An assistant that reads a customer inquiry is useful. One that changes the customer's CRM record is operational. One that sends a price under your company's name has made a business commitment.

Those are three different levels of authority. Recent announcements from Google and Microsoft are pushing the boundary closer to everyday work.

Sources checked October 9, 2026. Product availability below reflects the cited announcements; confirm your account’s eligibility and controls before enabling access.

What changed

Google Cloud announced a universal Gemini work agent on October 8, 2026, describing a system that can use skills and tools across enterprise applications. Google emphasizes agent identity, permission controls, audit trails, and spending limits. This is a vendor announcement, not an independent reliability result.

Google Cloud: Introducing the Gemini agent (October 8, 2026)

Google Workspace announced integrations with tools including HubSpot, QuickBooks, Salesforce, Asana, and Mailchimp on September 15. Google marked the rollout available to eligible editions and says admins can disable third-party connectors. Its September 30 correction updated the admin path. Connecting a service does not automatically authorize every action.

Google Workspace: Third-party integrations (September 15; corrected September 30, 2026)

Microsoft's September 25 Copilot announcement described Home, Code, and Autopilot, an agent meant to work while its user is away. Home and Code were announced for gradual Frontier rollout, with Autopilot to enter private preview. A preview is not general availability.

Microsoft: Home, Code, and Autopilot (September 25, 2026)

The permission decision

Treat access as four separate boundaries: read a record, draft a response, stage a change for review, and commit an action that changes the world outside the assistant. These boundaries should not carry the same approval policy. A wrong draft is easier to correct than a mistaken customer quote or invoice change.

First decide whether this job needs AI using our AI vs. automation guide, then review which data the tool may receive.

The Agent Action Contract

Copy these fields before enabling any business connector:

  • Job: What single outcome is in scope?
  • Source of truth: Which approved record resolves conflicts?
  • May read: Which inboxes, folders, and fields?
  • May draft: Which messages, notes, and summaries?
  • May stage: Which proposed changes require review?
  • May commit without approval: List exact actions, or write 'none.'
  • Never touch: Which records, financial changes, deletions, or exports?
  • Escalation: When must a person decide?
  • Evidence: Where are sources, approvals, and actions logged?
  • Recovery: Who can undo mistakes?
  • Stop rule: Which error pauses the pilot?

Make the contract enforceable

A prompt asking the AI to be careful is not an enforceable permission policy. Match these boundaries to the connector’s actual permissions and approval controls. If it cannot restrict an action, keep that connection out of the pilot.

A worked example

Illustrative, not a real customer case or first-hand test. A contractor wants to save time on incoming inquiries. Start with synthetic emails and sample CRM records. Permit the assistant to read, draft replies, and propose CRM notes. Keep all sends and record edits behind human approval. Block quoting prices, promising dates, merging contacts, and touching invoices.

Prepare 20 synthetic cases, including missing information, duplicate names, complaints, and discount requests. Log whether the tool selected the right record, asked for missing facts, and respected forbidden actions. These are a test plan, not claimed test results. If quality is adequate, evaluate a narrow approved pilot including correction and review time.

Example stop rule

For this contractor test, any unapproved send or record edit stops the pilot. The owner disconnects the tool, checks the action log, and corrects affected records before retesting. Passing 20 synthetic cases is a screening step, not proof of reliability on live customer work.

Act, watch, wait

Act: Audit workspace connectors, turn off unnecessary connections, select one low-risk workflow, and complete the Action Contract before testing with approved non-sensitive data.

Watch: Verify plan eligibility, real connector capabilities, approval gates, audit logs, spending controls, and recoverability. Calculate time saved after review and mistakes.

Wait: Avoid autonomous refunds, payments, bulk emails, deletions, and sensitive exports without documented safeguards and a real business need.

The skeptical case

Rules-based automation may still be more reliable and economical for deterministic work. Agent access does not eliminate hallucinations, misleading source content, or privacy risks. Announcements are not evidence that every account can perform every action. This article distinguishes vendor statements from editorial inference and does not claim hands-on product tests.

See our guides: AI vs. automation, data handling, and evaluating pilots.

The connection

Perhaps enterprise agents take longer to reach small businesses than today's demos imply. That is a fair skeptical forecast. But access to mail, calendars, and customer records already matters. The competitive advantage is not the flashiest assistant; it is knowing what it may read, propose, change, and never touch.