Gemini can now read and write into your CRM from Gmail — who in your SMB decided that?
On September 18, 2026, Google announced that Gemini in Workspace connects directly, via the Model Context Protocol (MCP), to seven business tools — Asana, Atlassian Rovo, HubSpot, Intuit Mailchimp, Intuit QuickBooks, Monday and Salesforce — from Gmail, Docs, Sheets, Drive and Chat. Activation is per-connector, set by an admin at the organizational-unit level, not per employee. What that means for an SMB running its CRM or accounting through one of these tools.
On September 18, 2026, Google announced on the official Google Workspace Updates blog that Gemini in Workspace can now connect directly, through the Model Context Protocol (MCP), to seven third-party business tools: Asana, Atlassian Rovo, HubSpot, Intuit Mailchimp, Intuit QuickBooks, Monday and Salesforce. In practice, an employee can now look up or update a HubSpot contact, check a QuickBooks invoice, or create an Asana task straight from the Gemini side panel in Gmail, Docs, Sheets, Drive or Chat — no tab-switching required.
What actually changes in your Workspace
- →Each connector is turned on individually, by an administrator, in the admin console (Apps > Google Workspace > Gemini for Workspace > Third-Party Connectors), at the level of an organizational unit or a group.
- →Once a connector is enabled, every employee in that scope can use it from the Gemini panel in Docs, Sheets, Slides and Chat — activation is not granted person by person by default.
- →Google states that data is not reviewed by humans or used to train its models outside your domain without permission, and points to indirect prompt-injection defenses plus granular DLP (data loss prevention) controls.
- →For a custom MCP server outside the seven official connectors, Google explicitly warns that it does not control, monitor or secure that third-party server — trust rests entirely on the company that installs it.
What the research says
The MCP protocol itself is still proving its robustness. A 2026 study by Xiaofan Li and Xing Gao (University of Delaware), accepted at IEEE/IFIP DSN 2026, A First Look at the Security Issues in the Model Context Protocol Ecosystem, analyzed 67,057 MCP servers across six public registries. It found that weak vetting and ownership checks at the registry level let adversarial or hijacked servers reach hosts, and that once integrated, falsified tool metadata can steer a model’s reasoning toward unintended actions without independent verification. Google’s seven connectors are ones it vetted itself — but the same MCP architecture is open to any custom server, with the exposure this study documents.
On the governance side, a 2026 study by Julia Ballerini, Marco Pino, Martin Kuděj and Alberto Ferraris, published in the International Journal of Entrepreneurial Behavior & Research, Too much of a good thing? Entrepreneurial orientation and the non-linear governance effects of SaaS platforms, surveyed 180 UK and US entrepreneurs and a secondary dataset of 238 European start-ups. It found that the relationship between how intensively a company uses interconnected SaaS platforms and its strategic alignment follows an inverted U: past a certain integration threshold, each additional connector erodes governance coherence rather than improving it, unless matched by investment in oversight. Turning on seven connectors at once, without a prior plan, is close to the exact scenario the study warns against.
What it changes for your SMB
If your company runs Google Workspace alongside HubSpot, Salesforce, Mailchimp or QuickBooks — a common setup among French SMBs on a cloud CRM — this update is not a technical curiosity. It opens a new channel through which customer data moves between systems, and the first checkpoint is administrative, not technical.
- →Ask your Workspace administrator which of the seven connectors are already enabled, and for which organizational unit — default activation can expose an entire scope of employees, not just the sales team that actually uses HubSpot or Salesforce.
- →Enable only the connectors tied to an identified need: an Asana connector open to the whole company when only the project team uses it is unnecessary access to remove.
- →Treat any custom MCP server outside the seven official connectors with the same suspicion as an unknown browser extension asking for full CRM access — Google says so itself: it does not secure it.
- →Update your GDPR record of processing activities: Gemini reading and writing customer data in HubSpot or Salesforce is a new data flow to document, distinct from the Gemini/Workspace processing already declared.
- →This is exactly the kind of aggregation — CRM, accounting, inbox — that a custom-built reporting agent or operations watchdog agent already handles with access rules defined case by case; Google’s version turns on in one click for an entire scope, which shifts the responsibility from design upfront to control after the fact.
The convenience on offer is real: no more switching tabs to update a customer record or create a task. But group-level activation, by organization or by unit rather than by person, means one checkbox ticked too quickly by a busy administrator can hand an entire CRM to employees who never needed it. Before enabling a single connector, take inventory of who actually needs to talk to which tool — the list of seven available connectors says nothing about who, in your SMB, should really be using them.
Frequently asked questions
My company doesn’t use HubSpot, Salesforce or the other listed tools — am I affected?+
Not directly by this specific update, but the mechanism is worth watching: Google keeps adding official connectors over time, and a custom MCP server already lets you connect any internal tool — with the risks that implies if no one vets the connection.
Who can turn a connector on or off in my company?+
Only a Google Workspace administrator, from the admin console — it is not a setting an individual employee can enable from their own account.
Free resource
The self-assessment grid: 20 tasks AI can automate
Sales, admin, support, operations: the 20 tasks AI agents already handle in SMEs — with, for each one, the tell-tale sign that your team is concerned.
Read next
Business & compliance
The EU Cyber Resilience Act’s vulnerability-reporting duty is now live — and it may already apply to your software
13 September 2026·5 min read
Business & compliance
CNIL fines Extia €300,000 over botched erasure requests: what it changes for any SMB that recruits
10 September 2026·4 min read
Business & compliance
CNIL fines a hospital €500,000 for no MFA, no VPN: the RGPD security checklist that applies to your SMB too
4 September 2026·5 min read