Can free-plan users not use the Gmail connector at all now?
Not entirely unusable. Per Anthropic's official support documentation, the Google Workspace connectors (Gmail, Google Calendar, Google Drive) themselves are available to all users, including the free plan, for searching email, organizing an inbox, and drafting replies. But the two more advanced capabilities added in this update — "directly sending, replying, and forwarding" and "Drive file management (share, move, trash, upload)" — are currently limited to paid plans.
Put simply, the connector's basic reading functionality is available to everyone; what this update actually restricts to paid plans is the new layer of "executing an actual action on your behalf." Free-plan users can still read email and organize their inbox through the connector — they just still have to handle the actual sending step themselves.
If I'm not comfortable letting Claude send email automatically, can I just use the read and organize functionality without enabling send capability at all?
Yes. This new capability is an addition on top of the existing connector, not a forced replacement of how it previously worked. Users can choose to keep the existing usage pattern of "Claude only handles reading, organizing, and drafting, and I handle the actual sending step myself" — there's no obligation to enable automatic sending permission just because the new feature launched.
Also, even if you choose to give Claude sending capability, the default approval mechanism still asks for your consent before each send, reply, or forward — unless you (or an enterprise account's administrator) proactively turn off that confirmation mechanism, there's no scenario where something gets "automatically sent out without you ever seeing the content at all." For users who aren't comfortable, keeping the default approval mechanism active while carefully approving each send individually is a practically viable middle path.
When an enterprise account administrator decides whether to let members skip per-action confirmation, what practical judgment criteria are worth considering?
A more sensible judgment criterion is first assessing whether the email content this account handles daily is highly standardized, low-risk type content (like fixed-format notifications or simple scheduling confirmations), or involves high-risk content like business secrets, client privacy, or formal external communication. If an account mainly handles the former, enabling skip-confirmation genuinely saves a lot of repetitive operational time; if an account often handles the latter, keeping the per-action confirmation protection avoids real damage that could result from a single automated send going wrong.
Another practical consideration is that this decision doesn't need to be applied uniformly across the whole organization — as noted earlier, an administrator can decide "which members" can skip confirmation, meaning risk-control settings can be differentiated based on different roles' and accounts' actual work content, rather than the whole organization being uniformly enabled or disabled.
Could the scope of email and files Claude can access exceed what I could already see in my own Google account?
No. Per Anthropic's official support page, Claude operates entirely mirroring the user's existing permissions within Google Workspace — content you didn't originally have access permission to in Gmail or Drive, Claude likewise can't access. Connecting Claude doesn't grant it extra access capability beyond your own account's permission scope. Anthropic also commits, in the same documentation, not to train models on your Gmail, Drive, or Calendar connector data, keeping this private information private.
This means the risk this update brings is mainly concentrated at the level of "will Claude execute an action you didn't expect on your behalf" (like automatically sending an email you haven't seen), rather than the level of "will Claude access content you couldn't already see." Understanding this distinction helps focus what's worth paying attention to during setup on the right thing.
On August 18, 2026, Anthropic announced through its official account that Claude's Google Workspace connector has closed its most obvious long-standing gap: Claude can now not only read email, organize an inbox, and draft replies, but also directly send messages, while also gaining the ability to manage files in Google Drive. This article covers what this update actually changes, how to set it up, and the risk-control details worth knowing before you do.
Claude's Gmail connector isn't a new feature — it could already search email, organize an inbox, and draft replies based on message content. But there was a clear limitation until now: once a draft was written, the user had to manually open Gmail, review the content, and click send themselves — Claude itself had no permission to send directly. That limitation is now lifted: a user just needs to ask Claude to reply to an email, and Claude can complete both writing and sending on its own, without the manual confirmation step in between. This capability covers three actions: replying, sending new messages, and forwarding existing ones.
Previously, Claude's access to Google Drive was mainly about reading and understanding file content. This update adds the ability to actually operate on files, including sharing, moving, trashing, and uploading — effectively handing routine Drive management tasks to Claude as well, rather than passively reading content to answer questions.
For Team or Enterprise plans, before these steps can begin, an organization's account administrator needs to first enable these two connectors at the organization level in the admin panel, before individual members can complete the connection and authorization themselves.
The part of this update most worth paying attention to isn't "it can send email" itself — it's how the default confirmation mechanism is designed. Per Anthropic's documentation, for sending, replying, and forwarding, Claude by default asks for user approval before actually sending, to avoid a message going out before the user has seen the content. But on Team and Enterprise plans, an organization's owner or administrators can choose to let specific members skip this per-action confirmation step, letting Claude automatically execute a send action in certain situations without stopping to ask every time. This means the actual degree of risk control this feature provides varies noticeably by account type and administrator settings — individual users and enterprise account users don't get quite the same default experience.
This update is currently limited to all paid plans — free plan users can't use the new sending and Drive management capabilities yet. For work situations involving a lot of standardized replies or routine notifications (like customer support or administrative correspondence), handing this kind of low-risk, fixed-content email to Claude to complete automatically saves genuine operational time. But precisely because this feature has moved beyond "purely producing text" into "executing an actual action on your behalf," the thing worth focusing effort on during setup isn't whether the feature is good to use — it's confirming exactly how the approval mechanism is configured. Especially if you're an administrator on an enterprise account, deciding whether to let members skip per-action confirmation should itself be treated as a risk-control setting that deserves careful evaluation, not simply an efficiency toggle.