update · TowCue Editorial Team
Gemini Notebook audit logs arrive in Workspace: what admins can now see
Google Workspace now gives eligible admins detailed Gemini Notebook audit logs. See what is tracked, how to use the data for AI governance, and the regional-data limitation that still matters.
Quick answer
Google announced comprehensive Gemini Notebook audit logs for Google Workspace on September 3, 2026. The feature began a gradual rollout that Google says can take up to 15 days, so this is not a September 6 launch; it is a recent enterprise feature that may still be appearing in eligible tenants.
For organizations already allowing Gemini Notebook at work, the update closes an important visibility gap. Administrators can now review how users interact with Gemini Notebook through the Audit and investigation tool and, on supported editions, the Security investigation tool. Logged context can include the actor, event type, IP address, resource information, notebook visibility, source metadata and Studio artifact details.
The practical value is not "more logs." It is the ability to answer governance questions such as: Who changed sharing permissions? Which source was referenced? What artifact was generated? Which account performed the action?
There is also a material limitation. Google says audit-log storage follows standard Workspace regional routing policies, but Gemini Notebook user data such as notebooks, sources and chat histories is stored globally and does not currently support data regionalization. Teams with strict data-residency requirements should not treat auditability as the same thing as regional data control.
For wider context, read TowCue's Gemini review, the Gemini connected-apps workflow update, and the AI agent best-practices guide.
What Google added
Workspace administrators can search Gemini Notebook log events in the Admin console. Google documents attributes including:
- Actor: the email address of the user who performed an action
- Date and event description
- Event: for example, a sharing-permissions change
- IP address and related network context
- AI plan tier
- Prior visibility and current visibility
- Resource ID, title, type and owner details
- Source ID, name, type and URL
- Studio artifact ID, name and type
The exact attributes vary by event, and Google says the list can change. That matters when teams build durable compliance queries: do not assume every event will populate every field.
The logs are available by default to Workspace customers that have access to the relevant audit and investigation tools. BigQuery export is not automatically enabled; an administrator must turn that on separately.
Why this matters for enterprise AI governance
A common AI rollout mistake is to focus on model quality and permissions while leaving observability for later. That works until the first internal question arrives: "What happened to this document?"
Gemini Notebook is especially sensitive because its value comes from combining source material with model-generated analysis. In a work setting, those sources may include internal documents, research material, meeting notes or project files. A governance process therefore needs evidence about access, sharing and transformation, not just whether the product was enabled.
The new logs create a more useful chain of evidence. An administrator can search for a user or event, inspect associated resources and sources, and preserve results for investigation. On supported editions, reporting rules and alerts can also be built on log-event data.
That changes the rollout conversation. Instead of asking only "Should employees use Gemini Notebook?", security and IT teams can define monitorable conditions for how it is used.
A practical 30-minute setup for admins
A low-risk first pass does not require a full SIEM project.
- Open Admin console → Reporting → Audit and investigation → Gemini Notebook log events.
- Review the default seven-day window and confirm that expected user activity appears.
- Add columns for actor, event, source information, resource information, visibility and IP context.
- Run a test with a non-sensitive notebook: add a source, generate an artifact and change a sharing setting if your policy allows it.
- Confirm the corresponding events are searchable and that the fields your team cares about are actually populated.
- Save one investigation for a realistic scenario such as unexpected sharing-permission changes.
- If you need longer-term analytics or correlation with other systems, evaluate BigQuery export separately.
This is deliberately a verification exercise, not a broad monitoring policy. The goal is to learn what evidence the product actually produces before writing controls that depend on it.
What BigQuery changes
Google also documents a BigQuery schema for Gemini Notebook logs. Exporting logs to BigQuery can make the data more useful for teams that need trend analysis, cross-system correlation or custom retention workflows.
For example, an organization could analyze changes in notebook visibility, identify recurring source types, or correlate Notebook activity with other approved security telemetry. But exporting data also creates another governed dataset. Access permissions, retention, query costs and downstream handling need their own controls.
TowCue's recommendation is to avoid exporting "because we can." Start with a specific question that the Admin console cannot answer efficiently, then decide whether BigQuery adds enough operational value to justify another data pipeline.
The data-region limitation is important
The most important caveat in Google's announcement is easy to overlook: the logs and the Notebook user data do not have the same regionalization story.
Google states that audit-log storage follows standard Workspace regional routing policies. However, notebooks, sources and chat histories are stored globally and currently do not support data regionalization.
That distinction matters to organizations with contractual, regulatory or internal residency requirements. A complete audit trail can help prove what happened, but it does not change where the underlying application data is stored.
Before expanding Gemini Notebook to regulated or location-sensitive workloads, ask two separate questions:
- Can we observe and investigate the activity we need?
- Are the data-location and processing conditions acceptable for this workload?
A yes to the first question does not imply a yes to the second.
Who should act now
Workspace security and IT teams
If Gemini Notebook is already enabled, verify the new data source and build one or two realistic saved searches. This is the group that gets the most immediate value.
Compliance teams
Use the logs to improve evidence collection, but review the global user-data storage limitation separately. Do not describe the feature internally as solving data residency.
Team leads using Notebook for research
You do not need to become an administrator, but you should expect enterprise Notebook use to become more observable. That is generally good for accountable collaboration, especially when shared sources and generated artifacts feed business decisions.
Small teams without formal governance requirements
The feature may not change your daily workflow. The broader lesson still applies: when an AI tool becomes part of a repeatable business process, ask what evidence exists when something goes wrong.
TowCue take
This is a more important enterprise AI update than it looks.
AI products are moving from experimental assistants into systems that read company context, generate durable artifacts and influence decisions. At that point, observability becomes a product capability, not an administrative afterthought.
Gemini Notebook now gives eligible Workspace admins substantially better visibility into user and resource activity. That makes controlled deployment easier to defend because teams can test, investigate and document actual behavior rather than relying only on policy documents.
But the update also shows why enterprise AI evaluation needs multiple layers. Auditability, permissions, retention, data residency and model behavior are different controls. A strong result in one layer does not cancel a limitation in another.
TowCue would treat the new audit logs as a reason to improve a Gemini Notebook rollout, not as a reason to expand it automatically. First verify the events your organization can actually see, define a small set of meaningful investigations, and separately review whether globally stored Notebook user data fits the workload.
Research sources
- Google Workspace Updates — Introducing comprehensive audit logs for Gemini Notebook in the Workspace Admin console (September 3, 2026)
- Google Workspace Help — Gemini Notebook log events (last updated September 4, 2026)
- Google Workspace Help — Schema for Gemini Notebook logs in BigQuery
- Gemini Notebook Help — Learn about Gemini Notebook