GEMINI ENTERPRISE AGENT PLATFORM // TRACK 1 / 3
Admin & Governance for Gemini Enterprise
COMING SOON
The operations track. Provision tenants, configure connectors for Microsoft 365 + ServiceNow + Google data, wire up Workforce Identity Federation, harden the security posture, and stand up adoption analytics, the playbook for 85% activation in 90 days.
One Cohort. Ten Modules. A Production-Ready Admin Playbook.
Grounded in Google Cloud's first-party documentation (configure-identity-provider, connectors/*, security-overview), Google Skills #1191, and Skills #1674 (AI Boost Bootcamp) for the Day 0 Foundation Sprint. Built for the IT and platform team who has to roll out the Gemini Enterprise Agent Platform across an enterprise and stand up the operational scaffolding for the long term. Closes with a group-project capstone: design a governance policy and rollout plan for your own org.
What You'll Configure
- 🚀
Day 0 Foundation Sprint
GE vs Workspace vs GEAP, terminology, security primer.
- 🏢
Tenant Provisioning & Licensing
Stand up a Gemini Enterprise tenant and assign licences at scale.
- 🔑
Workforce Identity Federation
Configure Entra ID, Okta, AD FS via OIDC and SAML.
- 🔗
Data Connectors
SharePoint, OneDrive, Outlook, ServiceNow, and Google data.
- 🔐
Fine-Grained Access Control
Group ACLs, document-level permissions, role isolation.
- 🧰
Curated Agent Gallery
Enable pre-built Google agents for your workforce.
- 🔒
Network Security Hardening
VPC-SC, Private Service Connect, Model Armor, CMEK.
- 📈
Adoption Analytics
Licence activation, agent count, token usage, budget alerts.
- 🎧
Helpdesk Runbooks
Common tickets, escalation paths, day-2 operations.
- 🥇
Capstone Project
Design a governance policy and 90-day rollout plan for your org.
Tools You'll Use
THE CURRICULUM
What You Will Configure
Day 0 Foundation Sprint + 4 days of hands-on labs tied to Google Cloud's first-party admin docs, capped by a governance-policy capstone.
DAY 0,FOUNDATION SPRINT (PRE-WORK, SELF-PACED)
2 to 3 HRS · SELF-PACEDMandatory primer bundled with every track. Sourced from Google Skills #1674 (AI Boost Bootcamp) + #1401. Covers what Gemini Enterprise is (vs Gemini for Workspace vs the Gemini Enterprise Agent Platform, the platform formerly known as Vertex AI); GCP basics for non-technical tracks; the agentic lifecycle (Build → Scale → Govern → Optimize); and terminology alignment (agents, RAG, grounding, ADK, GEAR). Completion check before Day 1.
TENANT PROVISIONING & LICENSING
45 MINGoogle Cloud project setup; enabling Discovery Engine, Gemini Enterprise Agent Platform, Cloud Storage, and IAM APIs. License assignment via Workforce Identity (lowercase email mapping). Group-based rollout: pilot → expand → GA. Single-email identifier requirement; alias handling. Quotas: 3,000 readers per document.
IDENTITY: WORKFORCE IDENTITY FEDERATION
60 MINIdentity provider choice: Google Identity vs 3rd-party (Entra ID, Okta, AD FS) via OIDC / SAML 2.0. Workforce Pool creation. Attribute mapping (google.subject = assertion.email.lowerAscii()). License assignment via google.subject. IAM roles. Caveats: one IdP per location; provider type changes require data-store recreation.
DATA SOURCE CONNECTORS
75 MINHands-on configuration for SharePoint, OneDrive, Outlook, ServiceNow (and 14 more: Jira Cloud, Confluence Cloud, Dropbox, Drive, Calendar, GCS, BigQuery, Looker, GitHub, Salesforce, HubSpot, SAP, Adobe AEM, EntraID). Indexed vs federated sync. Gemini Enterprise Assist for guided setup. Structured vs unstructured data, one type per source.
AGENT GALLERY & STANDARD AGENT CONFIGURATION
45 MINAgent Gallery vs Agent Garden vs Agent Finder. Enable pre-built Google agents (Deep Research, Idea Generation, NotebookLM Enterprise, Data Insights). Agent Garden templates (code modernisation, financial analysis, invoice processing). Org-default agents. Discovering 3rd-party partner agents.
FINE-GRAINED USER ACCESS CONTROLS
60 MINGroup-based ACLs and document-level permissions preserved from source systems (SharePoint, OneDrive, Drive). Per-data-store visibility scoping. Role isolation patterns for multi-faculty / multi-department tenants. Service-account vs human-identity separation. Per-app data-store membership. Quota math for the 3,000-readers-per-document limit. Audit the access surface before go-live.
NETWORK SECURITY & COMPLIANCE HARDENING
60 MINVPC Service Controls perimeters. Private Service Connect for hybrid / on-prem. Firewall egress controls. Model Armor for prompt + response screening. CMEK in Cloud KMS. Compliance posture (HIPAA, FedRAMP High, SOC 2). Agent Anomaly + Threat Detection (Security Command Center). Audit logging strategy.
ADOPTION ANALYTICS & OPERATIONAL OWNERSHIP
45 MINLicense activation tracking: target 85% within 3 months. Agent creation analytics. Token / API usage tracking (millions to billions scale). Per-team cost attribution + budget allocation. Alert thresholds (80% / 100%). Real-time dashboards. Discovery Workshops as an adoption driver (4 to 10 sessions per persona).
HELPDESK & SUPPORT OPERATIONS
30 MINCommon admin ticket patterns and runbooks. The IT Resolution Hub example uses ServiceNow + Jira + technical docs as 3 data stores in one App. User permission troubleshooting (esp. for Microsoft data via Entra ID groups). Data-store sync failure diagnosis. Decommissioning behaviour.
GEMINI ENTERPRISE FOR CUSTOMER EXPERIENCE (ELECTIVE)
180 MIN · ELECTIVEOptional Day 4 module for CX-facing orgs. Conversational Agents + Agent Assist + CX Agent Studio + CX Insights + Search for CX, all configured under the same Gemini Enterprise Agent Platform admin plane. Virtual-agent workflows, real-time knowledge surfacing for human agents, post-call analytics. Skip if your org has no customer-contact-centre footprint.
CAPSTONE: GOVERNANCE POLICY & ROLLOUT PLAN
240 MIN · GROUP PROJECTSynthesis. Working in small groups, produce two deliverables for your own org,(1) a Gemini Enterprise governance policy covering identity, ACLs, network controls, model-armor rules, audit logging, and decommissioning; and (2) a 90-day rollout plan with discovery workshops, champion programme, activation targets, and budget guardrails. Peer review + instructor critique. Take it back to your CISO and CIO the same week.
OPS TOOLKIT: ENTERPRISE ARCHITECTURE & ROLLOUT BLUEPRINT
60 MINReference architecture for rolling out Gemini Enterprise across the org: tenant topology, connector mesh (M365 + ServiceNow + Google data), Workforce Identity Federation, agent runtime surfaces, and consumption endpoints. Phased rollout patterns (pilot → department → enterprise), environment promotion (dev → stage → prod), DR + multi-region posture, and the decision tree for landing-zone choices. Walk away with an architecture diagram you can hand to a CIO.
OPS TOOLKIT: LOGGING
45 MINCloud Logging for the Gemini Enterprise stack. Admin Activity logs, Data Access logs, System Event logs, and Policy Denied logs, what each captures, retention defaults, and how to enable the noisy ones safely. Log sinks to BigQuery + GCS for long-term audit. Log-based metrics for alerting on access anomalies. PII-aware log scrubbing. The exact log queries SREs and security reviewers will ask you for.
OPS TOOLKIT: DEBUGGING & TRACING
60 MINCloud Trace + OpenTelemetry for end-to-end request tracing across connectors, identity, retrieval, and agent calls. Reproducing a failed user query from trace ID to root cause. Common failure modes: ACL propagation delay, connector throttling, identity assertion mismatch, grounding miss. Live debugging walkthrough using real (sanitised) production traces. When to escalate to Google support and what to attach.
OPS TOOLKIT: COST OPTIMIZATION
60 MINFinOps for Gemini Enterprise. Pricing model breakdown (per-seat + per-call + storage + connector sync). Cost-attribution patterns by department / project / use case using labels and folders. Budget alerts and auto-actions. Quota strategy: protective quotas vs growth quotas. Caching, model routing, and prompt-size discipline as the three biggest cost levers. The 5 reports every FinOps lead wants monthly.
OPS TOOLKIT: LLM OPS USING GEMINI ENTERPRISE
75 MINEnd-to-end LLM Ops lifecycle on the platform you administer. Prompt versioning and A/B rollout via Prompt Management. Eval pipelines with Agent Evaluation (autoraters, golden datasets, regression gates). Shadow traffic + canary releases for new model versions or system-prompt changes. Drift detection on inputs, outputs, and tool-call patterns. Governance hooks: who can promote a prompt to prod, audit trail of model-version changes, rollback path. The platform-side controls that make agent CI/CD safe.
OPS TOOLKIT: COMMON ISSUES & FIXES
60 MINThe Day-2 playbook. Top 20 production failures we see across engagements, each with symptom, root cause, and the exact fix: connector sync stuck, ACL drift, identity federation 401s, data-store recreation traps, model-armor false positives, quota exhaustion under bursty load, audit-log gaps, decommissioning leftovers. Reference card you'll keep open during the first 90 days of rollout.
Your Instructors
Prem Kumar
AI Architecture Expert
"Anyone can build an AI demo. I teach you how to build the architecture behind systems that scale, because the gap between prototype and production is where most teams get stuck."
Specialty
What You Need Before Day 1
Required
- Laptop with internet access (macOS, Windows, or Linux)
- Day 0 Foundation Sprint (bundled, 2 to 3 hours self-paced before Day 1)
- Working admin experience with a SaaS or Cloud platform
Not Required
- Prior Google Cloud admin experience
- Programming experience
If you already administer a Microsoft 365 or Google Workspace tenant, you have the right baseline. The Day 0 sprint closes any remaining gap on Gemini Enterprise Agent Platform terminology.