Everyday Claude

Connectors: what you hand over when you connect Drive

Claude

A connector inherits your access, so its reach equals yours. That is the security model and the risk in one sentence.

Applies to
Claude Fable 5.1 Claude Opus 5 Claude Sonnet 5 Claude Haiku 4.5
Last verified
Reviewed by
Timothy Fehr

Connecting Google Drive takes one click and grants something worth understanding first. The governing rule, in Anthropic's own words: "Claude mirrors your existing permissions — you cannot access information you don't already have access to in Google Workspace."

That is a genuine safety property. It is also the whole risk, stated precisely, and which of the two it feels like depends entirely on how much you personally have access to.

Your access is the blast radius

If you can open every folder in a shared drive, so can the connector. Nobody at a company with broad internal sharing has a small footprint here, and most people have never counted theirs.

The number to know is not what you use. It is what you could open. For most people those differ by an order of magnitude, and the second one is the figure that matters when you are deciding whether to connect an account.

Anthropic states that Claude accesses data only when a request needs it and retrieves the minimum required. That limits routine exposure. It does not change the ceiling, which is set by your account.

What it can do, not just read

Reading is the part people picture. The Workspace connectors also cover actions: drafting and sending mail, creating and deleting calendar events, and sharing, moving or trashing files in Drive.

By default Claude asks before sending email or sharing, moving or trashing files. On Team and Enterprise plans, "owners decide whether members can allow these actions to run without asking each time" — which is the setting to look at before assuming the prompts will always be there.

What is actually extracted

Less than people assume. Anthropic states: "Claude extracts text content only from Google Drive files. Images embedded in documents are not processed." Comments and suggestions in Google Docs are not accessible either. On Gmail, attachment content is not reachable — metadata only.

So a Doc whose argument lives in a diagram, or a review whose substance is in the comment thread, arrives stripped of the part you cared about. The answer will not mention the gap.

Storage and training

Retrieved data is encrypted in transit and at rest, and is "retained with its associated chat, so you can delete any retrieved data by deleting the chat." Deleting the chat is the deletion mechanism, which is worth knowing before you tidy up a conversation you meant to keep.

On training, the same article states: "We do not train our models on your Gmail, Drive, or Calendar connector data". It also notes that for consumer accounts which opted into training, retrieved data may be used to improve the models. Those two statements sit in tension, and the reconciling variable is your own account setting, not anything about connectors. Check which setting you are on before you lean on the blanket sentence.

Try this

Before connecting a work account, open Drive and search for a term that would appear in something sensitive but not yours to read: a salary band, a contract, someone's review. Whatever comes back is inside the connector's reach from the moment you connect.

What goes wrong

Connecting the account you have, when a scoped one would do. A separate account with access to the specific material is a materially smaller grant, and it costs one login.

Assuming read-only. The Workspace connectors send mail and trash files. Check whether the approval prompts are on before assuming they will catch it.

Forgetting the connector is still attached. Access granted for one afternoon's task persists until revoked, and the risk arrives later than the convenience did.

Treating a summary as a full read. Diagrams, embedded images, Doc comments and mail attachments are outside what gets extracted, so a confident summary can be built on a genuinely partial view of the document.

How to check it worked

After a connector-backed answer, ask which specific files it opened, then open one yourself and compare. If it names files, you can audit the reach. If it answers from something vaguer, you have learned that you cannot yet tell what it read — which is the thing to fix before the next question rather than after.

Sources

  1. Use Google Workspace connectors — Anthropic Help Center Tier 1 2026-09-02
  2. Use connectors to extend Claude's capabilities — Anthropic Help Center Tier 1 2026-09-02