> ## Documentation Index
> Fetch the complete documentation index at: https://docs.gc.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect Google Workspace

> Allow GC AI in the Google Admin console when Google blocks Google Drive, Gmail, or another Google connection

Google Drive, Gmail, Google Docs, Google Sheets, and Google Calendar connect through GC AI's Google apps. Each person connects their own Google account, and GC AI acts with that person's existing Google access.

Most organizations need no setup. Some Google security settings block third-party apps until a Google Workspace admin allows them. When that happens, Google shows the error in its own sign-in window and does not send it back to GC AI. GC AI cannot see the reason or work around it, so an admin needs to allow GC AI in the Google Admin console.

## When you need this

Ask your Google Workspace admin to allow GC AI if Google shows one of these errors when you connect or reconnect:

| Error | What it means |
| - | - |
| `Error 400: policy_enforced` | Your account is enrolled in Google's Advanced Protection Program. Advanced Protection blocks most non-Google apps from Google Drive and Gmail data unless your admin trusts the app. |
| `Error 400: admin_policy_enforced` | Your organization limits which third-party apps can reach Google data, and GC AI is not on the allowed list yet. |

A working connection can also stop when an account joins Advanced Protection. Google ends GC AI's access, and Contract Intelligence sources from that Google Drive stop syncing. Reconnecting shows the same error until your admin trusts GC AI.

## Trust GC AI (Google Workspace admins)

You need a Google Workspace admin account with the Service Settings privilege.

<Steps>
  <Step title="Open API controls">
    Sign in to the [Google Admin console](https://admin.google.com) and go to **Security → Access and data control → API controls**. Select **Manage Third-Party App Access** (some consoles label it **Manage App Access**).
  </Step>

  <Step title="Find GC AI">
    Under **Configured apps**, select **Add app → OAuth App Name or Client ID** (or **Configure new app**). Search for the client ID from the table below, then select the GC AI app and its client ID.
  </Step>

  <Step title="Choose who it applies to">
    If Google asks for a scope, pick the organizational units or groups that include the people who were blocked. Trusting GC AI for a different unit leaves them blocked.
  </Step>

  <Step title="Trust the app">
    Choose **Trusted**, then confirm with **Configure** (or **Continue**, then **Finish**). Repeat for the other client ID if your team uses both.
  </Step>
</Steps>

If your Admin console looks different, follow Google's guide to [control which apps access Google Workspace data](https://support.google.com/a/answer/7281227) and trust the client IDs below.

| GC AI app | Client ID |
| - | - |
| Google Drive, including Contract Intelligence sources | `286966249634-dm830kp6hagsosn38gggb8b70uukvmpu.apps.googleusercontent.com` |
| Gmail, Google Docs, Google Sheets, and Google Calendar | `286966249634-rknjbju52su2e0t2g97nq3r26hkr26g5.apps.googleusercontent.com` |

Trusted lets GC AI ask for access to Google Drive, Gmail, Google Docs, Google Sheets, and Google Calendar. It does not grant access on its own. Each person still signs in and approves GC AI for their own account, and GC AI reaches only what that person can already open.

## Connect again

After your admin trusts GC AI, connect your Google account again:

* **Contract Intelligence:** open the Vault and go to **Document Sources**. Select **Reconnect** on the Google Drive source, or **Add source** if Google blocked your first connection. Syncing resumes once the source reconnects.
* **Agent Connectors:** open **Settings → Integrations → Agent Connectors** and select **Connect** on the Google app, or **Reconnect** if it is already listed as connected.
* **Document Storage:** open **Settings → Integrations → Document Storage** and select **Connect** on Google Drive, or **Reconnect** on the account that stopped working.

## Personal Google accounts

A personal Google account in Advanced Protection has no admin, and Google offers no way to allow a single app for it. To bring those documents into Contract Intelligence, upload them to the Vault directly.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.