Grok connector guide
Grok connectors for Google Workspace: what connects and how to scope it
xAI documents two built-in Google connections: Gmail & Google Calendar, and Google Drive. The Drive connector covers Drive files, Docs, Sheets and Slides. These are OAuth connections maintained by xAI; Business and Enterprise teams need an administrator to provision them before members can connect.
What the built-ins cover
Gmail & Google Calendar gives Grok access to email messages and calendar events. Google Drive covers Drive files and the content types stored in Docs, Sheets and Slides. Treat the suite services as capabilities of those connections rather than separate native connectors unless the live catalogue says otherwise.
Built-in status means xAI maintains the connector and the connection uses OAuth. It does not mean every user sees identical actions, every Google field is available or every provider plan is included.
- Gmail: search and use permitted mailbox context.
- Google Calendar: inspect event context and supported calendar tools.
- Drive: retrieve permitted files and metadata.
- Docs, Sheets and Slides: accessed through the Drive connection.
Choose a Google account boundary
The most important setup decision is which Google identity to connect. A founder's mailbox or unrestricted shared drive can reveal far more than a pilot needs. Prefer a role-appropriate work account and a small, representative corpus.
Google Workspace administrators should review the OAuth application, requested scopes and organisational access policy. Individual users should still inspect the consent screen and understand which content their source-system permissions expose.
- Avoid personal accounts for company workflows.
- Use project folders or a test shared drive where the product supports that boundary.
- Remove unnecessary shared-file access before connecting.
- Document who can disconnect or reprovision the connector.
Pilot read workflows before actions
Start with retrieval: find a document, summarise a thread, assemble a meeting brief or explain a spreadsheet. These tasks are easier to verify against source records and do not change external systems.
If the live connector exposes write or send tools, add them one at a time. Require a visible preview and human confirmation for messages, calendar changes and file edits.
- Meeting brief: calendar event plus a specified Drive folder.
- Client history: a named Gmail thread, not the whole mailbox.
- Document comparison: two selected files with citations.
- Spreadsheet explanation: a copy or non-sensitive range for the first test.
Know the business-admin step
For Grok Business and Enterprise, xAI says a team administrator must provision a connector in the cloud console before members can use it. Provisioning is separate from each user's provider authentication and source permissions.
A robust rollout checks both layers: the Grok organisation policy and the Google identity's access. Removing access in either system should be tested as part of offboarding.
- Provision only the connectors needed for the pilot.
- Assign a business owner and a technical administrator.
- Test with a non-admin user.
- Record last review and revisit after connector changes.
Questions to ask before production use
Confirm whether the connector meets your data residency, retention, legal and regulated-data requirements. Review xAI and Google terms directly; this directory does not replace those reviews.
The fastest safe rollout is narrow enough that you can identify exactly which records a good answer should use. If you cannot describe that boundary, the connection is too broad for the first test.