היקפי הרשאות ואישורים של OAuth לשלבים ברצף פעולות ב-Workspace Studio

כשיוצרים ומריצים רצפים של פעולות אוטומטיות ב-Google Workspace Studio, האבטחה ופרטיות הנתונים מובנות במוצר כברירת מחדל. ‫Workspace Studio משתמש במודל זהויות עם הרשאות מינימליות. המשמעות היא שתהליכים אוטומטיים מריצים משימות ברקע רק עם ההרשאות המינימליות שנדרשות לביצוע כל פעולה בנפרד, במקום גישה רחבה ובלתי מוגבלת לכל חשבון Google של המשתמש.

כדי להגדיר את האוטומציה בצורה בטוחה ולשמור על שקיפות לגבי הגישה לנתונים של הארגון, כדאי להשתמש במדריך הזה כדי לזהות את ההרשאות שנדרשות לכל שלב בתהליך. בדף הזה מפורטים סוגי השלבים בתהליך וסוגי ההרשאות הנדרשות של Open Authorization ‏ (OAuth).

איך היקפי הרשאות של OAuth משפיעים על השימוש ב-Studio

כשמשתמשים ב-Workspace Studio, היקפי הרשאות OAuth משפיעים על האופן שבו יוצרים, מפעילים ומנהלים את התהליכים בדרכים הבאות:

  • הרשאה חד-פעמית: בפעם הראשונה שמוסיפים שלב שכולל אינטראקציה עם שירות של Google (כמו Gmail או Google Drive), מוצגת הודעת אימות מ-Google. הפעולה הזו מאשרת את ההיקף הספציפי של השלב הזה, כדי שהתהליך יוכל לפעול באופן עצמאי ברקע.
  • הרצה אסינכרונית ברקע: אחרי שמפעילים את התהליך, הוא מורץ באופן אסינכרוני בתשתית של Google. התהליך מבצע משימות (כמו תזמון אירוע ביומן או כתיבת טיוטה) רק באמצעות ההיקפים הספציפיים שאישרתם, גם כשאתם לא מחוברים באופן פעיל.
  • פיקוח אדמיניסטרטיבי מרכזי: אדמינים יכולים לראות את כל התהליכים הפעילים בארגון באמצעות ההגדרות של ניהול גישת סוכנים במסוף Admin. כדי לשמור על בטיחות הנתונים של הארגון, אתם יכולים להשהות רצפי פעולות ספציפיים או להגביל את הגישה להיקפי הרשאות ספציפיים של OAuth (למשל, להסיר את הגישה ל-Drive ולהשאיר את Gmail פעיל). מידע נוסף

פתרון בעיות שקשורות להרשאות לא מספיקות

אם תהליך לא פועל ומוצגת השגיאה 'אין הרשאות מספיקות' או 'משהו השתבש' ביומן הפעילות, בודקים את הדברים הבאים:

  • צריך להעניק מחדש הרשאה לתהליך העבודה: פותחים את תהליך העבודה בכלי ליצירת תהליכי עבודה, לוחצים על שמירת השינויים ופועלים לפי ההנחיות בתיבת ההרשאה כדי לרענן אסימוני OAuth שפג תוקפם או שחסרים.
  • חסימות של בקרת גישה מבוססת-הקשר (CAA): אם הארגון שלכם אוכף מדיניות לגבי מכשירים או כתובות IP באופן מחמיר, יכול להיות שביצועים של תהליכים ברקע ייחסמו. מוודאים שמזהה הלקוח הראשי של Workspace Studio פטור מהגבלות CAA.

שלבים בתהליך והיקפי הרשאות נדרשים של OAuth

בטבלה הזו מפורטים השלבים הרגילים ב-Workspace Studio והיקפי ההרשאות של OAuth שכל שלב דורש כדי לפעול ברקע.

שם השלב הגדרות אישיות והיקף
שלבים לשימוש ב-AI Studio
פרימיטיבים של AIP (Ask Gemini, ‏ Ask a Gem, ‏ Create with Gemini, ‏ Deep Research, ‏ Recap unread emails, ‏ Extract, ‏ Decide, ‏ Summarize) https://www.googleapis.com/auth/drive
https://www.googleapis.com/auth/documents
https://www.googleapis.com/auth/spreadsheets
https://www.googleapis.com/auth/cloud_search.query
כללי ושירותים
לפי לוח זמנים לא רלוונטי
שליחת webhook לא רלוונטי – צד ג'
בדיקה: לא רלוונטי – לוגיקה פנימית
סינון רשימה לא רלוונטי – לוגיקה פנימית
Gmail
כשמתקבל אימייל https://www.googleapis.com/auth/gmail.readonly https://www.googleapis.com/auth/gmail.event_trigger https://www.googleapis.com/auth/workspace.workflows.trigger 
אני רוצה לקבל התראה באימייל https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly
שליחת אימייל https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
לכתוב טיוטה של אימייל https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly
העברת אימייל https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
ניסוח תשובה https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
איך עונים לאימייל https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
הוספה או הסרה של תוויות https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
סימון כפריט שנקרא או כפריט שלא נקרא https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
סימון בכוכב או ביטול הסימון בכוכב https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
העברה לארכיון (או מחיקה) https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
Google Chat
כשמישהו מצטרף למרחב https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
כשמתקבלת הודעה בצ'אט https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
כשמתייגים אותי https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
כשמתווספת תגובה באמוג'י https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
אני רוצה לקבל התראה ב-Chat https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships
שליחת מרחב https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces.create https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
שליחה לאחרים https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships
מענה להודעה https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships
Google Sheets
כשיש שינוי בגיליון https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly
הוספת שורה https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
עדכון השורות https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
ניקוי השורות https://www.googleapis.com/auth/spreadsheet https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
שליפת תוכן מהגיליון https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
Google Docs
יצירת מסמך ב-Google Docs https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly
הוספה למסמך https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly
יומן Google ו-Tasks
על סמך פגישה https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/calendar.events.readonly 
יצירת משימה https://www.googleapis.com/auth/tasks
יצירת אירוע https://www.googleapis.com/auth/calendar.events
הזמנת משתתפים https://www.googleapis.com/auth/calendar.events
Google Drive
כשפריט מתווסף לתיקייה https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly
כשמתבצעת עריכה של קובץ https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
כשבוצעה עריכה של פריט בתיקייה https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly
העברת קובץ https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
העתקת קובץ https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
שמירת קבצים מצורפים https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
יצירת תיקייה https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
Google Meet
כשמסכמים פגישה https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.meet.readonly https://www.googleapis.com/auth/meetings.space.created https://www.googleapis.com/auth/calendar.events.readonly https://www.googleapis.com/auth/meetings.space.readonly
Google Forms
כשמתקבלת תשובה לטופס https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/forms.responses.readonly https://www.googleapis.com/auth/forms.body.readonly https://www.googleapis.com/auth/drive.readonly (רק לתמיכה בקבצים ב-DLP בטפסים)
NotebookLM
הוספת מקור ל-NotebookLM https://www.googleapis.com/auth/drive.readonly
שליחת שאלה ל-NotebookLM https://www.googleapis.com/auth/drive.readonly