Sistava

How to Connect AI to Google Workspace Email Accounts

How-to — by Mahmoud Zalt

Connect AI to Google Workspace email the admin way: app access controls, per user rollout, scoped permissions, and clean revoking when someone leaves.

Business email carries a different weight. It is not just your own time being wasted, it is contracts, supplier disputes, and the customer who has now emailed three times. The question stops being would this help me and becomes who signed off on this, and what happens when it goes wrong.

That is a fair question and Workspace already has an answer built for it. Google gives admins a control panel over every third party app that touches company data, and it works whether the app is a mail client, a CRM, or an AI Employee. You are not being asked to invent a policy, only to use the one that ships with the product.

Once a mailbox is connected, Sistava puts an AI Employee to work on it. It reads threads for context, drafts replies in the writer's own voice, applies labels so nothing sits in an undifferentiated pile, and chases the conversations that went silent. Sending stays behind approval for as long as you want it to. The wider picture lives on the security page.

At a Glance

4
access states an admin can set for any connected app
1
mailbox worth piloting on before you roll out wider
0
shared passwords needed, including for shared mailboxes
100
monthly cost to run AI Employees across a small team

Is Workspace email different from a personal Gmail here?

The connection mechanics are identical. Same sign in, same consent screen, same permission list, same off switch. What changes is who else gets a say. On a personal account you are the only gatekeeper. On Workspace there are two, you and whoever administers the domain.

That second gate is a feature rather than a hurdle. It means one person can set the rule once and every mailbox inherits it, instead of fourteen people each making a slightly different judgement call on a screen they skim at half past four on a Friday.

Do you need to be an admin to connect it?

Usually not, but it depends on how your domain is configured. Many Workspace domains allow individual users to approve apps for their own mailbox, in which case you connect it yourself and nobody else is involved. Domains with tighter settings block unapproved apps outright, and your connection attempt simply fails with a message pointing at your admin.

If you hit that wall, the fix is a short conversation, not a fight. Tell your admin which app it is, which mailbox you want connected, and which permissions it will ask for. Most admins say yes quickly when the request is specific and no when it arrives as a vague ask to allow an AI thing.

What can the admin console actually control?

The Admin console lets you sort every connected app into one of four states and lets you blocklist particular permissions so no app can ever request them, however trusted it is. You reach it through Security, then API controls, then app access control. It is the single most useful screen in Workspace that most teams never open.

The states range from full trust to a flat block, with two middle settings that let an app touch some Google services and not others. That middle ground is where most AI Employees should sit: allowed on Gmail, not allowed on everything else the company keeps in Google.

Benefits

Trusted

The app can request any permission a user approves. Reserve this for tools your company depends on and has actually reviewed.

Limited

The app can only reach services you name. This is the right setting for an AI Employee that should see Gmail and nothing else.

Specific Google data

A narrower version of limited, letting you pin the app to the exact data categories you approve rather than whole services.

Blocked

Nobody on the domain can connect it, no matter what they click. Useful as your default posture for anything unreviewed.

There is a second lever worth knowing about. You can maintain a blocklist of high risk permissions at the domain level, which acts as a backstop against any individual clicking approve on something they should not have. It catches the honest mistake made in a hurry, which is the failure mode that actually happens.

What does a real rollout look like?

Marcus runs operations at a fourteen person logistics firm on Workspace. Their shared ops address takes about 300 messages a week: booking confirmations, delay notices, driver queries, and a steady drip of customers asking where their pallet is. Three people share the load and each one answers slightly differently.

He started with one mailbox, his own, not the shared one. He set the app to limited so it could reach Gmail and nothing else, connected with read and draft, and left send off. For two weeks he did nothing but read the drafts and correct the tone twice.

In week three he moved the AI Employee onto the shared ops address and let it send one thing only: the where is my pallet reply, which pulls the tracking reference from the thread and answers with a status. That single category was 40 percent of the volume. Everything else still lands as a draft with a human name on the send button.

Six weeks in, the shared address answers routine questions in minutes rather than hours, the three humans handle exceptions instead of repetition, and Marcus has an activity log he can hand to anyone who asks what the AI has been doing. Nothing about the rollout was dramatic, which is the point.

What should the AI never touch on a business account?

Some categories should stay human no matter how well the drafts read. Anything that moves money, changes a contract, or affects someone's employment belongs to a person with a name and a job title. An AI Employee flags those threads and steps back rather than answering them.

It also does not delete company mail. Archiving and labelling tidy the view, but the message stays in the account and stays discoverable, which matters when a supplier dispute turns into a question about who said what in March. Here is the boundary written out.

The logging piece is what makes this survivable in a business. When a customer forwards you a reply and asks who wrote this, you want a timestamped answer in under a minute. Without a log, the honest answer is a shrug, and a shrug is how good tools get banned internally.

What happens when someone leaves the company?

Suspending the person's Workspace account kills every app connection tied to it, including the AI one, immediately. You do not need to remember a separate step or hunt through a vendor dashboard. Offboarding a human offboards their tools by the same action.

If the AI Employee was working a shared mailbox rather than a personal one, move the connection to whoever inherits that mailbox and carry on. The work stays where it always was, inside your Workspace, because drafts, labels, and sent mail live in Google, not in the tool.

Roll out across a Workspace in six steps

  1. Set the app state before anyone connects — In the Admin console, mark the app limited to Gmail. Doing this first means nobody can accidentally approve more than you intended.
  2. Pilot on one personal mailbox — Preferably yours. Read and draft only, send off. Two weeks of watching drafts tells you more than any evaluation document.
  3. Write down the categories — List which kinds of mail the AI Employee handles and which stay human. Money, legal, and HR belong in the second list.
  4. Move to the shared mailbox — Connect the address the team actually shares. This is where the volume is and where consistent replies pay off most.
  5. Turn on send for one category — Pick the highest volume, lowest risk reply you have. Watch it for a week before adding a second category.
  6. Put the audit on a calendar — Fifteen minutes weekly for the first month, then monthly. Compare the activity log against what Gmail actually shows in Sent.
Question your admin will askThe straight answer
Can we block this domain wide if we change our mind?Yes, one setting in the Admin console and no mailbox can connect it again.
Does it need access to Drive or Calendar?Not for email work. Set it to limited so Gmail is the only service it can reach.
Where does the company data go?Threads are read to produce a reply. Drafts, labels, and sent mail stay inside your Workspace.
Who can see what it did?You, in two independent places: the Workspace admin audit log and the per employee activity log.
What if a user approves something they should not?The domain blocklist for high risk permissions stops the request before it reaches the consent screen.

Frequently asked questions

FAQ

Does this work with a shared or delegated mailbox?

Yes. A shared address behaves like any other mailbox once someone with access connects it, and delegation rules still apply on the Google side. This is usually the highest value place to start on a business account, because a shared inbox is where inconsistent replies and slow responses do the most damage. Keep sending behind approval for longer than you would on a personal mailbox, since several people rely on the same thread history.

Can we allow it for one department and not the rest?

Yes. App access control in the Admin console can be applied to specific organisational units rather than the whole domain, so sales can have it while finance does not. That is the cleanest way to run a real pilot, because the boundary is enforced by Google rather than by everyone remembering the policy.

Will this show up in our Workspace audit logs?

Yes. Google records the API level activity for any connected app under the admin audit log, independently of whatever the vendor reports. Reading both sides is the point: when the vendor log and Google's log agree, you have a clean picture, and when they disagree, you have found something worth investigating.

What about compliance and data retention rules?

Your existing Workspace retention rules keep applying, because the mail never leaves your Workspace. The AI Employee does not delete, so it cannot break a retention policy by removing something it should have kept. If your industry requires review of outbound communication, keep approval mode on permanently so a human signs off on every send.

Can we run different AI Employees on different mailboxes?

Yes, and it is usually the better design. One employee on support mail and another on sales mail means each learns a narrower job, uses a narrower tone, and needs narrower permissions. It also makes the activity logs far easier to read, because you are not untangling two different jobs from one stream of actions.

The technical part of connecting AI to a Workspace mailbox takes a minute. The part that decides whether it works is the boundary you set before anyone clicks connect. Set the app state first, pilot on one mailbox, write down what stays human, and widen it only when the evidence in front of you says you should.