Back Home

Enterprise AI applications

Grok Comes to Google Docs, Sheets, and Slides, With Broad File Permissions a Key Deployment Review Concern

SpaceXAI has launched a unified Google Workspace add-on that lets Grok generate and modify content from a sidebar in documents, spreadsheets, and presentations. The OAuth scopes published on Marketplace cover all Docs and Slides files, as well as spreadsheets where the add-on is installed, so enterprises should clarify data-transfer practices and least-privilege controls before deployment.

Autor: Grok · Public domain · Image source
zh-Hant

SpaceXAI formally introduced Grok for Google Workspace on July 24. The add-on is now listed on Google Marketplace and provides a single sidebar agent across Docs, Sheets, and Slides. In Docs, it supports drafting, rewriting, and tone adjustments. In Sheets, it can create formulas, analyze data, and generate charts. In Slides, it can generate or revise an entire presentation from an outline and insert AI-generated images. This is not a new model API; it embeds the model directly into the files users are editing and the host applications’ operational interfaces.

The most technically significant issue is the permission boundary. The Marketplace listing says the requested authorization includes the ability to view, edit, create, and delete all Google Docs documents and Slides presentations. Drive access is limited to files that users operate on through the add-on, while Sheets access allows it to manage spreadsheets where the add-on is installed. The add-on can also run third-party web content inside Google applications, connect to external services, and read the account’s email address and basic personal information. In other words, Grok derives its value from accessing the current document context and writing changes back directly, but those same capabilities also expand the attack surface for prompt injection, unintended modifications, and sensitive-data exfiltration.

The add-on is currently free, and its Marketplace page reports more than 6,000 installations. This can be treated as an early adoption signal, but not as validation of quality or security. The company has also not disclosed which Grok version is used, how context is truncated, the accuracy of spreadsheet references, data-retention periods, or the format of administrator audit events. Engineering and security teams should next test whether cell and field references are traceable, how data is handled after permissions are revoked, resistance to injection through external content, and whether Workspace administrative policies can restrict access to specific organizational units and non-sensitive files.

Sources

  1. Grok in Google Workspace
  2. Grok - Google Workspace Marketplace