Cakupan dan izin OAuth untuk langkah-langkah alur Workspace Studio

Saat Anda membuat dan menjalankan alur otomatis di Google Workspace Studio, keamanan dan privasi data akan otomatis disertakan secara default. Workspace Studio menggunakan model identitas dengan hak istimewa terendah, yang berarti alur otomatis menjalankan tugas latar belakang hanya menggunakan izin minimum yang diperlukan untuk melakukan setiap tindakan, bukan memiliki akses luas dan tidak dibatasi ke seluruh Akun Google pengguna.

Untuk mengonfigurasi otomatisasi dengan aman dan mempertahankan visibilitas tentang cara data organisasi Anda diakses, gunakan panduan ini untuk mengidentifikasi izin yang diperlukan untuk setiap langkah dalam alur. Halaman ini menyediakan pemetaan setiap jenis langkah alur dan cakupan Open Authorization (OAuth) yang diperlukan.

Pengaruh cakupan OAuth terhadap penggunaan Studio

Saat Anda menggunakan Workspace Studio, cakupan OAuth akan memengaruhi cara Anda membuat, menjalankan, dan mengelola alur dengan cara berikut:

  • Otorisasi satu kali: Saat pertama kali menambahkan langkah yang berinteraksi dengan layanan Google (seperti Gmail atau Google Drive), Anda akan mendapatkan dialog login Google. Tindakan ini akan mengotorisasi cakupan tertentu untuk langkah tersebut sehingga alur dapat berjalan secara independen di latar belakang.
  • Eksekusi latar belakang asinkron: Setelah diaktifkan, alur akan berjalan secara asinkron di infrastruktur Google. Alur akan menjalankan tugas (seperti menjadwalkan acara Kalender atau menulis draf) hanya menggunakan cakupan tertentu yang Anda setujui, bahkan saat Anda tidak aktif login.
  • Pengawasan admin terpusat: Sebagai admin, Anda dapat melihat semua alur aktif di seluruh organisasi menggunakan setelan Pengelolaan Akses Agen di konsol Admin. Anda dapat menjeda alur tertentu atau menargetkan dan membatasi cakupan OAuth tertentu (seperti menghapus akses Drive sambil membiarkan Gmail aktif) untuk menjaga keamanan data organisasi Anda. Pelajari lebih lanjut

Memecahkan masalah izin yang tidak memadai

Jika alur tidak berjalan dan menampilkan error "Izin Tidak Memadai" atau "Terjadi error" di Log Aktivitas, periksa hal berikut:

  • Otorisasi ulang alur Anda: Buka alur di Builder, klik Simpan Perubahan, dan ikuti perintah apa pun di kotak otorisasi untuk memperbarui token OAuth yang sudah tidak berlaku atau tidak ada.
  • Blokir Akses Kontekstual (CAA): Jika organisasi Anda menerapkan kebijakan IP atau perangkat secara ketat, eksekusi alur latar belakang terkadang dapat diblokir. Pastikan ID Klien Workspace Studio inti dikecualikan dari batasan CAA.

Langkah alur dan cakupan OAuth yang diperlukan

Tabel ini menguraikan langkah-langkah Workspace Studio standar dan cakupan OAuth yang diperlukan setiap langkah untuk berjalan di balik layar.

Nama langkah Konfigurasi dan cakupan
Langkah AI Studio
Primitif AIP (Minta Gemini, Minta Gem, Buat dengan Gemini, Deep Research, Rekap email yang belum dibaca, Ekstrak, Putuskan, Ringkas) https://www.googleapis.com/auth/drive
https://www.googleapis.com/auth/documents
https://www.googleapis.com/auth/spreadsheets
https://www.googleapis.com/auth/cloud_search.query
Umum dan utilitas
Sesuai jadwal T/A
Kirim webhook T/A - Pihak Ketiga Eksternal
Periksa apakah T/A - Logika internal
Filter daftar T/A - Logika internal
Gmail
Saat saya menerima email https://www.googleapis.com/auth/gmail.readonly https://www.googleapis.com/auth/gmail.event_trigger https://www.googleapis.com/auth/workspace.workflows.trigger
Beri tahu saya melalui email https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly
Kirim email https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
Buat draf email https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly
Teruskan email https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
Buat draf balasan https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
Balas email https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
Tambahkan atau hapus label https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
Tandai sebagai telah dibaca atau belum dibaca https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
Bintangi atau hapus bintang https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
Arsipkan (atau hapus) https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
Google Chat
Saat seseorang bergabung ke ruang https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
Saat saya menerima pesan chat https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
Saat saya disebut https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
Saat reaksi emoji ditambahkan https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
Beri tahu saya di Chat https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships
Kirim ruang chat https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces.create https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
Kirim ke pengguna lain https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships
Balas pesan https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships
Google Spreadsheet
Saat sheet diubah https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly
Tambahkan baris https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
Perbarui baris https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
Kosongkan baris https://www.googleapis.com/auth/spreadsheet https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
Dapatkan isi sheet https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
Google Dokumen
Buat dokumen Google https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly
Tambahkan ke dokumen https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly
Google Kalender dan Tugas
Berdasarkan rapat https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/calendar.events.readonly
Buat tugas https://www.googleapis.com/auth/tasks
Buat acara https://www.googleapis.com/auth/calendar.events
Tambahkan tamu https://www.googleapis.com/auth/calendar.events
Google Drive
Saat item ditambahkan ke folder https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly
Saat file diedit https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
Saat item dalam folder diedit https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly
Pindahkan file https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
Salin file https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
Simpan lampiran https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
Buat folder https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
Google Meet
Saat catatan rapat https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.meet.readonly https://www.googleapis.com/auth/meetings.space.created https://www.googleapis.com/auth/calendar.events.readonly https://www.googleapis.com/auth/meetings.space.readonly
Google Formulir
Saat respons formulir diterima https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/forms.responses.readonly https://www.googleapis.com/auth/forms.body.readonly https://www.googleapis.com/auth/drive.readonly (hanya untuk dukungan file DLP di Formulir)
NotebookLM
Tambahkan Sumber ke NotebookLM https://www.googleapis.com/auth/drive.readonly
Tanyakan pada NotebookLM https://www.googleapis.com/auth/drive.readonly