Gemini Work Agent Adds Claude and Coworker Accounts
Google’s private-preview enterprise agent promises days-long execution, separate worker identities, and model choice, putting governance and spending controls at the center of adoption.
Listen
AI narration
12:01
0:00 / 12:01
AI SummaryGenerated from this article
Google announced a new Gemini work agent for enterprise customers in private preview that executes tasks for days after employees log off, operates as a coworker with its own email address and storage, and routes work to Anthropic's Claude or Google's models. The platform emphasizes governance through dedicated agent identities, role-based permissions, audit trails, and spending caps while supporting persistent execution, temporary subagents for parallel work, and connections to Workspace, Microsoft 365, Slack, Salesforce, ServiceNow, and databases including BigQuery and Snowflake.
Enterprise security teams should test permission boundaries, subagent access restrictions, and incident response capabilities before broader deployment, verifying that audit trails cover all agent actions, spending caps take effect promptly, and external connectors preserve access restrictions.
Google’s new Gemini work agent can keep working after an employee closes their laptop, coordinate temporary subagents, and operate as a coworker with its own email address and storage. It can also route work to Anthropic’s Claude rather than relying exclusively on Google’s models.
Announced on October 8, 2026, the platform combines questions, knowledge work, media creation, and code generation and execution through one interface and API, according to Google’s Gemini agent announcement. The ambition is to turn Gemini Enterprise into a place where employees delegate ongoing work, rather than simply request answers.
The availability caveat is substantial: The Verge reports that the universal agent is limited to enterprise customers in private preview. This is not a generally available consumer launch, and the cited announcement and reporting provide neither a general-availability date nor public pricing for the agent.
Gemini Can Keep Working for Days
Google describes persistent cloud execution that preserves memory, context, and personalization across devices and channels. Work can continue for hours or days, whether users access Gemini through a browser, mobile device, desktop, command line, or connected workplace application.
That separates two capabilities often bundled together in agent announcements. Remembering a conversation helps an assistant resume work; persistent execution lets it continue doing the work without an active session. Google says Gemini supports both, alongside scheduled tasks and event-triggered activity.
The agent can also create temporary, job-specific subagents, each with its own identity. These can coordinate parallel and sequential steps in a larger assignment. Google distinguishes these temporary workers from persistent coworker agents, which retain a defined role across sessions and changing responsibilities.
For a business, that architecture potentially allows one delegated objective to span research, document preparation, and code execution without requiring an employee to initiate each step. That is an interpretation of the announced capabilities, not evidence that every such workflow is reliable today.
Persistence also raises the standard for oversight. A task that runs overnight needs clear ownership, observable progress, and defined limits. A successful demonstration of a short task cannot establish the reliability of a days-long process with multiple dependencies.
Coworker Accounts Separate Agent Actions From Human Actions
Work with Zeniteq
Let’s work together
We’re open to thoughtful collaborations with teams building in AI. Explore the ways we can work together.
The coworker identity is one of the announcement’s most consequential details. Google says these agents receive dedicated email addresses, persistent storage, and their own Workspace accounts, including calendars, Drive access, and directory presence.
Employees can interact with them through familiar collaboration mechanisms: sharing material, sending email, mentioning them, or adding them to a group chat. Google says coworker agents see only what users or teams share with them, subject to existing sharing permissions.
A separate account gives administrators something concrete to govern. Instead of treating automated work as an extension of an employee’s identity, the company can assign permissions to the agent and attribute its activity to that agent.
That distinction matters during an investigation. If an agent changes a document or accesses a system, its audit identity should help distinguish the automated action from work performed directly by a person. Google says actions are recorded against the agent rather than the human user.
Dedicated identities do not establish safe behavior by themselves. Buyers still need to understand how permissions change, how credentials are revoked, and how access restrictions propagate through connected services and delegated subagents. Those are operational checks, not details settled merely by giving an agent an email address.
Anthropic’s Claude Can Run Beneath the Gemini Agent
Google is explicitly separating the agent platform from the model doing the reasoning. Gemini is the work agent, but the underlying model can come from either Google’s Gemini family or Anthropic’s Claude.
According to TechCrunch’s launch reporting, the agent selects a model by default, while users can also choose one themselves. Google says additional private and open models are planned for the future. Those future options should not be confused with models available in the preview.
This makes model flexibility a practical platform feature. An enterprise could retain its agent’s context, skills, and integrations while changing which model handles a task. That reduces the need to treat every model decision as a decision about the entire workplace interface.
It does not remove platform dependence. The surrounding memory, orchestration, identity, and tool infrastructure still belongs to Google’s environment.
Google argues that matching models to tasks can improve quality on difficult work and reduce costs on simpler jobs. That remains a vendor claim rather than an independently established result for this agent. Buyers should evaluate the router against their own workloads and determine whether model selection respects their data-handling policies.
The Connector List Extends Well Beyond Workspace
Google’s announced reach includes Workspace, Microsoft 365, Slack, Confluence, Git, Jira, Salesforce, and ServiceNow. Its database connections include BigQuery, Databricks, Postgres, and Snowflake.
The company also says Gemini can work with Model Context Protocol servers inside or outside an organization’s network. MCP provides a way for agents to access tools and context through connected servers. Google additionally describes shared registries where teams can publish tools and reusable skills.
The practical consequence is that Gemini is intended to coordinate work across existing systems, rather than require every workflow to move into Google applications. Its ability to write and execute code broadens that scope further.
However, a connector’s presence does not establish what actions it supports, which permissions it requires, or how reliably it handles errors. Enterprise evaluations should distinguish read-only access from write access and administrative operations. Connecting an agent to a database for analysis is a different risk decision from authorizing changes to business records.
Dots and Muse Set the Context, Not a Proven Ranking
TechCrunch places Google’s announcement alongside the recent debut of ChatGPT’s Dots and consumer-facing agents such as Meta’s Muse. The shared direction is delegation: users assign work instead of conducting only a conversation.
Google’s documented proposition emphasizes enterprise operation. The announcement specifies persistent execution, separate coworker accounts, temporary subagents, cross-vendor model routing, and agent-specific governance. Together, those features describe an organizational platform, not merely a new assistant interface.
The available reporting does not establish a feature-by-feature comparison with Dots or Muse. It would therefore be premature to claim that Gemini has better persistence, stronger security, or superior task completion than either competitor.
For enterprise buyers, the useful comparison is how each product handles authority and accountability. Can administrators assign an agent its own permissions? Can they trace delegated actions, restrict model use, enforce network policies, and contain spending? Google has announced mechanisms addressing those questions. Whether they work as required is what the private preview needs to establish.
Audit Trails and Sandboxes Need to Survive Real Workflows
Google’s agent security architecture describes unique agent identities, administrator-approved role-based permissions, and identity mapping to external systems through standards such as OAuth.
It also describes an Agent Sandbox with its own network boundary. Traffic entering and leaving agents, including communication between agents, passes through an Agent Gateway that enforces organizational policies in real time. Google says audit trails record agent actions and that its observability tools can monitor those logs.
These are relevant controls for software that can execute code, communicate with colleagues, and act across multiple services. Their value depends on coverage: a policy boundary is useful only if the operations that matter actually pass through it.
Before adoption, security teams should test several failure cases:
Whether a subagent can obtain broader permissions than its assigned work requires.
Whether instructions encountered in retrieved content can trigger unauthorized tool use.
Whether external connectors preserve the intended access restrictions.
Whether administrators can reconstruct a task across model calls, tools, and subagents.
Whether an agent’s access can be promptly revoked during an incident.
These are proposed evaluation questions, not reports of discovered vulnerabilities. Sandboxing, permissions, and logging address different risks; none independently proves that a model will interpret every instruction safely.
Spending Controls Matter Before Deployment Expands
Persistent work changes cost exposure. An agent that continues for days, delegates tasks, and writes and runs code creates more opportunities for resource consumption than a single prompt-response exchange.
Google announces multi-model orchestration, Smart Routing, and real-time spend caps as ways to control enterprise AI costs. Those mechanisms deserve attention, but the cited materials do not provide enough public pricing detail to calculate the cost of a representative universal-agent workflow.
Procurement teams should verify what a cap covers, how quickly it takes effect, and what happens to active work when the budget is exhausted. They should also establish whether spending visibility includes subagents, model usage, and any separately billed infrastructure or connected services. These are contract and configuration questions, not capabilities to assume from the phrase “spend caps.”
The same caution applies to customer evidence. Google says sportswear brand On tested the new dynamic model-selection capability. Its discussion of Shopify and PayPal describes broader multi-model strategies, not proof that every announced universal-agent feature has been validated at their scale.
The strongest adoption case is therefore a bounded private-preview evaluation: one measurable workflow, limited permissions, explicit model policies, visible audit records, and a defined budget. Google’s competitive move is to bring delegation and enterprise administration into the same platform. The preview’s value will depend on whether those controls remain effective when the agent keeps working without someone watching every step.