You connect your own accounts, so GC AI can only access information you already have permission to see in each connected app. Your existing access controls in that app always apply.
How access works
Agent Connectors are enabled by default at the organization level, not the user level. A connector has three layers:- Enabled by the organization
- Connected by the member
- Tool permissions allowed by the member
What you can do
- Use data in chat: Search email threads, files, calendar, Slack, CRM records, and other connected apps without leaving the conversation
- Take actions: Draft and send replies, schedule meetings, post updates, create tasks, and more, with per-action approval
- Control permissions: Read actions default to Always allow; write and delete actions default to Needs approval. You can set any action to Always allow, Needs approval, or Block
- Connect from chat: When an app is not connected, GC AI can show a connect card that takes you to the right connector in Settings
Manage Agent Connectors (admins)
Enabled means members can connect the connector without an organization admin activating it in GC AI first. Microsoft 365 connectors can still require one-time tenant admin consent. Enabled does not mean an account is connected or GC AI can access data. Organization admins manage connector access in Settings → Policies → Connector policies. Admins may also set custom rules for specific members.
USPTO uses Enabled instead of Full access because it has no write tools.
Admins can review which members connected each app from the connector policy page.
Agent Connectors and Document Storage use separate policies
Document Storage and Agent Connectors use separate access controls, although they may share the same account connection. Document Storage syncs and indexes external files as persistent Contract Intelligence sources. Agent Connectors access data through the connector and can take actions in chat. Both preserve the connector’s user permissions and require individual authorization.New Agent Connectors
Admins can turn off Enable new integrations by default under Connector policies in Settings → Policies. Agent Connectors added after the toggle is turned off start Disabled for that organization. Existing Agent Connectors keep their current policies. Disabling new connectors does not disable connectors that were already available. Admins must review those connectors individually.This toggle controls new Agent Connectors. It does not control Document Storage for Contract Intelligence.
Connect an app
- Open Settings → Integrations → Agent Connectors.
- Select Connect on the app you want.
- Review the pre-connect summary (what the connector does and which tools it exposes).
- Complete that provider’s sign-in flow.
Connecting an account does not expand the member’s access in the connector app. GC AI can access only the data and actions available to that member there.
Connect a connector
Some connectors need setup in the provider before you authorize them in GC AI. See the per-connector setup guides:Use connected apps in chat
Once an app is connected, ask GC AI in plain language. Examples:- “Find my latest email thread with Acme about the indemnity cap.”
- “List my Gmail labels and show unread counts on INBOX.”
- “Search my Drive for the Q3 board deck.”
- “Summarize the last five messages in my Slack thread with procurement.”
- “What meetings do I have tomorrow that mention the Series B?”
- “Draft a reply to the counterparty’s latest email and ask for their comments on section 4.”
- “Schedule a 30-minute follow-up with Jordan next Tuesday.”
- “Post to #legal that the MSA redline is ready for review.”
- “Summarize HubSpot activity for Acme this week.”
- “Who is the HubSpot company owner for Acme?”
- “Look up Acme in HubSpot and put its lifecycle stage in a field named Counterparty status.”
- “Find the OneNote page with our disclosure committee checklist and summarize the open questions.”
- “Summarize the Jira issues blocking the privacy review.”
- “Show me the latest updates on the Monday.com board for the policy refresh.”
- “Search my Airtable intake base for open NDAs and add a row for the Acme request.”
- “Add a Todoist task to send the signed MSA to procurement by Friday.”
- “Find the Ironclad workflow for Acme’s MSA and summarize its approval status.”
Control what GC AI can do
Tool permissions control what GC AI may do after an account is connected. The organization’s policy sets the maximum access a member may grant. Under each connected app in Settings, expand Tools. A member can change each tool to Always allow, Needs approval, or Block.
When a member selects Needs approval, an approval card appears in chat with Approve, Always approve, and Deny.
Disconnect or reconnect
- Disconnect any connector in Settings → Integrations to revoke access immediately.
- If a connector shows Reconnect required, authorization expired or was invalidated by the provider. Select Reconnect and sign in again.