The paste is the leak
Company data pasted into any AI tool leaves no trace in any log. Workspace policy sees that Gemini is on for an account, not what went into it.
Gemini is grounded in Gmail and Drive for every Workspace user, Gemini Enterprise adds agents that act on Salesforce, Jira and ServiceNow, and Gemini CLI runs on developer laptops. BrowserShield stops company data at the paste. The gateway decides every agent action that reaches your systems. AgenShield governs the CLI on the device.

Gemini does not need a connector to reach Workspace data. It is grounded in it by default. Enterprise adds the rest of the company, and the CLI adds the laptop.
Workspace and Gemini Enterprise controls are the right controls to keep. They govern access to the product, not what a person pastes, what an agent does to your systems, or what the CLI does on a device.
Company data pasted into any AI tool leaves no trace in any log. Workspace policy sees that Gemini is on for an account, not what went into it.
An agent built in Gemini Enterprise by a team runs on connected data with actions attached. Nothing says who is accountable when it writes to a system.
It runs on standing credentials that already reach your repos and cloud projects. Nothing on the machine says whether the person or the agent chose the action.
You can see that Gemini was used. You cannot show an auditor which pastes were stopped, which agent actions were judged, against which policy, and what was decided.
The gateway decides. Shield enforces where the gateway cannot see. For Gemini that is BrowserShield at the paste, the gateway on Enterprise agents, and AgenShield on Gemini CLI.
For Gemini in the browser the leak is the paste, so BrowserShield does the work. Gemini CLI runs in the terminal, so AgenShield governs it on the device like any other coding agent.
Out-of-policy actions like touching production secrets or mass-deleting files are stopped before they execute. Everything else flows. Ships through your MDM.
Keys and sensitive data are recognised as they are pasted into AI tools, and the paste is blocked. Employees keep their tools. Only the leak stops.
Illustrative verdicts under a typical policy. Paste rows are BrowserShield. Agent rows are the gateway. CLI rows are AgenShield.
| Gemini action | Verdict | Why |
|---|---|---|
| Ask a question with no company data in the prompt | allow | Nothing sensitive in the paste. The tool in use is recorded, the person keeps working. |
| Paste an API key or access token into a prompt | deny | Recognised at the paste and blocked before it leaves the tab. The person sees why. |
| Use a personal Gemini account with company data | deny | Outside the governed Workspace. Blocked at the paste, the person is pointed to the company account. |
| Enterprise agent reads Salesforce records through the gateway | mask | The read runs. Personal data is masked at the gateway before it enters the model context. |
| Enterprise agent creates a ServiceNow change request | human-in-the-loop | A write on a live system. The agent's owner approves before it lands. |
| Enterprise agent calls an internal API outside its grant | deny | Outside scope. Blocked at the gateway and logged against the agent and owner. |
| Gemini CLI edits files inside the working tree | allow | In scope for the developer and the task. Logged, not interrupted. |
| Gemini CLI reads cloud credentials on a developer laptop | deny | A credential has no place in an agent's context. Stopped on the device, before execution. |
Verdicts are illustrative defaults. Every row is a policy you write once and Agen enforces per action, per identity.
Thirty minutes on the way your teams already use Gemini. We show the verdict on each action, the named human behind the session, and the record it leaves. Bring your hardest question.
An analyst pastes a spreadsheet block into Gemini to ask a question. BrowserShield recognises customer records in the paste and blocks it. The rest of the session continues.
Your admin settings, data regions and connectors stay exactly as they are.
The same three capabilities govern Gemini and every other agent you run, internal and external.
Continuous discovery across your IdP, gateway, devices, cloud, and registries. Nothing has to self-register: agents are found, risk-scored, and resolved to a named human before they act.
Company data stopped at the paste, Enterprise agents decided at the gateway, Gemini CLI governed on the device.