How to integrate data into Gemini Enterprise with Windsor.ai
Windsor.ai is listed as a third-party connector in Gemini Enterprise. Once you connect it, Gemini Enterprise can answer questions about the data you have connected to Windsor.ai from more than 350 sources, such as Google Ads, Facebook Ads, Instagram, TikTok, YouTube, Amazon Ads, LinkedIn and Shopify. It can also make changes in platforms that support write actions, for example pausing a campaign or changing a budget.
Google calls this connection a data store. You create it in the Google Cloud console, connect it to a Gemini Enterprise app, and then authorize it with your Windsor.ai account.
Get started with Windsor.ai: free forever plan, no credit card. onboard.windsor.ai
Prerequisites
Before you start, make sure you have the following:
- Gemini Enterprise Standard, Plus, Frontline or Pay-as-you-go. These editions are set up in the Google Cloud console, which this guide uses. The Business edition has its own setup and includes a smaller selection of connectors. See Google’s edition comparison.
- A Google Cloud project that belongs to your organization. The project must be under a Google Workspace or Cloud Identity organization, not a personal Gmail account. Without an organization, access control in Step 6 cannot be configured. See Google’s guide to creating and managing projects.
- Billing enabled on the project. You can check this on the Billing projects page, or see Google’s guide to verify the billing status of your projects.
- Gemini Enterprise activated in the project. If you have not used Gemini Enterprise before, follow Google’s Gemini Enterprise quickstart. If you create an app while following it, you can use that app in Step 8.
- A Windsor.ai account with at least one connected data source. The free forever plan covers one data source. To query several sources together, paid plans start at $19/month for 3 sources. See Windsor.ai pricing.
Steps to connect Windsor.ai to Gemini Enterprise
Step 1: Prepare your Windsor.ai account
- Log in at onboard.windsor.ai.
- Connect at least one data source (Google Ads, Facebook Ads, Shopify and others) if you have not already. See our connector setup guides.
Note: Gemini can only query data sources that are connected in Windsor.ai.
Step 2: Confirm you have Discovery Engine access
- Open IAM and check that the correct project is selected at the top.
- Click Grant access.
- Under New principals, add the user who will set up the data store.
- Under Role, select Discovery Engine Editor.
- Click Save.

Note: If saving fails with a permissions error, ask your Google Cloud admin to assign the role.
Step 3: Create the data store
- Open Gemini Enterprise in the Google Cloud console and confirm you are in the correct project.
- In the left menu, click Data stores.
- Check the location selector at the top of the page. It shows Current location: global by default. Change it to the US or EU multi-region only if you need to (see the note below).
- Click Create data store.

- Under Third-party data sources, find Windsor.ai (use the search box if the list is long) and click Add data source.

Note: The console only shows resources in the selected location, so a data store created in one location does not appear in the others. Google recommends the global location unless you have security or regulatory reasons to keep data in the US or EU, because global has better response times, the latest model versions and the newest features. The location you pick here must match the multi-region you select in Step 6.
Step 4: Configure data scope
- In the Data section, an Advanced options area may show an Enable static IP checkbox. You can leave it off: Windsor.ai uses Google-managed OAuth and does not filter requests by IP address.
- Click Continue.

- Under Entities to search, select Connectors.
- Click Continue.

Note: Turning on static IP does not break the connection, but Google only lets you set it when you create the data store. To change it later, you have to delete the data store and create it again.
Step 5: Select actions to enable
The Actions step lists the Windsor.ai actions:
- Execute Action: runs a write action on a connected Windsor.ai account, such as pausing a campaign or changing a budget.
- Contact Windsor: sends feedback, a support request or a feature request to Windsor.ai.
- Select the actions you need. Reading data works without either of them. This guide uses Select all actions, so Gemini can also make changes.
- Click Continue.

Note: You can change the enabled actions later. Open the data store, click Actions, then Reload custom actions.
Step 6: Set the configuration details
- Under Multi-region, select the location: global (recommended), us or eu. It must match the location from Step 3 and cannot be changed later.
- Enter a Data connector name.
- Optional: enter a Tag, a stable identifier for this data store across versions. It cannot be changed once set.
- Optional: attach an existing Sensitive Data Protection policy to inspect and de-identify data that Gemini Enterprise retrieves through this data store.
If you chose global
No encryption setup is needed. Configure access control (below) before you continue.

If you chose US or EU
An Encryption settings section appears with the message “This resource requires single-region keys”. Choose one option:
- Google-managed encryption key (selected by default): no other setup is needed, and you can ignore the single-region key message.
- Cloud KMS key: only if your organization requires its own keys. Select a Key management type and your key from the Cloud KMS key list. Your single-region keys must be registered first: click Go to settings page, and see Google’s guide to register a single-region key for third-party connectors.


Then configure access control for this location (below). Access control is set per location, so you need to do this even if you already set it up for global.
Configure access control
This is a one-time setting per project and location. If it is already set up, you will not see the prompt and can skip this part.
- Click Configure access control, or go to the AI Applications page, then Settings, then Authentication.
- Click the pencil icon next to the location you chose, for example global.

- In the Add identity provider panel, select one option:
- Google Identity: if your organization uses Google accounts or Google Workspace. This is the most common choice.
- 3rd Party Identity: if your organization uses a provider such as Okta or Microsoft Entra ID. Your organization admin must set up Workforce Identity Federation first, and you need the IAM Workforce Pool Admin role (roles/iam.workforcePoolAdmin) on the organization, not the project.
- Click Save.

- Go back to the data store page, click Reload, then click Continue.

Note: If you see the error “Identity provider not configurable”, your project does not belong to an organization. See Prerequisites. Choose the identity provider carefully: the console warns that changing it later stops access-controlled data stores from working until you delete and recreate them.
Step 7: Select the pricing model
- Choose a pricing model:
- General pricing (selected by default): you pay for what you use. Google suggests it for variable traffic or for getting started.
- Configurable pricing: a monthly subscription with predictable costs, for consistent workloads.
This guide keeps General pricing.
- Click Create.

- On the Data stores page, click your data store name to see its status. When the state changes from Creating to Active, the Windsor.ai data store is ready.

Note: This is Google Cloud pricing for the data store, charged to the billing account linked to your Google Cloud project, separately from your Windsor.ai plan. The console also warns that charges may apply until the data store is linked to a Gemini Enterprise app, which you do in Steps 8 and 9.
Step 8: Create or choose a Gemini Enterprise app
You use the data store through a Gemini Enterprise app, which is where you ask questions. If you already have an app in the same location as your data store (for example global), skip to Step 9.
- In the Gemini Enterprise console, click Apps in the left menu, then Create app.

- On the Search and assistant tab, click Learn More on the Gemini Enterprise card.

- Enter an App name, for example “Windsor.ai Analytics Assistant”.
- Under Choose a location, select the same multi-region as your data store.
- Optional: expand Advanced options and enter your Company name, which helps the model identify your company in answers. Leave Include cross-domain documents unchecked. It only applies to Google Drive.
- Click Create. The app opens on its Overview page.

Note: If this is the first Gemini Enterprise app in the project, Google creates a 30-day trial license for Gemini Enterprise with it. Gemini Enterprise licenses are billed by Google.
Step 9: Connect the data store to the app
- Open the app’s Overview page. For an existing app, click Apps in the left menu and select it.
- Click Connected data stores in the left menu.
- Click Add existing data stores.

- Select the data store you created in Step 3.
- Click Connect.

Step 10: Authorize Gemini Enterprise to access Windsor.ai
Authorize the connection before you ask anything. Until you do, queries against this data store return no results.
- Go to the app’s Overview page.
- Under Your Gemini Enterprise webapp is ready, click the web app URL, or click Copy URL and open it in your browser. You do not need Configure webapp for this guide.

- In the web app, click the puzzle piece icon below the Ask Gemini Enterprise box.
- Next to Windsor.ai, click Authorize.

- In the Application Access Request window, click Allow Access. If you are not signed in to Windsor.ai, sign in first.
- Windsor.ai opens and shows your connected data sources. To let Gemini make changes in your connected platforms, turn on Write actions. This setting applies only to your Windsor.ai user, not to the rest of your team.
- Click Finish.

- Back in the web app, Windsor.ai now shows a toggle instead of Authorize. Make sure the toggle is on.

Step 11: Start analyzing your data with Gemini
Open the web app and ask about your data, for example:
Show me my Google Ads spend for the last 30 days.

For more questions, browse the Windsor.ai prompt library.
To make a change, ask for it in the same way. Gemini shows the request for review and asks you to confirm it before it runs:
Post a comment "Thanks for the support!" on Instagram media [media_id]
Replace [media_id] with the ID of your post. Comments work on Instagram Business and Creator accounts. If the account was connected to Windsor.ai before comment access was available, reconnect it in Windsor.ai first.

See every available change, by platform, in Windsor.ai write actions.
Important notes
- Data privacy: Gemini Enterprise sends your query to the Windsor.ai API. Google’s model may rewrite the query first, and the rewrite can include parts of your earlier questions in the same session. If other third-party data stores are connected to the app, the query may be sent to them too. Once the query reaches Windsor.ai, our terms of service and privacy policy apply.
- Supported locations: global, US and EU.
- Public preview: the Windsor.ai data store is in public preview under Google’s Pre-GA terms. Support may be limited and the console may change.
- One Windsor.ai data store per app: Google recommends connecting only one data store with actions from the same connector type to an app.
- VPC Service Controls: a VPC Service Controls perimeter cannot be enforced on an existing Windsor.ai data store. To use VPC Service Controls, delete the data store and create it again after enabling them.
Helpful links
- Windsor.ai prompt library: questions to ask about your data.
- Windsor.ai write actions: every change Gemini can make, by platform.
- Google’s Windsor.ai data store documentation: Google’s reference for the same setup.
Get started with Windsor.ai: free forever plan, no credit card. onboard.windsor.ai
FAQs
What does the "Identity provider not configurable" error mean?
It means your project does not belong to an organization, usually because it was created with a personal Gmail account. Use a project created under your organization.
Do I need to fix the "You don't have permissions to fetch Workforce Pools" message?
No. The message only matters for the 3rd Party Identity option. If you select Google Identity, you can ignore it.
Does a project Owner need the Discovery Engine Editor role?
No. The Owner role already includes those permissions, and it shows as Owner in the IAM list.
Why can Gemini read my data but not make changes?
Check both sides:
- In the Google Cloud console, open your data store and click Actions. Execute Action must show as enabled.
- In Windsor.ai, Write actions must be on. See Step 10.
Why can't Gemini find my data after I authorized Windsor.ai?
Data can take about 10 minutes to show up after you connect the data store to the app (Step 9). Wait, then refresh the web app. Also check that the data store status is Active, the Windsor.ai toggle is on in the web app, and the data source is connected in Windsor.ai (Step 1).
Do I need to repeat the setup after connecting a new data source in Windsor.ai?
No. New data sources are available in Gemini Enterprise without repeating the setup.
Does Gemini Enterprise store a copy of my Windsor.ai data?
No. Your data is not indexed or stored in Gemini Enterprise. Each question is sent to Windsor.ai, which returns the answer from your connected sources at that moment.
Is Gemini Enterprise included in my Windsor.ai plan?
No. Google Cloud bills Gemini Enterprise and the data store to the billing account linked to your project. Your Windsor.ai plan is billed separately.
Do I need single-region keys if I choose the US or EU location?
No, not with the default Google-managed encryption key. You need them only if you use your own encryption key (Cloud KMS key). The console shows the single-region key message as soon as you choose US or EU, and with the Google-managed key you can ignore it and continue.
What do I need to use my own encryption key (Cloud KMS key)?
One multi-region key plus three single-region keys: europe-west1, europe-west4 and europe-north1 for EU, or us-east1, us-central1 and us-west1 for US. Create them in Cloud KMS and register them under Settings, then CMEK, before you create the data store. Your security or IT team usually handles this. Registered keys generate Cloud KMS charges even when no data store uses them. See Google’s customer-managed encryption keys guide.
Get started with Windsor.ai: free forever plan, no credit card