Google's new coworker agents each get a Workspace account with a mailbox, calendar, Drive and a directory listing, and Google has not said what one costs or who owns it.
That makes the Gemini agent, announced at Gemini at Work 2026 on October 8, an identity and licensing decision before it is a purchase. If you run Google Workspace or Gemini Enterprise, the questions to settle now are who sponsors each agent account, what it is allowed to see, and what happens to its work when a spend cap pauses it.
What Google Actually Announced
Google announced one agent that chats, works on its own and writes code, plus "coworker agents" that hold a standing role and their own Workspace identity. In the launch post adapted from Thomas Kurian's keynote, Google calls the Gemini agent "your new single, universal agent for work" and says you give it "objectives, not instructions." It runs in the cloud, so work that takes "hours or days keeps running after you close your laptop," and it can spin up "temporary, job-specific agents, each with their own identity."
A coworker agent is a persistent agent with a defined role that lives in your directory like an employee. Per the same post, it "receives its own Workspace account, including an email address, calendar, Drive, and presence in your company directory," with addresses in the form @agents.company.com. You create one by describing the role. Colleagues add it to a Chat space, @mention it, or tag it in a Doc comment, where it suggests edits and shows up "under its own name in version history."
Google says the agent orchestrates "across our Gemini family of models and Claude models from Anthropic today," with other private and open models promised later. It also works in Microsoft 365 and Slack, and connects to Salesforce, ServiceNow, Jira, Snowflake, Databricks and any MCP server, so a coworker agent's reach can extend well past your Google tenant.
Google's Gemini Enterprise Agent Platform supplied the identity, registry and gateway layers back in April, which we covered in Google's three-layer agent stack. This launch puts those layers into Workspace accounts that colleagues can email.
What Google Did Not Publish
Google published no price, no plan list and no general availability date for the agent or for coworker agents. VentureBeat's launch report says Google has not announced a separate price for the universal agent or said whether every capability will be included in existing Gemini Enterprise subscriptions, and gave no GA date. The same report says Google has not explained "how provisioning and licensing will work," or whether admins can switch off parts of an agent's Workspace presence. AI Weekly's summary says nothing about seat fees or how agent accounts are counted as users.
The only availability labels in Google's own post sit on the industry packs: Financial Services and Legal are "now in preview," while Government, Healthcare and Retail are "coming soon." Do not read those labels as the status of the agent itself.
The licensing gap is the costly one, because a Workspace account is normally a billed seat. Google's admin help on adding a user account says that on a Flexible Plan, "adding user accounts automatically increases your monthly payment," that Annual Plan customers may need to buy licenses first, and that Business editions cap out at 300 users. Google has not said whether a coworker agent's account follows those rules. If it does, a team that creates 40 agents on a Business edition has spent 40 of its 300 slots. If it doesn't, you need to know what bills instead.
How Microsoft Already Answers the Same Questions
Microsoft has published the sponsorship and licensing rules that Google has not. That gives you a checklist to take to your Google account team, whatever you think of either stack.
An agent's user account in Entra Agent ID is a separate user subtype tied to a parent agent identity. Microsoft's agent user account documentation says it is optional, created explicitly, mapped one-to-one to its agent identity, cannot hold a password or passkey, and cannot be assigned privileged admin roles. For a mailbox and Teams presence, Microsoft says to create the agent through Teams; an account made directly through the Graph API gets no Microsoft 365 capabilities.
Sponsorship is mandatory. Microsoft's owners, sponsors and managers page says "at least one sponsor is required for each agent identity and agent identity blueprint," that sponsors decide on "renewal, extension, or removal," and that sponsorship "should be maintained to ensure succession when an employee who's a sponsor moves or leaves."
Licensing is per person, not per agent. Microsoft's Agent 365 licensing FAQ lists Agent 365 at $15 per user per month standalone and inside Microsoft 365 E7 at $99, says "agents do not require their own licenses," and requires the owner, sponsor or manager of an agent to hold the license. Our Agent 365 pricing breakdown and the Okta vs Entra Agent ID vs SailPoint comparison cover what that buys.
Microsoft's rules are written down and Google's are not yet. Until Google publishes its own, every coworker agent your teams create is an account whose owner, seat cost and offboarding path you are guessing at.
What the Governance Story Covers and Where It Stops
Google's governance claims are strong on paper and stop short of the questions an identity team asks first. The launch post says "every agent gets its own identity, cryptographically attested and governed like an employee, with least-privilege permissions," that "every action Gemini takes is written to an audit trail and attributed to the agent rather than to a person," and that agents run in an Agent Sandbox with traffic passing through Agent Gateway. A coworker agent "sees only what you share with it."
The case for Google's design is real. Attributing actions to the agent instead of the human who launched it fixes the main weakness of shared service accounts, which we flagged when @ChatGPT in Slack and Teams gave unlicensed staff a shared account. Share-based access also means the agent cannot inherit a manager's full Drive.
What the post leaves open:
- Who is accountable. Nothing says an agent must name a human sponsor, or what happens to the account when its creator leaves. Our piece on the Gems to Skills migration showed what happens when only an item's creator can act on it.
- What the audit trail retains. An agent's own audit log is not the decision record a regulator asks for. Our agent audit logging guide lists the events to demand.
- Whose terms apply when work routes to Claude. Google's own Claude on Google Cloud documentation states that "Anthropic models are not a Google product" and that their availability falls under separate terms. If Smart Routing sends a coworker agent's task to Claude, your legal team should know which terms cover that prompt.
What a Spend Cap Pause Means for a Running Agent
Spend caps stop the bill but also stop the agent, which matters when work runs for days. Google's post says you set real-time caps in the Cloud Billing Console, Gemini tracks token and sandbox costs per project, and when a cap trips "that project's agent pauses," resuming "with a single click in the console."
Those controls predate the launch. IT Brief's August 27 report describes email alerts at 50%, 80% and 100% of budget, agent API calls pausing at the cap, and admins either resuming by hand or letting overages run at pay-as-you-go rates. The same report lists Flexible Savings Plan discounts of 10% for one year and 20% for three, with pay-as-you-go limited to select customers at the time.
Per-project caps make chargeback straightforward. They also mean one runaway job can pause every agent in that project, including a coworker agent halfway through a multi-day close or a customer thread. Google has not said what a paused coworker agent's mailbox does with incoming mail. Ask before you put one on a shared inbox.
What to Do Before You Turn It On
This Week:
- Ask your Google account team four questions in writing: does a coworker agent consume a Workspace license, does it count toward the 300-user Business cap, which Gemini Enterprise editions include the agent, and when does it reach GA.
- Check whether your Admin console lets you restrict who can create agent accounts, and default it to a named pilot group until you have the answers.
This Month:
- Write a one-page agent account policy: every coworker agent names a human sponsor and a backup, joins only named Chat spaces and shared drives, and is reviewed at the sponsor's departure, mirroring Microsoft's documented sponsor rules.
- Put each pilot agent in its own Cloud project with its own spend cap, so one runaway job pauses one agent, and set the 50% alert to page the sponsor.
- Ask Google's account team, also in writing, which data processing terms apply when Smart Routing sends a task to Claude.
Before Renewal:
- If you also run Microsoft 365, compare the two models side by side: Agent 365 licenses the sponsor at $15 per user per month with no per-agent fee; get Google's equivalent number before either renewal, and read our note on Copilot billing Autopilot outside the $30 seat first.
The Bottom Line
Google has given its agent the trappings of an employee: a directory entry, a mailbox and a name in version history. Service accounts followed a similar path. They were cheap to create, often had no clear owner, and left identity teams cleaning up orphans long after the project ended. Coworker agents start with the same profile and add a mailbox and a model bill on top.
Get Google's licensing answer in writing before the first team creates an agent account.
Continue Reading
- Agent Identity, Registry, Gateway: Google's 3-Layer Agent Stack
- Okta vs Entra Agent ID vs SailPoint: Two Issue, One Governs
- Microsoft Agent 365 Pricing: $15 Standalone vs $99 E7 Bundle
- Claude for Google Workspace Skips Your Retention and ZDR in Beta
- Gemini Gems Become Skills Only Their Creators Can Switch On
- OpenAI's Dots Beta Skips Data Residency and Your OTel Collector
