- Google announced a Gemini agent for work that can hold its own email, calendar and Drive account. It is in private preview for enterprise customers.
- Google says each agent action is logged to the agent, not to a person. That shifts accountability questions onto the organization.
- Before piloting, ask who owns each agent, what it can reach, how long its memory is kept, and who reviews its logs.
For decades an organization chart listed people. Google's latest announcement adds an entry that is software. The company says its new Gemini agent can be given a role, an email address, a calendar and a seat in the company directory.
The idea worth examining is not that the agent is smart. It is that the agent is treated as a colleague. Once software has a name in the directory, security, HR and finance each inherit a question they have not had to answer before.
What Google announced
At its Gemini at Work event, Google Cloud introduced what it calls a single, universal agent for work. It answers questions, does knowledge work, creates images and media, and writes and runs code from one prompt box. The Verge reports it will sit inside the Gemini Enterprise app and is available only to enterprise customers in private preview.
Google says the agent works inside Gmail, Drive, Docs, Slides, Sheets, Chat and Calendar. It can also be reached from phones, desktops, the command line, Microsoft 365 and Slack. Because it runs in the cloud, Google says it keeps one set of memory and context across all of them.
How it works
Google describes four building blocks. Each one changes what an organization has to manage.
First, tools. The agent connects to systems such as Salesforce, ServiceNow, Jira, BigQuery and Snowflake. It can also use any server that speaks the Model Context Protocol (MCP), an open standard for linking agents to software.
Second, skills. These are reusable instructions that teach the agent a multi-step job. Teams can publish their own to a shared company registry.
Third, memory. Google lists four kinds: session, semantic, procedural and episodic. Procedural memory includes skills the agent writes for itself. Episodic memory records everything it has done before.
Fourth, sub-agents. The main agent can create temporary, job-specific agents, each with its own identity. It can also act as a coworker agent with a persistent role. Google says a coworker agent sees only what you share with it.
Google also says the agent picks the model for each job. It names Gemini models and Anthropic's Claude models today. It lists spend caps and a feature called Smart Routing as cost controls.
The shift: from tool to account holder
Think of a contractor given a building badge. The badge is useful because it is specific. It says who the person is, which doors open, and what the logs show. Google is applying the same logic to software, and the logic is sound.
Google says every agent gets a cryptographically attested identity, governed like an employee, with least-privilege permissions. It says the identity is stamped into logs and into any virtual machine the agent starts. Each action is written to an audit trail attributed to the agent rather than to a person.
That last detail deserves attention. A clean log tells you the agent acted. It does not say which human delegated the work or approved the result. Accountability still has to be assigned by the organization.
SOMPO's figure, which Google reports, shows how fast the count can grow. Google also says Orange Spain deployed more than 1,000 custom agents. If each agent is an identity, someone must also keep track of who owns it, and when it should be retired.
What is not yet known
This is a vendor announcement, and the customer results are Google-reported. Google says Bradesco cut document review from one hour to five minutes. Those figures have not been independently checked here.
The product is also in private preview. The source text provided ends partway through Google's governance section. It names Agent Sandbox and Agent Gateway but does not describe how the gateway works, so those controls cannot be assessed yet.
Questions to put to your team
Google frames the test as two factors: whether you can govern the agents, and whether you can afford them. Four questions follow from that.
Who owns each agent? Every agent identity needs a named human owner. Without one, an audit trail has nobody to call.
What can it reach? Agents connect through tools and MCP servers. Ask who approves each connection, and who reviews permissions after a role changes.
What does it remember? Episodic and semantic memory build a store of company knowledge. Ask where it is held, how long, and who can read it.
Who reads the logs? Real-time monitoring only helps if someone is assigned to watch. Decide who is paged when an agent behaves oddly.
The lesson here is simple. Giving software a badge is easy. Deciding who answers for it is the real work, and it has to be settled before the pilot, not after.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Google Cloud.





