Skip to main content

BigQuery

BigQuery is Google Cloud's serverless data warehouse. The Glean BigQuery connector lets Glean Assistant query and analyze your BigQuery datasets on demand, so users can ask analytical questions in natural language and get answers computed against your warehouse at request time.

info

BigQuery is a tools-only connector. Glean does not crawl or index BigQuery tables, and BigQuery rows do not appear in Glean search results. Every request runs as a live query against BigQuery.

How it works​

Glean connects to Google's BigQuery service at https://bigquery.googleapis.com/mcp over HTTP, using Glean-managed central OAuth. Admins do not need to create an OAuth client or provide a client ID, client secret, or callback URL.

Because authentication is per user, results always reflect the requesting user's own Google Cloud access. A user can only access the projects, datasets, and tables that their Google account and IAM roles allow. Glean does not build a separate permission index for BigQuery, and the connector does not accept service account keys or API keys.

Supported tools​

After you connect, the setup page advances to the Tools step and lists the tools currently available for BigQuery:

ToolPurposeAccess
list_dataset_idsList the datasets in a projectRead-only
list_table_idsList the tables in a datasetRead-only
get_dataset_infoInspect metadata for a datasetRead-only
get_table_infoInspect a table's schemaRead-only
execute_sql_readonlyRun read-only SQL, rejecting statements that modify data or schema and Python user-defined function statementsRead-only
execute_sqlRun SQL, including statements that modify dataRead and write
get_query_resultsRetrieve query results, check whether a query has completed, and fetch additional result pagesRead-only
get_jobInspect a job's status and statisticsRead-only
cancel_jobCancel a running BigQuery jobNot read-only

For per-tool behavior and the current tool list, see Google's BigQuery documentation.

note

execute_sql can modify data, and cancel_job can cancel running jobs. These tools are not read-only. To limit Glean to read-only tools, use a Google Cloud IAM deny policy to restrict both tools by name or by the read/write attribute.

Google may change the tools exposed through the BigQuery MCP server. Review the Tools step in the Admin console to confirm the tools currently available.

Requirements​

Google Cloud requirements​

  • A Google Cloud project. Enable the BigQuery API on each project where you want to use the BigQuery MCP server.
  • The BigQuery API is enabled by default for new projects. The administrator who enables it needs the Owner or Service Usage Admin role, which carries the serviceusage.services.enable permission.
  • The following roles, granted on the project to every end user who will query BigQuery through Glean:
RolePurpose
roles/mcp.toolUserMake tool calls
roles/bigquery.jobUserRun BigQuery jobs
roles/bigquery.dataViewerRead BigQuery data

These roles enable standard MCP access and read-only queries. DML or DDL operations may require additional BigQuery permissions on the target resources, such as roles/bigquery.dataEditor or equivalent granular permissions.

Glean requirements​

  • Access to the Glean Admin console.

Configuration and setup​

Complete steps 1 and 2 in Google Cloud, then step 3 in the Glean Admin console.

Step 1: Enable the BigQuery API​

Enable the BigQuery API on the project you want to connect. The BigQuery remote MCP server is enabled automatically when you enable the BigQuery API. See Google's Before you begin for details.

Step 2: Grant the required IAM roles​

Grant roles/mcp.toolUser, roles/bigquery.jobUser, and roles/bigquery.dataViewer on the project to each user who will query BigQuery through Glean. You can do this from the IAM page in the Google Cloud console, or from the command line:

gcloud projects add-iam-policy-binding PROJECT_ID \
--member="user:USER_EMAIL" --role="roles/mcp.toolUser"

gcloud projects add-iam-policy-binding PROJECT_ID \
--member="user:USER_EMAIL" --role="roles/bigquery.jobUser"

gcloud projects add-iam-policy-binding PROJECT_ID \
--member="user:USER_EMAIL" --role="roles/bigquery.dataViewer"

Replace PROJECT_ID with your project ID and USER_EMAIL with the user's email address.

Step 3: Connect BigQuery in Glean​

  1. In the Glean Admin console, go to Connectors → Add connector → BigQuery.
  2. Enter a Display name. This is what Glean Assistant calls the connection, for example BigQuery.
  3. Configure Maximum data processed per query (GiB). If blocked-resource restrictions are enabled for your workspace, optionally configure Blocked datasets and Blocked tables. See Query restrictions for the accepted formats and behavior.
  4. Select Save, then Authorize. Glean opens Google's consent flow and requests the https://www.googleapis.com/auth/bigquery scope so that Glean Assistant can query datasets on your behalf.

After consent completes, the setup page advances to the Tools step and lists the BigQuery tools that Glean Assistant can use.

Query restrictions​

During BigQuery setup, configure Maximum data processed per query (GiB). This required per-query limit defaults to 5,120 GiB (5 TiB) and must be a positive whole number. The limit applies to each query, not to a daily or monthly quota.

If blocked-resource restrictions are enabled for your workspace, you can also configure these optional fields:

  • Blocked datasets: Enter exact dataset names in project.dataset format. For a domain-scoped project ID, the project portion can contain dots before the colon, such as example.com:analytics.sensitive_dataset.
  • Blocked tables: Enter exact table names in project.dataset.table format, such as my-project.sensitive_dataset.sensitive_table.

Wildcards and pattern-based entries are not supported. Before Glean runs execute_sql or execute_sql_readonly, it performs a dry run to validate the query and estimate the amount of data processed. Glean rejects a query before execution when it references a blocked dataset or table or when its estimated bytes processed exceed the configured limit. An estimate equal to the configured limit is allowed. Metadata tools are not subject to this byte limit.

When blocked datasets or tables are configured, the following statement-type restrictions apply:

  • execute_sql_readonly allows only SELECT statements.
  • execute_sql allows SELECT, INSERT, UPDATE, DELETE, MERGE, CREATE TABLE, CREATE TABLE AS SELECT, ALTER TABLE, DROP TABLE, and DROP VIEW statements.

If Glean cannot safely validate a query, it fails closed and does not execute the query. This can occur when BigQuery returns incomplete referenced-table metadata, when a query references 50 or more tables and the list may be truncated, or when the query uses an unsupported statement type such as a SCRIPT or dynamic multi-statement query while blocked datasets or tables are configured.

The maximum-data setting is an additional safeguard, not a billing guarantee. Continue to use least-privilege IAM and your normal BigQuery cost and quota controls.

Verify the connection​

  1. As an end user with the three required IAM roles, open Glean Assistant.
  2. Ask a question that requires warehouse data, for example a count or an aggregation over a table you can read in BigQuery.
  3. Confirm that a BigQuery tool fires and that the answer reflects live data.
  4. Ask the same question as a user who does not have access to that dataset in BigQuery, and confirm that the query is rejected.

Permissions and security​

  • Per-user authentication: Glean authenticates to BigQuery on each user's behalf. Every query runs under the requesting user's Google account, and BigQuery enforces that user's IAM roles and dataset access.
  • No indexed copy: BigQuery rows are not crawled or indexed into Glean Search. Query results may appear in the Assistant conversation and, when tool-trace externalization is enabled, tool descriptions, arguments, and results may be exported to a customer-configured OTLP endpoint.
  • Authentication: New connections use Glean-managed central OAuth. Service account keys and API keys are not supported.
  • Restricting writes: To prevent data changes, use a Google Cloud IAM deny policy to restrict the execute_sql tool by name or read/write attribute, or deny the relevant BigQuery write permissions.

Limitations​

  • BigQuery data is not indexed and does not appear in Glean search results.
  • Query results are limited to a maximum of 3,000 rows.
  • execute_sql and execute_sql_readonly limit query processing time to three minutes. Longer queries are canceled automatically.
  • Google Drive external tables cannot be queried through the SQL tools.
  • execute_sql_readonly rejects DML statements, DDL statements, and Python UDFs.

For current limits, see Google's BigQuery documentation.

Troubleshooting​

See also​

  • Google Cloud tools — a separate integration, configured under Admin console → Tools, that includes SQL and analytics tools for BigQuery.