Google Workspace Studio で自動フローを構築して実行する場合、セキュリティとデータのプライバシーはデフォルトで組み込まれています。Workspace Studio は最小権限の ID モデルを使用します。つまり、自動フローは、ユーザーの Google アカウント全体への広範な無制限のアクセス権を持つのではなく、個々のアクションを実行するために必要な最小限の権限のみを使用してバックグラウンド タスクを実行します。
自動化を安全に構成し、組織のデータへのアクセス方法を把握するには、このガイドを使用して、フローの各ステップに必要な権限を特定します。このページでは、各フローのステップタイプと、必要な Open Authorization(OAuth)スコープのマッピングを示します。
OAuth スコープが Studio の使用に与える影響
Workspace Studio を使用する場合、OAuth スコープは、フローの構築、実行、管理に次のような影響を与えます。
- 1 回限りの承認: Google サービス(Gmail や Google ドライブなど)とやり取りするステップを初めて追加するときに、Google ログインのメッセージが表示されます。これにより、そのステップの特定のスコープが承認され、フローがバックグラウンドで独立して実行できるようになります。
- 非同期のバックグラウンド実行: フローが有効になると、Google のインフラストラクチャで非同期に実行されます。フローは、ユーザーがアクティブにログインしていない場合でも、承認した特定のスコープのみを使用してタスク(カレンダーの予定のスケジュール設定や下書きの作成など)を実行します。
- 管理者の集中管理: 管理者は、管理コンソールのエージェント アクセス管理設定を使用して、組織内のすべてのアクティブなフローを表示できます。特定のフローを一時停止したり、個々の OAuth スコープをターゲットにして制限したり(Gmail を有効にしたままドライブへのアクセスを削除するなど)して、組織のデータを安全に保つことができます。詳細
権限不足のトラブルシューティング
フローが実行されず、アクティビティ ログに「権限が不足しています」または「エラーが発生しました」というエラーが表示された場合は、次の点を確認してください。
- フローを再認証する: Builder でフローを開き、[変更を保存] をクリックして、認証ボックスのプロンプトに沿って期限切れまたは不足している OAuth トークンを更新します。
- コンテキストアウェア アクセス(CAA)によるブロック: 組織でデバイス ポリシーや IP ポリシーが厳格に適用されている場合、バックグラウンド フローの実行がブロックされることがあります。コア Workspace Studio クライアント ID が CAA 制限の対象外であることを確認します。
フローの手順と必要な OAuth スコープ
次の表に、Workspace Studio の標準的な手順と、各手順がバックグラウンドで実行するために必要な OAuth スコープを示します。
| ステップの名前 | 構成とスコープ |
|---|---|
| Studio AI ステップ | |
| AIP プリミティブ(Gemini に相談、Gem に相談、Gemini で作成、Deep Research、未読メールの要約、抽出、決定、要約) | https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/cloud_search.query |
| 全般とユーティリティ | |
| スケジュールを設定 | なし |
| Webhook を送信する | N/A - 外部のサードパーティ |
| Check if | N/A - 内部ロジック |
| リストをフィルタする | N/A - 内部ロジック |
| Gmail | |
| メールを受信したとき | https://www.googleapis.com/auth/gmail.readonly https://www.googleapis.com/auth/gmail.event_trigger https://www.googleapis.com/auth/workspace.workflows.trigger |
| メールで通知する | https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly |
| メールを送信する | https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly |
| メールの下書きを作成する | https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly |
| メールを転送する | https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly |
| 返信を下書き | https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly |
| メールに返信する | https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly |
| ラベルを追加または削除する | https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly |
| 既読または未読にする | https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly |
| スターを付ける、または外す | https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly |
| アーカイブ(または削除)する | https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly |
| Google Chat | |
| 誰かがスペースに参加したとき | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces |
| チャット メッセージを受信したとき | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces |
| 自分の名前リンクが追加されたとき | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces |
| 絵文字のリアクションが追加されたとき | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces |
| Chat で通知する | https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships |
| チャット スペースを送信する | https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces.create https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces |
| 他のユーザーに送信 | https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships |
| メッセージに返信する | https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships |
| Google スプレッドシート | |
| シートの変更時 | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly |
| 行を追加する | https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly |
| 行を更新 | https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly |
| 行をクリア | https://www.googleapis.com/auth/spreadsheet https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly |
| シートのコンテンツを取得 | https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly |
| Google ドキュメント | |
| Google ドキュメントを作成する | https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly |
| ドキュメントに追加 | https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly |
| Google カレンダーと ToDo リスト | |
| 会議に基づく | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/calendar.events.readonly |
| タスクを作成 | https://www.googleapis.com/auth/tasks |
| イベントを作成 | https://www.googleapis.com/auth/calendar.events |
| ゲストを追加する | https://www.googleapis.com/auth/calendar.events |
| Google ドライブ | |
| フォルダにアイテムが追加されたとき | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly |
| ファイルが編集されたとき | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly |
| フォルダ内のアイテムが編集されたとき | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly |
| ファイルを移動する | https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly |
| ファイルをコピーする | https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly |
| 添付ファイルの保存 | https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly |
| フォルダを作成する | https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly |
| Google Meet | |
| 会議メモの場合 | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.meet.readonly https://www.googleapis.com/auth/meetings.space.created https://www.googleapis.com/auth/calendar.events.readonly https://www.googleapis.com/auth/meetings.space.readonly |
| Google フォーム | |
| フォームの回答が届いたとき | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/forms.responses.readonly https://www.googleapis.com/auth/forms.body.readonly https://www.googleapis.com/auth/drive.readonly(フォームでの DLP ファイルのサポートの場合のみ) |
| NotebookLM | |
| NotebookLM にソースを追加する | https://www.googleapis.com/auth/drive.readonly |
| NotebookLM に質問する | https://www.googleapis.com/auth/drive.readonly |