Agentic Engineering
Claude Can Now Send Your Email. Log the Approvals
Anthropic gave Claude send-and-delete rights in Gmail and Drive with approval on by default — and made the approval log your only audit trail.
Anthropic gave Claude the ability to send, reply to, and forward Gmail and to share, move, and trash Google Drive files, with per-action approval on by default and organization owners deciding who may waive it. The company’s Google Workspace connector documentation is explicit that Claude “can send, reply to, and forward emails from Gmail, and asks for your approval by default before each of these actions.” The same day, Anthropic said Claude Cowork reached mobile and web across all paid plans and extended its 50% Claude Code weekly-limit boost through August 31 — 12 days past the August 19 expiry.
The write bit is the news. Read access to a mailbox leaks information; write access takes actions with your name on them, and it does so from a session that may now be running on a phone with no laptop open. Anthropic shipped write tools for the Microsoft 365 connector on July 7, covering draft, send, calendar, OneDrive, and SharePoint. Gmail and Drive followed 42 days later. Both suites now let a model act on the corpus where your company keeps its commitments.
The approval log is the only artifact that survives
Default-on approval is the right default and a weak control. It depends on a human reading a modal that appears dozens of times a day, and Anthropic’s own documentation notes that on Team and Enterprise plans owners may let members skip per-action confirmation. The moment approval fatigue meets a waiver setting, the guarantee reverts to whatever the connector logs.
That matters because the failure mode is already documented in the neighboring product. Microsoft this week patched CoSnitch, a critical Copilot flaw that Varonis says chained automatic prompt execution, exfiltration through connected apps, and persistent memory poisoning. Varonis reported the hole on December 31 and Microsoft completed the fix on August 18 — 231 days, with a partial mitigation landing February 1 along the way. Varonis’s technical write-up of the disclosure describes exactly the surface Claude now inherits: an assistant with OAuth reach into Gmail, Drive, and Calendar, and a natural-language channel that treats fetched content as instruction-bearing.
Anthropic’s own product documentation concedes the mechanism. Its guidance on code execution and file creation warns that “a bad actor” can “inconspicuously add instructions via external files or websites” and that Claude “can be tricked into sending information from its context (for example, prompts, projects, data via MCP, Google integrations) to malicious third parties.” That is the vendor telling you the control is behavioral, not architectural. The 231-day Copilot number is the operator’s real planning input: when a connector flaw is found in a suite this large, the window between disclosure and complete remediation is measured in quarters.
What to change this week
The upgrade is worth taking, and the conditions are cheap. Turn write actions on for a named pilot group rather than the whole tenant, keep per-action approval mandatory for that group, and require that every approved send and every Drive deletion lands in an exportable log you can reconcile against Gmail’s own sent folder. If your organization cannot produce that reconciliation, you have adopted an agent that acts under your identity without an audit trail — the same gap the paper found when Claude Code’s auto mode needed hard denies rather than soft prompts.
Write the denial list before the allow list. Approval interfaces optimize for the yes; the actions worth blocking outright are the ones no reviewer can undo — permanent deletion, forwarding outside the company domain, and sharing a Drive file with a link anyone can open. Those three belong in a policy that never presents a modal at all, because a control that can be clicked through under deadline pressure is a suggestion. Everything else can safely live behind per-action confirmation.
Scope the blast radius before scope creep does it for you. Drive write access includes trashing files; Gmail write access includes forwarding, which is the single most efficient exfiltration primitive in an enterprise. Restrict the connector to accounts without broad shared-drive rights, and confirm at the Google Workspace admin layer which application is actually trusted, since Anthropic’s documentation notes admins may need to allow Claude explicitly before connectors function at all.
Then price it honestly. The Cowork expansion to mobile and web means sessions run remotely and continue when the laptop closes, which is genuinely useful and removes the ambient supervision most teams were unconsciously relying on. Pair it with the extended Claude Code weekly limits and the practical result is more autonomous agent-minutes per seat this month than last, with the same number of humans watching. That is a throughput gain and a governance debt in the same release.
The verdict: enable it, gate it, and log it. The evidence that would change this call is a published connector audit log with per-action provenance and retention that admins can export — at which point approval stops being a modal and starts being a record. Until then, treat every write-enabled connector as a service account with your face on it. The same discipline governs the layer beneath: as today’s lead on Stripe’s $7.5 billion purchase of the model gateway argues, controls only count when the log shows what actually ran.
Sources
- Anthropic — Google Workspace connectors, including Gmail send and default approval
- Anthropic — Claude apps release notes, including July 7 Microsoft 365 write tools
- Anthropic — prompt-injection warning for code execution and Google integrations
- Varonis — CoSnitch disclosure and the connected-app exfiltration pattern
- Computerworld — Microsoft’s 231-day path from CoSnitch report to full patch
- The Verge — Claude Cowork reaching mobile and web alongside the connector upgrade
- Android Authority — the Claude Code weekly-limit extension to August 31