Tools and skills
| Capability | Contents | Authority |
|---|---|---|
| Tools | MCP server actions that read from or write to connected systems | Limited by server, action, parameter, user authorization, and connection policy |
| Skills | Reusable instructions, supporting files, and static flags | Do not grant authority by themselves |
One integration can provide Actions, Knowledge, or both. Those capabilities share the provider connection when possible, while retaining separate access and readiness.
A catalog that keeps up with its sources
Public MCP servers and skills are reconciled from complete upstream snapshots every night. New, changed, deprecated, and removed listings stay visible as catalog state instead of silently aging in place.
Curated integrations also compare releases, available actions, documentation, and endpoint health with the last reviewed version. A source change is evidence for review; it never publishes a curated capability or expands company access by itself.
Approve actions
The catalog is the home for each tool. Enable it, connect a provider account when required, and open Manage to choose actions and parameters. Runtime access combines that configuration with current server state, user authorization, and connection policy.
- Approve all actions or a selected set.
- Limit which parameters an approved action can receive.
- Require human approval for a requested action when policy calls for it.
- Remove access on the next request when membership, catalog, consent, or approval changes.
Default-deny behavior
Missing policy never grants access. A model-only connection receives no MCP servers. A tool connection receives only the effective servers, actions, and parameters in its policy.
Connect user accounts
The workspace controls connector availability and action scope. Each user authorizes a provider account through OAuth; sign-in and consent remain with the provider.
Google Workspace
One company setup makes Gmail, Drive, Docs, Sheets, Slides, Calendar, Chat, and People API available through the same integration. An administrator uses one Google Cloud project and one OAuth web client. Each person then starts one guided connection for only the services that have approved actions.
| Service | What approved actions can help with |
|---|---|
| Gmail | Find conversations and prepare drafts |
| Google Drive | Find, read, copy, and create files |
| Google Docs | Read and update documents |
| Google Sheets | Read and update spreadsheets |
| Google Slides | Read and update presentations |
| Google Calendar | Find, schedule, update, and respond to events |
| Google Chat | Find conversations and send messages |
| People API | Find profiles, contacts, and directory people |
Google currently provides these servers through its Developer Preview Program. The setup guide opens Google Cloud with every required service selected, then walks an administrator through Chat, consent, OAuth, and connection verification.
Set up Google WorkspacePrivate tools and skills
Add a workspace-owned Streamable HTTP server, create a private skill, or import a skill package from a GitHub repository. Releases retain source, version, digest, review state, and publication receipt.