> ## Documentation Index
> Fetch the complete documentation index at: https://conductorone-hunner-patch-1.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect Gemini Enterprise to C1

> Give Gemini Enterprise users access to C1-governed tools, with every tool call attributed to the person who made it.

Google [Gemini Enterprise](https://cloud.google.com/gemini/enterprise) calls the C1 MCP gateway as a tool source. Your users ask Gemini Enterprise a question, Gemini calls a C1 tool on their behalf, and C1 enforces your access policies against that person's identity. Tool calls are attributed to individual users, not to a shared service account.

<Note>
  **Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough.
</Note>

## What you'll do

Setup spans two products, and some stages depend on someone other than you, so line those up before you start. Stages 1 through 6 are for the administrator who connects the MCP server, and end with you confirming the connection works. Stage 7 then gives other people access to use it. The roles each stage needs are in [Required roles](#required-roles).

| Stage | Where | Depends on |
| :- | :- | :- |
| 1. [Prepare Google Cloud](#prepare-google-cloud) | Google Cloud | An **organization** policy administrator |
| 2. [Prepare Gemini Enterprise](#prepare-gemini-enterprise) | Gemini Enterprise | A Gemini Enterprise subscription |
| 3. [Host the client metadata document](#host-the-client-metadata-document) | Google Cloud, command line only | Nothing else |
| 4. [Create the data store](#create-the-data-store) | Gemini Enterprise, console only | Nothing else |
| 5. [Enable the actions](#enable-the-actions) | Gemini Enterprise | Your own C1 tool access |
| 6. [Verify the connection](#verify-the-gemini-enterprise-connection) | Gemini Enterprise and C1 | Nothing else |
| 7. [Give users access](#give-users-access) | Gemini Enterprise and C1 | A C1 administrator to assign access profiles, if that is not you |

Most Google Cloud steps can be done in the console or from the command line. Where both work, the step shows each in its own tab.

## Before you begin

Confirm all of these before you start. The organization policy change in particular can take time to arrange.

* In C1, AI access management is enabled for your tenant, which is a one-time task for a **Super Administrator**. Managing AI clients and assigning toolsets then needs **Super Administrator** or **AI Governance Administrator**. See [Enable AI access management](/product/admin/enable-ai-access-management).
* **You need C1 tool access yourself.** Tool discovery lists only the tools your access profiles allow, and someone with no toolset sees no tools at all. See [Tools and toolsets](/product/admin/tools-and-toolsets). Access for the people who will use the connection comes later, in [Give users access](#give-users-access).
* A Google Cloud project with a Gemini Enterprise app already created. In the console, open **Gemini Enterprise** and select **Create app**, or see Google's [Create a Gemini Enterprise app](https://docs.cloud.google.com/gemini/enterprise/docs/create-app) documentation. To create one from the command line instead, see [Prepare Google Cloud](#prepare-google-cloud).
* A Gemini Enterprise subscription with licenses available to assign. A new app starts with no users licensed.
* Someone who holds `roles/orgpolicy.policyAdmin` at the **organization** level, lined up to change one to three organization policies. Project **Owner** does not include it.
* A project where you may publish one public file. If your organization blocks public sharing, host the client metadata document from a project dedicated to it, because allowing public sharing is a project-wide change. See [Host the client metadata document](#host-the-client-metadata-document).
* **Optional.** The [gcloud CLI](https://cloud.google.com/sdk/docs/install), authenticated with `gcloud auth login`, if you prefer the command line for the Google Cloud steps.

## Collect the values you'll reuse

The steps below reuse these values. Collect the first set now. The rest do not exist yet, and the table says which stage produces each one.

<Callout icon="globe" color="#c937ae" iconType="regular">These examples use `conductor.one`. If your organization is on the EU data residency instance, substitute `c1eu.ai` in URLs, client IDs, and hostnames.</Callout>

| Value | Where to get it | Example |
| :- | :- | :- |
| **Tenant** | The subdomain of your C1 URL. It is also the prefix of your MCP server URL. | `acme` |
| **MCP server URL** | In C1, open your user profile menu and select **AI & API** > **AI connections**. Copy the URL shown at the top of the page. | `https://acme-mcp.conductor.one/v1` |
| **Project ID** | The Google Cloud console project picker, or `gcloud config get-value project`. | `acme-gemini` |
| **Project number** | `gcloud projects describe YOUR_PROJECT_ID --format="value(projectNumber)"`. This is not the same as the project ID, and a few API calls need it. | `514280176422` |
| **Your email** | The Google identity you run these commands as, and the first person to be licensed. | `admin@acme.com` |
| **App location** | At the top of the Gemini Enterprise **Apps** page, next to **Current location**. | `global` |
| **App ID** | The ID of your Gemini Enterprise app, shown on its **Overview** page. Apps created with the command in this guide use `c1-gemini-app`. | `c1-gemini-app` |
| **Bucket name** | A Cloud Storage bucket name you choose. It must be globally unique across all of Cloud Storage. | `acme-c1-oauth-client` |
| **Client ID** | Produced in [Host the client metadata document](#host-the-client-metadata-document). | `https://storage.googleapis.com/acme-c1-oauth-client/gemini-enterprise-oauth-client.json` |
| **Web app URL** | Produced in [Sign in to the web app](#sign-in-to-the-web-app). | `https://vertexaisearch.cloud.google.com/home/cid/<id>` |

<Note>
  The commands in this guide use `global`, which is what most setups run. If your app is in a different location, substitute it everywhere `locations/global` appears.
</Note>

Your OAuth endpoints follow from the tenant. Confirm them against your tenant's published metadata:

```bash theme={null}
curl -s https://<your-tenant>-mcp.conductor.one/.well-known/oauth-authorization-server
```

Read two fields from that response:

| Field in the response | Value for tenant `acme` |
| :- | :- |
| `authorization_endpoint` | `https://acme.conductor.one/auth/v1/authorize` |
| `token_endpoint` | `https://acme.conductor.one/auth/v1/token` |

## Required roles

These are the roles for the administrator who sets up the connection and adds MCP servers. People who only use MCP servers that are already set up need much less. See [Give users access](#give-users-access).

### Roles to prepare the project

You need these once for each Google Cloud project.

| Role | Scope | Why |
| :- | :- | :- |
| `roles/serviceusage.serviceUsageAdmin` | Project | Enable the required APIs |
| `roles/orgpolicy.policyAdmin` | **Organization** | Allow custom MCP data connectors. Project **Owner** is not sufficient. |
| `roles/storage.admin` | Project | Create the bucket that serves the client metadata document, and make it public. Needed only if you host the document yourself. |
| Project **Owner**, or `roles/resourcemanager.projectIamAdmin` | Project | Grant the roles in this guide to yourself and to your users |

### What you need to add MCP servers

You need all of these to create the C1 data store in this guide. The same requirements apply to any MCP server you add to the app later.

| Requirement | Why |
| :- | :- |
| `roles/discoveryengine.admin` on the project | Create data stores and reload and enable their actions. During first setup, it also covers setting the identity provider and assigning licenses. |
| A Gemini Enterprise license, and one sign-in to the web app | Tool discovery runs as you, and it fails for anyone who has never opened the web app. See [Sign in to the web app](#sign-in-to-the-web-app). |
| C1 tool access | Discovery lists only the tools your own access profiles allow. See [Tools and toolsets](/product/admin/tools-and-toolsets). |

`roles/discoveryengine.editor` is **not** enough to add MCP servers. It can read data stores and connectors but cannot create or change them, and every step that adds a server writes to one or the other. Owners hold the missing permissions, so the gap only shows for administrators who are not Owners.

If your organization restricts which hostnames a data connector may reach, each new MCP server's hostname must also be allowed, which needs `roles/orgpolicy.policyAdmin`. See [Allow custom MCP data connectors](#allow-custom-mcp-data-connectors).

### Check and grant roles

To check what you already hold on the project:

```bash theme={null}
gcloud projects get-iam-policy YOUR_PROJECT_ID \
  --flatten="bindings[].members" \
  --filter="bindings.members:user:YOUR_EMAIL" \
  --format="value(bindings.role)"
```

To grant a role in the console, go to **IAM & Admin** > **IAM**, select **Grant access**, enter the email, and choose the role. To grant one from the command line:

```bash theme={null}
gcloud projects add-iam-policy-binding YOUR_PROJECT_ID \
  --member="user:YOUR_EMAIL" \
  --role="roles/discoveryengine.admin"
```

## Prepare Google Cloud

Enable two APIs, then turn off the organization policy that blocks custom MCP data connectors. If you do not have a Gemini Enterprise app yet, you can create one from the command line between the two.

### Enable the Google Cloud APIs

The project needs two APIs. The Cloud Storage API is enabled on new projects by default, so hosting the client metadata document needs no extra API.

| API to enable | Service ID | Why |
| :- | :- | :- |
| Discovery Engine API | `discoveryengine.googleapis.com` | Backs Gemini Enterprise apps, data stores, and tool discovery |
| Organization Policy API | `orgpolicy.googleapis.com` | Required to read or change the policy in [Allow custom MCP data connectors](#allow-custom-mcp-data-connectors) |

Enable both in the console or from the command line.

<Tabs>
  <Tab title="Console">
    <Steps>
      <Step>
        Go to **APIs & Services** > **Library**.
      </Step>

      <Step>
        Search for **Discovery Engine API** and select **Enable**.
      </Step>

      <Step>
        Search for **Organization Policy API** and select **Enable**.
      </Step>
    </Steps>
  </Tab>

  <Tab title="Command line">
    ```bash theme={null}
    gcloud services enable \
      discoveryengine.googleapis.com \
      orgpolicy.googleapis.com \
      --project=YOUR_PROJECT_ID
    ```

    To confirm which APIs are enabled on the project:

    ```bash theme={null}
    gcloud services list --enabled --project=YOUR_PROJECT_ID
    ```
  </Tab>
</Tabs>

Both APIs are now enabled on the project. No other APIs are required: the Connectors, Application Integration, Secret Manager, and IAM APIs are not needed for any step in this guide.

### Optional: Create the app from the command line

Skip this if you already have an app. There is no `gcloud` surface for creating one, so call the API directly:

```bash theme={null}
curl -s -X POST \
  -H "Authorization: Bearer $(gcloud auth print-access-token)" \
  -H "X-Goog-User-Project: YOUR_PROJECT_ID" \
  -H "Content-Type: application/json" \
  "https://discoveryengine.googleapis.com/v1alpha/projects/YOUR_PROJECT_ID/locations/global/collections/default_collection/engines?engineId=c1-gemini-app" \
  -d '{
    "displayName": "c1-gemini-app",
    "solutionType": "SOLUTION_TYPE_SEARCH",
    "industryVertical": "GENERIC",
    "appType": "APP_TYPE_INTRANET",
    "searchEngineConfig": {
      "searchTier": "SEARCH_TIER_ENTERPRISE",
      "searchAddOns": ["SEARCH_ADD_ON_LLM"]
    }
  }'
```

An app created this way has no subscription attached. Add one under **Manage users** in the console before you assign licenses.

### Allow custom MCP data connectors

Google Cloud blocks custom MCP data connectors by default through the `constraints/discoveryengine.managed.disableCustomMcpServerConnector` organization policy. Turn it off for this project before you create the data store. The override applies at the project level, but the person applying it needs `roles/orgpolicy.policyAdmin`, which project **Owner** does not include.

If the policy is enforced, creating the data store fails at the final step with:

```text theme={null}
Operation denied by org policy on resource '...':
["constraints/discoveryengine.managed.disableCustomMcpServerConnector":
"This constraint, when enforced, restricts the creation of data connectors
that use a custom MCP server as their data source."]
```

Check whether it is enforced on your project:

```bash theme={null}
gcloud org-policies describe \
  discoveryengine.managed.disableCustomMcpServerConnector \
  --project=YOUR_PROJECT_ID --effective
```

Turn it off in the console or from the command line.

<Tabs>
  <Tab title="Console">
    <Steps>
      <Step>
        In the Google Cloud console, go to **IAM & Admin** > **Organization policies**.
      </Step>

      <Step>
        Filter for `discoveryengine.managed.disableCustomMcpServerConnector` and open it.
      </Step>

      <Step>
        Select **Manage policy**.
      </Step>

      <Step>
        Select **Override parent's policy**, then set the enforcement to **Off**.
      </Step>

      <Step>
        Select **Set policy**.
      </Step>
    </Steps>
  </Tab>

  <Tab title="Command line">
    Save this as `policy.yaml`:

    ```yaml theme={null}
    name: projects/YOUR_PROJECT_ID/policies/discoveryengine.managed.disableCustomMcpServerConnector
    spec:
      rules:
        - enforce: false
    ```

    Then apply it:

    ```bash theme={null}
    gcloud org-policies set-policy policy.yaml
    ```
  </Tab>
</Tabs>

Re-run the `describe` command above. The effective policy reports `enforce: false`, and your project can create custom MCP data connectors.

<Note>
  Organization policy changes take a minute or two to take effect. Until then the console returns the same denial message, so a failure immediately after you apply the policy does not mean the policy is wrong.
</Note>

<Accordion title="If your organization restricts outbound hostnames">
  Some organizations enforce `constraints/discoveryengine.managed.allowedEgressFqdns`, which limits the hosts a data connector may reach. It applies only to projects with VPC Service Controls enabled, or to projects your organization has added to the constraint's enforced list, so most setups never meet it. Check it with:

  ```bash theme={null}
  gcloud org-policies describe discoveryengine.managed.allowedEgressFqdns \
    --project=YOUR_PROJECT_ID --effective
  ```

  If the constraint has never been set, this command returns `NOT_FOUND: Requested entity was not found`. That is the healthy answer and means nothing is restricting egress.

  If it does apply, allow the two hostnames your tenant uses. Use hostnames only, not full URLs. This is a boolean constraint that takes parameters, not a list of allowed values. Save this as `egress.yaml` and apply it with `gcloud org-policies set-policy egress.yaml`, keeping any hostnames your organization already allows:

  ```yaml theme={null}
  name: projects/YOUR_PROJECT_ID/policies/discoveryengine.managed.allowedEgressFqdns
  spec:
    rules:
      - enforce: true
        parameters:
          allowedEgressFqdns:
            - <your-tenant>-mcp.conductor.one
            - <your-tenant>.conductor.one
  ```

  On the EU data residency instance, allow `<your-tenant>-mcp.c1eu.ai` and `<your-tenant>.c1eu.ai` instead.
</Accordion>

## Prepare Gemini Enterprise

Set the identity provider, license yourself, and sign in to the web app once, in that order. The data store form cannot be submitted without an identity provider, and tool discovery fails later for anyone who is unlicensed or has never opened the web app.

### Set the identity provider

Gemini Enterprise needs an identity provider selected for the location your app runs in. Until one is set, creating a data connector fails with **You must configure your access control settings before you continue**.

<Warning>
  Set this before you create any data store. Google's own warning on this screen is that changing the identity provider later stops access-controlled data stores working, and that you must delete and recreate every one of them to update their permissions.
</Warning>

Set it in the console or from the command line.

<Tabs>
  <Tab title="Console">
    <Steps>
      <Step>
        In the Google Cloud console, open **Gemini Enterprise**.
      </Step>

      <Step>
        Select **Settings**, then the **Authentication** tab.
      </Step>

      <Step>
        Find the row for your app's location, such as `global`, and select the edit icon.
      </Step>

      <Step>
        Choose **Google Identity** if your users sign in with Google Workspace or Cloud Identity accounts, or **3rd Party Identity** if you federate through a workforce identity pool.
      </Step>

      <Step>
        Select **Save**.
      </Step>
    </Steps>

    The row for your location now names the provider instead of reading **Identity provider is not set up**.

    This page reports **You don't have permissions to fetch Workforce Pools** unless you hold a role that can read workforce pools at the organization level. The message is harmless if you are choosing **Google Identity**, which does not use them.
  </Tab>

  <Tab title="Command line">
    For Google accounts:

    ```bash theme={null}
    curl -s -X PATCH \
      -H "Authorization: Bearer $(gcloud auth print-access-token)" \
      -H "X-Goog-User-Project: YOUR_PROJECT_ID" \
      -H "Content-Type: application/json" \
      "https://discoveryengine.googleapis.com/v1alpha/projects/YOUR_PROJECT_ID/locations/global/aclConfig" \
      -d '{
        "name": "projects/YOUR_PROJECT_ID/locations/global/aclConfig",
        "idpConfig": { "idpType": "GSUITE" }
      }'
    ```

    The response echoes `"idpType": "GSUITE"` once it is set.
  </Tab>
</Tabs>

### Assign Gemini Enterprise licenses

A new Gemini Enterprise app has a subscription but no licensed users, and the users list reads **No existing users**. Assign a license to yourself now, because you need one to finish setup. Licenses for the people who will use the connection come later, in [Give users access](#give-users-access).

<Tabs>
  <Tab title="Console">
    <Steps>
      <Step>
        Open **Gemini Enterprise**.
      </Step>

      <Step>
        Select **Manage users**.
      </Step>

      <Step>
        Confirm a subscription is listed and **Active**, and note how many licenses are unassigned.
      </Step>

      <Step>
        Select **Add users**.
      </Step>

      <Step>
        Enter your email address, choose the subscription, and select **Submit**.
      </Step>
    </Steps>
  </Tab>

  <Tab title="Command line">
    List the subscriptions available to assign:

    ```bash theme={null}
    curl -s -H "Authorization: Bearer $(gcloud auth print-access-token)" \
      -H "X-Goog-User-Project: YOUR_PROJECT_ID" \
      "https://discoveryengine.googleapis.com/v1alpha/projects/YOUR_PROJECT_ID/locations/global/licenseConfigs"
    ```

    Each returned `name` ends in the subscription ID, such as `free_trial_gemini` for a trial or a generated ID for a purchased subscription. Use one whose `state` is `ACTIVE`. Expired subscriptions stay in this list and cannot be removed.

    Then assign it, using your project **number** inside `licenseConfig`:

    ```bash theme={null}
    curl -s -X POST \
      -H "Authorization: Bearer $(gcloud auth print-access-token)" \
      -H "X-Goog-User-Project: YOUR_PROJECT_ID" \
      -H "Content-Type: application/json" \
      "https://discoveryengine.googleapis.com/v1alpha/projects/YOUR_PROJECT_ID/locations/global/userStores/default_user_store:batchUpdateUserLicenses" \
      -d '{
        "inlineSource": {
          "userLicenses": [
            {
              "userPrincipal": "YOUR_EMAIL",
              "licenseConfig": "projects/YOUR_PROJECT_NUMBER/locations/global/licenseConfigs/YOUR_SUBSCRIPTION_ID"
            }
          ]
        }
      }'
    ```
  </Tab>
</Tabs>

Your address now appears in the users list with a license and an assignment date.

<Accordion title="If no active subscription is listed after you bought licenses">
  Licenses are distributed to a project **and a location**, and the app can use only licenses in its own location. A purchase can place them in a different location, such as `us`, from an app in `global`. To see where they went, list your billing account's subscriptions and read `licenseConfigDistributions`:

  ```bash theme={null}
  curl -s -H "Authorization: Bearer $(gcloud auth print-access-token)" \
    -H "X-Goog-User-Project: YOUR_PROJECT_ID" \
    "https://discoveryengine.googleapis.com/v1alpha/billingAccounts/YOUR_BILLING_ACCOUNT_ID/billingAccountLicenseConfigs"
  ```

  Each key names a project number and location, and its value is how many licenses are there. If the licenses are not in your app's location, redistribute them to it in the console.
</Accordion>

### Sign in to the web app

Open the Gemini Enterprise web app once, as yourself. Tool discovery runs as the signed-in user, and it fails for anyone who has never opened the web app, with only a generic **Failed to reload custom actions** to show for it. Signing in through **Verify Auth** when you create the data store does not count, because that authorizes the connector, not the web app.

Get the web app URL in the console or from the command line.

<Tabs>
  <Tab title="Console">
    <Steps>
      <Step>
        In the Google Cloud console, open **Gemini Enterprise**.
      </Step>

      <Step>
        Select your app, then open **Overview**.
      </Step>

      <Step>
        Copy the web app URL shown there. It looks like `https://vertexaisearch.cloud.google.com/home/cid/<id>`, where `<id>` is a generated identifier.
      </Step>
    </Steps>
  </Tab>

  <Tab title="Command line">
    Read the `configId` from the app's web app configuration. Substitute your app ID, which is `c1-gemini-app` if you created the app with the command in [Prepare Google Cloud](#prepare-google-cloud):

    ```bash theme={null}
    curl -s -H "Authorization: Bearer $(gcloud auth print-access-token)" \
      -H "X-Goog-User-Project: YOUR_PROJECT_ID" \
      "https://discoveryengine.googleapis.com/v1alpha/projects/YOUR_PROJECT_ID/locations/global/collections/default_collection/engines/YOUR_APP_ID/widgetConfigs/default_search_widget_config" \
      | grep configId
    ```

    The web app URL is `https://vertexaisearch.cloud.google.com/home/cid/` followed by that value.
  </Tab>
</Tabs>

<Note>
  Copy the URL rather than building it from your app's name. A URL such as `https://vertexaisearch.cloud.google.com/home/cid/c1-gemini-app` loads a **400** page that reads **You are not assigned an active license**, even for users who hold one. The error points at licensing, but the cause is the URL.
</Note>

Open the URL and select **Get started** on the welcome panel. One sign-in by one licensed user unblocks tool discovery for the whole connector.

To confirm the sign-in registered, check that `lastLoginTime` is present:

```bash theme={null}
curl -s -H "Authorization: Bearer $(gcloud auth print-access-token)" \
  -H "X-Goog-User-Project: YOUR_PROJECT_ID" \
  "https://discoveryengine.googleapis.com/v1alpha/projects/YOUR_PROJECT_ID/locations/global/userStores/default_user_store/userLicenses"
```

A user with a license but no `lastLoginTime` has never opened the web app, and tool discovery will fail for them.

## Host the client metadata document

Gemini Enterprise signs each user in to C1 with OAuth, so it needs a client ID. For C1, a client ID is a URL. It points at a small public JSON file that describes the client, called a *Client ID Metadata Document*, and C1 fetches it to identify the client. Neither Google nor C1 hosts one for Gemini Enterprise yet, so you host it. For why, see [Frequently asked questions about connecting Gemini Enterprise](#frequently-asked-questions-about-connecting-gemini-enterprise).

This stage is command line only. The document must be reachable without authentication, and a public Cloud Storage bucket works.

<Steps>
  <Step>
    Create a bucket, using the bucket name you chose in [Collect the values you'll reuse](#collect-the-values-youll-reuse):

    ```bash theme={null}
    gcloud storage buckets create gs://YOUR_BUCKET \
      --project=YOUR_PROJECT_ID \
      --location=us-central1 \
      --uniform-bucket-level-access
    ```
  </Step>

  <Step>
    Save this JSON as `gemini-enterprise-oauth-client.json`, replacing `YOUR_BUCKET` with your bucket name. Two fields are unforgiving: `client_id` must exactly equal the URL the file is served from, and `redirect_uris` must contain Google's redirect endpoint verbatim.

    ```json theme={null}
    {
      "client_id": "https://storage.googleapis.com/YOUR_BUCKET/gemini-enterprise-oauth-client.json",
      "client_name": "Gemini Enterprise",
      "client_uri": "https://cloud.google.com/gemini/enterprise",
      "redirect_uris": ["https://vertexaisearch.cloud.google.com/oauth-redirect"],
      "grant_types": ["authorization_code", "refresh_token"],
      "response_types": ["code"],
      "token_endpoint_auth_method": "none"
    }
    ```
  </Step>

  <Step>
    Upload it:

    ```bash theme={null}
    gcloud storage cp gemini-enterprise-oauth-client.json gs://YOUR_BUCKET/
    ```
  </Step>

  <Step>
    Make it publicly readable. Two organization policies can block this binding. If it fails, see **If an organization policy blocks the public binding** below.

    ```bash theme={null}
    gcloud storage buckets add-iam-policy-binding gs://YOUR_BUCKET \
      --member=allUsers \
      --role=roles/storage.objectViewer
    ```
  </Step>

  <Step>
    Confirm the document resolves. It returns the JSON you saved, and its `client_id` matches the URL you requested:

    ```bash theme={null}
    curl -s https://storage.googleapis.com/YOUR_BUCKET/gemini-enterprise-oauth-client.json
    ```
  </Step>
</Steps>

That URL is your client ID. The client has no secret, so nothing expires and nothing needs rotating.

<Accordion title="If an organization policy blocks the public binding">
  The two constraints below are separate from the constraint in [Allow custom MCP data connectors](#allow-custom-mcp-data-connectors), and both need `roles/orgpolicy.policyAdmin`. To change either in the console, use the same **IAM & Admin** > **Organization policies** flow described there, searching for the constraint name below instead.

  **Domain restricted sharing.** If `constraints/iam.allowedPolicyMemberDomains` is enforced, granting `allUsers` fails with:

  ```text theme={null}
  HTTPError 412: One or more users named in the policy do not belong to a permitted customer.
  ```

  The constraint does not accept `allUsers` as an allowed value, so the override has to permit all values. Save this as `drs.yaml` and apply it with `gcloud org-policies set-policy drs.yaml`:

  ```yaml theme={null}
  name: projects/YOUR_PROJECT_ID/policies/iam.allowedPolicyMemberDomains
  spec:
    rules:
      - allowAll: true
  ```

  <Warning>
    This override is project-wide, not bucket-scoped. Any resource in the project can then be shared publicly. Publish the document from a project dedicated to it rather than one holding other data, and remove the override as soon as you stop hosting the document.
  </Warning>

  **Public access prevention.** If `constraints/storage.publicAccessPrevention` is enforced, the binding is refused regardless of the constraint above. Save this as `pap.yaml` and apply it with `gcloud org-policies set-policy pap.yaml`:

  ```yaml theme={null}
  name: projects/YOUR_PROJECT_ID/policies/storage.publicAccessPrevention
  spec:
    rules:
      - enforce: false
  ```

  Check the effective value of either constraint with:

  ```bash theme={null}
  gcloud org-policies describe storage.publicAccessPrevention \
    --project=YOUR_PROJECT_ID --effective
  ```

  Organization policy changes take a minute or two to take effect, in both directions. After you apply the override, the binding can still fail with the same `412` for a short while, and `describe --effective` may report the new value before enforcement catches up. Retry the binding rather than assuming the override is wrong, and confirm success by fetching the document URL.
</Accordion>

## Create the data store

Connect the C1 MCP gateway to your Gemini Enterprise app. This is the one step that only works in the console. See [Frequently asked questions about connecting Gemini Enterprise](#frequently-asked-questions-about-connecting-gemini-enterprise) for why.

Before you open the form, check these. Each one, if missed, fails the form or the steps after it:

* [Prepare Gemini Enterprise](#prepare-gemini-enterprise) is finished. If you leave the form partway through to set the identity provider, you return to a partially reset form and it is easy to submit it incomplete.
* Your client ID URL resolves, as in [Host the client metadata document](#host-the-client-metadata-document), and you have your tenant's OAuth endpoints from [Collect the values you'll reuse](#collect-the-values-youll-reuse).
* You use the **Custom MCP Server** card, not a server imported from Agent Registry. A connector created from a registry import fails tool discovery with `Failed to reload custom actions` and a `FAILED_PRECONDITION` error.

<Warning>
  The data connector name generates an ID that cannot be changed later. Choose it before you begin, and keep it short and lowercase with hyphens, such as `c1-mcp-gateway`.
</Warning>

Create the data store in the console.

<Steps>
  <Step>
    In the Google Cloud console, open **Gemini Enterprise**.
  </Step>

  <Step>
    Select your app.
  </Step>

  <Step>
    Select **Connected data stores**, then select **New data store**.
  </Step>

  <Step>
    In **Select a data source**, search for `Custom MCP`.
  </Step>

  <Step>
    On the **Custom MCP Server** card, select **Add MCP server**.
  </Step>

  <Step>
    Under **Authentication settings**, choose **OAuth 2.0**.
  </Step>

  <Step>
    Complete the fields. Use the domain that matches your C1 tenant: `conductor.one` on the default instance, or `c1eu.ai` on the EU data residency instance. The third column is where this form most often goes wrong.

    | Field | Value | Watch out for |
    | :- | :- | :- |
    | **MCP Server URL** | `https://<your-tenant>-mcp.conductor.one/v1` or `https://<your-tenant>-mcp.c1eu.ai/v1` | Ends with `/v1`. |
    | **Authorization URL** | `https://<your-tenant>.conductor.one/auth/v1/authorize` or `https://<your-tenant>.c1eu.ai/auth/v1/authorize` | No trailing parameters. |
    | **Authorization URL Parameters** | `&resource=` followed by your MCP Server URL, such as `&resource=https://<your-tenant>-mcp.conductor.one/v1` | Required. C1 binds tokens to a resource, so omitting this yields a token your MCP endpoint rejects. |
    | **Token URL** | `https://<your-tenant>.conductor.one/auth/v1/token` or `https://<your-tenant>.c1eu.ai/auth/v1/token` | No special handling |
    | **Client ID** | Your client metadata document URL | The full `https://` URL, not a bare identifier. |
    | **Client Secret** | `none` | Proof Key for Code Exchange (PKCE) needs no secret, but the console requires a value in this field, and Google's documentation says to enter `none`. C1 never reads it. |
    | **Scopes** | `openid profile email offline_access` | Space-separated, not comma-separated. |
    | **Enable PKCE Support** | Selected | Not selected by default. C1 requires PKCE, so the flow fails without it. |
    | **Use HTTP Basic Authentication** | Cleared | **Selected by default.** Leaving it selected sends credentials in an `Authorization` header, which does not work for a client with no secret. |
  </Step>

  <Step>
    Select **Verify Auth**. A window opens for you to sign in through your identity provider and authorize the connection.
  </Step>

  <Step>
    Select **Continue**.
  </Step>

  <Step>
    Enter your **Data connector name**, then select **Continue**.

    Leave **Location** as it is, and leave **Sensitive data protection policy** empty unless your organization requires one.
  </Step>

  <Step>
    Select **Create**.

    Some versions of the console add a **Select the pricing model** step first. If you see it, leave **General pricing** selected unless your organization has chosen a subscription, then select **Create**.
  </Step>
</Steps>

The form shows **Successfully logged in** after you authorize. The connector is created immediately and reaches the **Active** state within a minute.

## Enable the actions

Gemini Enterprise calls MCP tools *actions*, and imports every one of them turned off. Choose which to enable, then turn them on in the data store's **Actions** tab. The app's own **Actions** page only links back there. A data store supports a maximum of 100 enabled actions, and a shorter list makes the agent's tool selection more accurate.

### Reach every tool without spending your action budget

The C1 gateway publishes far more tools than the 100 a data store can enable. Rather than choosing a hundred of them, enable these twelve. They let the agent find and run any tool your access profiles allow:

| Tool | What it does |
| :- | :- |
| `search_tools` | Finds the right tool for a task across everything you can reach, and returns its input and output schema |
| `execute` | Runs a short TypeScript program that calls those tools, so several calls happen in one step |
| `get_execution` | Collects the result of a program that ran too long to answer inline |
| `list_guides`, `load_guide` | Fetch usage guides for the more involved flows |
| `create_vfs`, `create_vfs_artifact`, `list_vfs_files`, `get_vfs_download_url` | Give that program a scratch filesystem, and hand results back as files |
| `find_api_objects`, `count_api_objects` | Look up and count C1 objects such as users, apps, and entitlements, without writing a program |
| `query_metrics` | Return bucketed time series for reporting questions in one call |

Add whichever named C1 actions your users ask for by name on top of those, and the rest stay reachable through `search_tools`. The enabled set only decides what is offered. Every call is still evaluated against the calling user's access profiles, so this changes what the agent can find, never what a person is allowed to do.

<Note>
  Enable `get_execution` alongside `execute`. A program that runs longer than about 25 seconds returns a pending status and an execution ID instead of a result, and `get_execution` is what collects it. Without it those runs cannot be recovered and the agent reports a failure for work that actually succeeded.
</Note>

### Turn on the actions

Wait for the connector state to reach **Active** before you start, because the reload fails while the connector is still creating. Discovering the tool list happens only in the console. After that, you can set the enabled actions in the console or from the command line.

<Tabs>
  <Tab title="Console">
    <Steps>
      <Step>
        Open the data store, then select the **Actions** tab.
      </Step>

      <Step>
        Select **Reload custom actions**, and wait for the **Custom actions reloaded** confirmation. Gemini Enterprise calls your MCP server for its tool list and holds the request open while it waits, which takes about 30 seconds. The table stays empty until it finishes, so navigating away early looks like a silent failure.
      </Step>

      <Step>
        Select the actions to expose.
      </Step>

      <Step>
        Select **Enable actions**.
      </Step>
    </Steps>
  </Tab>

  <Tab title="Command line">
    Discover the tools first with **Reload custom actions** in the console. Once they are discovered, the enabled set is an ordinary field you can write, which is easier to keep consistent across environments than clicking through the table.

    Read the current list:

    ```bash theme={null}
    curl -s -H "Authorization: Bearer $(gcloud auth print-access-token)" \
      -H "X-Goog-User-Project: YOUR_PROJECT_ID" \
      "https://discoveryengine.googleapis.com/v1alpha/projects/YOUR_PROJECT_ID/locations/global/collections/YOUR_COLLECTION_ID/dataConnector"
    ```

    `dynamicTools` holds every discovered tool and `bapConfig.enabledActions` holds the enabled ones. Your collection ID is the one shown as **Collection ID** on the data store's **Details** tab.

    Write a new set with a `PATCH`, sending the complete list, since it replaces rather than merges:

    ```bash theme={null}
    curl -s -X PATCH \
      -H "Authorization: Bearer $(gcloud auth print-access-token)" \
      -H "X-Goog-User-Project: YOUR_PROJECT_ID" \
      -H "Content-Type: application/json" \
      "https://discoveryengine.googleapis.com/v1alpha/projects/YOUR_PROJECT_ID/locations/global/collections/YOUR_COLLECTION_ID/dataConnector?updateMask=bapConfig.enabledActions" \
      -d '{
        "bapConfig": {
          "enabledActions": [
            "search_tools",
            "execute",
            "get_execution",
            "list_guides",
            "load_guide",
            "create_vfs",
            "create_vfs_artifact",
            "list_vfs_files",
            "get_vfs_download_url",
            "find_api_objects",
            "count_api_objects",
            "query_metrics"
          ]
        }
      }'
    ```
  </Tab>
</Tabs>

The actions you selected are now enabled on the connector. No one can call them yet: each user must authorize the connector themselves, starting with you in [Verify the Gemini Enterprise connection](#verify-the-gemini-enterprise-connection).

## Verify the Gemini Enterprise connection

Confirm the connection works before you give anyone else access. Seeing actions listed does not prove it: the setup is confirmed only when a user calls a C1 tool and C1 records the call against that person. You are already licensed and signed in, so that user can be you.

<Steps>
  <Step>
    Complete the steps in [What each user does](#what-each-user-does) yourself, through the tool call.
  </Step>

  <Step>
    In C1, go to **AI** > **C1 Gateway** and select the **AI clients** tab. Gemini Enterprise is listed with a registration type of **CIMD**, and **People connected** counts the users who have authorized it. The **AI connections** tab shows one row per user. Users can see their own connections under their profile menu at **AI & API** > **AI connections**.

    The **Verified** column shows the domain that serves your client metadata document, so a self-hosted document reads `storage.googleapis.com`. That is expected while you host the document yourself.
  </Step>

  <Step>
    Confirm the tool call was logged. Every call through C1 MCP records the end user, the tool, the result, and a denial reason when refused. See [Audit AI tool usage](/product/admin/audit-ai-tool-usage).
  </Step>
</Steps>

The connection is working, and every tool call is attributed to the user who made it. You can now give other people access.

If the agent does not call a tool, returns nothing, or reports a denial, see [Troubleshoot Gemini Enterprise connection errors](#troubleshoot-gemini-enterprise-connection-errors). A denial that names a missing toolset or access profile is C1 working as configured, not a broken integration.

## Give users access

This section covers only what a person needs to **use** MCP servers that are already set up. None of it lets them add or change MCP servers, and they need none of the roles in [Required roles](#required-roles).

Each user needs all of these:

| Requirement | Why |
| :- | :- |
| An account in the Google directory your app signs users in with | Gemini Enterprise signs users in with it. A Cloud Identity Free account is enough, so the user needs no Google Workspace license or mailbox. |
| A Gemini Enterprise license | Without one, the web app shows **You are not assigned an active license**. |
| `roles/discoveryengine.user` on the project | Opens the web app, authorizes the connector, and calls its actions. `roles/discoveryengine.viewer` is not enough, because it cannot authorize a connector or call an action. |
| C1 tool access | Their access profiles decide which tools they can call, and a user with no toolset sees no tools. See [Tools and toolsets](/product/admin/tools-and-toolsets). |
| The web app URL | The address they open. Get it as in [Sign in to the web app](#sign-in-to-the-web-app). |

### Grant access to users

An administrator grants these, with `roles/discoveryengine.admin` and project **Owner** or `roles/resourcemanager.projectIamAdmin`.

<Steps>
  <Step>
    Assign each user a license, in the console under **Gemini Enterprise** > **Manage users** > **Add users**, or with the command in [Assign Gemini Enterprise licenses](#assign-gemini-enterprise-licenses). The command takes several users at once:

    ```bash theme={null}
    curl -s -X POST \
      -H "Authorization: Bearer $(gcloud auth print-access-token)" \
      -H "X-Goog-User-Project: YOUR_PROJECT_ID" \
      -H "Content-Type: application/json" \
      "https://discoveryengine.googleapis.com/v1alpha/projects/YOUR_PROJECT_ID/locations/global/userStores/default_user_store:batchUpdateUserLicenses" \
      -d '{
        "inlineSource": {
          "userLicenses": [
            {
              "userPrincipal": "USER_ONE_EMAIL",
              "licenseConfig": "projects/YOUR_PROJECT_NUMBER/locations/global/licenseConfigs/YOUR_SUBSCRIPTION_ID"
            },
            {
              "userPrincipal": "USER_TWO_EMAIL",
              "licenseConfig": "projects/YOUR_PROJECT_NUMBER/locations/global/licenseConfigs/YOUR_SUBSCRIPTION_ID"
            }
          ]
        }
      }'
    ```
  </Step>

  <Step>
    Grant each user `roles/discoveryengine.user` on the project:

    ```bash theme={null}
    gcloud projects add-iam-policy-binding YOUR_PROJECT_ID \
      --member="user:USER_EMAIL" \
      --role="roles/discoveryengine.user"
    ```
  </Step>

  <Step>
    In C1, give each user an access profile that includes the tools they should reach. This needs **Super Administrator** or **AI Governance Administrator**. See [Tools and toolsets](/product/admin/tools-and-toolsets).
  </Step>

  <Step>
    Send each user the web app URL and the steps in [What each user does](#what-each-user-does).
  </Step>
</Steps>

Each user now has everything they need to sign in and authorize the connector.

### What each user does

Each user does this once, for themselves. Enabling actions as an administrator authorizes nobody, and until a user authorizes, the assistant answers that it has no C1 integration, even though the actions are enabled and the connector is **Active**. These steps are written so you can send them to your users as they are.

<Steps>
  <Step>
    Open the Gemini Enterprise web app URL your administrator sent you, signed in with your work Google account.
  </Step>

  <Step>
    In the message box, select the **Connectors** icon. The C1 connector is listed with an **Authorize** link beside it.
  </Step>

  <Step>
    Select **Authorize**, sign in through your identity provider, and approve. The connector then shows a toggle, switched on.
  </Step>

  <Step>
    Ask a question that needs a C1 tool, naming the connector, such as "Using the C1 connector, list the access reviews in C1."
  </Step>

  <Step>
    The assistant names the action it wants to call and waits. Select **Send** to confirm it.
  </Step>
</Steps>

The assistant calls the C1 tool and answers with the result, limited to what your C1 access allows.

## Troubleshoot Gemini Enterprise connection errors

Errors are grouped by when they appear: while setting up, while discovering tools, or while people use the connector.

### Errors while setting up the connection

| Symptom | Cause | Fix |
| :- | :- | :- |
| **Operation denied by org policy** when you create the data store | The `disableCustomMcpServerConnector` constraint is enforced, or the override has not propagated. | Turn the constraint off and wait several minutes. See [Allow custom MCP data connectors](#allow-custom-mcp-data-connectors). |
| The override is set but the denial persists | An enforced organization- or folder-level policy overrides your project setting. | Re-run the `describe --effective` command. If it still reports `enforce: true`, ask your organization policy administrator to add the project exception. |
| `PERMISSION_DENIED` on `gcloud services enable` | The caller lacks `roles/serviceusage.serviceUsageAdmin` on the project. | Grant it. See [Required roles](#required-roles). |
| `PERMISSION_DENIED` on `gcloud storage buckets create` or the `allUsers` binding | The caller lacks `roles/storage.admin` on the project. | Grant it. See [Required roles](#required-roles). |
| **You must configure your access control settings before you continue**, and **Create** is greyed out | No identity provider is set for the app's location. | Set one, then return to the form. See [Set the identity provider](#set-the-identity-provider). |
| `404` on the client metadata URL | Nothing is hosting a document at that URL, or the file is not publicly readable. | Confirm you are using a URL you host yourself. The C1-hosted URL is not available yet. See [Host the client metadata document](#host-the-client-metadata-document). |
| **We encountered some problems during authentication** | The client ID is wrong, or the sign-in window was closed or blocked. | Confirm the client ID resolves, allow popups for the console, and retry **Verify Auth**. |
| The form will not accept an empty **Client Secret** | The console treats the field as required. | Enter `none`, as in [Create the data store](#create-the-data-store). C1 never reads it. |
| **Client ID** and **Client Secret** are blank on the **Re-authenticate** panel | Expected. The console never displays stored credentials, on a working connector or a broken one. | Nothing to fix. To change them, type both in again and select **Verify Auth**. |

### Errors while discovering tools

| Symptom | Cause | Fix |
| :- | :- | :- |
| **Failed to reload custom actions** on a connector that is **Active** | The most common cause by far is that the signed-in user has never opened the Gemini Enterprise web app. | Open the web app as that user, then reload again. See [Sign in to the web app](#sign-in-to-the-web-app). |
| **Failed to reload custom actions** on a connector imported from Agent Registry | Registry-imported connectors fail discovery with `FAILED_PRECONDITION`. | Recreate the data store from the **Custom MCP Server** card. See [Create the data store](#create-the-data-store). |
| **Failed to reload custom actions**, and the user has signed in | The connector is still creating, `discoveryengine.googleapis.com` is not enabled, the user holds no license, or no identity provider is set. | Wait for **Active**, then check each in turn. See [Prepare Gemini Enterprise](#prepare-gemini-enterprise). |
| **Reload custom actions** shows no error and no actions | Most often the reload is still running. It takes about 30 seconds. | Wait for the **Custom actions reloaded** confirmation, then reload the page. |
| The action list stays empty after the reload finishes | C1 returned an empty tool list for the authorizing user, which happens when that user has no toolset. | Assign the authorizing user an access profile that includes the tools you expect, then reload again. See [Tools and toolsets](/product/admin/tools-and-toolsets). |

<Tip>
  The console toast is not a reliable signal. To see whether a reload actually succeeded, read the audit log:

  ```bash theme={null}
  gcloud logging read 'protoPayload.methodName:"RefreshDataConnectorTools"' \
    --project=YOUR_PROJECT_ID --limit=5 --freshness=10m \
    --format="value(timestamp,severity,protoPayload.status.message)"
  ```

  A `401` entry on its own is normal: the console retries and a successful reload logs an entry with no error a few seconds later. Judge by that later entry, not by the first error.
</Tip>

### Errors while people use the connector

| Symptom | Cause | Fix |
| :- | :- | :- |
| **400. You are not assigned an active license** when opening the web app | Most often, the URL was built from the app's name rather than copied, so it does not identify the app. Otherwise the user holds no license, or the subscription has expired. | Copy the URL from the app's **Overview** page or get it with the command in [Sign in to the web app](#sign-in-to-the-web-app). If that URL also fails, check the user's license in [Assign Gemini Enterprise licenses](#assign-gemini-enterprise-licenses). |
| The assistant answers that it has "no ConductorOne integration" | The user has not authorized the connector in the web app. Enabling actions authorizes nobody. | In the message box, open **Connectors** and select **Authorize** beside your connector. See [What each user does](#what-each-user-does). |
| The assistant picks a web search instead of a C1 action | No enabled action matches the request, so nothing is callable. | Enable the actions the request needs, and name the connector in the prompt. |
| A user's tool calls are denied while another user's succeed | C1 is enforcing that user's access profile. This is expected behavior. | Check the denial reason in the audit log. See [Audit AI tool usage](/product/admin/audit-ai-tool-usage). |
| Authorization works, then breaks about an hour later | The connector uses a dynamically registered client whose secret expired. | Host a Client ID Metadata Document and use its URL as the client ID instead of registering dynamically. See [Host the client metadata document](#host-the-client-metadata-document). |
| Tool calls fail immediately after a working **Verify Auth** | The token is not bound to your MCP endpoint. | Set **Authorization URL Parameters** to `&resource=` followed by your MCP Server URL. See [Create the data store](#create-the-data-store). |
| `failed to fetch client metadata` | C1 fetches its own client metadata document over the public internet, and your tenant hostname does not resolve publicly. | This affects self-managed C1 deployments rather than C1 cloud tenants. [Contact the C1 support team](mailto:support@c1.ai). |

<Note>
  To correct an authentication value, edit the existing connector's settings rather than recreating it. The connector name cannot be changed after creation, as noted in [Create the data store](#create-the-data-store), so changing it means creating a new data store and removing the old one.
</Note>

## What this integration cannot do

These constraints come from Gemini Enterprise and Google Cloud.

* **VPC Service Controls and Private Service Connect are not supported** for custom MCP data stores. If your Google Cloud perimeter requires either, this integration cannot run inside it.
* Gemini Enterprise supports **egress mode only**. It calls out to your MCP server; your MCP server cannot call in.
* A data store supports a maximum of **100 enabled actions**.

C1's gateway already satisfies Google's other requirements for a custom MCP server: it uses StreamableHTTP transport rather than server-sent events, and it presents a certificate from a publicly trusted authority.

## Frequently asked questions about connecting Gemini Enterprise

<AccordionGroup>
  <Accordion title="Why do I have to host the client metadata document myself?">
    Google is the party that should host it, since Gemini Enterprise is the client it describes. Today it does not, and Google's own instructions are to register the MCP server as an OAuth client with your identity provider and take a client ID from it. Until Google publishes a document, somebody else has to host one on Google's behalf.

    C1 plans to host one at `https://<your-tenant>.conductor.one/auth/v1/client-metadata/gemini-enterprise`, but it has not shipped, so every tenant returns a `404` from that URL. It is a stopgap rather than the end state, because a client identity carries the most weight when the client's own vendor publishes it. [Contact the C1 support team](mailto:support@c1.ai) for timing.

    When Google publishes a client metadata document for Gemini Enterprise, use that URL as the client ID and retire whatever you were hosting.
  </Accordion>

  <Accordion title="Why not register a client through dynamic registration instead?">
    An unapproved dynamic registration's secret expires one hour after it is issued, and rotating it preserves the original expiry rather than extending it, so the connector fails at its first token refresh. A client metadata document has no secret, so nothing expires.
  </Accordion>

  <Accordion title="Can I create the data store from the command line?">
    No. The public Discovery Engine API refuses it:

    ```text theme={null}
    Data Connector parameters must be one of: oauth_access_token but got: instance_uri
    ```

    It accepts only a pre-obtained access token, not the OAuth client configuration, so it cannot run the per-user authorization this integration depends on. Discovering the tool list is console-only too, because the method behind **Reload custom actions** is not on the public endpoint. Choosing which actions are enabled can be scripted once the tools are discovered. See [Enable the actions](#enable-the-actions).
  </Accordion>

  <Accordion title="Does a shared client ID mean Gemini Enterprise sees everyone's data?">
    No. The client ID identifies Gemini Enterprise as an application, not as a user. Every person authorizes individually through your identity provider and receives their own token. C1 evaluates each tool call against that person's access profiles, and their activity is logged under their own identity.
  </Accordion>

  <Accordion title="Why does the Client Secret not matter?">
    The client is a public OAuth client with no secret. Client ID Metadata Document clients cannot use shared secrets, so C1 never reads the field. Security comes from the authorization code flow with PKCE, which you turn on with **Enable PKCE Support**.
  </Accordion>

  <Accordion title="Do I need Agent Gateway or Agent Registry?">
    No. A working connector reports `use_agent_gateway_egress: false`, so its traffic never passes through Agent Gateway, and a setup built with no gateway and no registry discovers tools and serves live tool calls normally. C1 governs the tool calls.

    Agent Registry is a catalog of approved MCP servers. Listing the C1 gateway there is a separate exercise that changes nothing about this integration. If you do list it, still create your data connector from the **Custom MCP Server** card: a connector imported from the registry fails tool discovery.
  </Accordion>

  <Accordion title="How do I cut off access in a hurry?">
    In C1, open **AI** > **C1 Gateway**, select the **AI clients** tab, find the Gemini Enterprise client, and use its **kill switch**. It revokes all tokens for that client immediately, for every user. To cut off one person instead, use **Revoke** on their row in the **AI connections** tab. See [Manage AI clients](/product/admin/ai-clients).
  </Accordion>

  <Accordion title="Can I see what tools Gemini Enterprise called?">
    Yes. Every tool call through C1 MCP is logged with the end user, the tool, the result, and a denial reason when refused. See [Audit AI tool usage](/product/admin/audit-ai-tool-usage).
  </Accordion>
</AccordionGroup>

## Pages related to governing AI tool access

These pages cover the C1 side of the integration.

* [Tools and toolsets](/product/admin/tools-and-toolsets) covers the access profiles that decide which tools each user can call.
* [Manage AI clients](/product/admin/ai-clients) covers lifecycle states, the kill switch, and allowed client types.
* [Connect to the C1 MCP](/product/admin/c1-mcp) covers the same gateway from desktop AI assistants.
* [Audit AI tool usage](/product/admin/audit-ai-tool-usage) covers what C1 logs for every tool call.
