Building a Governed Claude MCP Integration for Google Sheets & Drive
We built a governed MCP integration that lets an AI agent work securely with operational spreadsheet data, while critical write operations remain controlled, traceable, and recoverable.
- AI Integration
- MCP Development
- 10 min read
Stat Strip
At a Glance
A data-driven organization wanted Claude to take an active part in its Google Sheets and Google Drive workflows. The goal was an agent that could find files, retrieve operational data, transform it, and write approved changes back to the source, with no copying and pasting in between.
The hard part was write access.
The agent needed enough of it to do useful work, and the people running the business needed to stay in control of every change.
Ariel Software Solutions designed and built a custom Model Context Protocol (MCP) integration that connects Claude with Google Sheets and Google Drive. The integration comes with approval controls, audit logging, revision recovery, and a way to handle large datasets without pushing the full data through the model’s context window.
Moving from AI Assistance to AI Action
Letting an AI assistant change a spreadsheet the business depends on takes far more engineering than having it answer questions about one.
The organization needed Claude to work with operational data across Google Sheets and Drive, with three major risks under control.
- Control: A misunderstood instruction, a wrong range, or an unintended operation should never be able to change live business data silently.
- Scale: Large spreadsheets can hold hundreds or thousands of rows. Sending entire datasets through an LLM conversation raises token consumption, adds latency, and puts needless pressure on the context window.
- Accountability and recovery: Once AI can modify operational data, users need to see what changed and have a way to recover from an unwanted change.
Connecting Claude to Google’s APIs covered only the first step. The system also needed a governance layer between the AI agent and the business data.
A Custom MCP Server Between Claude and Google Workspace
Ariel built a custom MCP server that acts as the controlled interface between Claude and Google Sheets and Google Drive.
The MCP layer exposes specific tools for approved operations and controls how each one runs. The model never gets unrestricted access to the systems underneath.
Claude works with business data through structured MCP tools, and write operations stay behind safeguards.
Core architecture
Claude Desktop / AI Agent
↓
Custom MCP Server
↓
Governance & Approval Layer
↓
Google Sheets API + Google Drive API
↓
Operational Sheets, Files & Shared Drives
Alongside this flow, the system handles auditing and revision history, so changes can be traced and, where supported, restored.
The tool surface covers spreadsheet reading and writing, Drive operations, revision management, and approval controls.
Practical Google Sheets & Drive Tools for Claude
Ariel built focused MCP capabilities around the operations users actually need Claude to perform, with no catch-all “Google integration.”
The capabilities fall into four groups:
- Google Sheets operations: Retrieving spreadsheet data, updating existing content, formatting cells, and creating new tabs.
- Google Drive operations: Finding files by folder, retrieving content from nested folder structures, moving files, and running controlled file-management operations.
- Version and recovery operations: Retrieving revision information and reverting supported files to a selected earlier version.
- Audit operations: Recording changes in a dedicated audit trail, so any activity can be traced back.
With these tools, Claude can work directly with the organization’s existing Google Workspace environment, reducing the need to manually copy spreadsheet data into AI conversations while routing supported operations through purpose-built MCP tools.
The AI Proposes the Change, and the Operator Stays in Control
A key requirement was to keep the operator in control before critical model-generated write operations were applied to live data.
For mutating operations, Ariel designed a two-phase approval workflow. Before a critical write runs, the system can generate a preview of the intended change. The operator sees exactly what will happen before approving it.
Each change request follows the same sequence:
AI requests change → System previews impact → Human reviews → Human approves → Tool executes → Activity is recorded
Without approval, the write operation does not proceed.
The approval pattern applies across multiple mutation types in the integration, rather than protecting only a single kind of spreadsheet operation.
This adds an important governance layer between the AI agent and the underlying business system: Claude can propose and prepare the action, while the operator retains control over whether the critical change is executed.
Moving Data by Reference to Keep the AI Context Clear
Large spreadsheet operations add another challenge.
Pulling hundreds or thousands of rows straight into an LLM conversation can use up much of the context window, raise token usage, and make transformations less reliable.
For bulk operations, Ariel uses a different approach.
Large payloads can be written to a temporary file. Claude receives a reference and a limited preview, processes the data through the workflow, and the server then picks up the result for the approved write operation.
The data path looks like this:
Large dataset → Temporary reference → Transformation → Approved write-back
The path it avoids:
Large dataset → Entire dataset inside LLM context → Entire transformed dataset returned through the conversation
Only the information needed to coordinate the operation travels through the model context.
The approach keeps AI-assisted spreadsheet workflows practical as data volumes grow.
AI Actions Stay Traceable
Once an AI system can modify operational information, someone always asks the same question.
What exactly did it change?
The integration answers it with a dedicated audit mechanism.
For relevant write operations, the system records details such as the timestamp, target file, operator context, and a preview of the change in an audit log tied to the shared environment.
The integration also uses Google Drive’s revision capabilities and exposes revision history and revert functions through MCP.
Revision recovery adds one more safeguard. If an approved change later needs to be reversed, the workflow has a recovery path.
Approval, auditing, and revision recovery protect AI-driven changes at three points: before the change runs, as it happens, and after it lands.
Retrieval That Understands More Than Individual Files
The organization’s operational documents and spreadsheets sat in structured folders and nested folder hierarchies.
Ariel extended the integration with folder-aware search and nested retrieval. Claude finds the relevant information itself, so users no longer have to hand it every individual file.
Folder-aware retrieval matters most in workflows where only a specific subset of operational data should reach the AI.
The architecture supports targeted retrieval based on the structure and purpose of the underlying data, so the entire Drive never has to act as one large knowledge source.
A Service Account with Explicitly Scoped Access
Approval controls govern how Claude performs critical actions. Google Workspace permissions provide another layer of control by determining which files and folders the integration can access in the first place.
The integration uses a dedicated Google service account for its Google Sheets and Drive operations. Access is governed through the permissions granted to that account, allowing the integration to work with designated Shared Drive content rather than requiring unrestricted access to the organization’s wider Google Workspace environment.
This separation creates two distinct layers of control: Google permissions determine what the integration can access, while the MCP governance layer controls how supported actions are performed against that data.
- Purpose-specific access: The service account is configured for the Google Sheets and Drive functionality required by the integration.
- Permission-based visibility: Access to files and folders follows the permissions granted to the service account.
- Shared Drive controls: Operational data can be kept within designated Shared Drive structures with permissions appropriate to the required workflows.
- Separated credentials: Google credentials are handled by the integration layer rather than being supplied to Claude through the conversation.
Preserving the Original File Structure
Google Drive workflows can involve different file types, and careless update logic can change a file’s format or MIME type without warning.
During development, Ariel refined the update workflow so modifications keep the original file type and underlying format intact.
Users rarely notice a detail like this. It matters because an integration working on real operational data cannot afford to change file formats by accident.
Production Integrations Also Need to Handle Failure
A temporary network or API failure can leave an operation hanging indefinitely. An AI agent working on live systems needs a way out of that state.
During implementation, Ariel identified reliability risks on important Google API write paths and introduced an explicit retry strategy with exponential backoff and a bounded timeout.
The policy uses up to five attempts and a 45-second ceiling, so a stalled operation ends in a visible failure the user can act on.
The retry layer runs below anything the user sees in Claude, and the agent depends on it whenever it works with live systems.
Supporting Claude Desktop Across Different Environments
Building the MCP server was only part of the work.
The integration also had to work reliably across Claude Desktop installations, where the configuration location can differ by operating system and installation method.
Ariel built configuration-resolution and setup logic that handles multiple installation scenarios and never relies on one hard-coded location.
The setup detects likely configuration sources, validates each candidate, preserves the existing configuration, and creates a backup before making any change.
The setup process supports 12 documented Claude Desktop configuration scenarios. They include Windows installation variations that can otherwise make an MCP server fail to load without any warning.
Deployment becomes a repeatable process that no longer depends on one developer’s manual setup.
Claude Works With Operational Data Without Removing Human Oversight
The result was a shift from manually moving information between Google Workspace and Claude to letting Claude work with the operational data through purpose-built MCP tools, while keeping human oversight around critical write operations.
The finished integration gives the organization a practical foundation for using Claude directly within its Google Sheets and Drive workflows. Instead of repeatedly copying data back and forth between Google Workspace and AI conversations, users can call purpose-built MCP tools to find, retrieve, transform, and work with the underlying information.
The architecture also puts safeguards around the actions that matter most.
- Claude retrieves and transforms operational data.
- Large datasets move through the workflow without filling the model’s context.
- Write operations can pass through human review and approval.
- Changes can be captured in an audit trail.
- Revision history gives supported operations a recovery path.
- Folder-aware retrieval lets workflows target the relevant parts of Drive content.
The outcome is a governed AI integration, built around what it really takes to let an AI agent work inside business systems.
Technologies Used
Why This Matters Beyond Google Sheets
The same architectural problem shows up whenever organizations move from AI that answers questions to AI that takes actions.
An agent might work with spreadsheets, document repositories, CRMs, internal applications, or other systems of record. In each case, the organization has to settle five questions:
- What can the AI access?
- What actions can it perform?
- Which actions require human approval?
- How are those actions audited?
- What happens if something goes wrong?
MCP provides a standardized way to expose tools and context to AI systems. The engineering work sits in the layer around those tools, which keeps them safe and reliable in real business workflows.
Ariel built that layer for Google Sheets and Drive. We can build it for the systems your business runs on.
Building an AI Agent That Needs Access to Your Business Systems?
Ariel Software Solutions builds custom MCP servers and governed AI integrations that connect Claude and other AI agents with the systems businesses already use.
From Google Workspace and document repositories to internal applications, APIs, and operational platforms, we design integrations around three principles:
- Useful: The integration automates real work.
- Controlled: Humans remain in charge of what the AI changes.
- Traceable: The business can see what the AI did and trust the result.