As a Google Workspace administrator, you manage how and when Workspace Studio flows access your organization's Google data. This setting helps you balance user productivity and automation with your organization's security, compliance, and privacy standards.
By default, newly created flows run with the same data access privileges as the user that created them. This means a flow can automatically read, modify, and share Google data, such as files in Drive, emails in Gmail, and content in Docs, on a user's behalf.
Managing flows access to data is important for these reasons:
- Prevent accidental data exposure: Restricting flow access ensures that agents don't inadvertently share sensitive or restricted organization data.
- Enforced policy compliance: You can set default access levels for your entire organization or target specific organizational units (OUs) to comply with data governance regulations.
- Control AI-powered data sources: For flows that use Gemini AI steps, you can restrict whether the AI is permitted to search internal Workspace data, external public websites, or both.
- Maintain centralized oversight: Your Google Admin console is a single place to review, pause, or restrict data access for individual flows created across your domain.
See a list of all flows and manage data access
You can review all the flows created by users in your organization and, if needed, change or pause their access to Google data. Use Studio admin settings to block access to specific steps.
- In your Admin console, go to Menu
Agents
Agent access management.
- To filter the list to only flows, click Type
Studio flow.
- To see more information about the flow, change data access, pause data access, or reactivate a flow, click Actions and the corresponding option.
- Pause data access–Blocks the flow's access to Google data and stops any in-progress or future runs.
- Change access–Block access or restrict to certain scopes. The flow can still run, but might not work as expected.
Note: Only newly created flows by allowlisted testers will show in the Agent access management page. Existing flows will continue to operate as they did before.
Set default data access for flows
By default, flows have access to the same Workspace data as their creator. You can block access to Workspace data for flows by default instead for your entire organization or an organizational unit.
Note: Blocking access to Workspace data will cause most flows to stop running.
- In your Admin console, go to Menu
Agents
Settings.
- Click Default access for Studio flows.
- (Optional) At the left, select an organizational unit to apply the setting to.
- To block access by default, select Don't allow agent access.
- Click Save. If you chose an organizational unit, click Override.
Manage access to specific steps for flows
As an administrator, you can control which steps users can add to their flows. For details, see:
Set which sources Gemini steps can use
As an administrator, you can control the sources which Gemini can search and use to create responses in Workspace Studio flows. This can occur when a flow includes AI-powered steps. The sources which Gemini searches can be data on public websites or any Workspace data a user can access.
When you block a source, Studio users see the source option dimmed and unavailable.
Note: By default, both source options are allowed.
- In the Google Admin console, go to Menu
Apps
Google Workspace
Workspace Studio.
- Click Gemini data sources.
- Check the box for the sources you want to allow Gemini to search:
- Allow Gemini to search Workspace data
Allow Gemini to search public websites
If you uncheck an option and a user's flow is affected, the user sees a notification in the Studio activity log.
Click Save.