Two enterprise admins at a holographic Gemini Enterprise admin console showing an agent registry & governance panel, IAM least-privilege policies, Model Armor security policies, and a fleet-health dashboard with healthy states on a dark navy background.

GEMINI ENTERPRISE AGENT PLATFORM // TRACK 1 / 3

Admin & Governance for Gemini Enterprise

COMING SOON

The operations track. Provision tenants, configure connectors for Microsoft 365 + ServiceNow + Google data, wire up Workforce Identity Federation, harden the security posture, and stand up adoption analytics, the playbook for 85% activation in 90 days.

4 Day Cohort
10 Modules + Capstone
18+ Connectors Covered
Google Cloud Premier Partner Google Cloud Premier Partner
Built for IT Admins Platform Owners Security Engineers EdTech & IT Services

One Cohort. Ten Modules. A Production-Ready Admin Playbook.

Grounded in Google Cloud's first-party documentation (configure-identity-provider, connectors/*, security-overview), Google Skills #1191, and Skills #1674 (AI Boost Bootcamp) for the Day 0 Foundation Sprint. Built for the IT and platform team who has to roll out the Gemini Enterprise Agent Platform across an enterprise and stand up the operational scaffolding for the long term. Closes with a group-project capstone: design a governance policy and rollout plan for your own org.

assignment_turned_in

What You'll Configure

  • 🚀

    Day 0 Foundation Sprint

    GE vs Workspace vs GEAP, terminology, security primer.

  • 🏢

    Tenant Provisioning & Licensing

    Stand up a Gemini Enterprise tenant and assign licences at scale.

  • 🔑

    Workforce Identity Federation

    Configure Entra ID, Okta, AD FS via OIDC and SAML.

  • 🔗

    Data Connectors

    SharePoint, OneDrive, Outlook, ServiceNow, and Google data.

  • 🔐

    Fine-Grained Access Control

    Group ACLs, document-level permissions, role isolation.

  • 🧰

    Curated Agent Gallery

    Enable pre-built Google agents for your workforce.

  • 🔒

    Network Security Hardening

    VPC-SC, Private Service Connect, Model Armor, CMEK.

  • 📈

    Adoption Analytics

    Licence activation, agent count, token usage, budget alerts.

  • 🎧

    Helpdesk Runbooks

    Common tickets, escalation paths, day-2 operations.

  • 🥇

    Capstone Project

    Design a governance policy and 90-day rollout plan for your org.

settings

Tools You'll Use

Gemini Enterprise logo
Gemini Enterprise
Google Cloud logo
Google Cloud
Vertex AI logo
Vertex AI
🪪
Workforce Identity

THE CURRICULUM

What You Will Configure

Day 0 Foundation Sprint + 4 days of hands-on labs tied to Google Cloud's first-party admin docs, capped by a governance-policy capstone.

00

DAY 0,FOUNDATION SPRINT (PRE-WORK, SELF-PACED)

schedule2 to 3 HRS · SELF-PACED

Mandatory primer bundled with every track. Sourced from Google Skills #1674 (AI Boost Bootcamp) + #1401. Covers what Gemini Enterprise is (vs Gemini for Workspace vs the Gemini Enterprise Agent Platform, the platform formerly known as Vertex AI); GCP basics for non-technical tracks; the agentic lifecycle (Build → Scale → Govern → Optimize); and terminology alignment (agents, RAG, grounding, ADK, GEAR). Completion check before Day 1.

01

TENANT PROVISIONING & LICENSING

schedule45 MIN

Google Cloud project setup; enabling Discovery Engine, Gemini Enterprise Agent Platform, Cloud Storage, and IAM APIs. License assignment via Workforce Identity (lowercase email mapping). Group-based rollout: pilot → expand → GA. Single-email identifier requirement; alias handling. Quotas: 3,000 readers per document.

02

IDENTITY: WORKFORCE IDENTITY FEDERATION

schedule60 MIN

Identity provider choice: Google Identity vs 3rd-party (Entra ID, Okta, AD FS) via OIDC / SAML 2.0. Workforce Pool creation. Attribute mapping (google.subject = assertion.email.lowerAscii()). License assignment via google.subject. IAM roles. Caveats: one IdP per location; provider type changes require data-store recreation.

03

DATA SOURCE CONNECTORS

schedule75 MIN

Hands-on configuration for SharePoint, OneDrive, Outlook, ServiceNow (and 14 more: Jira Cloud, Confluence Cloud, Dropbox, Drive, Calendar, GCS, BigQuery, Looker, GitHub, Salesforce, HubSpot, SAP, Adobe AEM, EntraID). Indexed vs federated sync. Gemini Enterprise Assist for guided setup. Structured vs unstructured data, one type per source.

04

AGENT GALLERY & STANDARD AGENT CONFIGURATION

schedule45 MIN

Agent Gallery vs Agent Garden vs Agent Finder. Enable pre-built Google agents (Deep Research, Idea Generation, NotebookLM Enterprise, Data Insights). Agent Garden templates (code modernisation, financial analysis, invoice processing). Org-default agents. Discovering 3rd-party partner agents.

05

FINE-GRAINED USER ACCESS CONTROLS

schedule60 MIN

Group-based ACLs and document-level permissions preserved from source systems (SharePoint, OneDrive, Drive). Per-data-store visibility scoping. Role isolation patterns for multi-faculty / multi-department tenants. Service-account vs human-identity separation. Per-app data-store membership. Quota math for the 3,000-readers-per-document limit. Audit the access surface before go-live.

06

NETWORK SECURITY & COMPLIANCE HARDENING

schedule60 MIN

VPC Service Controls perimeters. Private Service Connect for hybrid / on-prem. Firewall egress controls. Model Armor for prompt + response screening. CMEK in Cloud KMS. Compliance posture (HIPAA, FedRAMP High, SOC 2). Agent Anomaly + Threat Detection (Security Command Center). Audit logging strategy.

07

ADOPTION ANALYTICS & OPERATIONAL OWNERSHIP

schedule45 MIN

License activation tracking: target 85% within 3 months. Agent creation analytics. Token / API usage tracking (millions to billions scale). Per-team cost attribution + budget allocation. Alert thresholds (80% / 100%). Real-time dashboards. Discovery Workshops as an adoption driver (4 to 10 sessions per persona).

08

HELPDESK & SUPPORT OPERATIONS

schedule30 MIN

Common admin ticket patterns and runbooks. The IT Resolution Hub example uses ServiceNow + Jira + technical docs as 3 data stores in one App. User permission troubleshooting (esp. for Microsoft data via Entra ID groups). Data-store sync failure diagnosis. Decommissioning behaviour.

09

GEMINI ENTERPRISE FOR CUSTOMER EXPERIENCE (ELECTIVE)

schedule180 MIN · ELECTIVE

Optional Day 4 module for CX-facing orgs. Conversational Agents + Agent Assist + CX Agent Studio + CX Insights + Search for CX, all configured under the same Gemini Enterprise Agent Platform admin plane. Virtual-agent workflows, real-time knowledge surfacing for human agents, post-call analytics. Skip if your org has no customer-contact-centre footprint.

10

CAPSTONE: GOVERNANCE POLICY & ROLLOUT PLAN

schedule240 MIN · GROUP PROJECT

Synthesis. Working in small groups, produce two deliverables for your own org,(1) a Gemini Enterprise governance policy covering identity, ACLs, network controls, model-armor rules, audit logging, and decommissioning; and (2) a 90-day rollout plan with discovery workshops, champion programme, activation targets, and budget guardrails. Peer review + instructor critique. Take it back to your CISO and CIO the same week.

11

OPS TOOLKIT: ENTERPRISE ARCHITECTURE & ROLLOUT BLUEPRINT

schedule60 MIN

Reference architecture for rolling out Gemini Enterprise across the org: tenant topology, connector mesh (M365 + ServiceNow + Google data), Workforce Identity Federation, agent runtime surfaces, and consumption endpoints. Phased rollout patterns (pilot → department → enterprise), environment promotion (dev → stage → prod), DR + multi-region posture, and the decision tree for landing-zone choices. Walk away with an architecture diagram you can hand to a CIO.

12

OPS TOOLKIT: LOGGING

schedule45 MIN

Cloud Logging for the Gemini Enterprise stack. Admin Activity logs, Data Access logs, System Event logs, and Policy Denied logs, what each captures, retention defaults, and how to enable the noisy ones safely. Log sinks to BigQuery + GCS for long-term audit. Log-based metrics for alerting on access anomalies. PII-aware log scrubbing. The exact log queries SREs and security reviewers will ask you for.

13

OPS TOOLKIT: DEBUGGING & TRACING

schedule60 MIN

Cloud Trace + OpenTelemetry for end-to-end request tracing across connectors, identity, retrieval, and agent calls. Reproducing a failed user query from trace ID to root cause. Common failure modes: ACL propagation delay, connector throttling, identity assertion mismatch, grounding miss. Live debugging walkthrough using real (sanitised) production traces. When to escalate to Google support and what to attach.

14

OPS TOOLKIT: COST OPTIMIZATION

schedule60 MIN

FinOps for Gemini Enterprise. Pricing model breakdown (per-seat + per-call + storage + connector sync). Cost-attribution patterns by department / project / use case using labels and folders. Budget alerts and auto-actions. Quota strategy: protective quotas vs growth quotas. Caching, model routing, and prompt-size discipline as the three biggest cost levers. The 5 reports every FinOps lead wants monthly.

15

OPS TOOLKIT: LLM OPS USING GEMINI ENTERPRISE

schedule75 MIN

End-to-end LLM Ops lifecycle on the platform you administer. Prompt versioning and A/B rollout via Prompt Management. Eval pipelines with Agent Evaluation (autoraters, golden datasets, regression gates). Shadow traffic + canary releases for new model versions or system-prompt changes. Drift detection on inputs, outputs, and tool-call patterns. Governance hooks: who can promote a prompt to prod, audit trail of model-version changes, rollback path. The platform-side controls that make agent CI/CD safe.

16

OPS TOOLKIT: COMMON ISSUES & FIXES

schedule60 MIN

The Day-2 playbook. Top 20 production failures we see across engagements, each with symptom, root cause, and the exact fix: connector sync stuck, ACL drift, identity federation 401s, data-store recreation traps, model-armor false positives, quota exhaustion under bursty load, audit-log gaps, decommissioning leftovers. Reference card you'll keep open during the first 90 days of rollout.

Your Instructors

Prem Kumar

Prem Kumar

AI Architecture Expert

"Anyone can build an AI demo. I teach you how to build the architecture behind systems that scale, because the gap between prototype and production is where most teams get stuck."

Specialty

Data Platform Architecture AI-Enabled Systems Full-Stack Engineering Technical & AI Strategy High-Performance Team Building

What You Need Before Day 1

Required

  • Laptop with internet access (macOS, Windows, or Linux)
  • Day 0 Foundation Sprint (bundled, 2 to 3 hours self-paced before Day 1)
  • Working admin experience with a SaaS or Cloud platform

Not Required

  • Prior Google Cloud admin experience
  • Programming experience

If you already administer a Microsoft 365 or Google Workspace tenant, you have the right baseline. The Day 0 sprint closes any remaining gap on Gemini Enterprise Agent Platform terminology.

Frequently Asked Questions

IT admins, platform owners, security engineers, and EdTech / IT-services teams responsible for rolling out the Gemini Enterprise Agent Platform across the organisation.
A mandatory 2 to 3 hour self-paced primer bundled with every track. It aligns terminology (agents, RAG, grounding, ADK, GEAR), explains how Gemini Enterprise differs from Gemini for Workspace and the Gemini Enterprise Agent Platform, and covers GCP basics. Completion is checked before Day 1.
A two-part group project: a governance policy and a 90-day rollout plan for your own organisation, built so you can hand them to your CISO and CIO the same week.