AI에 일정을 물어보려면 먼저 캘린더를 붙여야 합니다. 메일도 마찬가지입니다.

지난 글에서 계정을 맡기는 AI에 무엇을 허용할지 봤다면, 이번에는 실제로 붙이는 이야기입니다. 무엇이 되고 무엇이 안 되는지가 생각보다 뚜렷하게 갈립니다.

가장 먼저 알아둘 것은 기본값입니다. 메일을 보내거나 답장하거나 전달할 때, 클로드는 매번 사용자 승인을 받습니다. 읽는 것과 보내는 것이 다르게 취급됩니다.

■ 붙이면 무엇이 되나

구글 워크스페이스 커넥터는 지메일과 구글 캘린더, 구글 드라이브 셋입니다. 앤트로픽은 모든 이용자가 클로드와 클로드 데스크톱에서 쓸 수 있다고 적었습니다.

메일 쪽은 자연어로 검색해 읽고, 서식과 맥락을 갖춘 초안을 쓰고, 보내고 답장하고 전달하는 것까지 됩니다. 라벨과 스레드로 정리하거나 저장된 초안 목록을 보는 것도 포함됩니다. 다만 첨부파일은 메타데이터까지만 접근하고 내용은 읽지 않습니다.

캘린더 쪽이 실무에 바로 걸립니다. 일정과 캘린더를 보고, 접근 권한이 있는 공유 캘린더까지 봅니다. 일정을 만들고 고치고 지우는 것도 되고, 참석자 목록을 관리하거나 초대에 수락·거절·미정으로 답할 수도 있습니다.

특히 쓸 만한 건 참석자들 사이의 공통 가능 시간을 찾아 주는 기능입니다. 여럿의 일정을 맞추느라 메일을 주고받던 일이 줄어듭니다.

드라이브 쪽은 문서를 검색해 가져오고, 시트와 슬라이드, PDF, 이미지, MS 오피스 파일을 읽습니다. 파일을 올리고 공유하고 옮기고 휴지통에 넣는 것도 되는데, 이 동작들 역시 기본적으로 매번 승인을 받습니다.

주의할 점이 하나 적혀 있습니다. 클로드는 구글 드라이브 파일에서 텍스트만 뽑아냅니다. 문서 안에 박힌 이미지는 처리하지 않습니다.

■ 승인은 누가 정하나

그럼 매번 승인받는 걸 끌 수는 없을까요?

개인 요금제에서는 기본값이 승인입니다. 팀과 엔터프라이즈에서는 소유자가 구성원에게 승인 없이 실행하도록 허용할지 정합니다. 개인이 임의로 푸는 구조가 아닙니다.

붙이는 순서도 요금제에 따라 다릅니다. 팀과 엔터프라이즈는 소유자나 최고 소유자가 계정 단위로 커넥터를 먼저 켜야 개별 이용자가 인증할 수 있습니다. 개인은 바로 자기 구글 계정으로 인증하면 됩니다.

켜고 끄는 자리는 대화창 아래입니다. 더하기 버튼을 누르면 커넥터 목록이 나오고 개별로 켜고 끌 수 있습니다.

권한 범위에 관한 설명도 분명합니다. 연결한 구글 계정의 지메일·캘린더·드라이브만 접근하고, 질문이나 요청이 있을 때만 필요한 최소한을 가져옵니다. 그리고 클로드는 이용자의 기존 권한을 그대로 따릅니다. 워크스페이스에서 볼 수 없던 자료는 클로드로도 볼 수 없습니다. 권한이 늘어나지는 않는 구조.

학습 쪽도 적혀 있습니다. 앤트로픽은 지메일과 드라이브, 캘린더 커넥터 데이터로 모델을 학습하지 않는다고 밝혔습니다. 커넥터로 가져온 데이터는 해당 대화와 함께 앤트로픽 서버에 보관되고, 저장 중과 전송 중 모두 암호화된다고 했습니다.

■ 컴퓨터가 꺼져 있어도 도는 일

붙여 두면 무엇까지 맡길 수 있을까요?

붙이고 나면 다음 단계가 예약 작업입니다. 한 번 설명해 두면 정해진 주기로 알아서 돌아갑니다.

앤트로픽이 든 용도가 구체적입니다. 지난 24시간의 슬랙 메시지나 메일, 캘린더 일정을 요약하는 일일 브리핑, 드라이브와 스프레드시트 자료를 모으는 주간 보고서, 주제나 경쟁사를 정기적으로 추적하는 반복 리서치, 지정한 폴더의 파일 정리, 프로젝트 관리 도구에서 뽑는 팀 업데이트입니다.

핵심은 실행 위치입니다. 예약 작업은 원격에서 돌기 때문에 컴퓨터가 잠자기 상태이거나 클로드 데스크톱 앱이 닫혀 있어도 주기대로 실행됩니다. 왼쪽 사이드바의 '예약됨'에서 예정된 실행과 지난 실행을 볼 수 있습니다.

다만 예외가 둘 있습니다. 예약 작업은 커넥터와 클로드 계정에 저장된 파일로 동작하고, 내 컴퓨터의 폴더에는 묶을 수 없습니다. 그리고 로컬 파일이나 앱이 필요한 작업은 로컬에서만 실행됩니다.

만드는 방법은 둘입니다. 클로드에게 말로 시키면 이름과 주기, 하는 일을 정리해 보여 주고 '예약'을 누르면 등록됩니다. 직접 채우려면 예약 작업 페이지에서 새 작업을 만들어 프롬프트와 주기를 고르면 됩니다. 주기는 시간별·일별·주별·평일·수동 중에서 고릅니다.

예약 작업은 유료 요금제 전용입니다. 프로·맥스·팀·엔터프라이즈에서 됩니다.

■ 회사 메일이 아웃룩이라면

구글을 안 쓰는 회사는 어떨까요?

국내 직장에서는 구글보다 마이크로소프트 365를 쓰는 곳이 많습니다. 여기엔 먼저 확인할 조건이 있습니다.

마이크로소프트 365 커넥터는 마이크로소프트 비즈니스 요금제에 묶인 엔트라 테넌트가 있어야 합니다. 개인 계정은 안 됩니다. @outlook.com이나 @hotmail.com 주소로는 연결할 수 없다고 명시돼 있습니다.

설정도 개인이 혼자 끝낼 수 없습니다. 팀과 엔터프라이즈에서는 클로드 조직 소유자가 커넥터를 켜야 하고, 모든 테넌트에서 엔트라 전역 관리자가 한 번 동의를 해 줘야 합니다. 쓰기 기능까지 열려면 관리자가 갱신된 권한에 다시 동의해야 합니다.

대신 데이터가 어디 있는지는 분명히 적혀 있습니다. 커넥터는 보안 프록시로 동작하고, 마이크로소프트 365의 문서와 메일, 파일은 테넌트에 남습니다. 질의가 실행되는 동안에만 필요한 것을 가져오고 파일 내용을 캐시하지 않는다고 했습니다. 대상은 아웃룩과 셰어포인트, 원드라이브, 팀즈입니다.

■ 붙이기 전에 볼 것

정리하면 이렇습니다.

  • 읽기와 보내기는 다릅니다 — 발송·답장·전달은 기본적으로 매번 승인을 받습니다
  • 승인 해제는 개인이 못 정합니다 — 팀·엔터프라이즈에서 소유자가 결정합니다
  • 권한은 늘어나지 않습니다 — 워크스페이스에서 못 보던 자료는 클로드로도 못 봅니다
  • 첨부와 이미지는 빠집니다 — 첨부는 메타데이터까지, 문서 속 이미지는 처리하지 않습니다
  • 예약 작업은 유료 전용입니다 — 대신 컴퓨터가 꺼져 있어도 원격에서 돌아갑니다
  • 로컬 파일이 걸리면 예외입니다 — 그 작업은 내 컴퓨터에서만 실행됩니다
  • MS 365는 회사 계정이어야 합니다 — 개인 아웃룩 주소로는 아예 연결되지 않습니다

커넥터를 붙이는 일은 설정 몇 번으로 끝나지만, 무엇이 자동으로 실행되고 무엇이 승인을 거치는지는 붙이기 전에 알아 두는 편이 낫습니다. 메일 한 통이 나가고 나면 되돌릴 수 없으니까요.

To ask an AI about your schedule, you first have to connect the calendar. Same for mail.

The last piece looked at what to allow an AI handling your accounts. This one is about actually connecting it - and what works and what does not turns out to be sharply divided.

Start with the default. When Claude sends, replies to or forwards mail, it asks for your approval each time. Reading and sending are treated differently.

■ What connecting gets you

The Google Workspace connectors are three: Gmail, Google Calendar and Google Drive. Anthropic says they are available to all users on Claude and Claude Desktop.

On mail, Claude can search and read using natural language, draft with proper formatting and context, and send, reply and forward. It can organize with labels and threads and list saved drafts. Attachments are the exception: it accesses attachment metadata, not attachment content.

Calendar is where the practical gains are. Claude views events and calendars including shared ones you have access to, creates, updates and deletes events, manages attendee lists, and responds to invitations with accept, decline or tentative.

The most useful piece is finding mutual availability across attendees - the back-and-forth of matching several people's calendars shrinks.

On Drive, Claude searches and retrieves documents and reads Sheets, Slides, PDFs, images and MS Office files. It can upload, share, move and trash files - and those actions, too, ask for your approval by default.

One caveat is stated plainly: Claude extracts text content only from Google Drive files. Images embedded in documents are not processed.

■ Who decides on approvals

Can the per-action approval be switched off?

On personal plans the default is to ask. On Team and Enterprise, owners decide whether members may let these actions run without approval. It is not something an individual can loosen alone.

The connection order differs by plan too. On Team and Enterprise, an Owner or Primary Owner must enable connectors at the account level before individual users can authenticate. Personal users authenticate with their Google account directly.

The controls sit below the chat box: click the plus sign and toggle individual connectors on or off.

The scope is explicit. Claude can only access Gmail, Calendar and Drive data for the Google account you connected, accesses it only when you ask, and retrieves the minimum needed. It mirrors your existing permissions - you cannot reach anything you could not already reach in Google Workspace.

Training is addressed as well. Anthropic says it does not train models on your Gmail, Drive or Calendar connector data. Retrieved data is stored on Anthropic servers with the associated chat, encrypted at rest and in transit.

■ Work that runs while your computer sleeps

Once connected, how much can you hand over?

Once connected, scheduled tasks are the next step: describe the work once and it runs on a cadence.

Anthropic's listed uses are concrete - daily briefings summarizing the past 24 hours of Slack messages, emails or calendar events; weekly reports compiling data from Drive and spreadsheets; recurring research tracking topics or competitors; file organization in a designated folder; and team updates from project management tools.

The key point is where they run. Scheduled tasks run remotely, so they keep their cadence even when your computer is asleep or the Claude Desktop app is closed. Click "Scheduled" in the left sidebar to review upcoming and past runs.

Two exceptions apply. Scheduled tasks work with your connectors and files saved to your Claude account, and cannot be tied to a folder on your computer. And a task that requires local files or apps will only run locally.

There are two ways to create one. Describe it to Claude and it proposes a name, schedule and instructions for you to confirm with "Schedule." Or set it up manually from the Scheduled tasks page, choosing a prompt and a cadence - hourly, daily, weekly, on weekdays or manually.

Scheduled tasks are paid-plan only: Pro, Max, Team and Enterprise.

■ If your work mail is Outlook

And if your company does not run Google?

Plenty of Korean workplaces run Microsoft 365 rather than Google. There is a precondition to check first.

The Microsoft 365 connector requires a Microsoft Entra tenant tied to a Microsoft Business plan. Personal accounts do not work - @outlook.com and @hotmail.com addresses cannot be used to connect.

Setup is not something one person finishes alone either. On Team and Enterprise a Claude organization owner enables the connector, and in every tenant a Microsoft Entra Global Administrator grants a one-time consent. Enabling write tools requires the administrator to consent again to the updated permission set.

In exchange, where the data sits is stated clearly. The connector operates as a secure proxy, and your Microsoft 365 documents, emails and files remain in your tenant. It retrieves data on demand during active queries and does not cache file content. The services covered are Outlook, SharePoint, OneDrive and Teams.

■ Before you connect

To summarize:

  • Reading and sending differ - send, reply and forward ask for approval each time by default
  • You cannot lift that yourself - on Team and Enterprise the owner decides
  • Permissions do not expand - what you cannot see in Workspace stays invisible in Claude
  • Attachments and images are excluded - metadata only, and embedded images are not processed
  • Scheduled tasks are paid-only - but they run remotely even with your computer off
  • Local files are the exception - such tasks run only on your machine
  • MS 365 needs a work account - personal Outlook addresses cannot connect at all

Connecting takes a few clicks, but knowing what runs automatically and what waits for approval is better learned beforehand. Once an email goes out, it does not come back.