Product1 publisher3 min readPublished
Claude Can Now Press Send In Gmail, And Your Workspace Admin Owns That Decision
Anthropic has removed the per-message approval step from Claude's Gmail connector on paid plans. Approval stays on by default, but Team and Enterprise admins decide who may switch it off.
The Product Desk · Product desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Anthropic has expanded Claude's Gmail integration so the AI can reply to, send and forward emails on a user's behalf without requiring approval every time.
- The capability builds on an existing Claude connector for Google Workspace that already allowed users to work with Gmail, Google Calendar and Google Drive; sending an email was the notable missing piece.
- Anthropic says approval remains the default.
- Users can choose whether Claude needs confirmation before sending emails.
- Team and Enterprise administrators can determine whether members are allowed to let these send actions happen without repeated approval.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
Anthropic has expanded Claude's Gmail integration so the assistant can reply to, send and forward messages on a user's behalf without stopping for approval on each one [1]. The consequential detail is not the drafting, which the connector already did, but where the switch sits: on Team and Enterprise plans, administrators decide whether members are permitted to let these actions run without repeated approval [5].
The capability is an extension of the existing Claude connector for Google Workspace, which already covered Gmail, Google Calendar and Google Drive; sending was the piece that was missing [2]. It is available only on paid Claude plans [6]. Anthropic says approval remains the default, and individual users can choose whether Claude needs confirmation before a message goes out [3][4]. In a managed tenancy, that means unreviewed sending requires two separate deliberate acts: an administrator allowing it and a user turning it on [12].
Digital Trends frames the change as a category shift rather than a feature bump: producing a reply and leaving the decision to a human is one thing, and an agent that can actually press Send is taking action on the user's behalf [7]. The practical asymmetry is the part worth writing into policy. A badly worded draft sitting in the compose window is cheap to fix; a message that has already left the account is not [8]. Digital Trends notes that the approval prompt is the safety valve, and that removing it moves responsibility onto users and, for workplace accounts, onto administrators [9].
Against that, the upside is real and boring, which is usually a good sign. Routine replies, follow-ups and forwarding are exactly the repetitive work an agent can absorb with little human involvement [10].
So the operational question for anyone running a Workspace tenancy is no longer whether the model writes acceptable email. It is which roles, if any, should be allowed to send without a human in the loop, and on what evidence that permission gets granted. The obvious splits are by blast radius rather than seniority: internal threads versus external ones, named recipients versus distribution lists, replies versus forwards. Forwarding deserves separate thought, because it moves existing content, including whatever else is in the thread, to a new recipient [1].
Two things to watch. First, the granularity of the admin control as reported is coarse: Digital Trends describes approval settings varying by account type and administrators deciding whether members are allowed to skip repeated approval, and does not describe per-recipient scoping or logging of what the assistant sent [11][5]. Anyone drafting a policy will want to confirm what is actually visible after the fact before turning the checkpoint off for a team. Second, the default. Approval-on-by-default means nothing changes for organisations that do nothing [3], which makes this a rare case where inaction is a defensible position for a quarter while you watch what the early adopters send by mistake.
The direction of travel is clear enough: assistants that operate inside the services people already use rather than describing what to do in them [7]. Email is a reasonable first test because the failure mode is legible. Someone receives a message you did not read.