AI4 min read

Google gives the Gemini agent its own workplace identity

One universal agent that plans objectives, delegates to subagents, routes across Gemini and Claude, and acts under its own @agents.company.com identity, with per-project spend caps and an audit trail attributed to the agent.

What happened

Summary of reporting by TechCrunch

Google Cloud presented the Gemini agent at its Gemini at Work event on 8 October: a single agent in the Gemini Enterprise app that takes objectives, plans multi-step tasks, invokes tools and connectors (Google Workspace, Microsoft 365, Slack, Jira, Confluence, Git, BigQuery, Databricks, Postgres, Snowflake, and MCP), and delivers completed output. The agent maintains persistent memory across devices, spins up job-specific subagents that run for hours, and routes tasks to Gemini models or Anthropic Claude in private preview. TechCrunch The Verge

Identity forms the central architectural choice: each coworker agent receives its own Workspace account, an email address on an agents.company.com domain, calendar, Drive, and directory listing, acting under its own name in comments and document history. Actions are logged to an audit trail attributed directly to the agent rather than a human employee, secured by attested identities, least-privilege permissions, an Agent Sandbox, and an Agent Gateway. CIO.com

Google pairs task completion with infrastructure controls: multi-model orchestration, Smart Routing to cost-effective models, real-time per-project spend caps in the Cloud Billing Console that pause agents when reached, pay-as-you-go pricing, Flexible Savings Plans offering 10 or 20 percent discounts, and deferred execution at up to half the inference cost. Industry analysts view the launch as a move to control the enterprise agent runtime, while noting the line between Workspace and Gemini Enterprise remains fluid. CIO Dive

Read the original at TechCrunch

The Azrty take

Gemini's new agent proves identity, routing and budgets are the enterprise battleground, and that is a layer GCC organisations should own rather than rent.

The business point is that Google has stopped selling models to enterprises and started selling the control plane: identity, audit, routing and budgets in one subscription. For GCC organisations already on Google Workspace or Gemini Enterprise this is close to free upside, one front door that plans work across BigQuery, Slack and ServiceNow with spend caps attached. For everyone else the risk is sharper. As Nick Patience of The Futurum Group noted to CIO Dive, models are interchangeable, but the memory, skills and context an agent accumulates sit in Google's layer, and that is where the switching cost will live.

The deployment evidence is real. PayPal routes 10 million multi-model requests per week and says Gemini Enterprise cut model deployment from weeks to minutes. Bradesco cut document review from one hour to five minutes and risk inconsistencies by 60 percent. Orange Spain runs more than 1,000 custom agents; SOMPO built over 10,000 agents across 34,000 employees and took model development from one week to one day. In the GCC, Google's own keynote lists Ooredoo Qatar and Qatar University, the latter past 2,000 agents. Cost pressure runs alongside: Google says per-token prices are down 98 percent since 2024 while volumes exploded.

Most teams will treat this as a licence question. It is an identity question. Once a coworker agent holds a mailbox and a directory entry it is a principal in your IAM: DLP, eDiscovery, legal hold and retention must cover non-human accounts. In the UAE and GCC that collides with data residency and PDPL duties: when an agent commits your organisation in a mail thread under its own name, who signed? Google's own pages (keynote, cost controls) add per-project spend caps that pause agents, Savings Plans at 10 or 20 percent off, deferred execution at up to half the inference cost.

Technically, we would keep the control layer ours. Put a gateway in front of every model before this scales: FastLLM Proxy, our OpenAI-compatible gateway that fronts your own LLM servers and 80 hosted providers, keeps routing, budgets and access control in infrastructure you run, so swapping Gemini, Claude or a self-hosted model is a routing change, not a rewrite. Irreversible actions (external mail, payments, production changes) go through a person in Dhole, our workflow engine, and agent memory lives in a service you can export. The policy sketch we would enforce at that layer:

# policy sketch: agent traffic stays behind a gateway you control
routing:
  - task: planning_and_reasoning
    models: [gemini-argon, claude]
    fallback: gemini-flash
  - task: extraction_and_classification
    models: [gemma]          # cheapest adequate model wins
budgets:
  project_monthly_cap_usd: 5000
  on_exceed: pause_and_notify
identity:
  agent_principals: ["agent:events-coordinator@agents.company.com"]
  scopes: ["read:confluence", "write:docs", "comment:chat"]
  human_approval_required: ["external_email", "payment", "production_change"]

What to do now

  1. If you run Google Workspace Business or Enterprise or Gemini Enterprise, ask your account team this month for private preview access to the Gemini agent, and scope the pilot to one workflow with a measurable baseline (document QA or credit memos), capturing the agent audit trail from day one.
  2. In the Google Cloud Billing Console, set a firm monthly spend cap per project now, keep the default alert thresholds at 50, 80 and 100 percent, and allow pay-as-you-go overages only where continuous operation matters. If token spend is steady, price a Flexible Savings Plan: 10 percent off one year, 20 percent off three.
  3. Fix the agent identity model before any coworker pilot: whether agents get directory accounts on a segregated domain such as agents.company.com, which groups they join, and a hard rule that external email, payments and production changes need human approval. Put it in your IdP groups and DLP rules, not a policy doc.
  4. Stand up a model gateway (FastLLM Proxy or equivalent) as the single OpenAI-compatible endpoint for every agent, with per-project budgets and routing rules, so Gemini, Claude and self-hosted models stay interchangeable and your spend caps apply even where the agent platform's do not.
Build your AI platform and control planeAzrty designs and runs your AI infrastructure: OpenAI-compatible model gateways, private clusters, and budget controls on your own terms.
Google CloudGeminiAI AgentsFastLLM ProxyEnterprise AICloud Infrastructure

More from the Brief

Google gives the Gemini agent its own workplace identity: the Azrty take | Azrty Brief