All guides
Policy design8 min read

Google Workspace AI agent policy checklist

A concise checklist for policy patterns across Gmail, Calendar, Drive, Sheets, Docs, Chat, Classroom, YouTube, and other Google apps.

A useful policy is specific enough to evaluate automatically and clear enough for an operator to explain. Start with action effect and resource sensitivity, then add app-specific boundaries.

Communication apps

  • Gmail: auto-allow thread reads and drafts; approve external sends and label-wide changes.
  • Google Chat: approve messages to new spaces or external members.
  • Contacts: separate read-only access from creates, edits, and deletes.

Productivity apps

  • Calendar: allow availability reads; approve invitations and destructive event changes.
  • Drive: allow search within scope; approve sharing, permission revocation, and deletion.
  • Sheets: allow reads and bounded appends; approve overwrites and broad range changes.
  • Docs, Slides, and Keep: preview structural edits; gate changes to shared resources.
  • Tasks: permit listing; policy-check creation, completion, and deletion.

Content, education, and media apps

  • Forms: allow response reads; approve changes to questions or settings.
  • Blogger and YouTube: approve publishing, comments, sharing, and deletion.
  • Classroom: gate roster, coursework, and student-facing announcements.
  • Google Photos: separate library reads from sharing and album changes.
  • Drive Activity: keep activity queries read-only and use them as supporting evidence.

Apply controls consistently

Across all 16 wired apps, Pakkawork exposes immutable contract, scope, host, and generated risk metadata. Gmail, Calendar, Drive, Sheets, and Docs currently execute supported contracts through identity checks, policy, and approval. The other 11 apps remain catalogue-only, and provider-state verification is limited to 22 contracts with implemented post-conditions.

Frequently asked

Should app policy be based only on the Google service name?

No. Policy should evaluate the exact contract, effect, risk, agent, principal, arguments, and tenant context. Two actions in the same app can carry very different risk.

Can Pakkawork enforce both organization-wide and workspace rules?

Pakkawork applies a locked system safety floor first, then deterministic tenant rules beneath it. Tenant policy cannot override the floor.