Google Gemini Agent: Coworker Agents With Their Own Email

TL;DR
Google's new Gemini agent can spin up coworker agents with their own Workspace account, email address and audit trail. What Google announced, what it left out, and what builders should copy.
Last updated: October 8, 2026 - written the day of the announcement from Google's own post and press coverage. Google had not published pricing or an availability date when this went up.
The Google Gemini agent announced at Gemini at Work 2026 is a single "universal agent for work" that can also create coworker agents: persistent, role-based agents that get their own Workspace account, an email address, a calendar, a Drive and an entry in the company directory. Google Cloud announced it on October 8. The headline feature is the email address. The more useful part for anyone building agents is the governance model that comes with it.
What Google actually announced#
The primary documents are Google's short announcement and Thomas Kurian's longer keynote post. Stripped of customer logos, the claims are:
- One agent, many surfaces. Gemini answers questions, does knowledge work, generates media and writes and runs code through a single agent and a single API, reachable from web, mobile, desktop, a command line, Workspace, Microsoft 365 and Slack.
- Persistent execution. It runs in the cloud with one set of memory and context, and Google says work that takes hours or days keeps running after you close your laptop. The post names four memory types: session, semantic, procedural and episodic.
- Sub-agents and coworker agents. Gemini can create temporary job-specific sub-agents, each with its own identity. A coworker agent is the persistent version: a defined role, "@agents.company.com" email, its own storage, and access only to the context you or your team give it.
- Tools and skills registries. It connects to systems like Jira, Git, Salesforce, BigQuery and Postgres, and to any MCP server inside or outside your network. Teams can publish tools and skills to a shared company registry.
- Model choice. Google says the agent runs each job on the model that fits, across Gemini models and Anthropic's Claude today, with other models planned.
The governance model is the real product#
Google frames enterprise agents as four questions: who is the agent, what may it do, what did it do, and what must it never touch. Its answers, per the keynote post:
- Identity: each agent gets a cryptographically attested identity, governed like an employee and stamped into its logs and into any virtual machine it starts.
- Permissions: role-based access approved by security administrators, with identity mapped through standards such as OAuth when the agent calls an external system.
- Audit: every action is written to an audit trail attributed to the agent rather than a person.
- Policy: agents run in an Agent Sandbox with its own network boundary, and an "Agent Gateway" acts as an AI network firewall for all traffic in, out and between agents. You write a policy once and it applies to every agent.
- Cost: real-time spend caps per project that pause the agent when hit, plus smart routing across models. The Cloud Billing hard limits themselves were announced in August, according to VentureBeat, so only the agent hookup is new.
This is the same shape the agent identity argument has been making: verifiable identity, scoped capability, audit trail. Google is the first large vendor to ship it as a default rather than a roadmap slide.
The angle: identity moves from the human to the agent#
My read, and it is analysis rather than something Google states: the interesting shift is attribution. Most agents today act as you, with your tokens and your permissions, and the log says you did it. A coworker agent acts as itself and sees only what is shared with it. That fixes the oldest problem in agent security, which is that an agent inheriting a human's whole permission set is a confused deputy waiting to happen.
It also changes who is accountable. When the audit trail names the agent, the question "who answers for this" lands on whoever created and scoped that agent, which is why OpenAI's Dots and Anthropic's Claude Tag are both fighting over the same ground: the persistent, team-visible agent. VentureBeat lists Microsoft Copilot's Autopilot, OpenAI's Dots and SpaceXAI's Grok Bot as direct competitors, and notes Anthropic is taking the opposite route by embedding Claude inside Docs, Sheets and Slides. Google's distinct bet is the multi-model one: the agent layer, memory and skills stay put while the model underneath swaps, and Claude is a first-class option.
What a builder does Monday#
You cannot use this yet - Google gave no availability date - but you can copy the pattern in the agents you run today:
- Give every long-running agent its own credentials. A separate service account or API key per agent, not your personal token. Revocation then means deleting one thing.
- Log the agent as the actor. Write the agent identifier into every tool-call log line, not the human who started it.
- Scope by sharing, not by inheritance. Hand the agent specific folders, repos or channels. Google's own phrasing is that access "follows the sharing and membership your team already uses".
- Put a spend cap and a pause behavior in front of anything that loops. Decide in advance whether a capped agent stops or degrades.
- Run through the checklist before connecting tools. The agent security checklist covers read, write, call, log and rollback, and zero-touch MCP OAuth shows how enterprise auth is converging for the MCP side.
What Google did not say#
- No price for the Gemini agent, and no statement whether it is included in existing Gemini Enterprise subscriptions, per VentureBeat.
- No general availability date or rollout schedule, and no independent benchmarks for long, cross-application tasks.
- No account of how an administrator revokes an agent. The Next Web points out that the post explains how permissions are granted, identity mapped and spending capped, but not how you take access away.
- Not every Gemini agent instance is described as having its own Workspace account. VentureBeat reads the dedicated account as one configuration, not a requirement.
What people are actually saying#
I could not find a Hacker News or Reddit discussion of substance within hours of the announcement; the main thread I found is an r/Bard post that reposts Google's own blurb. Treat the reaction below as press and analyst commentary, not a community census.
- The enthusiastic reading is breadth: VentureBeat frames it as Google turning a set of assistants into one platform that takes whole assignments.
- The regulatory reading comes from TNW: hours earlier the UK Information Commissioner's Office had said ten AI developers made data protection changes and opened a call for evidence on agent risks, due November 20. Agent autonomy "is not an excuse for poor compliance", its director of technology regulation said, per TNW.
- The counter-case is Google's track record in agentic work. In a Hacker News thread on Gemini 3.1 Pro from earlier this year, several developers argued Gemini models were strong at reasoning but unreliable in agent loops and tool use. That is an old thread about an older model, so it is context rather than a verdict on this launch.
Sources#
- Google Cloud: Gemini agent announcement (October 8, 2026)
- Google Cloud blog: Welcome to Gemini at Work 2026 (October 8, 2026)
- VentureBeat: Google Cloud unveils persistent Gemini Agents
- The Next Web: Google launches workplace AI agent that gets its own email address
- r/Bard thread (title and search excerpt only)
- Hacker News: Gemini 3.1 Pro
Continue Reading#
- Agent Identity Is the Missing Security Layer for AI Workflows - the identity, scope, revocation and audit argument Google just productized
- OpenAI Dots: Always-On Agents Need a Control Plane - the competing persistent-agent launch and where its approvals sit
- Anthropic Claude Tag Turns Slack Into a Shared Agent Workspace - the shared-agent-in-a-team-channel approach from Anthropic
- The Agent Security Checklist I Use Before Connecting Tools - read, write, call, log and rollback before an agent gets access
- MCP Zero-Touch OAuth for Enterprise Auth - how enterprise authorization for MCP servers is converging
Get the next deep dive like this in your inbox
One email a week on News and the rest of the AI dev stack. Free.
Read next on AI coding tools
Agent Identity Is the Missing Security Layer for AI Workflows
The Linux Foundation's Agent Name Service proposal points at a real gap in AI agent infrastructure: agents need verifiable identity, scoped capabilities, revocation, and audit trails before they can safely act across tools.
7 min readOpenAI Dots: Always-On Agents Need a Control Plane
OpenAI Dots turns ChatGPT into a long-running work agent. The useful developer question is not whether it is cute, but where approvals, permissions, and sandboxes sit.
7 min readAnthropic Claude Tag Turns Slack Into a Shared Agent Workspace
Claude Tag is Anthropic's new Slack-based beta for Team and Enterprise users. The important shift is not chat convenience - it is shared agent identity, channel context, and team-visible work.
8 min readNew here? Start with
Technical content at the intersection of AI and development. Building with AI agents, Claude Code, and modern dev tools - then showing you exactly how it works.







