Software · Customer experience
Full-organisation Gemini Enterprise rollout for a CX software company: Okta identity, ten connectors across first-party, federated, ingested and BYO-MCP sources.
The brief was simple to say and easy to get wrong: give everyone in the company one place to ask questions across the tools they already use, with the same permissions they already have.
Ten connectors in four flavours. First-party Google Workspace sources (Gmail, Drive, Calendar). Federated sources that are queried live and respect the source system's ACLs (Confluence, Jira, Slack, Workday, SharePoint). An ingested source where a copy is indexed (Salesforce). And a bring-your-own MCP server for GitHub, so engineers could ask about code and pull requests.
Okta SSO with SCIM provisioning. The claim mapping is small and unforgiving: the Google subject is the user's primary email, lower-cased; groups map by display name. The Workforce Identity Federation pool must never be swapped after creation or every data store has to be rebuilt — so we documented it, tested it, and did not touch it again.
Google sells a Workspace add-on and a connector platform under names that overlap. The client's admin bought one expecting the other. We now open every rollout with a one-page "which Gemini is this" explainer, because the confusion costs a week if it surfaces at procurement.
The same playbook has since run for a 500-user financial-services firm in three waves and a 300-user domain registry with HubSpot and BigQuery connectors.
Tell us what system the answer lives in and who needs it. We'll reply with a view on whether it's a two-week assessment, a five-week pilot, or something else.