AI agent · Gemini Enterprise

Gemini Enterprise, with every gated call waiting for you.

Gemini Enterprise, Google's assistant for businesses, reaches your services only through PrivacyFence, which reviews reads before release and holds changes for your approval. It works with organization mode only: PrivacyFence run by your organization, reachable over public HTTPS. On your own computer, use Claude Desktop, Claude Code or ChatGPT desktop instead.

Limits

Know the limits before you set it up.

  • Organization mode only. Gemini Enterprise calls PrivacyFence from Google's servers, and a PrivacyFence on your own computer listens on localhost only.
  • An administrator registers it first. Unlike claude.ai and ChatGPT, Gemini Enterprise does not register itself: an administrator registers it through /register, then creates the data store in the Google Cloud console.
  • Each person signs in once. Everyone who uses it, the administrator included, authorises it once from the Gemini Enterprise web app.
  • At most 100 actions per data store. PrivacyFence can list more (the test deployment listed 109), so the administrator chooses which tools to enable. A tool that is not enabled is invisible to Gemini Enterprise.
  • It can't upload files. Gemini Enterprise has no file to send to an upload link, and a download larger than about 75 KB comes back as a link you open in your browser.

How it connects

From Google's servers, as a custom MCP server.

Why an organization deployment

Gemini Enterprise calls MCP servers from Google's servers, not from your computer. A PrivacyFence on your own computer listens on localhost only, on purpose, so Gemini Enterprise cannot reach it. An organization deployment is reachable over public HTTPS, with a certificate from a publicly trusted certificate authority.

Registered once by an administrator

Gemini Enterprise does not register itself. An administrator registers it once with PrivacyFence's /register endpoint, then adds a custom MCP server data store in the Google Cloud console with OAuth and PKCE. Each person then signs in once from the Gemini Enterprise web app.

Set it up

Register it, add the data store, then authorise.

Local mode

Not available: Gemini Enterprise cannot reach a PrivacyFence on your own computer. Use Claude Desktop on macOS or Windows, Claude Code on macOS, Windows or Linux, or ChatGPT desktop on macOS.

Organization mode

  1. In the Google Cloud project, allow custom MCP servers and enable the Discovery Engine, Connectors and Secret Manager APIs.
  2. Register Gemini Enterprise with the deployment's /register endpoint, under the name Gemini Enterprise.
  3. Create a Custom MCP Server data store with the URL https://pf.example.com/mcp, OAuth 2.0 and PKCE, and connect it to your app.
  4. Each person clicks Authorise on the PrivacyFence row in the web app's chat bar and signs in with their organization account.
  5. Enable the actions to offer, and connect your services at https://pf.example.com/connect.

Set it up Organization deployment

Confirmations

Gemini shows its steps. PrivacyFence's card decides.

PrivacyFence tells Gemini Enterprise truthfully what each tool does: reads are read-only, writes are writes, and the two tools that delete something are marked destructive. Before a tool call, Gemini Enterprise shows its own steps, ending in Action Confirmed.

A gated call still waits for PrivacyFence's approval card at /approvals, whatever Gemini was told or allowed. Gemini Enterprise does not wait for it: it posts the approval link in the chat and asks you to say when you have approved. Approve the card, tell Gemini, and it makes the call again.

Files

Small files inline, larger ones through a link you open.

Gemini Enterprise cannot move file bytes itself. A download of up to about 75 KB comes back in the tool result. A larger one becomes a short-lived, one-time link, which Gemini shows you to open in your browser. Uploads, such as a new Drive file or an email attachment, are not possible from Gemini Enterprise. Files has the sizes and lifetimes.

To read a document, no download is needed: PrivacyFence returns a PDF, Word, PowerPoint or Excel file from Drive as text.

How it's identified

A name is a claim until an administrator pins it.

Gemini Enterprise's calls carry the name it was registered with, Gemini Enterprise, so the approval card says Says it is Gemini Enterprise, marked Not verified, because any program that can reach the deployment can register under the same name. An administrator can pin the registration on Settings → AI systems, and the cards for it are then verified.

Which AI system is asking

Client settings worth knowing

Choose up to 100 actions.

  • At most 100 actions. Gemini Enterprise enables at most 100 actions per data store, and PrivacyFence can list more when many services are connected. A tool that is not enabled is invisible to Gemini, so leave out the ones people rarely ask for.
  • Authorise from the web app. Every person, the administrator included, authorises once from the web app's chat bar. Signing in from the console alone does not let Gemini make tool calls.
  • Signing in again. A sign-in lasts 30 days; after that, click Authorise again.

Next

Other clients, and what they can reach.

Compare the AI clients PrivacyFence is tested with, or see what each connector lets them read and change.