Key Takeaways

  • The September 3 rollout adds Gemini Notebook logs for eligible Workspace audit and investigation tools.
  • Useful fields include the actor, event time, source identifiers, and sharing visibility; not every field appears for every event.
  • Admin-console visibility and BigQuery export are different controls with different setup requirements.
  • Log location should not be confused with the storage location of notebooks, source documents, and chats.

Google Workspace administrators can now inspect Gemini Notebook activity through the Admin console’s audit tools. The September 3 rollout adds visibility into actions and resource context, but exporting those records to BigQuery remains a separate configuration that is off until enabled.

There is also a data-location boundary worth understanding before making an internal promise: Google says the underlying notebooks, sources, and chat histories remain globally stored without data regionalization. Choosing a location for exported logs does not relocate the notebook content.

Hero: Construction at Google's Mountain View campus, June 2019. Archive context photograph; Gemini Notebook logs are not shown. Photo by Gregory Varnum, source, CC BY-SA 4.0. Cropped and resized by ToolSurge; derivative retains the same license.

Start with the question the log should answer

The new records are useful when an administrator needs to reconstruct an action: who interacted with a resource, when a sharing change occurred, or which source was involved. That is a different job from asking whether a generated summary was accurate or useful.

Google’s rollout announcement describes the feature for customers with access to the relevant audit and investigation tools. It names user identity, IP information, resource context, and notebook visibility among the available categories. The rollout began September 3 and may take up to 15 days to become visible.

Our recommendation is to choose one operational question first. “Show relevant sharing changes for this notebook” is easier to validate than “monitor all AI risk.” A narrow question tells you which fields, permissions, and retention settings matter.

For an end user’s research workflow, our NotebookLM review discusses working with source material. This update is about administrator evidence around that activity, not a new guarantee about the content an AI produces.

Example query results in the BigQuery console, not Gemini Notebook audit records
The BigQuery quickstart's example query-results interface. This sample is not a Gemini Notebook audit dataset; administrators query their own exported records after configuring access and export. Unmodified official documentation screenshot. Credit: Google, source, CC BY 4.0.

Find the right data source and verify your access

The event documentation directs administrators to Reporting, Audit and investigation, then Gemini Notebook log events. It identifies an Audit & Investigation privilege for that path. The separate security investigation interface has its own administrative access requirement.

Begin with a small date range and an event or actor filter. Google says the default view covers the previous seven days and can be changed. The event time is displayed in the browser’s default time zone, so record the zone when comparing a console result with another log or support report.

An empty result has several possible explanations: the wrong date window, a filter that excludes the action, insufficient access, no relevant activity, or a feature not yet visible for that account. It does not independently prove that nobody used the product.

For a validation exercise, ask an authorized colleague to perform a harmless action on a test notebook, record the approximate time, and inspect the matching event. This is a proposed setup check; we did not access a private Workspace tenant or measure this rollout’s latency ourselves.

Use identifiers before drawing conclusions from names

Google documents fields for the actor, event, source ID, source name, source type, source URL, artifact information, and prior or current visibility. It also cautions that not all attributes are reported for every event and that the list can change.

Our practical advice is to keep the resource identifier with the human-readable name. Names are convenient in a report but can be duplicated or changed. An identifier gives the next investigator a more stable point to inspect.

Treat an IP address carefully. Google notes that it can represent a proxy or VPN rather than the user’s physical location. Use it as one piece of context, not as a definitive statement that someone was in a particular city or personally performed an action from that place.

Choose the displayed columns to match your question. A concise table with actor, time, event, resource ID, and visibility is easier to review than a wide export full of fields that nobody uses. Add other attributes when they resolve a specific uncertainty.

A console export is not a continuous pipeline

The event guide supports exporting search results to Sheets or CSV, with limits that depend on the available tool. That is useful for a focused investigation or a one-off report. It should not be mistaken for a continuously maintained BigQuery dataset.

The BigQuery setup guide describes a separate Admin-console configuration under Reporting and Data integrations. You select a Cloud project, configure the required access, and choose a new dataset. Activity-log export requires billing to be enabled for the project; the documentation says sandbox mode does not export that activity-log data.

Those are meaningful operational choices. Decide who owns the project, who can read the exported records, and who is responsible for its ongoing cost. Turning on an export without identifying those owners creates a second copy of sensitive operational information that can outlive the original purpose.

Start with the console if it already answers the question. Add a continuous export when you need repeatable analysis, joins with other evidence, or an explicitly maintained reporting workflow.

Regional logs do not mean regional notebooks

The launch makes a specific distinction: audit-log storage follows Workspace’s regional routing policies, while Gemini Notebook user data is globally stored and does not currently support regionalization. An export dataset’s location is another configuration choice within that larger picture.

In an internal review, list those data categories separately. A row for exported logs should not silently stand in for source documents, notebook contents, chat histories, or other copies. This is a way to make the system understandable, not a claim that choosing one setting satisfies every organizational requirement.

If a team has a firm location requirement, take the provider’s exact statement to the person responsible for that requirement. Do not translate “we can choose an export region” into “all AI data stays in that region.” The announcement does not support that conclusion.

The broader lesson is similar to the boundary in our Copilot content-exclusion guide: a control has value when its precise scope is understood. Adjacent controls do not automatically inherit its behavior.

Verify the dataset you actually receive

Once export is configured, inspect the created dataset, available tables, timestamps, and access permissions. Compare a known test event with the console view. Your acceptance evidence should show that the expected record reached the intended destination, not just that the settings page saved successfully.

Google says BigQuery exports and the Reports API do not have identical filtering capabilities. In particular, its export guide warns against assuming that a Reports API organizational-unit parameter has a corresponding BigQuery column. Inspect the schema before adapting an existing report query.

The same guide discusses table expiration and backfill in several sections that are not fully consistent. Rather than deriving a retention promise from one sentence, inspect the actual dataset and table expiration configuration and confirm the current provider guidance before relying on it. Record what your configuration demonstrably retains.

Our recommended report includes the collection window, time zone, data source, latest observed event, and any missing field relevant to the question. Those details help another administrator distinguish a real behavioral change from a query or collection change.

What happens next

Choose a small operational use case, verify a known event, and decide whether the console is sufficient. If you enable export, give its destination, permissions, retention, and cost explicit owners. Review the resulting records before building alerts on top of them.

An alert should point to an action someone can take. A flood of notifications about ordinary activity can obscure the one event that needs attention. Start with a clearly defined condition, inspect representative matches, and refine it when actual results show the condition is too broad.

The release provides more visibility. The useful outcome is a question your team can answer from identifiable records, with the limits of those records understood.

Quick poll

Which evidence would be most useful to your team?

Our take: verify one known event before building a broader monitoring workflow.

FAQ

Are BigQuery exports enabled automatically? No. The launch says the export remains disabled until an administrator turns it on.

Does a regional log dataset regionalize notebook content? No. Google explicitly says notebooks, sources, and chat histories remain globally stored without data regionalization.

Will every event contain every documented field? No. The Help Center says attributes vary by event and the list is not exhaustive.

Does an empty search prove there was no activity? No. First check the account’s access, date range, time zone, filters, and a known test event.