What the listing actually asks for

The listing sits in the Google Workspace Marketplace under the name Grok, published by SpaceXAI, last updated on 21 July 2026. It costs nothing, it has passed six thousand installs, and it runs inside Docs, Sheets and Slides. Installing it takes roughly the effort of adding a browser extension, and it leaves no trace in any system your finance team watches.

The permissions are the part worth reading slowly. The listing asks to see, edit, create and delete all Google Docs documents, and to do the same to all Google Slides presentations. It also asks to view and manage spreadsheets where it is installed, to connect to external services, to display and run third-party web content in prompts and sidebars, and to read the primary account email address. The word doing the work in those strings is all. This is not access to the document open on screen. It is access to the document estate that account can reach, which in a normal company includes every file a colleague has ever shared with that person.

The vendor decision moved to whoever clicks Install

Why it matters: the choice of which AI company processes your commercial documents is now made by whoever clicks Install, not by anyone who has read a contract. Procurement was built to catch vendors arriving through the front door, with an invoice, a security questionnaire and a signature. The add-in marketplace is a side door that was always there, and a frontier model walked through it.

The control does exist. In the Google Admin console the path runs from Menu to Apps, then Google Workspace Marketplace apps, then Apps list, then User Install Settings, and it offers three states: users can install any apps, only allowlisted apps, or no apps. That is the entire decision, and most organisations have never opened the page to look at which of the three they are running.

The allowlist carries a catch that cuts both ways. Google's own documentation states that the allowlist affects users who have Manage access to apps set to allow only allowlisted apps, which means an allowlist assembled while the setting sits on any apps is decorative. The same documentation is blunt about the other direction: users lose access to an app when you remove it from the allowlist, even if they still have it installed. The revocation is real, and it reaches installations you never approved.

Outlook runs a different ladder

The same company shipped a Grok add-in for Outlook through the Microsoft Marketplace, on the same distribution logic: standard marketplace, standard install, no enterprise agreement in the path. Microsoft governs mail add-ins with four cumulative permission levels rather than a scope list. They run restricted, read item, read/write item, and read/write mailbox, and each one contains the ones below it.

The top rung deserves a minute of your attention. Microsoft describes read/write mailbox as allowing an add-in to read and write all properties of any item in the mailbox, to create, read and write any folder or item, and to send an item from that mailbox. Sending is the line to sit with, because an add-in at that level is not a reader of your mail but a participant in it. Microsoft also tells you where to look: the requested permissions appear in the Marketplace listing before you install, and the required permissions of already-installed add-ins are visible in the Exchange Admin Center. Check the tier your tenant has actually granted rather than assuming it, because the listing is the only place that answer is authoritative.

Your processor agreement does not stretch this far

Under the GDPR your company is the controller for the personal data sitting in those documents and mailboxes, which is to say client names, staff records, pricing, everything a working business writes down. Any third party processing that data on your behalf needs a controller-to-processor agreement under Article 28. That is not a formality that legal can paper over afterwards; it is the instrument that says what the processor may do with the data and what happens when it is finished.

The agreements you already hold cover Google and Microsoft. They do not extend to a separate publisher operating its own service under its own terms, and the Marketplace listing is explicit about that: the privacy policy and terms of service both point to the publisher's own domain, not to your Workspace contract. In the United Kingdom the Information Commissioner's Office treats controller diligence over processors as a live obligation rather than a filing exercise, and a British firm whose staff have installed a third-party AI add-on across a document estate has taken on a processor it has never assessed.

The zero price is precisely why this bypasses everything. Nothing is invoiced, so no purchase order is raised, so no pound or euro approval threshold is crossed, so the vendor review that a paid seat would have triggered automatically never runs. Free software does not mean free of obligation, and the cheapest tool in your estate can carry the widest data access in it.

The setting to check before Friday

Start with the inventory rather than the policy. Open the Admin console, read the list of Marketplace apps your users have already installed, and note which of the three install states you are running. If it is any apps, you have not chosen a vendor policy, you have chosen to have none. Then do the equivalent in the Exchange Admin Center for Outlook add-ins and read the permission tier each one declares. Allow the 24 hours Google warns about when you change the setting, which is exactly why this belongs on a calm Thursday and not in the middle of an incident.

The wider lesson outlasts this one add-on. The app marketplace is now a procurement channel, and it is the only one in your business with no approval step, no invoice and no counterparty review. Treat an install prompt asking for all documents the way you would treat a supplier asking for a copy of the file server, because functionally that is the request. The add-on is not the problem; the fact that nobody had to ask you is.