OAuth-scopes en -machtigingen voor Workspace Studio-workflowstappen

Wanneer u geautomatiseerde workflows bouwt en uitvoert in Google Workspace Studio, zijn beveiliging en gegevensprivacy standaard ingebouwd. Workspace Studio gebruikt een identiteitsmodel met minimale bevoegdheden, wat betekent dat geautomatiseerde workflows achtergrondtaken uitvoeren met alleen de minimale machtigingen die nodig zijn om elke afzonderlijke actie uit te voeren, in plaats van brede, onbeperkte toegang te hebben tot het volledige Google-account van de gebruiker.

Om uw automatisering veilig te configureren en inzicht te behouden in hoe de gegevens van uw organisatie worden benaderd, gebruikt u deze handleiding om de vereiste machtigingen voor elke stap in een workflow te bepalen. Deze pagina biedt een overzicht van elk type workflowstap en de bijbehorende Open Authorization (OAuth)-scopes.

Hoe OAuth-scopes van invloed zijn op uw gebruik van Studio.

Wanneer u Workspace Studio gebruikt, hebben OAuth-scopes invloed op de manier waarop u uw flows bouwt, uitvoert en beheert, op de volgende manieren:

  • Eenmalige autorisatie: De eerste keer dat u een stap toevoegt die interactie heeft met een Google-service (zoals Gmail of Google Drive), krijgt u een Google-aanmeldingsprompt. Hiermee wordt de specifieke scope voor die stap geautoriseerd, zodat de workflow onafhankelijk op de achtergrond kan worden uitgevoerd.
  • Asynchrone uitvoering op de achtergrond: Nadat een workflow is ingeschakeld, wordt deze asynchroon uitgevoerd op de infrastructuur van Google. De workflow voert taken uit (zoals het inplannen van een agenda-afspraak of het schrijven van een concept) met uitsluitend de specifieke scopes die u hebt goedgekeurd, zelfs wanneer u niet actief bent aangemeld.
  • Gecentraliseerd beheerdersbeheer: als beheerder kunt u alle actieve flows binnen uw organisatie bekijken via de instellingen voor agenttoegangsbeheer in uw beheerdersconsole. U kunt specifieke flows pauzeren of individuele OAuth-scopes selecteren en beperken (zoals het verwijderen van Drive-toegang terwijl Gmail actief blijft) om de gegevens van uw organisatie te beschermen. Meer informatie

Problemen met onvoldoende machtigingen oplossen

Als een workflow niet wordt uitgevoerd en er een foutmelding 'Onvoldoende machtigingen' of 'Er is iets misgegaan' in het activiteitenlogboek verschijnt, controleer dan het volgende:

  • Autoriseer uw flow opnieuw: Open de flow in de Builder, klik op Wijzigingen opslaan en volg de aanwijzingen in het autorisatievenster om verlopen of ontbrekende OAuth-tokens te vernieuwen.
  • Context-Aware Access (CAA)-blokkeringen: Als uw organisatie strikte apparaat- of IP-beleidsregels hanteert, kunnen achtergrondprocessen soms worden geblokkeerd. Zorg ervoor dat de kern-Workspace Studio-client-ID is vrijgesteld van CAA-beperkingen.

Stroomstappen en vereiste OAuth-scopes

Deze tabel geeft een overzicht van de standaardstappen in Workspace Studio en de OAuth-scopes die elke stap op de achtergrond nodig heeft.

Stapnaam Configuratie en bereik
Studio AI-stappen
AIP-primitieven (Vraag Gemini, Vraag een Gem, Creëer met Gemini, Grondig onderzoek, Ongelezen e-mails samenvatten, Extraheer, Beslis, Samenvatten) https://www.googleapis.com/auth/drive
https://www.googleapis.com/auth/documents
https://www.googleapis.com/auth/spreadsheets
https://www.googleapis.com/auth/cloud_search.query
Algemene en nutsvoorzieningen
Volgens een schema Niet van toepassing
Webhook verzenden Niet van toepassing - Externe 3P
Controleer of Niet van toepassing - Interne logica
Een lijst filteren Niet van toepassing - Interne logica
Gmail
Wanneer ik een e-mail ontvang https://www.googleapis.com/auth/gmail.readonly https://www.googleapis.com/auth/gmail.event_trigger https://www.googleapis.com/auth/workspace.workflows.trigger
Stel me per e-mail op de hoogte. https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly
Stuur een e-mail https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
Stel een e-mail op https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly
Een e-mail doorsturen https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
Stel een antwoord op https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
Een e-mail beantwoorden https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
Labels toevoegen of verwijderen https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
Markeer als gelezen of niet gelezen https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
Ster of geen ster https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
Archiveren (of verwijderen) https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
Google Chat
Wanneer iemand zich bij een ruimte voegt https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
Wanneer ik een chatbericht ontvang https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
Als ik genoemd word https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
Wanneer een emoji-reactie wordt toegevoegd https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
Laat het me weten via de chat. https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships
Chatruimte verzenden https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces.create https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
Stuur naar anderen https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships
Beantwoord het bericht https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships
Google Sheets
Wanneer het blad verandert https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly
Voeg een rij toe https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
Rijen bijwerken https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
Rijen wissen https://www.googleapis.com/auth/spreadsheet https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
Haal de inhoud van het blad op https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
Google Docs
Maak een Google-document aan https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly
Voeg toe aan een document https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly
Google Agenda en Taken
Gebaseerd op een vergadering https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/calendar.events.readonly
Taak aanmaken https://www.googleapis.com/auth/tasks
Evenement aanmaken https://www.googleapis.com/auth/calendar.events
Voeg gasten toe https://www.googleapis.com/auth/calendar.events
Google Drive
Wanneer een item aan een map wordt toegevoegd https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly
Wanneer een bestand wordt bewerkt https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
Wanneer een item in een map wordt bewerkt https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly
Verplaats bestand https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
Kopieer bestand https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
Bijlagen opslaan https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
Maak een map aan https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
Google Meet
Bij het notuleren van vergaderingen https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.meet.readonly https://www.googleapis.com/auth/meetings.space.created https://www.googleapis.com/auth/calendar.events.readonly https://www.googleapis.com/auth/meetings.space.readonly
Google Forms
Wanneer een formulierreactie binnenkomt https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/forms.responses.readonly https://www.googleapis.com/auth/forms.body.readonly https://www.googleapis.com/auth/drive.readonly (alleen voor DLP-bestandsondersteuning in formulieren)
NotebookLM
Voeg bron toe aan NotebookLM https://www.googleapis.com/auth/drive.readonly
Vraag het aan NotebookLM https://www.googleapis.com/auth/drive.readonly