Workspace Studio フローの手順の OAuth スコープと権限

Google Workspace Studio で自動フローを構築して実行する場合、セキュリティとデータのプライバシーはデフォルトで組み込まれています。Workspace Studio は最小権限の ID モデルを使用します。つまり、自動フローは、ユーザーの Google アカウント全体への広範な無制限のアクセス権を持つのではなく、個々のアクションを実行するために必要な最小限の権限のみを使用してバックグラウンド タスクを実行します。

自動化を安全に構成し、組織のデータへのアクセス方法を把握するには、このガイドを使用して、フローの各ステップに必要な権限を特定します。このページでは、各フローのステップタイプと、必要な Open Authorization(OAuth)スコープのマッピングを示します。

OAuth スコープが Studio の使用に与える影響

Workspace Studio を使用する場合、OAuth スコープは、フローの構築、実行、管理に次のような影響を与えます。

  • 1 回限りの承認: Google サービス(Gmail や Google ドライブなど)とやり取りするステップを初めて追加するときに、Google ログインのメッセージが表示されます。これにより、そのステップの特定のスコープが承認され、フローがバックグラウンドで独立して実行できるようになります。
  • 非同期のバックグラウンド実行: フローが有効になると、Google のインフラストラクチャで非同期に実行されます。フローは、ユーザーがアクティブにログインしていない場合でも、承認した特定のスコープのみを使用してタスク(カレンダーの予定のスケジュール設定や下書きの作成など)を実行します。
  • 管理者の集中管理: 管理者は、管理コンソールのエージェント アクセス管理設定を使用して、組織内のすべてのアクティブなフローを表示できます。特定のフローを一時停止したり、個々の OAuth スコープをターゲットにして制限したり(Gmail を有効にしたままドライブへのアクセスを削除するなど)して、組織のデータを安全に保つことができます。詳細

権限不足のトラブルシューティング

フローが実行されず、アクティビティ ログに「権限が不足しています」または「エラーが発生しました」というエラーが表示された場合は、次の点を確認してください。

  • フローを再認証する: Builder でフローを開き、[変更を保存] をクリックして、認証ボックスのプロンプトに沿って期限切れまたは不足している OAuth トークンを更新します。
  • コンテキストアウェア アクセス(CAA)によるブロック: 組織でデバイス ポリシーや IP ポリシーが厳格に適用されている場合、バックグラウンド フローの実行がブロックされることがあります。コア Workspace Studio クライアント ID が CAA 制限の対象外であることを確認します。

フローの手順と必要な OAuth スコープ

次の表に、Workspace Studio の標準的な手順と、各手順がバックグラウンドで実行するために必要な OAuth スコープを示します。

ステップの名前 構成とスコープ
Studio AI ステップ
AIP プリミティブ(Gemini に相談、Gem に相談、Gemini で作成、Deep Research、未読メールの要約、抽出、決定、要約) https://www.googleapis.com/auth/drive
https://www.googleapis.com/auth/documents
https://www.googleapis.com/auth/spreadsheets
https://www.googleapis.com/auth/cloud_search.query
全般とユーティリティ
スケジュールを設定 なし
Webhook を送信する N/A - 外部のサードパーティ
Check if N/A - 内部ロジック
リストをフィルタする N/A - 内部ロジック
Gmail
メールを受信したとき https://www.googleapis.com/auth/gmail.readonly https://www.googleapis.com/auth/gmail.event_trigger https://www.googleapis.com/auth/workspace.workflows.trigger 
メールで通知する https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly
メールを送信する https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
メールの下書きを作成する https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly
メールを転送する https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
返信を下書き https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
メールに返信する https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
ラベルを追加または削除する https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
既読または未読にする https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
スターを付ける、または外す https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
アーカイブ(または削除)する https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
Google Chat
誰かがスペースに参加したとき https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
チャット メッセージを受信したとき https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
自分の名前リンクが追加されたとき https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
絵文字のリアクションが追加されたとき https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
Chat で通知する https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships
チャット スペースを送信する https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces.create https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
他のユーザーに送信 https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships
メッセージに返信する https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships
Google スプレッドシート
シートの変更時 https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly
行を追加する https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
行を更新 https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
行をクリア https://www.googleapis.com/auth/spreadsheet https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
シートのコンテンツを取得 https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
Google ドキュメント
Google ドキュメントを作成する https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly
ドキュメントに追加 https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly
Google カレンダーと ToDo リスト
会議に基づく https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/calendar.events.readonly 
タスクを作成 https://www.googleapis.com/auth/tasks
イベントを作成 https://www.googleapis.com/auth/calendar.events
ゲストを追加する https://www.googleapis.com/auth/calendar.events
Google ドライブ
フォルダにアイテムが追加されたとき https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly
ファイルが編集されたとき https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
フォルダ内のアイテムが編集されたとき https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly
ファイルを移動する https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
ファイルをコピーする https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
添付ファイルの保存 https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
フォルダを作成する https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
Google Meet
会議メモの場合 https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.meet.readonly https://www.googleapis.com/auth/meetings.space.created https://www.googleapis.com/auth/calendar.events.readonly https://www.googleapis.com/auth/meetings.space.readonly
Google フォーム
フォームの回答が届いたとき https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/forms.responses.readonly https://www.googleapis.com/auth/forms.body.readonly https://www.googleapis.com/auth/drive.readonly(フォームでの DLP ファイルのサポートの場合のみ)
NotebookLM
NotebookLM にソースを追加する https://www.googleapis.com/auth/drive.readonly
NotebookLM に質問する https://www.googleapis.com/auth/drive.readonly