There is a particular flavour of frustration in an AI that can describe your problem in perfect detail and then do nothing about it. That is the story in Android Police’s piece on Drive cleanup: the author’s Google Drive root is a landfill of nameless PDFs and screenshots, Gemini can survey the mess and offer commentary, but Google’s chat integration with Drive is read-only by design. Google actually shipped file-moving by natural language for nine months, then pulled it in April 2026. Meanwhile Claude’s Google Workspace connectors picked up write access in August — create folders, move files, upload, review recent changes — with an approval prompt on every action by default. The author pointed it at the pile and it sorted it, well enough to catch an invoice whose filename date disagreed with the date printed inside it.
I find this comparison genuinely interesting, and not because of which company wins. It is a preview of a decision every small business and homelab is about to face: when do you let an AI agent act, instead of advise? And the answer is never “flip the switch and let it work.” It is a pattern — plan, confirm, apply — that keeps the hands attached to a brain you trust.
Read-only AI is a consultant; write-access AI is a tool
A read-only assistant generates a report about your mess. It might even generate a beautiful folder structure proposal. Then you spend your Saturday executing it. That is the consultant arrangement, and it is exactly as useful as it sounds when the mess is eleven hundred files deep. The entire value of an agent is that the doing is included. Google’s caution is not wrong — giving a language model delete rights over a shared drive is a genuinely scary idea — but the resolution is not “never act.” The resolution is acting inside guardrails that make mistakes cheap and visible.
The pattern: plan, confirm, apply
Split the job into three phases and never let the agent collapse them:
- Plan. The agent inventories and proposes: every file it would touch, where it would move it, what it would rename it, what it would flag for human review. Nothing is modified. For a messy Drive, this is a document listing a few hundred operations, sorted by the agent’s confidence.
- Confirm. You review the plan — not every line, but the shape of it, plus every low-confidence item. This is the phase Anthropic’s approvals-on-by-default gives you for free, and it is the one worth keeping even after you trust the setup. The Android Police author had it right: the default is confirm-before-execute, and if you turn that off, you had better have a backup.
- Apply. The agent executes the approved plan. Ideally into a recycle bin or a staging folder first, not the void.
The magic is that the phase boundary gives you an audit trail for free. When someone asks “why is the 2024 invoices folder organised by vendor,” the answer is a document, not archaeology.
Guardrails that earn their keep
- Least privilege, enforced by accounts, not promises. The agent gets its own account with access to exactly one subtree — the shared “incoming” folder or the project directory. It cannot rearrange Finance’s area because it has no rights there. Scope in the connector settings, not in the prompt; a prompt is a suggestion, an ACL is a fact.
- Snapshot before bulk operations. Any agent run that will touch more than a dozen files starts from a restorable state. For anything on my own storage that means a copy to object storage first:
rclone copy /srv/share/incoming btrfs-snapshots:pre-agent/$(date +%F-%H%M) --transfers 8
- Rate-limit the blast radius. Cap the number of operations per run. If the plan is 1,400 moves, do 200 at a time and spot-check between batches. A bad pattern that survives 200 operations is contained; one that survives 1,400 is your weekend.
- Log what it did. Write the operation log somewhere durable. “The AI cleaned it up” is not an audit record; a list of source and destination paths is.
Make it recurring so the landfill never forms
The most telling line in the original piece is that the cleanup “barely scratched the surface” of the backlog. Of course it did — backlogs are formed by neglect over years, and they are re-formed by neglect in months. The win is not one heroic archaeology session; it is a small scheduled pass. A weekly or monthly run that sorts new arrivals into the structure, confirms the plan with you, and applies it. Ten minutes of review a week instead of a lost Saturday a year. Whatever your platform — Drive connectors, or the same pattern pointed at a Nextcloud mount or a Samba share with any scripted agent — the recurring cadence is the actual product.
Treat agents like keen junior sysadmins
The mental model that keeps all of this safe: an AI agent is a junior sysadmin with infinite energy, strong opinions about taxonomy, and no sense of which file is load-bearing. You would absolutely hand that person a broom — scoped to one room, with you checking the plan before they touch the filing cabinet. You would not hand them root and a free afternoon. Write-access AI is finally useful for exactly the same reason it is a little unnerving: it stops asking and starts doing. Give it hands, keep the confirmation gate, and point it at a room you can afford to have tidied.

