عند إنشاء مسارات عمل آلية وتشغيلها في Google Workspace Studio، يتم تضمين الأمان وخصوصية البيانات تلقائيًا. يستخدم Workspace Studio نموذج هوية بأقل امتيازات، ما يعني أنّ العمليات التلقائية تنفّذ مهامًا في الخلفية باستخدام الحد الأدنى من الأذونات المطلوبة لتنفيذ كل إجراء فردي، بدلاً من الحصول على إذن وصول واسع النطاق وغير مقيّد إلى حساب المستخدم بالكامل على Google.
لإعداد عملية التشغيل الآلي بأمان والحفاظ على إمكانية الاطّلاع على كيفية الوصول إلى بيانات مؤسستك، استخدِم هذا الدليل لتحديد الأذونات المطلوبة لكل خطوة في المسار. تقدّم هذه الصفحة عملية ربط بين كل نوع من أنواع خطوات سير العمل ونطاقات Open Authorization (OAuth) المطلوبة.
تأثير نطاقات OAuth على استخدامك لـ Studio
عند استخدام Workspace Studio، تؤثّر نطاقات OAuth في طريقة إنشاء عمليات سير العمل وتنفيذها وإدارتها بالطرق التالية:
- تفويض لمرة واحدة: في المرة الأولى التي تضيف فيها خطوة تتفاعل مع إحدى خدمات Google (مثل Gmail أو Google Drive)، سيَظهر لك طلب من Google لتأكيد تسجيل الدخول. يمنح هذا الإذن النطاق المحدّد لهذه الخطوة حتى يتمكّن المسار من العمل بشكل مستقل في الخلفية.
- التنفيذ غير المتزامن في الخلفية: بعد تفعيل أحد المسارات، يتم تنفيذه بشكل غير متزامن على بنية Google الأساسية. ينفّذ سير العمل المهام (مثل جدولة حدث في "تقويم Google" أو كتابة مسودة) باستخدام النطاقات المحدّدة التي وافقت عليها فقط، حتى عندما تكون غير مسجّل الدخول بشكل نشط.
- إشراف مركزي للمشرف: بصفتك مشرفًا، يمكنك الاطّلاع على جميع المحادثات النشطة في مؤسستك باستخدام إعدادات إدارة أذونات الوصول إلى الوكيل في "وحدة تحكّم المشرف". يمكنك إيقاف تدفقات معيّنة مؤقتًا أو استهداف نطاقات OAuth الفردية وتقييدها (مثل إزالة إذن الوصول إلى Drive مع إبقاء Gmail نشطًا) للحفاظ على أمان بيانات مؤسستك. مزيد من المعلومات
تحديد المشاكل في الأذونات غير الكافية وحلّها
إذا لم يتم تشغيل أحد التدفقات وظهر الخطأ "أذونات غير كافية" أو "حدث خطأ" في سجلّ الأنشطة، تحقّق مما يلي:
- إعادة تفويض سير العمل: افتح سير العمل في "أداة الإنشاء"، وانقر على حفظ التغييرات، واتّبِع أي طلبات تظهر في مربّع التفويض لتحديث رموز OAuth المميزة المنتهية الصلاحية أو غير المتوفّرة.
- عمليات الحظر في "الوصول الواعي بالسياق" (CAA): إذا كانت مؤسستك تفرض سياسات الجهاز أو عنوان IP بشكل صارم، قد يتم حظر عمليات تنفيذ سير العمل في الخلفية في بعض الأحيان. تأكَّد من أنّ معرّف عميل Workspace Studio الأساسي معفى من قيود CAA.
خطوات المسار ونطاقات OAuth المطلوبة
يوضّح هذا الجدول خطوات Workspace Studio العادية ونطاقات OAuth التي تتطلّبها كل خطوة للتشغيل وراء الكواليس.
| اسم الخطوة | الضبط والنطاق |
|---|---|
| خطوات الذكاء الاصطناعي في Studio | |
| العمليات الأساسية في AIP (اسأل Gemini، اسأل Gem، أنشئ باستخدام Gemini، Deep Research، تلخيص الرسائل الإلكترونية غير المقروءة، استخراج، اتّخاذ قرار، تلخيص) | https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/cloud_search.query |
| التطبيقات العامة والمساعدة | |
| وفقًا لجدول زمني | غير متاحة |
| إرسال ويب هوك | لا ينطبق - جهة خارجية |
| التحقّق مما إذا | لا ينطبق - منطق داخلي |
| فلترة قائمة | لا ينطبق - منطق داخلي |
| Gmail | |
| عند تلقّي رسالة إلكترونية | https://www.googleapis.com/auth/gmail.readonly https://www.googleapis.com/auth/gmail.event_trigger https://www.googleapis.com/auth/workspace.workflows.trigger |
| إرسال إشعار إلى بريدي الإلكتروني | https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly |
| إرسال رسالة إلكترونية | https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly |
| كتابة مسودة رسالة إلكترونية | https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly |
| إعادة توجيه رسالة إلكترونية | https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly |
| صياغة ردّ | https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly |
| الردّ على رسالة إلكترونية | https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly |
| إضافة تصنيفات أو إزالتها | https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly |
| وضع علامة "مقروءة" أو "غير مقروءة" | https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly |
| تمييز رسالة بنجمة أو إلغاء تمييزها | https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly |
| الأرشفة (أو الحذف) | https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly |
| Google Chat | |
| عند انضمام مستخدم إلى مساحة | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces |
| عند تلقّي رسالة محادثة | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces |
| عند الإشارة إليّ | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces |
| عند إضافة تفاعل باستخدام إيموجي | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces |
| إشعاري في Chat | https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships |
| إرسال مساحة Chat | https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces.create https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces |
| الإرسال إلى مستخدمين آخرين | https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships |
| الردّ على رسالة | https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships |
| جداول بيانات Google | |
| عند تغيير ورقة البيانات | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly |
| إضافة صف | https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly |
| تعديل الصفوف | https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly |
| محو الصفوف | https://www.googleapis.com/auth/spreadsheet https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly |
| الحصول على محتوى ورقة البيانات | https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly |
| مستندات Google | |
| إنشاء مستند Google | https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly |
| الإضافة إلى مستند | https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly |
| "تقويم Google" و"مهام Google" | |
| استنادًا إلى اجتماع | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/calendar.events.readonly |
| إنشاء مهمة | https://www.googleapis.com/auth/tasks |
| إنشاء حدث | https://www.googleapis.com/auth/calendar.events |
| إضافة مدعوين | https://www.googleapis.com/auth/calendar.events |
| Google Drive | |
| عند إضافة عنصر إلى مجلد | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly |
| عند تعديل ملف | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly |
| عند تعديل ملف في مجلد | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly |
| نقل الملف | https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly |
| نسخ الملف | https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly |
| حفظ المرفقات | https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly |
| إنشاء مجلد | https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly |
| Google Meet | |
| عند استخدام ملاحظات الاجتماع | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.meet.readonly https://www.googleapis.com/auth/meetings.space.created https://www.googleapis.com/auth/calendar.events.readonly https://www.googleapis.com/auth/meetings.space.readonly |
| نماذج Google | |
| عند تلقّي ردّ على نموذج | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/forms.responses.readonly https://www.googleapis.com/auth/forms.body.readonly https://www.googleapis.com/auth/drive.readonly (فقط لتفعيل ميزة "منع فقدان البيانات" في "نماذج Google") |
| NotebookLM | |
| إضافة مصدر إلى NotebookLM | https://www.googleapis.com/auth/drive.readonly |
| طرح سؤال على NotebookLM | https://www.googleapis.com/auth/drive.readonly |