OAuth-Bereiche und Berechtigungen für Workspace Studio-Flow-Schritte

Wenn Sie automatisierte Abläufe in Google Workspace Studio erstellen und ausführen, sind Sicherheit und Datenschutz standardmäßig integriert. Workspace Studio verwendet ein Identitätsmodell mit minimalen Berechtigungen. Das bedeutet, dass automatisierte Abläufe Hintergrundaufgaben nur mit den Berechtigungen ausführen, die für die jeweilige Aktion erforderlich sind. Sie haben also keinen umfassenden, uneingeschränkten Zugriff auf das gesamte Google-Konto des Nutzers.

In diesem Leitfaden erfahren Sie, welche Berechtigungen für die einzelnen Schritte eines Ablaufs erforderlich sind. So können Sie Ihre Automatisierung sicher konfigurieren und den Zugriff auf die Daten Ihrer Organisation im Blick behalten. Auf dieser Seite finden Sie eine Zuordnung der einzelnen Ablaufschritttypen und der erforderlichen OAuth-Bereiche (Open Authorization).

Auswirkungen von OAuth-Bereichen auf die Nutzung von Studio

Wenn Sie Workspace Studio verwenden, wirken sich OAuth-Bereiche auf die Erstellung, Ausführung und Verwaltung Ihrer Abläufe aus:

  • Einmalige Autorisierung:Wenn Sie zum ersten Mal einen Schritt hinzufügen, der mit einem Google-Dienst interagiert (z. B. Gmail oder Google Drive), erhalten Sie eine Aufforderung von Google zur Anmeldung. Dadurch wird der spezifische Bereich für diesen Schritt autorisiert, sodass der Ablauf unabhängig im Hintergrund ausgeführt werden kann.
  • Asynchrone Ausführung im Hintergrund:Nachdem ein Ablauf aktiviert wurde, wird er asynchron in der Infrastruktur von Google ausgeführt. Der Ablauf führt Aufgaben aus (z. B. einen Kalendertermin planen oder einen Entwurf schreiben) und verwendet dabei nur die von Ihnen genehmigten Bereiche, auch wenn Sie nicht aktiv angemeldet sind.
  • Zentrale Administratoraufsicht:Als Administrator können Sie in der Admin-Konsole unter Verwaltung des KI-Agentenzugriffs alle aktiven Abläufe in Ihrer Organisation einsehen. Sie können bestimmte Abläufe pausieren oder einzelne OAuth-Bereiche gezielt einschränken (z. B. den Drive-Zugriff entfernen, während Gmail aktiv bleibt), um die Daten Ihrer Organisation zu schützen. Weitere Informationen

Fehlerbehebung bei unzureichenden Berechtigungen

Wenn ein Ablauf nicht ausgeführt wird und im Aktivitätsprotokoll der Fehler „Unzureichende Berechtigungen“ oder „Ein Fehler ist aufgetreten“ angezeigt wird, prüfen Sie Folgendes:

  • Ablauf neu autorisieren: Öffnen Sie den Ablauf im Builder, klicken Sie auf Änderungen speichern und folgen Sie der Anleitung im Autorisierungsfeld, um abgelaufene oder fehlende OAuth-Tokens zu aktualisieren.
  • Blockierungen durch kontextsensitiven Zugriff:Wenn in Ihrer Organisation strenge Richtlinien für Geräte oder IP-Adressen gelten, kann die Ausführung von Abläufen im Hintergrund manchmal blockiert werden. Achten Sie darauf, dass die Workspace Studio-Client-ID von den Einschränkungen des kontextsensitiven Zugriffs ausgenommen ist.

Ablaufschritte und erforderliche OAuth-Bereiche

In dieser Tabelle sind die Standardablaufschritte von Workspace Studio und die OAuth-Bereiche aufgeführt, die für die Ausführung der einzelnen Schritte im Hintergrund erforderlich sind.

Schrittname Konfiguration und Bereich
Studio-KI-Schritte
AIP-Primitive (Frag Gemini, Frag einen Gem, Mit Gemini erstellen, Deep Research, Ungelesene E‑Mails zusammenfassen, Extrahieren, Entscheiden, Zusammenfassen) https://www.googleapis.com/auth/drive
https://www.googleapis.com/auth/documents
https://www.googleapis.com/auth/spreadsheets
https://www.googleapis.com/auth/cloud_search.query
Allgemein und Dienstprogramme
Nach Zeitplan
Webhook senden – (externer Drittanbieter)
Prüfen, ob – (interne Logik)
Liste filtern – (interne Logik)
Gmail
Bei Empfang einer E‑Mail https://www.googleapis.com/auth/gmail.readonly https://www.googleapis.com/auth/gmail.event_trigger https://www.googleapis.com/auth/workspace.workflows.trigger
Per E‑Mail benachrichtigen https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly
E‑Mail schreiben https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
E‑Mails verfassen https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly
E‑Mail weiterleiten https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
Antwort entwerfen https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
E‑Mails beantworten https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
Labels hinzufügen oder entfernen https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
Als gelesen oder ungelesen markieren https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
Mit Stern markieren oder Markierung entfernen https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
Archivieren (oder löschen) https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
Google Chat
Wenn jemand einem Gruppenbereich beitritt https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
Wenn ich eine Chatnachricht erhalte https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
Wenn ich erwähnt werde https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
Wenn eine Emoji-Reaktion hinzugefügt wird https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
Mich in Google Chat benachrichtigen https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships
Chatbereich senden https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces.create https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
An andere senden https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships
Auf Nachricht antworten https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships
Google Sheets
Wenn sich ein Tabellenblatt ändert https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly
Zeile hinzufügen https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
Zeilen aktualisieren https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
Inhalt der Zeilen löschen https://www.googleapis.com/auth/spreadsheet https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
Tabellenblattinhalte abrufen https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
Google Docs
Google-Dokument erstellen https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly
Einem Dokument hinzufügen https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly
Google Kalender und Tasks
Basierend auf einer Besprechung https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/calendar.events.readonly
Aufgabe erstellen https://www.googleapis.com/auth/tasks
Ereignis erstellen https://www.googleapis.com/auth/calendar.events
Gäste hinzufügen https://www.googleapis.com/auth/calendar.events
Google Drive
Wenn ein Element einem Ordner hinzugefügt wird https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly
Wenn eine Datei bearbeitet wird https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
Wenn ein Element in einem Ordner bearbeitet wird https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly
Datei verschieben https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
Datei kopieren https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
Anhänge speichern https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
Ordner erstellen https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
Google Meet
Wenn Besprechungsnotizen https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.meet.readonly https://www.googleapis.com/auth/meetings.space.created https://www.googleapis.com/auth/calendar.events.readonly https://www.googleapis.com/auth/meetings.space.readonly
Google Formulare
Bei Eingang einer Formularantwort https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/forms.responses.readonly https://www.googleapis.com/auth/forms.body.readonly https://www.googleapis.com/auth/drive.readonly (nur für die DLP-Dateienunterstützung in Formularen)
NotebookLM
Quelle zu NotebookLM hinzufügen https://www.googleapis.com/auth/drive.readonly
NotebookLM fragen https://www.googleapis.com/auth/drive.readonly