Claude Just Got Write Access to Gmail and Drive. The Approval Toggle Is the Whole Story
Anthropic gave Claude send, reply, and forward powers in Gmail plus share, move, and trash in Drive on the same day it pushed Cowork to every paid plan on web and mobile. A $20 Pro sub is now the cheapest way to hire a cloud agent with a Google account.
Anthropic shipped two changes in one day: the Google Workspace connectors stopped being read-only, and Claude Cowork stopped being a desktop exclusive. The announcements arrived back to back on August 18, and the headlines did exactly what headlines do. One outlet led with the idea that Claude can now send emails "even without your approval." The real story is quieter and, for anyone thinking about handing an AI their inbox, more interesting.
The two updates share one direction. Claude used to look at your data. It now works it. You can watch the tool literally reach into a conversation and do something that cannot easily be undone.
What Changed in Gmail and Google Drive
Anthropic's connectors have been around in read-heavy form for months: search mail, pull text out of Docs, check your calendar. The August 18 change closes the gap on actions. source
| Capability | Before August 18 | After August 18 |
|---|---|---|
| Gmail: search and read | Yes | Yes |
| Gmail: draft | Yes | Yes |
| Gmail: send, reply, forward | No | Yes |
| Drive: read Docs, Sheets, Slides | Yes | Yes |
| Drive: upload, create folders | Yes | Yes |
| Drive: share, move, trash | No | Yes |
source The write actions are the new surface. Claude can draft a reply to a pricing proposal, push back on the timeline, and send it. It can move last quarter's planning docs into the archive folder, or trash them. source source
There are real limits underneath. Gmail attachment content stays out of reach, only metadata comes through. Drive reads are text-only: no image parsing inside Docs, no xlsx-to-Sheets or pptx-to-Slides conversion, no adding comments. If you have Claude save a file back to Drive, that needs code execution turned on.
The Approval Question Everyone Misread
Let's be precise, because a headline like 9to5Google's sent readers in the wrong direction. source What Anthropic actually shipped: Claude asks for your approval before every send, reply, forward, share, move, and trash. That is the default, and Anthropic restates it three times in its support documentation, once in the Gmail permissions section, once in the Drive actions section, once in the FAQ. source
The hedged wording matters. On Team and Enterprise plans, an owner can decide whether members may let these actions run without asking every time. That permission is yours to be talked into, not the default. Headlines read it as "Claude sends your email now." The accurate version is "Claude can send your email, and it will ask first, until your admin decides otherwise."
Why the fuss anyway? Because these are the actions with no clean undo. A sent email reaches a real person. A shared link persists. A trashed file enters Google's deletion pipeline. That is a different blast radius from summarizing a thread. Approval-first is the sane posture for that, and it is what everyone security-conscious would want by default.
Answers Are Cited, and Your Data Is Not Trained On
Two details worth knowing before you connect anything. First, answers come with citations. When Claude pulls from an email or a document, it points back at the original, which makes it possible to check its work instead of trusting a summary. Second, the connector data is excluded from model training. Anthropic says it does not train on your Gmail, Drive, or Calendar data. source
Claude only touches the Google account you connect, only when you ask, and only the minimum needed to answer. On Team and Enterprise plans, an owner has to enable connectors at the organization level before anyone can authenticate.
Cowork Stopped Being a Desktop Thing
On the same day, Anthropic opened Claude Cowork to all paid accounts on web and mobile. Cowork is the agentic mode: you hand Claude a goal, it runs a multi-step task across connected apps, files, and the browser until the job is done. source The rollout began in July with Max subscribers. On August 18 it reached Pro, Max, and Team plans on claude.ai and the iOS and Android apps, with Enterprise as an opt-in for admins. source
The important shift is where the work runs. On web and mobile, Cowork sessions run in Anthropic's cloud, not on your machine. Your sessions and files live with your account and follow you across devices. Start a task on your phone, close your laptop, and the task keeps running; check in or redirect from anywhere. Features like scheduled tasks, connectors, and project sync work on every surface. source
Desktop still has more: live artifacts, local file access, browser and computer use. The web and mobile versions are in beta, and Anthropic's own docs still describe the rollout to Pro with the words "as it rolls out." Know that before you expect the full desktop experience from your browser. source
What This Means for Plan Economics
Claude Cowork is included on every paid plan. There is no separate Cowork subscription. That makes the $20 Pro plan the cheapest way to get a cloud agent with write access to your Google workspace.
| Plan | Monthly | What you get |
|---|---|---|
| Pro | $20 | Cowork on web, mobile, desktop; Gmail and Drive write connectors |
| Max 5x | $100 | 5x Pro usage, same agent features |
| Max 20x | $200 | 20x Pro usage for all-day multi-task operators |
| Team Standard | $25/seat ($20 annual) | Cowork, admin-controlled approvals |
| Enterprise | by quote | Cowork with admin opt-in, compliance controls |
One honest caveat. Cowork is agentic, and agentic work burns usage far faster than chat. Practitioners who run Cowork daily report it consuming five to twenty times a chat session's allowance per unit of work, which is exactly how a $20 plan quietly becomes a $100 decision once the agent becomes part of your day. source Budget for the ceiling you will actually hit, not the entry price.
Who Should Care
The upgrade is most relevant to three kinds of people. Solo founders and freelancers who live in Gmail and Drive and want a second pair of hands on administrative work get the full feature set for $20. Teams that have been nervous about unsupervised AI actions get the governance layer first: owners decide whether members can skip per-action approval, and they can disable connectors organization-wide. The skeptical crowd, everyone who read the "sends emails without your approval" headline and flinched, should know the default is the opposite of what they feared.
Read the permission settings before you connect a sensitive account. Approve the first few writes yourself, and watch how the citations hold up. Claude did not become your office assistant because it can send mail. It became one because it can send mail and stop and ask you first. That restraint is the part worth paying for.
Continue exploring
More decisions worth reading
Follow the thread from this article to the next practical buying question.
Buying advice
01The Rise of AI Agents: A 2026 Guide to the Best Autonomous Tools
Open guideBuying advice
02Google's Legal AI Bet Is Really a Governance Bet
Open guideBuying advice
03Keenable Wants to Rebuild Web Search for AI Agents
Open guideBuying advice
04