I was opening a Google Doc in a client's Workspace, and I pulled out the Gemini side panel on the right. Among the connection options was the name of the project management tool that team uses every day.
Their admin had not changed anything. Neither had I.
It turned out I was looking at the September 15, 2026 announcement, Connect to more tools with Gemini in Google Workspace. Asana, Atlassian Rovo, HubSpot, Intuit Mailchimp, Intuit QuickBooks, Monday and Salesforce now reach Gemini over MCP, the Model Context Protocol. And in the Getting started section, in plain type: ON by default.
What stopped me was not the feature. I had read that announcement the week it went out. I had simply never opened the screen it was describing.
On by default means it arrives without anyone touching a switch
Here is the announcement rewritten as places and numbers. The two rows people skim past are where it is managed and which plans are included, so I put both in the table.
| Item | Detail |
|---|---|
| Services | Asana, Atlassian Rovo, HubSpot, Intuit Mailchimp, Intuit QuickBooks, Monday, Salesforce |
| Where it appears | The Gemini side panel in Docs, Sheets and Slides, plus Ask Gemini in Google Chat |
| Default state | On, for anyone with Gemini for Workspace access |
| Where it is managed | Admin console → Apps → Google Workspace → Gemini for Workspace → Third-Party Connectors |
| Scope | Domain, organizational unit (OU), or group |
| Rollout | Available now on both Rapid Release and Scheduled Release |
| Editions | Business Standard and Plus, Enterprise Standard and Plus, Enterprise Essentials Plus, several education add-ons, and consumer Google AI Pro and Ultra |
The last row is the one I would not skip. This is not only a company Workspace change. If you pay for Google AI Pro or Ultra on a personal account, the same connection options show up for you too — and there is no admin in that picture except you.
The door is open, but you are still the one holding the key
Getting this backwards leads either to unnecessary alarm or to unearned calm.
What is on by default is permission to use a connector. For Gemini to actually read anything out of one of those services, the person using it has to sign in to that service and approve access. Nobody's Salesforce pipeline starts flowing into a document on its own.
At the same time, it is fair to say the path is now open for everyone, and only one approval stands at the end of it. If your team handles client records or deal data, that is worth one deliberate decision rather than a default you inherited.
For a while I tried to settle the question from the Admin console alone. It does not work, because the admin screen and the user screen answer different questions.
Counting what is on, from the Admin console
The path is short.
- Open the Admin console.
- Go to Apps, then Google Workspace, then Gemini for Workspace.
- Open Third-Party Connectors.
- Choose the scope on the left: whole domain, an OU, or a group.
- Read the on/off state for each service.
The tempting move is to switch everything off at the domain level. I would rather not. You take down the tools people actually pay for along with the ones nobody uses, and then you spend a week turning them back on one complaint at a time. If your OUs already separate sales from production, decide per OU — the reasoning is easier to explain that way, too.
Whatever you find, write it down before you close the tab. This is the shape I keep. The values are examples; swap in your own services and verdicts.
Checked: 2026-09-22
Scope: whole domain / OU=Sales / OU=Production
Connector Default Now Verdict Why
Asana ON ON keep daily project tracking
Atlassian Rovo ON OFF turn off no contract
HubSpot ON OFF turn off no contract
Intuit Mailchimp ON OFF turn off no contract
Intuit QuickBooks ON OFF turn off not used in our region
Monday ON OFF turn off no contract
Salesforce ON hold revisit evaluation in progress
Next review: 2026-10-20Once that file exists, the next announcement stops being a full audit and becomes a diff. Some weeks it is three lines. Occasionally two new rows appear.
Now look at the same thing from a user account
The Admin console tells you whether a connector may be used. It does not tell you who has actually signed in to the service behind it.
On the user side, opening the side panel in Docs, Sheets or Slides surfaces the available connections, and Ask Gemini in Google Chat reaches the same set. That screen is also where someone disconnects an account they no longer want linked.
For a small team, this order has been the quickest for me:
- Sign in as admin, open Third-Party Connectors, count what is on
- Sign in as yourself, open the side panel, see what is offered
- Ask the people who actually use it whether they have connected anything
The third step looks like the slow one. It is the fast one, because no amount of staring at the Admin console will answer it. If a feature is missing from your side panel entirely, I wrote separately about telling a slow rollout apart from an actual fault.
Reading the announcement and opening the screen are two different days
Back to that side panel. I had read the post on the day it went up. I wrote "check during the next cleanup" in my notebook, and then a week went by. That did not go well. Until I saw the tool's name sitting in a client's document, I had verified nothing.
I make the same mistake as an indie developer. When an external service behind one of my wallpaper apps changed a default, the notice was sitting in my inbox — and I opened the dashboard only after the numbers looked off. Reading and checking are separate pieces of work. It took me longer than I would like to notice that.
Open the screen the same day you read the announcement. The decision can wait. Opening it, counting, and writing down what you found belong to that same day — that is the one line I try not to cross, even in a busy week.
If you are drawing boundaries around what Gemini can reach, two related pieces may help: a Drive setting to try before you unshare anything, and the three places Gem sharing quietly stops.
A five-minute version
Open Third-Party Connectors and switch off only the services you have no contract with. Leave everything you pay for exactly as it is. Nobody's work breaks, and there is no judgment call to agonize over.
What to do about the ones that remain is a fine topic for your next team meeting. Open it, count it, write it down. That is the whole of what I learned this week.
Thank you for reading. If you have ever found something in your own tools that you never switched on, I hope this saves you a little of the backtracking it cost me.