail account and successfully paste it into a managed third-party CRM application. When they try to paste that same email address into their personal Gmail account, they are blocked and receive the following message: "This information can only be shared within your organization's Google Workspace apps.”

Getting started

  • End users: There is no end-user setting for this feature.

Rollout pace

Availability

  • Enterprise: Enterprise Standard and Plus
  • Education: Education Standard and Plus
  • Other Editions: Frontline Standard; Enterprise Essentials Plus; Cloud Identity Premium

Resources

Admins can now bulk export client-side encrypted (CSE) Slides using Vault or Data Export (takeout), and then convert those exports into PowerPoint files. This allows your organization to retain complete ownership, access, and control of sensitive data in a highly portable format.

Eligible Google Workspace admins can sign up for the CSE Office Interop beta program, which provides immediate access to CSE compatible export, import, takeout and office editing features. Organizations who’ve previously signed up for the beta program should see this feature in their domains now.

Getting started

  • Admins: Admins with eligible Workspace licenses can sign up for the CSE Office Interop beta. We’ll provide more information on how to get started if you’re accepted.
  • End users: This launch has no impact on end users.

Rollout pace

Availability

  • Enterprise: Enterprise Plus
  • Education: Education Standard and Plus
  • Other Editions: Frontline Plus, Assured Controls, Assured Controls Plus

Resources

Administrators can now apply a global context-aware access (CAA) policy to all SAML applications within their organization. This update introduces a default assignment that serves as a universal security baseline, automatically protecting any SAML-based app that does not have a specific policy already assigned. By establishing this "secure-by-default" posture, IT teams can help protect internal data and third-party SaaS tools as new applications are integrated into their ecosystem.

This global control significantly reduces the administrative burden of managing security for applications at scale. Instead of manually configuring rules for every individual SAML app, administrators can set a single policy to cover their entire environment. Specific application-level policies will still take precedence, allowing for granular control where needed while the global policy acts as a reliable safety net.

These default policies support both Monitor and Active modes, providing flexibility in how security requirements are phased in. Detailed audit logs will capture these enforcement events, and remediation messages help end users understand how to resolve access issues independently.

Admins can configure CAA policies for all SAML apps in the Admin console under Security > Context-aware Access > General settings

Admins can configure CAA policies for all SAML apps in the Admin console under Security > Context-aware Access > General settings.

Getting started

Rollout pace

Availability

  • Enterprise: Enterprise Standard and Plus
  • Education: Education Standard and Plus
  • Other Editions: Frontline Standard and Plus; Enterprise Essentials Plus; Cloud Identity Premium

Resources

What’s changing

We are updating the schema and event modeling for several Admin audit log events, specifically some of the events related to account security, Gmail, and Drive settings, along with other admin-defined setting audit logs. These improvements aim to make the logs more understandable, detailed, and precise.  A complete list of the updates can be found in the Help Center

The updates involve changes to event names, event types, and the volume of these affected log events. Some legacy events may be redundant as a part of this change. If you're using any legacy events, some of the updates might require changes to your existing queries, alerts, and reports to get the full benefit of the changes. Both the new and old events will continue to be available for you to make the necessary changes.

Who’s impacted

Admins 

Why it matters

Granular audit logs are critical to helping organizations investigate cybersecurity incidents and understand their data usage. The changes announced today expand the depth of analysis that can be performed.  

Rollout pace

Getting started

  • Admins:  As the changes become available, you can get started with your analysis in either the Audit and Investigation tool
  • End users: There is no end user setting for this feature.

Availability

  • Available for Google Workspace with Audit Log eligible licenses.  To learn more about the Audit Log availability for your license types, please review this article

What’s happening

Gmail is enhancing user security by enabling the Cross-Origin Opener Policy (COOP). As a result, developers of websites and browser extensions opening or manipulating the Gmail page may have to update their code to ensure continued functionality when enforcement begins on January 20, 2026. There is no action needed from Workspace admins or end users.

COOP background

Cross-Site Search (XS-Search) is a type of Cross-Site Leaks (XS-Leaks) attack that targets query-based search systems, like Gmail. Attackers exploit this vulnerability by gaining control of a Gmail window, either by opening a new popup or accessing an existing one via its window handle. Once they have this access, they can gather information via a side channel to determine if specific search results exist by repeatedly loading different search terms, thereby leaking sensitive user data.

COOP is a web security feature designed to isolate the web applications from untrusted origins. This measure will prevent attackers from accessing Gmail's window handle, thereby protecting users from various Cross-Site Search (XS-Search) attacks that rely on window handles for collecting side-channel information, such as frame counting. This also significantly hinders attacks like cache probing, which rely on timing and other observations for resources that Gmail loads for search results. While these attacks don't directly collect side-channel information through the window handles themselves, COOP prevents repeated searches and thereby increases difficulty and reduces effectiveness, making them far less of a threat.

Who’s impacted

Websites or browser extensions that open Gmail in a pop-up window and interact with that window by accessing its properties (closed, location, length, focus) or invoking its functions (close, postMessage). Also, browser extensions that are injected into Gmail page and access the opener handle which is a reference to the window that opened the current Gmail page.

Additional details

To enforce COOP, the Cross-Origin-Opener-Policy header will be present in the response:

Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gmail-web-coop-coep"
Report-To:{"group":"gmail-web-coop-coep","endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gmail-web"}]}

Getting started

  • Developers:
    • For websites and browser extensions opening Gmail, refactor the offending code to avoid accessing the window properties or functions through the window handle and instead, utilize alternative APIs to achieve the desired functionality (e.g., chrome.tabs, Messaging).
    • For browser extensions injected into the Gmail page, instead of trying to communicate with or access the opener, the browser extension should be updated so it doesn't need to interact with it at all and the extension's logic should be revised to work independently. If that is not possible, browser extensions can use existing APIs (e.g., chrome.tabs) to implement their logic.
  • Admins: There is no admin control for this feature.
  • End users: There is no end user setting for this feature. 

Rollout pace

  • Enforcement will begin on January 20, 2026. Rollout will be extended (potentially longer than 15 days for feature visibility).

Resources


What’s changing 

When your primary systems are compromised, you need a dependable partner to keep your organization operational. Our new Business Continuity editions are designed to serve as a robust backup solution that works in tandem with your primary, non-Google Workspace collaboration platform, providing a secure and familiar environment that can be activated when you need it most. 

We are introducing two distinct offerings to meet your specific needs: 

1. Business Continuity 
This edition is a true disaster recovery solution designed for a "cold" standby scenario. It provides a secure, isolated environment to ensure your leadership and critical teams can communicate and collaborate during a crisis. 

  • Core Functionality: Allows for syncing your active directory, ensuring your user directory is available when needed. 
  • Usage: Intended for limited use, with access to Google Workspace and generative AI tools like Gemini and NotebookLM for up to 21 days per year. 

2. Business Continuity Plus 
This is our full-featured solution for organizations that require a "hot" standby environment with more data readily available to drive immediate adoption and productivity. It is designed to keep your core functions operating with minimal disruption. 

  • Core Functionality: In addition to allowing for syncing directory, this edition allows for data syncing across any product, including but not limited to email, calendar, drive, chat and more. We recommend using a partner-based solution for implementation. 
  • Usage: Provides extended access to Google Workspace and generative AI tools for up to 60 days per year. 

Learn more about these new offerings in our main blog post: Break free from Microsoft 365’s lock-in, vulnerabilities, and outages with Google Workspace and partners

Getting started 

  • Admins: These solutions are intended for organizations who do not use Google Workspace for their primary collaboration platform. Contact your Google rep or partner to discuss suitability and purchase options. 
  • End users: No end user impact. 

Availability 

  • Available everywhere Google Workspace is sold. These solutions are intended for organizations who do not use Google Workspace for their primary collaboration platform. 

Resources 

What’s changing

Generally available today, Gmail client-side encryption (CSE) users can send end-to-end encrypted (E2EE) emails to anyone, even if the recipient uses a different email provider. Recipients will receive a notification and can easily access the encrypted message via a guest account, ensuring secure communication without the hassle of exchanging keys or using custom software. 

This capability, requiring minimal efforts for both IT teams and end users, abstracts away the traditional IT complexity and substandard user experiences of existing solutions, while preserving enhanced data sovereignty, privacy, and security controls. 


Securely viewing an E2EE email in a restricted version of Gmail 


Users sending an email will see a notification when composing their message 

Getting started 

  • Admins: This feature will be OFF by default and can be enabled at the OU and Group level. Visit the Help Center to learn more about turning Gmail E2EE on or off for your organization. Visit the Help Center for a Client-side encryption setup overview
  • End users: This feature will be on by default for users that have access to Gmail Client-side encryption. Visit the Help Center to learn more about Gmail Client-side encryption

Rollout pace


Availability 

Available for Google Workspace: 

  • Enterprise Plus with the Assured Controls add-on. 

Resources 



What’s changing 

Access Transparency, Access Management, and Access Approvals now cover Gemini App data. These features provide admins full transparency into when Gemini App data is viewed for support purposes, control over which Google support staff can view this data, and control over when this data can be viewed by Google for support purposes. 

The addition of Gemini App data to Access Transparency, Access Management, and Access Approvals expands on Google’s data commitments on customer data ownership, security, and privacy. 

  • Access Transparency provides real time logs whenever customer data is accessed by Google staff. 
  • Access Management allows admins to limit which Google staff can access their data such as US or EU Google staff. 
  • Access Approvals allow admins to require Google to request for explicit approval prior to accessing their data related to a support action. 

These controls have been extended to cover Gemini App data in addition to Gmail, Calendar, Drive, Docs, Sheets, Slides, Drawings, Sites, Chat, meet, and Gemini in Workspace data. 



Getting started 


Rollout pace 

  • This feature is available now. 

Availability 

  • Access Transparency is available for users with Enterprise Plus licenses 
  • Access Approvals is available for users with Assured Controls or Assured Controls Plus licenses 
  • Access Management is available for users with Assured Controls Plus licenses 

Resources 



What’s changing 

To support more granular incident investigations and to expand access to this critical security data, we’ve made a few changes to the Gmail Audit Logs. 

1. Addition of the Gmail log events to the audit and investigation tool 
Gmail log events, previously only available to customers with access to the Security investigation tool (Security > Security center > Investigation tool), will now also be available to customers with access to the audit and investigation tool (Reporting > Audit and investigation) when Gmail is enabled as an application. This is change is now available. 

2. Addition of the Gmail log events to the AdminSDK Reports API 
Gmail log events are now available in the Google Workspace Admin SDK Reports API, providing programmatic access to this data. 

3. Gemini Data Access Logging for Gmail log events 
Addressing customer feedback for more granularity in reporting on how Gemini accesses data, a “message content accessed” log event will now be triggered when the Gemini app or Gemini for Workspace apps access Gmail messages on behalf of a user. Those events will have a client type of “API” and an actor application name of “Gemini or Gemini for Workspace”. These events will become available to customers gradually over the next few weeks. 

Who’s impacted 

Admins 

Why it matters 

Granular audit logs are critical to helping organizations investigate cybersecurity incidents and understand their data usage. The changes announced today expand access to this critical data and expand the depth of analysis that can be performed. 

Rollout pace 

  • Gradual rollout - please see launch timing notes for each change listed above. 

Getting started 


Availability 

  • Available for Google Workspace with audit log eligible licenses. To learn more about the audit log availability for your license types, please review this Help Center article.