What you will be able to do
- Choose between uploading a file and connecting a live service for a given piece of knowledge
- Predict what Claude can actually read from an uploaded document or a connected Google Drive file
- Explain how connector access is bounded by the permissions of the person who connected it
- Scope a connector for an organisation with read-only tool permissions and domain restrictions
- Turn a connector off for one conversation versus revoking its access entirely
Key concept
Permission inheritance — A connector never widens what you can see. It reaches your apps using your own account's rights in the source system, so anything you cannot open there stays invisible to Claude.
1.Two ways to put knowledge in front of Claude
Knowledge reaches Claude either as a file you hand over or as a service you connect. Uploading is a one-directional act: you choose a document from your device and it sits either in a single chat or in a project's Files section, where every conversation in that project can use it. A connector is a standing bridge instead: Claude asks the service for what it needs at the moment you ask the question.
That difference decides most of the scenarios in this subdomain. A document that will never change again is a natural upload. A document that someone edits every week is a natural connector target, because Google Docs added to chats and projects are described as syncing directly from Drive, so the copy Claude reads is the current one.
2.What Claude actually reads from an uploaded file
Upload support is broader than PDFs: PDF, DOCX, CSV, TXT, HTML, ODT, RTF, EPUB, JSON and XLSX are all listed as document types, plus JPEG, PNG, GIF and WebP images. XLSX carries a condition worth remembering, because it depends on an account setting rather than on the file itself.
Reading depth is where people get caught. For anything other than a PDF, Claude pulls out the text and nothing else, so a diagram pasted into a DOCX contributes nothing. PDFs are graded by length.
| PDF length | What Claude processes |
|---|---|
| 100 pages or fewer | both text and visual elements (like images, charts, and graphics) |
| 101 to 1000 pages | text only, and doesn't analyze visual elements |
| over 1000 pages | rejected with an "Uploaded file is too large" error |
Text only. Above 100 pages the visual analysis drops away, so the diagram itself is not processed; only whatever text the PDF carries is available. The guidance for large documents is to divide them into smaller sections to stay within limits, which would also bring the diagram back inside the visual range.
Sources1
3.A connector borrows your permissions, it never grants new ones
Connectors let Claude reach your apps, retrieve data from them and take actions inside them, and the boundary of all three is your own account. If a file, channel or record is closed to you in the source system, the connector cannot reach it from Claude either. The Google Workspace article says the same thing from the other side: Claude can only touch the Gmail, Calendar and Drive data of the Google account you connected, and only when you actually ask for something that needs it.
Because connecting hands Claude the ability to read and potentially modify data in that service, the setup advice is deliberately conservative: connect only services you trust and need for your workflows, and read the permissions on the authentication screen rather than clicking through them.
At an Enterprise organization, no one has enabled connectors yet, and an employee tries to connect Google Drive. What must happen before the employee can authenticate?
Correct answer: D — An Owner or Primary Owner must first enable the connector organization-wide.
- A. Incorrect. There is no support-ticket whitelisting process; the control point is an org-level toggle set by an Owner or Primary Owner.
- B. Incorrect. Switching account types is irrelevant; the organization admin simply needs to enable the connector.
- C. Incorrect. No separate marketplace add-on installation is a prerequisite for the Drive connector.
- D. Correct. On Team and Enterprise plans, an Owner or Primary Owner must enable connectors org-wide before members can authenticate their own accounts.
4.Gmail and Google Drive: the concrete capabilities
The Google Workspace connectors are the worked example the exam guide names, and they are available to all users on Claude and Claude Desktop. In Gmail, Claude can search and read mail with natural-language queries, draft messages, manage labels and threads, list saved drafts, and send, reply and forward. There is a boundary inside the metadata capability: attachment metadata is reachable, attachment content is not.
In Drive, Claude can search and retrieve Docs, look up file metadata and previews, read Sheets, Slides, PDFs, images and MS Office files, upload files, create folders, view file permissions, list recent changes, and share, move or trash files. The same text-only rule from uploads reappears here: a Drive file is read as text, and images embedded in it are not processed.
Sending mail and moving files are consequential, so both are gated by default: Claude asks for your approval before each of those actions, and only on Team and Enterprise plans can owners decide whether members may let such actions run without asking each time.
No. The Gmail connector reaches attachment metadata, not attachment content, so the attached file's data was never available to it. Getting at the spreadsheet means a different route, such as the file living in Drive and being read through the Drive connector.
Sources2
5.Pulling Drive documents into project knowledge
The two halves of this subdomain meet in a project's Files section. Once Drive is connected, you open the project, click the plus button in Files, choose Drive, and either search your recent documents or paste a URL; the document then joins the project knowledge that Claude draws on in that project's chats. In an ordinary chat the same flow lives behind "Add from Google Drive", and multiple files can be added as long as they fit the conversation's context window.
There is one restriction that turns up in team scenarios and surprises people: this route is documented for private projects only, and the option is disabled once a project is shared. A team that wants shared context from Drive cannot lean on the Drive picker inside the shared project.
The payoff for using Drive rather than an upload is freshness. Google Docs added to chats and projects are described as syncing directly from Drive, so the weekly-changing handbook stays current without anyone re-adding it. Note the limit of what the documentation claims: only Drive-linked documents are described as syncing. The sources do not describe an uploaded file refreshing itself, and they do not describe how to remove a file from a project, so do not assume either behaviour on the exam beyond what is stated.
Using the Gmail connector, a user asks Claude to summarize the contents of a PDF attached to an email. What limitation should the user expect?
Correct answer: C — Claude can read the email metadata and body but cannot open the attachment's content.
- A. Incorrect. There is no documented size threshold that unlocks attachment reading; content stays inaccessible regardless of size.
- B. Incorrect. Attachment content is inaccessible for any file type, not just non-PDF formats.
- C. Correct. The Gmail connector exposes metadata and body content but does not process attachment content, so the PDF's contents remain inaccessible.
- D. Incorrect. Claude can still read the surrounding email even with an attachment present; only the attachment content is off-limits.
Sources2
6.Scoping connectors in a Team or Enterprise organisation
On Team and Enterprise plans a connector is not a personal decision. An Owner or Primary Owner must first enable it for the organisation, and that step alone gives nobody access: each person still authenticates individually afterwards. Two steps, in that order, and questions love to collapse them into one.
Once enabled, owners can narrow what the connector is allowed to do, org-wide, in a way individual users cannot override. Under Customize > Connectors you select the connector to see its Tool permissions, grouped by type such as read-only tools and write/delete tools, and set each category or permission to Always allow, Needs approval, or Blocked.
| Service | Allow | Prevent |
|---|---|---|
| search and summarize email | sending messages | |
| Google Drive | read files in Google Drive | creating or editing documents |
| Linear | view Linear issues | creating new ones or changing status |
These restrictions work alongside source-system permissions rather than replacing them. Allowing a write action in Claude still leaves the person needing that right in the underlying service, because restricting actions in Claude only narrows access and never grants more than the source system permits.
Enterprise organisations have one further lever aimed at data leaving the company. With the verified-domain connector restriction on, only Claude accounts inside the Enterprise can connect a supported service, Gmail and Google Drive among them, using an address on a verified domain. It is a safeguard against connecting a work account to the wrong Claude account, not a data-loss-prevention control, and it applies only to new connection attempts.
A user pastes a Google Doc URL into a chat with the Drive connector enabled and asks about the document's contents. What does Claude do?
Correct answer: D — Claude accesses and processes the referenced document once the message is sent.
- A. Incorrect. The connector is designed to retrieve the document automatically, so manual pasting is not required.
- B. Incorrect. Accessing a document via the connector does not create a permanent copy in project knowledge.
- C. Incorrect. Public sharing is not required, since the connector authenticates to the user's own private Google account.
- D. Correct. With the Drive connector, a pasted URL is accessed and processed when the message is sent, informing the response.
7.Maintenance: toggling, reviewing, and cutting off access
Managing what is already connected is its own task. Per conversation, the plus button in the lower left of the chat opens Connectors and lets you toggle a service on or off for that chat alone, which is how you keep an app out of one discussion. That toggle is not a revocation: the connection survives it.
When the intent is that Claude should no longer reach a service at all, the action is to disconnect it. Under Customize > Connectors you can disconnect a service, change its connection settings, or review its permissions and access levels, and disconnecting stops access immediately. OAuth permissions granted at setup can also be revoked from the third-party service's own security settings.
Two smaller maintenance habits round this out. Connected apps can be brought into a conversation by Claude on their own when they fit the request, so review the list of what is connected rather than assuming an app is dormant. And when many connectors are active, tool loading becomes a real cost: with ten or more active, the advice is to switch Tool access from Auto to On demand to leave the conversation more room.
Exam traps
Each one states something that sounds right. Open it to see what is actually true.
1.Once an owner enables a connector for the organisation, members can start using it right away.Why is that wrong?
Org-level enablement only makes the connector available. Every member still has to authenticate individually before it works for them.
Covered in Scoping connectors in a Team or Enterprise organisation
2.Toggling a connector off in the chat menu means Claude can no longer reach that service.Why is that wrong?
The toggle applies to that conversation only. Ending access means disconnecting the app under Customize > Connectors, which stops access immediately.
Covered in Maintenance: toggling, reviewing, and cutting off access
3.Connecting Drive or Gmail gives Claude, and therefore the user, a broader view of company data.Why is that wrong?
The connector runs on the connecting person's own rights. Anything closed to them in the source system stays unreachable through Claude.
Covered in A connector borrows your permissions, it never grants new ones
4.Setting a Drive tool permission to Always allow lets a member edit documents they could not otherwise edit.Why is that wrong?
Action settings in Claude only narrow what is possible; the member still needs the underlying permission in the source system.
Covered in Scoping connectors in a Team or Enterprise organisation
5.The Drive picker in a project's Files section is the obvious way to give a shared team project its knowledge.Why is that wrong?
That route is documented for private projects; the option is disabled in shared projects.
6.If a chart is in the document you uploaded, Claude can see it.Why is that wrong?
Only PDFs of 100 pages or fewer get visual analysis. For every other document type Claude extracts text alone.
7.Claude reads the spreadsheet attached to an email once Gmail is connected.Why is that wrong?
The Gmail connector reaches attachment metadata, not the content of the attachment.
Covered in Gmail and Google Drive: the concrete capabilities
8.Turning on the verified-domain connector restriction severs the work-account connections people already made from personal Claude accounts.Why is that wrong?
It only blocks new connection attempts; connections made before it was enabled stay connected, and admins are not notified.
Covered in Scoping connectors in a Team or Enterprise organisation
Sources
Every claim above is drawn from one of these pages, quoted as it was written on the date shown.
- 1.
“Files can be uploaded to individual chats or uploaded to a project's Files section for persistent reference across conversations.”
↩︎ Two ways to put knowledge in front of Claude“You must enable code execution and file creation in your account to upload XLSX files.”
↩︎ What Claude actually reads from an uploaded file“For large documents: If you're working with larger files, consider dividing them into smaller sections to stay within limits.”
↩︎ What Claude actually reads from an uploaded file“For non-PDF documents: Claude extracts text only from these files.”
↩︎ Exam trap 6 - 2.
“Google Docs added to chats and projects sync directly from Google Drive, so you're always working with the latest version.”
↩︎ Two ways to put knowledge in front of Claude“Claude only accesses your data when you explicitly ask a question or request an action requiring this information”
↩︎ A connector borrows your permissions, it never grants new ones“Send, reply to, and forward emails from Gmail. By default, Claude asks for your approval before each of these actions.”
↩︎ Gmail and Google Drive: the concrete capabilities“When Claude reads a Google Drive file, it extracts text content only. Images embedded in documents are not processed.”
↩︎ Gmail and Google Drive: the concrete capabilities“Your document is added to your project knowledge for Claude to access when chatting in that project.”
↩︎ Pulling Drive documents into project knowledge“The Google Drive connector is only available when adding to Files in private projects. This option will be disabled for shared projects.”
↩︎ Pulling Drive documents into project knowledge“The Google Drive connector is only available when adding to Files in private projects. This option will be disabled for shared projects.”
↩︎ Exam trap 5“Access email metadata, including attachment metadata (not attachment content)”
↩︎ Exam trap 7 - 3.https://support.claude.com/en/articles/11176164-use-connectors-to-extend-claude-s-capabilitiesOfficial docs
“Connectors let Claude access your apps and services, retrieve your data, and take actions within connected services.”
↩︎ A connector borrows your permissions, it never grants new ones“Only connect services you trust and need for your workflows.”
↩︎ A connector borrows your permissions, it never grants new ones“Before members of Team and Enterprise plans can use connectors, an Owner or Primary Owner needs to enable them for the organization.”
↩︎ Scoping connectors in a Team or Enterprise organisation“For each permission category or individual permission, select Always allow, Needs approval, or Blocked.”
↩︎ Scoping connectors in a Team or Enterprise organisation“For each service, you can disconnect it, modify connection settings, or review permissions and access levels.”
↩︎ Maintenance: toggling, reviewing, and cutting off access“If you have 10 or more connectors active, consider switching to On demand to give your conversations more room.”
↩︎ Maintenance: toggling, reviewing, and cutting off access“Claude inherits each person's permissions from the connected service.”
↩︎ Key concept“Enabling a connector makes it available to your team, but it doesn't automatically grant anyone access.”
↩︎ Exam trap 1“If someone can't access a specific file, channel, or record in the source system, the connector can't reach it from Claude either.”
↩︎ Exam trap 3“Restricting actions in Claude never grants more access than the source system permits—it only narrows it.”
↩︎ Exam trap 4 - 4.https://support.claude.com/en/articles/15402193-restrict-verified-domain-connectors-to-your-enterpriseOfficial docs
“only Claude accounts in your Enterprise organization can connect the supported connectors using an email address on your verified domains”
↩︎ Scoping connectors in a Team or Enterprise organisation“It doesn't replace data loss prevention.”
↩︎ Scoping connectors in a Team or Enterprise organisation“It doesn't disconnect existing connections. The restriction applies only to new connection attempts.”
↩︎ Exam trap 8 - 5.https://support.claude.com/en/articles/11175166-get-started-with-custom-connectors-using-remote-mcpOfficial docs
“You can revoke these permissions at any time by disconnecting the connector in Claude's settings or the third-party service's security settings.”
↩︎ Maintenance: toggling, reviewing, and cutting off access
Also cited
“Disconnect an app entirely: Go to Customize > Connectors, find the app, and disconnect it. Claude stops accessing it immediately.”
↩︎ Exam trap 2