نطاقات OAuth وأذونات خطوات مسار Workspace Studio

عند إنشاء مسارات عمل آلية وتشغيلها في Google Workspace Studio، يتم تضمين الأمان وخصوصية البيانات تلقائيًا. يستخدم Workspace Studio نموذج هوية بأقل امتيازات، ما يعني أنّ العمليات التلقائية تنفّذ مهامًا في الخلفية باستخدام الحد الأدنى من الأذونات المطلوبة لتنفيذ كل إجراء فردي، بدلاً من الحصول على إذن وصول واسع النطاق وغير مقيّد إلى حساب المستخدم بالكامل على Google.

لإعداد عملية التشغيل الآلي بأمان والحفاظ على إمكانية الاطّلاع على كيفية الوصول إلى بيانات مؤسستك، استخدِم هذا الدليل لتحديد الأذونات المطلوبة لكل خطوة في المسار. تقدّم هذه الصفحة عملية ربط بين كل نوع من أنواع خطوات سير العمل ونطاقات Open Authorization (OAuth) المطلوبة.

تأثير نطاقات OAuth على استخدامك لـ Studio

عند استخدام Workspace Studio، تؤثّر نطاقات OAuth في طريقة إنشاء عمليات سير العمل وتنفيذها وإدارتها بالطرق التالية:

  • تفويض لمرة واحدة: في المرة الأولى التي تضيف فيها خطوة تتفاعل مع إحدى خدمات Google (مثل Gmail أو Google Drive)، سيَظهر لك طلب من Google لتأكيد تسجيل الدخول. يمنح هذا الإذن النطاق المحدّد لهذه الخطوة حتى يتمكّن المسار من العمل بشكل مستقل في الخلفية.
  • التنفيذ غير المتزامن في الخلفية: بعد تفعيل أحد المسارات، يتم تنفيذه بشكل غير متزامن على بنية Google الأساسية. ينفّذ سير العمل المهام (مثل جدولة حدث في "تقويم Google" أو كتابة مسودة) باستخدام النطاقات المحدّدة التي وافقت عليها فقط، حتى عندما تكون غير مسجّل الدخول بشكل نشط.
  • إشراف مركزي للمشرف: بصفتك مشرفًا، يمكنك الاطّلاع على جميع المحادثات النشطة في مؤسستك باستخدام إعدادات إدارة أذونات الوصول إلى الوكيل في "وحدة تحكّم المشرف". يمكنك إيقاف تدفقات معيّنة مؤقتًا أو استهداف نطاقات OAuth الفردية وتقييدها (مثل إزالة إذن الوصول إلى Drive مع إبقاء Gmail نشطًا) للحفاظ على أمان بيانات مؤسستك. مزيد من المعلومات

تحديد المشاكل في الأذونات غير الكافية وحلّها

إذا لم يتم تشغيل أحد التدفقات وظهر الخطأ "أذونات غير كافية" أو "حدث خطأ" في سجلّ الأنشطة، تحقّق مما يلي:

  • إعادة تفويض سير العمل: افتح سير العمل في "أداة الإنشاء"، وانقر على حفظ التغييرات، واتّبِع أي طلبات تظهر في مربّع التفويض لتحديث رموز OAuth المميزة المنتهية الصلاحية أو غير المتوفّرة.
  • عمليات الحظر في "الوصول الواعي بالسياق" (CAA): إذا كانت مؤسستك تفرض سياسات الجهاز أو عنوان IP بشكل صارم، قد يتم حظر عمليات تنفيذ سير العمل في الخلفية في بعض الأحيان. تأكَّد من أنّ معرّف عميل Workspace Studio الأساسي معفى من قيود CAA.

خطوات المسار ونطاقات OAuth المطلوبة

يوضّح هذا الجدول خطوات Workspace Studio العادية ونطاقات OAuth التي تتطلّبها كل خطوة للتشغيل وراء الكواليس.

اسم الخطوة الضبط والنطاق
خطوات الذكاء الاصطناعي في Studio
العمليات الأساسية في AIP (اسأل Gemini، اسأل Gem، أنشئ باستخدام Gemini، Deep Research، تلخيص الرسائل الإلكترونية غير المقروءة، استخراج، اتّخاذ قرار، تلخيص) https://www.googleapis.com/auth/drive
https://www.googleapis.com/auth/documents
https://www.googleapis.com/auth/spreadsheets
https://www.googleapis.com/auth/cloud_search.query
التطبيقات العامة والمساعدة
وفقًا لجدول زمني غير متاحة
إرسال ويب هوك لا ينطبق - جهة خارجية
التحقّق مما إذا لا ينطبق - منطق داخلي
فلترة قائمة لا ينطبق - منطق داخلي
Gmail
عند تلقّي رسالة إلكترونية https://www.googleapis.com/auth/gmail.readonly https://www.googleapis.com/auth/gmail.event_trigger https://www.googleapis.com/auth/workspace.workflows.trigger 
إرسال إشعار إلى بريدي الإلكتروني https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly
إرسال رسالة إلكترونية https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
كتابة مسودة رسالة إلكترونية https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly
إعادة توجيه رسالة إلكترونية https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
صياغة ردّ https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
الردّ على رسالة إلكترونية https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
إضافة تصنيفات أو إزالتها https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
وضع علامة "مقروءة" أو "غير مقروءة" https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
تمييز رسالة بنجمة أو إلغاء تمييزها https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
الأرشفة (أو الحذف) https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
Google Chat
عند انضمام مستخدم إلى مساحة https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
عند تلقّي رسالة محادثة https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
عند الإشارة إليّ https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
عند إضافة تفاعل باستخدام إيموجي https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
إشعاري في Chat https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships
إرسال مساحة Chat https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces.create https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
الإرسال إلى مستخدمين آخرين https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships
الردّ على رسالة https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships
جداول بيانات Google
عند تغيير ورقة البيانات https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly
إضافة صف https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
تعديل الصفوف https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
محو الصفوف https://www.googleapis.com/auth/spreadsheet https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
الحصول على محتوى ورقة البيانات https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
مستندات Google
إنشاء مستند Google https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly
الإضافة إلى مستند https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly
"تقويم Google" و"مهام Google"
استنادًا إلى اجتماع https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/calendar.events.readonly 
إنشاء مهمة https://www.googleapis.com/auth/tasks
إنشاء حدث https://www.googleapis.com/auth/calendar.events
إضافة مدعوين https://www.googleapis.com/auth/calendar.events
Google Drive
عند إضافة عنصر إلى مجلد https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly
عند تعديل ملف https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
عند تعديل ملف في مجلد https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly
نقل الملف https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
نسخ الملف https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
حفظ المرفقات https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
إنشاء مجلد https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
Google Meet
عند استخدام ملاحظات الاجتماع https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.meet.readonly https://www.googleapis.com/auth/meetings.space.created https://www.googleapis.com/auth/calendar.events.readonly https://www.googleapis.com/auth/meetings.space.readonly
نماذج Google
عند تلقّي ردّ على نموذج https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/forms.responses.readonly https://www.googleapis.com/auth/forms.body.readonly https://www.googleapis.com/auth/drive.readonly (فقط لتفعيل ميزة "منع فقدان البيانات" في "نماذج Google")
NotebookLM
إضافة مصدر إلى NotebookLM https://www.googleapis.com/auth/drive.readonly
طرح سؤال على NotebookLM https://www.googleapis.com/auth/drive.readonly