Claude for Google Workspace Skips Your Retention and ZDR in Beta

Anthropic's Claude add-on for Google Docs, Sheets and Slides deletes data within 30 days regardless of your retention setting, has no ZDR or Bedrock/Vertex routing, and is barred from PHI in beta. Allowlist it for a pilot group.

By Rajesh Beri·October 7, 2026·10 min read
Share:
A laptop on an office desk showing a spreadsheet with a narrow assistant sidebar open on the right, next to a paper records-retention binder with a 30-day calendar page clipped to its cover.

Illustration generated using AI

If your Claude organization uses custom retention, Zero Data Retention, or Bedrock or Vertex AI routing, the new Claude add-on for Google Docs, Sheets and Slides follows none of them during its beta. Anthropic's own support article says inputs and outputs are deleted within 30 days, that custom organizational retention is not inherited, that ZDR is unavailable, that third-party inference is unsupported, and that HIPAA-ready organizations should not use it with protected health information. The right move for a Workspace admin is an allowlist for a named pilot group with the default "Ask before edits" mode left on, not an org-wide install.

The add-on itself is useful. The question for a CIO is whether it belongs inside the same compliance boundary as the rest of your Claude deployment, and in beta it does not.

What Anthropic Shipped on October 6

Claude for Google Workspace is a sidebar add-on that reads and edits the Google file you have open. Anthropic announced it on October 6, 2026 as a public beta on all paid Claude plans, alongside new Docs, Sheets and Slides connectors that let Claude create and edit Google files from a chat.

The feature list is practical. In Docs, Claude fixes a sentence or restyles a heading in place without disturbing the surrounding formatting. In Sheets, it writes formulas, builds pivot tables and native charts, adds tabs, and runs data cleaning through Python. In Slides, it builds new slides from the deck's existing layouts and themes and flags overlapping elements or unreadable text. Anthropic also says the add-on carries the same models, connectors and skills as the user's Claude account, including Salesforce and Google Drive connectors for pulling data in.

The Google Workspace Marketplace listing, last updated October 5, showed 8K+ installs when we checked it on October 7. The listing does not say how many of those installs came through admin deployment.

Independent coverage adds little beyond the announcement. Reworked restated the feature list and the enterprise controls, and AI Coder noted that Anthropic published no quantitative benchmarks for the add-on, so buyers have only the demo to go on.

Which Retention Rules Does the Beta Skip?

The beta skips your organization's custom retention period and replaces it with a fixed deletion window of 30 days. The support article states that "inputs and outputs are deleted from Anthropic's systems within 30 days," and that standard retention applies rather than any custom setting your organization configured.

That cuts in a direction many admins will not expect. On Claude Enterprise, Anthropic's retention documentation says data is retained indefinitely by default, and custom periods have a minimum of 30 days. So an organization that set a one-year or three-year retention period to satisfy a records schedule or e-discovery obligation will find that work done in the Docs sidebar disappears from Anthropic's systems in a month, well short of what its own records schedule requires.

Chat history makes this sharper. According to the same support page, history is stored locally per browser and per file, and does not sync across devices. A conversation that produced a contract redline lives in one employee's browser on one machine.

There is a partial fix for Enterprise customers. The support article says sessions from the Google extension are available through the Compliance API "with prompts, responses, tool calls, and the edits Claude made," and that an organization with a custom OpenTelemetry collector receives the full audit trail from Docs, Sheets and Slides sessions. If you need records past 30 days, you have to pull them out yourself before the window closes. Team plans do not get the Compliance API, which leaves them without a durable record of what the add-on did.

We have seen this pattern before. When Anthropic shipped Claude for Government, the only copy of each chat also sat on the user's machine, and agencies with records obligations had to build their own capture.

Who Should Not Turn It On Yet

Three kinds of organization should keep the add-on off until general availability changes the terms, because the support page excludes them outright.

ZDR customers. Zero Data Retention is unavailable in the beta. If your legal team negotiated ZDR, a Docs sidebar that keeps prompts and outputs for up to 30 days is outside that agreement. Our earlier piece on how ZDR was never fully zero is worth rereading before anyone argues the gap is small.

Organizations that route Claude through a cloud provider. The add-on does not support Amazon Bedrock, Google Vertex AI, Azure or LLM gateways. If you chose Bedrock or Vertex so that Claude traffic stays under your cloud contract, your data residency terms and your gateway logging, the add-on sends that traffic straight to Anthropic instead. Your security review approved one data path, and this is a second one.

HIPAA-covered entities. The support article says HIPAA-ready organizations are not covered and that users should not work with protected health information through the add-on. In a hospital or a payer, a Sheets file with member IDs is exactly the file someone will want Claude to clean.

The strongest case on the other side deserves a hearing. A 30-day deletion window is shorter than what most SaaS tools keep, Anthropic says it does not train on this content, and Enterprise customers can capture every session through the Compliance API. For an organization with no ZDR contract, no cloud-routed Claude and no PHI in Drive, the beta terms may be acceptable today. Each of those conditions has to be true, and someone has to check them.

What Do the Edit Controls Actually Stop?

The edit controls stop Claude from changing a file without a person approving each change, as long as nobody switches the default. The announcement describes two modes: "Ask before edits," the default, shows each change as an approval card, while "Accept all edits" lets Claude apply changes without stopping.

Some actions are held for review in either mode. The support article says Claude stops and asks before it inserts an image from a web address, adds a link, or removes anyone's access, and those prompts carry a "Security review" label with no "always allow" option. Those three are the obvious exfiltration and lockout paths, so the carve-out is sensible.

The scope is also narrower than a chat connector. The sidebar works only on the open file, cannot reach other Drive files, cannot share files or create automations, and stops a single long operation after six minutes. Anthropic says Claude's access matches your existing Google sharing permissions. That means a user who can already edit a sensitive finance model can have Claude edit it too, so the control you rely on is the sharing hygiene you already have.

The Marketplace listing asks for more than the file. It requests access to view and manage documents where the add-on is installed, display third-party web content in sidebars, and read the user's primary email address and personal info. Send that permission list to your security reviewer along with the feature list.

Approval cards also have a known weakness. Our human-in-the-loop buyer's guide found most approval gates turn into rubber stamps once reviewers see enough of them. An analyst who approves 40 formula changes in a row has probably stopped reading them.

Does It Beat the Gemini You Already Pay For?

On compliance, no: Gemini inside Workspace inherits controls that Claude's beta does not. On capability, it depends on your work, and Anthropic has not published numbers to settle it.

The cost comparison starts with what you already own. Google's pricing page lists Gemini in Docs, Sheets and Slides on Business Standard at $14 per user per month and above, though not on Starter. A Claude seat is extra. Claude's pricing page lists a Team standard seat at $25 a month, or $20 a month billed annually, and Enterprise at $20 per seat per month plus usage at API rates. On Enterprise, then, heavy Sheets work in the sidebar shows up as usage, not as a flat fee. If you are already watching Claude Enterprise spend controls, add the add-on to the dashboard.

The compliance comparison is lopsided in beta. Google's privacy hub for generative AI in Workspace says Gemini applies "your organization's existing controls and data handling practices," that admins can manage retention with Vault, and that Gemini can support HIPAA workloads. Claude's add-on does none of those three today.

Claude's case is the work itself: the model your team already prefers, Python-backed cleaning in Sheets, and the same connectors and skills employees use in the Claude app. If your analysts already live in Claude and paste spreadsheets into it, the add-on puts that work inside the file, with an audit trail on Enterprise. That beats copy and paste into a chat window, which is the real alternative in many companies.

The real decision is whether a second assistant in the same document is worth a second data path, and for which users. Our breakdown of the true cost of a Copilot seat applies here: the licence is the floor, and consumption plus governance work is the rest.


What to Do Before Anyone Installs It Org-Wide

This Week:

  1. Open the Google Admin console and check whether users can install Marketplace apps on their own. If they can, Claude may already be in your domain through personal Pro and Max accounts. Pull the list of installed apps.
  2. Ask your Claude account owner three yes/no questions in writing: do we have ZDR, do we route Claude through Bedrock, Vertex or a gateway, and do we hold PHI in Drive. Any yes means the add-on stays off.
  3. If all three are no, allowlist Claude for one Google group or organizational unit, not the whole domain. The support article confirms super admins can scope it to groups or OUs.

This Month:

  1. On Enterprise, confirm your Compliance API export or OpenTelemetry collector is capturing Docs, Sheets and Slides sessions, and that the records land in a store governed by your own retention schedule before the 30-day window expires.
  2. Tell the pilot group in writing to leave "Ask before edits" on. Then sample their approval rates after two weeks; near-100% approval on long batches means nobody is reading the cards.
  3. Run the same five real tasks in Gemini and in Claude on the pilot group's own files, and score the output. Anthropic published no benchmarks, so your test is the only one you will get.

Before General Availability:

  1. Ask Anthropic for dates on ZDR, custom retention inheritance and Bedrock or Vertex support for the add-on. Put the answers in your vendor file so you can check them at launch.
  2. Decide whether a Claude seat on top of Business Standard is justified for the pilot group, based on the task scores and the usage bill.

The Bottom Line

Office-suite AI keeps launching ahead of its controls. Claude's Microsoft 365 write tools raised the same question in July, and Google's own Gems to Skills migration shows the incumbent's assistant also changes under admins. The approach that fits is the one most admins already use for browser extensions: scope the install, capture the logs yourself, and expand when the vendor's terms match yours.

For now, put Claude on an allowlist for one group, keep Gemini as the default for everyone else, and export the Compliance API records before day 30.

Continue Reading

Share:

Frequently Asked Questions

Does Claude for Google Workspace follow my organization's custom data retention settings?

No, not during the beta. Anthropic's support article says inputs and outputs are deleted within 30 days and that custom organizational retention is not inherited. Enterprise customers can capture sessions through the Compliance API or an OpenTelemetry collector if they need to keep records longer.

Is Zero Data Retention available for the Claude add-on in Google Docs, Sheets and Slides?

No. Anthropic lists Zero Data Retention as unsupported in the beta, along with third-party inference through Amazon Bedrock, Google Vertex AI, Azure and LLM gateways.

Can I use Claude for Google Workspace with protected health information?

No. Anthropic says HIPAA-ready organizations are not covered by the beta and that users should not use the add-on with protected health information.

How do Google Workspace admins deploy or restrict the Claude add-on?

Super admins can install Claude for the whole organization, for specific groups or for organizational units from the Google Admin console, or allowlist it so users install it themselves. Removing it in the Admin console takes effect for users at their next file reload.

How much does Claude for Google Workspace cost compared with Gemini?

The add-on needs a paid Claude plan. Claude Team standard seats list at $25 a month or $20 billed annually, and Enterprise at $20 per seat plus usage at API rates. Gemini in Docs, Sheets and Slides is included from Google Workspace Business Standard at $14 per user per month.

Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe

Latest Articles

View All →