> ## Documentation Index
> Fetch the complete documentation index at: https://docs.barndoor.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Google Drive conditional rules

> Filter or block files by their Drive labels on the Barndoor-hosted Google Drive MCP server.

A Google Drive [conditional rule](/how-tos/data-control-center/field-controls/conditional-rules)
matches files by their Google Drive labels. For example, you can remove files
labeled **Confidential** from search results for the Finance group, or block
agents from changing them.

Setup has three steps:

1. [Prepare your Google Drive labels](#1-prepare-your-google-drive-labels) in
   the Google Admin console.
2. [Connect the Google Drive MCP server](#2-connect-the-google-drive-mcp-server)
   in Barndoor so it can read those labels.
3. [Create the conditional rule](#3-create-the-conditional-rule) in Field
   Controls.

This guide applies to the Barndoor-hosted [Google Drive MCP
server](/mcp-servers/google_drive) available in the MCP server directory. It
does not apply to Google's official remote Drive MCP server.

## Prerequisites

You need:

* Admin access to your Barndoor organization
* A Google Workspace edition that supports
  [Drive labels](https://developers.google.com/workspace/drive/labels/guides/create-label)
* At least one published, Drive-enabled label in your Google Workspace
* A Google Workspace user who can view the labels you want Barndoor to discover

## 1. Prepare your Google Drive labels

Barndoor discovers existing labels; it does not create or publish the label
taxonomy. Set up the labels in Google first.

1. Open [Label manager](https://admin.google.com/ac/dc/labels) in the Google
   Admin console, or navigate to **Security → Access and data control → Label
   manager**. You need the **Manage Classification Labels** privilege.
2. On **Classification labels**, create the labels your organization needs.
3. Enable the labels for Drive and publish them. Published Drive-enabled
   labels show **Drive** under **Applications** and **Published** under
   **Status**.

Only published, Drive-enabled labels visible to the connected identity appear
in Barndoor.

<Note>
  If you lack that privilege, Google may send you to `/permissiondenied` or a
  redirect-loop error. That is an authorization failure, not a broken link.
</Note>

<Check>
  Before continuing, confirm that at least one label is published and enabled for
  Drive in Label manager.
</Check>

## 2. Connect the Google Drive MCP server

<Info>
  In this guide, **service account** means the organization-level OAuth connection
  on the Barndoor server detail page. It does not mean a Google Cloud IAM service
  account. Connect a Google Workspace user that can view the labels you need.
</Info>

Barndoor's stored public OAuth credentials for Google Drive include the
restricted `drive.labels.readonly` scope, so most organizations can use them
as-is for label discovery.

1. Navigate to **Admin → MCP Servers**.
2. Add **Google Drive** from the Barndoor-hosted MCP server directory, or open
   an existing Google Drive server.
3. Leave **Use stored public OAuth credentials** enabled unless you already
   use a private client.
4. Confirm **Scopes** includes:

   ```text theme={null}
   https://www.googleapis.com/auth/drive.labels.readonly
   ```

   New servers inherit this from the catalog. An existing server may still have
   an older snapshotted list. If Labels is missing, add it or click **Reset to
   default scopes**.
5. Save the server configuration.
6. On the server detail page, connect the service account that conditional
   rules will use for live label discovery.

If the server was already connected, reconnect it after changing scopes.
Existing OAuth grants do not automatically receive newly added scopes. On the
Google consent screen, confirm that access to Drive labels is included.

`drive.labels.readonly` is the least-privilege scope for label discovery
(`list_labels` / `list_file_labels`). It does not let Barndoor apply labels or
edit files. For that, see [Enable write tools on existing
files](#enable-write-tools-on-existing-files).

<Check>
  The service account connection should show as connected, and the completed
  Google consent flow should include access to Drive labels.
</Check>

### Use a private OAuth client

A private client is optional for label discovery. Keep it if you already
configured one. You need one to [enable write tools on existing
files](#enable-write-tools-on-existing-files), and you may also want one if you
need scopes beyond the catalog defaults or want label traffic to run through
your own Google Cloud project.

1. In a Google Cloud project, enable the
   [Drive Labels API](https://console.cloud.google.com/apis/library/drivelabels.googleapis.com)
   and the
   [Google Drive API](https://console.cloud.google.com/apis/library/drive.googleapis.com).
2. Create a **Web application** OAuth client and add the production redirect
   URI from [Redirect URI Allowlisting](/how-tos/redirect-uri-allowlisting):

   ```text theme={null}
   https://app.barndoor.ai/callback
   ```

   If you are connecting from a Barndoor trial hostname, allowlist that
   hostname's `/callback` URI as well.
3. On **Google Auth Platform → Data Access**, add every scope Barndoor will
   request, including the default Google Drive scopes,
   `drive.labels.readonly`, and `drive` if you need write tools on existing
   files. Adding a scope on Data Access only makes it **available** to
   request. Barndoor must also list it on the server instance, then the user
   must reconnect.

   `drive` is a restricted scope. If your OAuth app's **Audience** is
   **Internal**, users in your Workspace can grant it without Google
   verification. An **External** app needs Google's restricted-scope
   verification first.
4. On the Google Drive server in Barndoor, turn off **Use stored public OAuth
   credentials**, paste the Client ID and Client Secret, confirm **Scopes**
   includes `drive.labels.readonly` (and `drive` for write tools on existing
   files), and save.
5. Connect or reconnect the service account.

<Note>
  The **Drive Labels API** provides the label taxonomy. The **Google Drive API**
  provides file search and file-label access. Enabling the separate **Drive MCP
  API** does not enable these tools.
</Note>

Tenants already on private OAuth can keep it. Switching back to stored public
credentials is optional and is not required for label discovery.

### Enable write tools on existing files

The catalog's default write scope is `drive.file`, which only covers files
the Barndoor OAuth app created or that the user opened with it. Write tools
called on any other file, which includes most of your existing Docs, Sheets,
and folders, fail with `appNotAuthorizedToFile`. This applies to
`update_file_labels` as well as `update_file`, `rename_file`, `move_file`, and
`create_permissions`.

To let these tools act on existing files, an admin must:

1. Add the full Drive scope to the Google Drive server's **Scopes**:

   ```text theme={null}
   https://www.googleapis.com/auth/drive
   ```

2. Switch the server to your own OAuth client. Barndoor's stored public OAuth
   credentials do not include the `drive` scope, so turn off **Use stored
   public OAuth credentials** and follow [Use a private OAuth
   client](#use-a-private-oauth-client).

3. Reconnect the service account and any users who already connected, and
   approve the new Drive access on the Google consent screen.

<Warning>
  `drive` grants read and write access to every file the connected user can
  access. Use [Field Controls](/how-tos/data-control-center/field-controls) and
  [MCP Policies](/how-tos/data-control-center/mcp-policies) to limit which
  tools agents can call and what they can see.
</Warning>

`update_file_labels` also needs the connected user to have permission to apply
that label, as configured in Label manager.

Without the `drive` scope, an agent can still work on a copy: `copy_file`
creates a file the connector owns, and write tools can change that copy.
People working on the original file won't see those changes.

## 3. Create the conditional rule

With labels published and the service account connected, you can build the
rule.

1. Navigate to **Data Control Center → Field Controls**.
2. Click **Add Conditional Rule**.
3. Enter a **Name** and select your Google Drive server under **Server**.
4. Optionally, add groups or roles under **Target Group / Role**. Leave it
   empty to apply the rule to all users.
5. Under **When**, select **Labels**, then choose one or more labels or label
   options. See [Choose labels and label
   options](#choose-labels-and-label-options).
6. Under **Applies to**, choose **All tools**, **Read** (tool results), or
   **Write** (create, update, and delete calls).
7. Under **Then**, choose **Filter** to remove matching files from results, or
   **Block** to deny matching calls or results. **Filter** isn't available for
   **Write**: writes are always blocked outright.
8. Click **Add Rule**.

<img src="https://mintcdn.com/barndoor/jYjKzlrvisdEId-v/images/data-control-center/platform-data-protection-conditional-rules-dialog-drive--live-labels.png?fit=max&auto=format&n=jYjKzlrvisdEId-v&q=85&s=53a5c679c2b8dff85a7fef8c15a60531" alt="Add Conditional Rule dialog for Google Drive with the Confidential and RESTRICTED labels selected, applying to Read with the Filter action" width="1344" height="1924" data-path="images/data-control-center/platform-data-protection-conditional-rules-dialog-drive--live-labels.png" />

The live list is loaded with the service account connection on the selected
Google Drive server. If the service account isn't connected, the **When**
section prompts you to connect it. Click **Connect service account**, complete
the OAuth flow, and retry the search.

<img src="https://mintcdn.com/barndoor/jYjKzlrvisdEId-v/images/data-control-center/platform-data-protection-conditional-rules-dialog-drive-labels--managed-connect--when.png?fit=max&auto=format&n=jYjKzlrvisdEId-v&q=85&s=6f2edc8a8547dc6b98d6f8cde4a352de" alt="When section prompting you to connect the service account to load Drive labels" width="1244" height="540" data-path="images/data-control-center/platform-data-protection-conditional-rules-dialog-drive-labels--managed-connect--when.png" />

<Check>
  Your organization's published labels should appear in the live results when
  you search under **Labels**.
</Check>

### Choose labels and label options

The **Labels** list includes every published label the service account can see,
plus each option of a label's selection fields, listed by its display name. For
example, a **Sensitivity** label with **Confidential** and **Internal** options
appears as three entries.

| You select | The rule matches |
| - | - |
| A label | Any file that has the label applied, whatever its field values |
| A label option | Files where that option is selected on the label |
| A typed title | Labels or options whose title matches, ignoring case |
| A pattern with `*` (for example `CONFIDENTIAL-*`) | Every label or option whose title matches the pattern |

Pick from the list where you can. Listed labels and options are matched by ID,
so the rule keeps working if someone renames the label. Typed titles and
patterns are matched by title, so renaming a label can break them. Use them for
labels the service account can't see. If you type the title of a label that is
listed, Barndoor uses the listed label instead.

Typed titles follow these rules:

* Case is ignored, but spaces, `-`, and `_` must match exactly:
  `Confidential-*` does not match **Confidential Internal**.
* Titles can use letters, numbers, spaces, `-`, and `_`, with `*` as a
  wildcard. For a title with other characters, pick the label from the list.
* `*` on its own isn't allowed, because it would match every labeled file. Pick
  the labels to cover, or add text around the `*`.

<img src="https://mintcdn.com/barndoor/jYjKzlrvisdEId-v/images/data-control-center/platform-data-protection-conditional-rules-value-picker--drive-live-labels.png?fit=max&auto=format&n=jYjKzlrvisdEId-v&q=85&s=d48c85173e97d1e3408315e2bf514cfa" alt="When section with the listed label Confidential and the typed title Confidential-* selected" width="1664" height="556" data-path="images/data-control-center/platform-data-protection-conditional-rules-value-picker--drive-live-labels.png" />

### What a rule matches

* **Read** checks the files that Google Drive tools return, such as search,
  list, get, and export results. **Filter** removes matching files and returns
  the rest. **Block** denies the whole result if any file matches. Files
  without a matching label pass through.
* **Write** checks the file a write tool acts on, for example `update_file`,
  `rename_file`, `move_file`, `trash_file`, `create_permissions`, or
  `update_file_labels`. Barndoor looks up the target file's labels before the
  call runs and blocks the call if they match.
* **All tools** applies both checks.

## Verify the setup

You can verify label discovery in either place:

* In **Field Controls**, the **Labels** condition of a conditional rule shows
  your published label titles in the live results.
* Through the Google Drive MCP server, the `list_labels` tool returns the
  published label taxonomy.

To verify a label on a specific file, apply the label in Google Drive and call
`list_file_labels` with that file's ID.

## Troubleshooting

<AccordionGroup>
  <Accordion title="list_labels returns a 403 for drivelabels.googleapis.com">
    On stored public OAuth, the Drive Labels API must be enabled on Barndoor's
    managed Google Cloud project. Contact Support if the error persists after
    you reconnect.

    On a private OAuth client, enable the **Drive Labels API** on the Google
    Cloud project that owns that client. Wait a few minutes, then retry.
  </Accordion>

  <Accordion title="File search returns a 403 saying the Drive API is disabled">
    On stored public OAuth, contact Support. On a private client, enable the
    **Google Drive API** on the same project, wait a few minutes, and retry.
  </Accordion>

  <Accordion title="The Google consent screen omits Labels or Drive file scopes">
    In Field Controls, the **When** section reports that the connected Google
    identity did not grant access to read Drive labels.

    <img src="https://mintcdn.com/barndoor/jYjKzlrvisdEId-v/images/data-control-center/platform-data-protection-conditional-rules-dialog-drive-labels--scope-required-managed--when.png?fit=max&auto=format&n=jYjKzlrvisdEId-v&q=85&s=f6a36d52241e13412f50ca732cf46bb4" alt="When section reporting that the connected Google identity did not grant access to read Drive labels, with a Reconnect service account button" width="1244" height="690" data-path="images/data-control-center/platform-data-protection-conditional-rules-dialog-drive-labels--scope-required-managed--when.png" />

    Confirm that **Scopes** on the Google Drive server includes
    `drive.labels.readonly`. If the instance still has an older snapshotted
    list, add the scope or click **Reset to default scopes**, then reconnect
    the service account. Existing grants do not receive new scopes
    automatically.

    If you use a private OAuth client, also confirm that **Data Access** on
    that client lists every scope Barndoor will request, including the default
    Drive scopes and `drive.labels.readonly`.
  </Accordion>

  <Accordion title="Label manager shows permission denied or a redirect loop">
    You are not authorized for [Label
    manager](https://admin.google.com/ac/dc/labels). Ask a Google Workspace
    super admin to grant **Manage Classification Labels**, then retry. The
    URL is correct even when Google redirects to `/permissiondenied`.
  </Accordion>

  <Accordion title="No published Drive labels are visible">
    <img src="https://mintcdn.com/barndoor/jYjKzlrvisdEId-v/images/data-control-center/platform-data-protection-conditional-rules-dialog-drive-labels--no-visible-labels--when.png?fit=max&auto=format&n=jYjKzlrvisdEId-v&q=85&s=4d47162bf68e7c121e25226f5b3c9a43" alt="When section reporting that no published Drive labels are visible to the connected Google identity, with a Retry button" width="1244" height="738" data-path="images/data-control-center/platform-data-protection-conditional-rules-dialog-drive-labels--no-visible-labels--when.png" />

    Confirm that the labels are published, enabled for Drive, and visible to the
    Google Workspace user connected through Barndoor's organization-level
    service account connection. An empty list usually means the API and OAuth
    grant are working but that user cannot see any eligible labels. You can
    still type a label title or a pattern for a label that isn't listed.
  </Accordion>

  <Accordion title="A write tool returns appNotAuthorizedToFile">
    The default `drive.file` scope can write only files this OAuth app created
    or that the user opened with it. Adding `drive.labels` does not change
    that. Add the `drive` scope on a private OAuth client and reconnect. See
    [Enable write tools on existing
    files](#enable-write-tools-on-existing-files). Otherwise, apply the label
    in the Drive UI, or have the agent edit a copy made with `copy_file`.
  </Accordion>
</AccordionGroup>

## Limitations

* Barndoor discovers existing labels but does not create or publish the label
  taxonomy. There is no `create_label` tool on the Google Drive connector.
* Reading labels on an existing file works with the default scopes. Applying
  labels or running other write tools on files Barndoor did not create needs
  the `drive` scope on your own OAuth client.
* Stored public OAuth is enough for label discovery. A private client is
  optional unless you need write tools on existing files.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.