Skip to main content
Authorizing an account, attaching it to a workspace, and giving an agent access are separate steps.

The three layers

  1. Connect an account. Complete provider authorization or the supported credential setup.
  2. Attach the connection to a workspace. Choose the connection and its workspace audience.
  3. Check agent access and permissions. Give private access or participation where needed, and permit the intended operations.
Completing OAuth alone does not attach the connection to a workspace or make tools available to an agent.

Add an integration

Open Integrations in workspace navigation, then Add integration. Choose an existing connection or Connect new. After authorization, confirm the intended account, choose its audience, and complete Add integration. Organization connections can also be managed in Settings → Integrations. GitHub uses its separate repository-selection flow. A connected GitHub account does not automatically attach every repository.

Organization connections and personal Google connections

Most supported service connections are managed at organization level. Active organization members can manage those connections, including disconnecting one created by another member. A private workspace attachment does not make the underlying organization connection private to its creator. Direct Google Calendar, Drive, and Gmail connections are different: each belongs to the connecting person and is bound to a workspace and service. Other organization members cannot manage or attach that person’s Google account as if it were a shared organization connection. Google setup depends on availability for your organization. Direct Google attachments default to private.

Use multiple accounts deliberately

Different accounts for the same provider remain separate connections. Select the exact account when attaching a connection or giving the agent a task. Use clear display names where supported, such as “Sales calendar” and “Personal calendar,” and check the underlying account label. A display-name change does not change the account, credentials, or permissions. Reconnecting the same supported account can preserve its identity and attachments. Authorizing another account should not be treated as silently replacing the first.

What the agent can see

A public workspace integration can expose reads to workspace agents without membership. Private attachments require access. Writes also need membership and the appropriate operation permission. The attachment generally represents the connected account’s provider-authorized scope. It is not automatically limited to whichever folder, issue, or calendar you mention in a prompt. Choose the account and authorization scope accordingly. The agent’s own audience remains separate from its integration access. See Sharing agents and their work.

Remove or disconnect

Removing a workspace attachment removes that workspace resource while preserving the connection and other attachments. Disconnecting an organization connection disables all of its attachments. For personal Google connections, management remains with their connecting user and bound workspace/service. Neither action recalls content that an agent already copied into a page or conversation. Model-provider keys are another category: BYOK affects model routing and billing, rather than adding a workspace toolkit. For Snowflake’s generated setup SQL, administrator registration, and connection verification, see Connect Snowflake. For installation authorization, repository selection, and agent access, follow Set up GitHub.