Google connector

Work Google runs through an admin completed setup, then each member opts in their mailbox. New links in a personal workspace are temporarily unavailable.

Google comes in two distinct lanes: a work lane for team workspaces, and a personal lane that is temporarily closed to new links.

Work Google in a team workspace

A workspace admin completes the Work Google setup in the workspace's Integrations tab. This connects the company's Google domain under admin governance; it is an admin wizard on that tab, never an in chat card. Once the setup is active, each member opts in their own work mailbox with one tap, either from the Integrations tab or from a link card an agent offers in chat (see How account linking flows work).

The setup shows the client ID a super admin authorizes, and the full scope list for each tier with a Copy scopes button beside it. Those lists copy comma separated, which is the format the Google Admin console's scopes field expects, so the paste goes in as is with nothing to edit by hand.

Starting that setup is not the same as finishing it. Google Workspace shows "Awaiting verification" until a super admin has authorized Bolter's client for the scopes in the Google Admin console and then pressed Verify on the Integrations tab. While it says that, nothing reads anything: members cannot opt in their work mailbox, and no agent can reach Gmail, Calendar, or Drive. The tile only reads Connected once verification has passed at least once. A connection that says Paused is a different thing: it was set up, it worked, and an admin turned it off, so resuming it needs no trip to the Admin console.

The work lane is read only by default: agents granted access can read Gmail, Calendar, and Drive. A wider tier that allows sending mail, writing calendar events, and creating or editing the agent's own Drive files exists, but raising the ceiling is an admin decision made in the setup, not something an agent or a re-link can do. The admin authorizes the wider scopes in the Google Admin console, then switches the Work Google connection to "Read and write" on the Integrations tab. Raising the tier alone grants no agent anything: the grant still has to carry the write option, as the next section explains.

Two layers sit between an agent and a Google write

Sending mail, changing a calendar, and writing a file each need two separate permissions, and both have to be in place.

  1. The connection's tier, on a work Google connection only. This is the ceiling the workspace admin authorized in the Work Google setup, read only by default. Nothing an agent or a member does raises it.
  2. The agent's own grant. Sending mail, writing calendar events, and writing files are separate opt ins on the grant itself, approved by the grant's owner on the approval card. A grant that covers Calendar but does not tick the calendar write option can read the calendar and nothing more.

Reading never needs either write permission. So an agent can be blocked on a write for two quite different reasons, and the fix differs: if the tier is still read only, an admin raises it in the Work Google setup; if the tier already allows writes, the agent asks for the missing option on its grant, or you edit the grant and tick it yourself. An agent that has just been refused a write should say which of the two is missing. If it sends you to an admin who has already raised the tier, check the grant.

Files on shared drives

Agents read files on shared drives, not just files in a member's own My Drive. Team owned folders such as contracts or procurement are usually shared drives, and an agent granted Drive access reads them the same way it reads anything else. You do not have to move a file into someone's My Drive to make it readable.

What decides whether an agent can open a file is who the file is shared with. A work Google connection reads as the member who opted in their mailbox, so an agent reaches exactly the files that member can already open in Google, and nothing more. If an agent reports that a file or folder cannot be found, share it with that member in Google, or check that their access was not removed. A file the member cannot open is a file the agent cannot open.

Two things worth knowing when a folder looks empty. Google reports a file you cannot access as missing rather than as forbidden, so "not found" can mean the file is not shared with you, and it can equally mean the link or id is wrong, stale, or points at something deleted. An agent should tell you both are possible rather than pick one, and you can settle it by opening the file yourself as the member whose mailbox is connected.

And moving a folder into a shared drive can change who reaches it. Permissions someone was given directly on the folder or file usually travel with it, but access that came from the folder's old parent does not, because it was inherited rather than granted. Someone who could only see the folder through where it used to live loses it, without anyone having changed the folder. Adding that person to the shared drive restores it.

Putting time on a calendar that is not connected

Not every calendar is connectable. iCloud in particular has no connector, so an agent cannot write to an iCloud calendar the way it writes to a connected Google one. There are two ways around it. You can add an app-specific password as a key and let the agent work with the iCloud calendar directly, described under "Pasted API keys" in Connected accounts and grants. Or, without setting anything up, you can get the time blocked out by inviting the calendar instead of writing to it.

Ask the agent to create the event on a calendar it can already write to, and to add the other calendar's address as an invitee. A blocking evening event on your work calendar, inviting your personal address and anyone else who needs to be there, arrives as an ordinary invitation. Accept it on your phone and it appears in your personal calendar. Everyone invited sees the same event, and the times stay in sync if it moves.

This needs the same two permissions as any other calendar write: a connection tier that allows writes, and the calendar write option on the agent's grant. Two things to know before relying on it. The event belongs to the calendar it was created on, so edits, cancellations and the organizer's name all come from there. And invitees see the address that created it, which may not be the one you would have chosen for a personal evening.

Personal Google: new links are temporarily unavailable

Linking a new Google account inside your personal workspace, such as an @gmail.com address, is refused right now. Bolter's Google app is pending Google's verification, and until it passes, new links from a personal workspace are refused. Team workspaces are unaffected. Do not expect an agent to offer one, and be wary of any instruction that claims otherwise.

Work accounts are refused on the personal lane

An account on a company Google domain can never be linked as a personal account. If you try, the link is refused and you are steered to the admin completed Work Google setup for your workspace, so work email is only ever connected under your company's own authorization.

Already linked accounts keep working

If a personal Google account was linked in the past, it still works: agents that hold a grant on it can keep reading Gmail and Calendar through it, and re-linking that same account to refresh it remains possible. The pause only blocks brand new links inside a personal workspace; it does not touch accounts already linked, or new Work Google setups in a team workspace.

Ready to run a process on Bolter?

Bolter is in invite-only beta. Start from a blueprint or describe the job in plain words.

Request access