Zakresy i uprawnienia OAuth dla kroków automatyzacji Workspace Studio

Gdy tworzysz i uruchamiasz zautomatyzowane przepływy w Google Workspace Studio, bezpieczeństwo i prywatność danych są domyślnie wbudowane. Workspace Studio korzysta z modelu tożsamości o najniższych uprawnieniach, co oznacza, że zautomatyzowane przepływy uruchamiają zadania w tle, używając tylko minimalnych uprawnień wymaganych do wykonania każdej czynności. Nie mają one szerokiego, nieograniczonego dostępu do całego konta Google użytkownika.

Aby bezpiecznie skonfigurować automatyzację i zachować wgląd w sposób uzyskiwania dostępu do danych organizacji, skorzystaj z tego przewodnika, aby określić uprawnienia wymagane na każdym etapie przepływu. Ta strona zawiera mapowanie każdego typu etapu przepływu i jego wymaganych zakresów Open Authorization (OAuth).

Jak zakresy OAuth wpływają na korzystanie z Workspace Studio

Gdy korzystasz z Workspace Studio, zakresy OAuth wpływają na sposób tworzenia, uruchamiania i zarządzania przepływami w następujący sposób:

  • Jednorazowa autoryzacja: gdy po raz pierwszy dodasz etap, który wchodzi w interakcję z usługą Google (np. Gmail lub Dysk Google), pojawi się prośba o zalogowanie się w Google. Autoryzuje to określony zakres dla tego etapu, dzięki czemu przepływ może działać niezależnie w tle.
  • Asynchroniczne wykonywanie w tle: po włączeniu przepływ działa asynchronicznie w infrastrukturze Google. Przepływ wykonuje zadania (np. planowanie wydarzenia w Kalendarzu lub pisanie wersji roboczej), używając tylko określonych zakresów, które zostały przez Ciebie zatwierdzone, nawet gdy nie jesteś zalogowany(-a).
  • Scentralizowany nadzór administratora: jako administrator możesz wyświetlić wszystkie aktywne przepływy w organizacji, korzystając z ustawień Zarządzanie dostępem agenta w konsoli administracyjnej. Aby chronić dane organizacji, możesz wstrzymać określone przepływy lub ograniczyć poszczególne zakresy OAuth (np. usunąć dostęp do Dysku, pozostawiając Gmaila aktywnego). Więcej informacji

Rozwiązywanie problemów z niewystarczającymi uprawnieniami

Jeśli przepływ nie działa i w dzienniku aktywności wyświetla się błąd „Niewystarczające uprawnienia” lub „Coś poszło nie tak”, sprawdź te kwestie:

  • Ponownie autoryzuj przepływ: otwórz przepływ w kreatorze, kliknij Zapisz zmiany i postępuj zgodnie z instrukcjami w polu autoryzacji, aby odświeżyć wygasłe lub brakujące tokeny OAuth.
  • Blokady dostępu zależnego od kontekstu: jeśli w organizacji obowiązują ścisłe zasady dotyczące urządzeń lub adresów IP, wykonywanie przepływów w tle może być czasami blokowane. Upewnij się, że identyfikator klienta podstawowego Workspace Studio jest wyłączony z ograniczeń dostępu zależnego od kontekstu.

Etapy przepływu i wymagane zakresy OAuth

Ta tabela zawiera listę standardowych etapów Workspace Studio i zakresów protokołu OAuth, których każdy etap wymaga do działania za kulisami.

Nazwa etapu Konfiguracja i zakres
Etapy AI w Workspace Studio
Prymitywy AIP (Zapytaj Gemini, Zapytaj Gem, Utwórz za pomocą Gemini, Deep Research, Podsumuj nieprzeczytane e-maile, Wyodrębnij, Zdecyduj, Podsumuj) https://www.googleapis.com/auth/drive
https://www.googleapis.com/auth/documents
https://www.googleapis.com/auth/spreadsheets
https://www.googleapis.com/auth/cloud_search.query
Ogólne i narzędzia
Zgodnie z harmonogramem Nie dotyczy
Wyślij webhooka Nie dotyczy – zewnętrzny sprzedawca
Sprawdź, czy Nie dotyczy – logika wewnętrzna
Filtruj listę Nie dotyczy – logika wewnętrzna
Gmail
Gdy dostanę e-maila https://www.googleapis.com/auth/gmail.readonly https://www.googleapis.com/auth/gmail.event_trigger https://www.googleapis.com/auth/workspace.workflows.trigger
Powiadom mnie e-mailem https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly
Wyślij e-maila https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
Napisz wersję roboczą e-maila https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly
Przekaż e-maila dalej https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
Utwórz wersję roboczą odpowiedzi https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
Odpowiedz na e-maila https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
Dodaj lub usuń etykiety https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
Oznacz jako przeczytane lub nieprzeczytane https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
Oznacz gwiazdką lub usuń to oznaczenie https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
Archiwizuj (lub usuń) https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
Google Chat
Gdy ktoś dołącza do pokoju https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
Gdy otrzymam wiadomość na czacie https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
Gdy ktoś doda o mnie wzmiankę https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
Gdy dodasz reakcję emotikonem https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
Powiadom mnie w Google Chat https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships
Wyślij na czat https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces.create https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
Wyślij do innych osób https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships
Odpowiedz na wiadomość https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships
Arkusze Google
Gdy arkusz się zmieni https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly
Dodaj wiersz https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
Aktualizuj wiersze https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
Wyczyść wiersze https://www.googleapis.com/auth/spreadsheet https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
Pobierz zawartość arkusza https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
Dokumenty Google
Utwórz dokument Google https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly
Dodaj do dokumentu https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly
Kalendarz Google i Zadania
Na podstawie spotkania https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/calendar.events.readonly
Utwórz zadanie https://www.googleapis.com/auth/tasks
Utwórz zdarzenie https://www.googleapis.com/auth/calendar.events
Dodaj gości https://www.googleapis.com/auth/calendar.events
Dysk Google
Gdy element zostanie dodany do folderu https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly
Gdy plik zostanie edytowany https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
Gdy element w folderze zostanie edytowany https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly
Przenieś plik https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
Kopiuj plik https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
Zapisz załączniki https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
Utwórz folder https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
Google Meet
Gdy notatki ze spotkania https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.meet.readonly https://www.googleapis.com/auth/meetings.space.created https://www.googleapis.com/auth/calendar.events.readonly https://www.googleapis.com/auth/meetings.space.readonly
Formularze Google
Gdy pojawi się odpowiedź z formularza https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/forms.responses.readonly https://www.googleapis.com/auth/forms.body.readonly https://www.googleapis.com/auth/drive.readonly (tylko w przypadku obsługi plików DLP w Formularzach)
NotebookLM
Dodaj źródło do NotebookLM https://www.googleapis.com/auth/drive.readonly
Zapytaj NotebookLM https://www.googleapis.com/auth/drive.readonly