Wenn Sie automatisierte Abläufe in Google Workspace Studio erstellen und ausführen, sind Sicherheit und Datenschutz standardmäßig integriert. Workspace Studio verwendet ein Identitätsmodell mit minimalen Berechtigungen. Das bedeutet, dass automatisierte Abläufe Hintergrundaufgaben nur mit den Berechtigungen ausführen, die für die jeweilige Aktion erforderlich sind. Sie haben also keinen umfassenden, uneingeschränkten Zugriff auf das gesamte Google-Konto des Nutzers.
In diesem Leitfaden erfahren Sie, welche Berechtigungen für die einzelnen Schritte eines Ablaufs erforderlich sind. So können Sie Ihre Automatisierung sicher konfigurieren und den Zugriff auf die Daten Ihrer Organisation im Blick behalten. Auf dieser Seite finden Sie eine Zuordnung der einzelnen Ablaufschritttypen und der erforderlichen OAuth-Bereiche (Open Authorization).
Auswirkungen von OAuth-Bereichen auf die Nutzung von Studio
Wenn Sie Workspace Studio verwenden, wirken sich OAuth-Bereiche auf die Erstellung, Ausführung und Verwaltung Ihrer Abläufe aus:
- Einmalige Autorisierung:Wenn Sie zum ersten Mal einen Schritt hinzufügen, der mit einem Google-Dienst interagiert (z. B. Gmail oder Google Drive), erhalten Sie eine Aufforderung von Google zur Anmeldung. Dadurch wird der spezifische Bereich für diesen Schritt autorisiert, sodass der Ablauf unabhängig im Hintergrund ausgeführt werden kann.
- Asynchrone Ausführung im Hintergrund:Nachdem ein Ablauf aktiviert wurde, wird er asynchron in der Infrastruktur von Google ausgeführt. Der Ablauf führt Aufgaben aus (z. B. einen Kalendertermin planen oder einen Entwurf schreiben) und verwendet dabei nur die von Ihnen genehmigten Bereiche, auch wenn Sie nicht aktiv angemeldet sind.
- Zentrale Administratoraufsicht:Als Administrator können Sie in der Admin-Konsole unter Verwaltung des KI-Agentenzugriffs alle aktiven Abläufe in Ihrer Organisation einsehen. Sie können bestimmte Abläufe pausieren oder einzelne OAuth-Bereiche gezielt einschränken (z. B. den Drive-Zugriff entfernen, während Gmail aktiv bleibt), um die Daten Ihrer Organisation zu schützen. Weitere Informationen
Fehlerbehebung bei unzureichenden Berechtigungen
Wenn ein Ablauf nicht ausgeführt wird und im Aktivitätsprotokoll der Fehler „Unzureichende Berechtigungen“ oder „Ein Fehler ist aufgetreten“ angezeigt wird, prüfen Sie Folgendes:
- Ablauf neu autorisieren: Öffnen Sie den Ablauf im Builder, klicken Sie auf Änderungen speichern und folgen Sie der Anleitung im Autorisierungsfeld, um abgelaufene oder fehlende OAuth-Tokens zu aktualisieren.
- Blockierungen durch kontextsensitiven Zugriff:Wenn in Ihrer Organisation strenge Richtlinien für Geräte oder IP-Adressen gelten, kann die Ausführung von Abläufen im Hintergrund manchmal blockiert werden. Achten Sie darauf, dass die Workspace Studio-Client-ID von den Einschränkungen des kontextsensitiven Zugriffs ausgenommen ist.
Ablaufschritte und erforderliche OAuth-Bereiche
In dieser Tabelle sind die Standardablaufschritte von Workspace Studio und die OAuth-Bereiche aufgeführt, die für die Ausführung der einzelnen Schritte im Hintergrund erforderlich sind.
| Schrittname | Konfiguration und Bereich |
|---|---|
| Studio-KI-Schritte | |
| AIP-Primitive (Frag Gemini, Frag einen Gem, Mit Gemini erstellen, Deep Research, Ungelesene E‑Mails zusammenfassen, Extrahieren, Entscheiden, Zusammenfassen) | https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/cloud_search.query |
| Allgemein und Dienstprogramme | |
| Nach Zeitplan | – |
| Webhook senden | – (externer Drittanbieter) |
| Prüfen, ob | – (interne Logik) |
| Liste filtern | – (interne Logik) |
| Gmail | |
| Bei Empfang einer E‑Mail | https://www.googleapis.com/auth/gmail.readonly https://www.googleapis.com/auth/gmail.event_trigger https://www.googleapis.com/auth/workspace.workflows.trigger |
| Per E‑Mail benachrichtigen | https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly |
| E‑Mail schreiben | https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly |
| E‑Mails verfassen | https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly |
| E‑Mail weiterleiten | https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly |
| Antwort entwerfen | https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly |
| E‑Mails beantworten | https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly |
| Labels hinzufügen oder entfernen | https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly |
| Als gelesen oder ungelesen markieren | https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly |
| Mit Stern markieren oder Markierung entfernen | https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly |
| Archivieren (oder löschen) | https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly |
| Google Chat | |
| Wenn jemand einem Gruppenbereich beitritt | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces |
| Wenn ich eine Chatnachricht erhalte | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces |
| Wenn ich erwähnt werde | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces |
| Wenn eine Emoji-Reaktion hinzugefügt wird | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces |
| Mich in Google Chat benachrichtigen | https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships |
| Chatbereich senden | https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces.create https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces |
| An andere senden | https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships |
| Auf Nachricht antworten | https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships |
| Google Sheets | |
| Wenn sich ein Tabellenblatt ändert | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly |
| Zeile hinzufügen | https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly |
| Zeilen aktualisieren | https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly |
| Inhalt der Zeilen löschen | https://www.googleapis.com/auth/spreadsheet https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly |
| Tabellenblattinhalte abrufen | https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly |
| Google Docs | |
| Google-Dokument erstellen | https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly |
| Einem Dokument hinzufügen | https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly |
| Google Kalender und Tasks | |
| Basierend auf einer Besprechung | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/calendar.events.readonly |
| Aufgabe erstellen | https://www.googleapis.com/auth/tasks |
| Ereignis erstellen | https://www.googleapis.com/auth/calendar.events |
| Gäste hinzufügen | https://www.googleapis.com/auth/calendar.events |
| Google Drive | |
| Wenn ein Element einem Ordner hinzugefügt wird | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly |
| Wenn eine Datei bearbeitet wird | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly |
| Wenn ein Element in einem Ordner bearbeitet wird | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly |
| Datei verschieben | https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly |
| Datei kopieren | https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly |
| Anhänge speichern | https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly |
| Ordner erstellen | https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly |
| Google Meet | |
| Wenn Besprechungsnotizen | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.meet.readonly https://www.googleapis.com/auth/meetings.space.created https://www.googleapis.com/auth/calendar.events.readonly https://www.googleapis.com/auth/meetings.space.readonly |
| Google Formulare | |
| Bei Eingang einer Formularantwort | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/forms.responses.readonly https://www.googleapis.com/auth/forms.body.readonly https://www.googleapis.com/auth/drive.readonly (nur für die DLP-Dateienunterstützung in Formularen) |
| NotebookLM | |
| Quelle zu NotebookLM hinzufügen | https://www.googleapis.com/auth/drive.readonly |
| NotebookLM fragen | https://www.googleapis.com/auth/drive.readonly |