Configure Canvas

This page describes how administrators can set up and configure Canvas in Gemini Enterprise for their users.

Canvas is generally available in the global, US, and EU regions. It is available for users of Gemini Enterprise Business edition, Standard and Plus editions.

Before you begin

Canvas is disabled by default. You can review and test Canvas before you choose to enable it for users.

To enable Canvas for your users, complete the following setup:

Turn on Canvas on the Gemini Enterprise app

For users to access the Canvas feature, a Gemini Enterprise administrator must turn on the Enable canvas toggle in the web app feature management settings. For more information, see Manage web app features.

Add Canvas permissions to a custom IAM role

Ensure users have the required permissions for Canvas:

  • Predefined roles: Users accessing Gemini Enterprise with standard roles like roles/discoveryengine.user don't need to make any changes, as the necessary permissions are included in the predefined roles.

  • Custom roles: For users accessing Gemini Enterprise using custom IAM roles, you must add the immersiveArtifacts permissions to the custom role. Without these permissions, users can't use Canvas. Canvas requires the following permissions:

    • discoveryengine.immersiveArtifacts.create
    • discoveryengine.immersiveArtifacts.delete
    • discoveryengine.immersiveArtifacts.export
    • discoveryengine.immersiveArtifacts.get
    • discoveryengine.immersiveArtifacts.list
    • discoveryengine.immersiveArtifacts.navigate
    • discoveryengine.immersiveArtifacts.update

    Because the permissions required for Canvas are in preview, you can't add them using the Google Cloud console. Instead, use the gcloud CLI. For example, to add these permissions to an existing project-level custom role, run the following command:

    gcloud iam roles update ROLE_ID \
      --project=PROJECT_ID \
      --add-permissions=discoveryengine.immersiveArtifacts.create,discoveryengine.immersiveArtifacts.delete,discoveryengine.immersiveArtifacts.export,discoveryengine.immersiveArtifacts.get,discoveryengine.immersiveArtifacts.list,discoveryengine.immersiveArtifacts.navigate,discoveryengine.immersiveArtifacts.update
    

    For more information about managing Gemini Enterprise IAM roles, see Access control with IAM.

Limitations

Canvas isn't supported on the mobile app. It is only available on the web app.

Quota consumption

Canvas queries and regular Gemini Enterprise app chat queries are counted in the same way and share the same quota.

Gemini Enterprise app displays the Usage limit reached error message when you chat with the assistant or use Gemini Enterprise features in either of the following scenarios:

  • Your project reached its monthly spend cap.
  • Your project exceeds its pooled quota limit for a specific feature and your Gemini Enterprise administrator hasn't enabled overages.

This error affects only the feature that reached its limit. You can continue using other features that have remaining quota.