OAuth-omfång och behörigheter för Workspace Studio-flödessteg

När du skapar och kör automatiserade flöden i Google Workspace Studio är säkerhet och datasekretess inbyggda som standard. Workspace Studio använder en identitetsmodell med minst privilegierade rättigheter, vilket innebär att automatiserade flöden kör bakgrundsuppgifter med endast de lägsta behörigheter som krävs för att utföra varje enskild åtgärd, istället för att ha bred, obegränsad åtkomst till hela användarens Google-konto.

För att konfigurera din automatisering på ett säkert sätt och bibehålla insyn i hur din organisations data nås, använd den här guiden för att identifiera de behörigheter som krävs för varje steg i ett flöde. Den här sidan innehåller en mappning av varje flödesstegstyp och dess obligatoriska OAuth-omfång (Open Authorization).

Hur OAuth-omfång påverkar din användning av Studio

När du använder Workspace Studio påverkar OAuth-omfång hur du bygger, kör och hanterar dina flöden på följande sätt:

  • Engångsautentisering: Första gången du lägger till ett steg som interagerar med en Google-tjänst (som Gmail eller Google Drive) får du en inloggningsfråga för Google. Detta auktoriserar det specifika omfånget för det steget så att flödet kan köras oberoende i bakgrunden.
  • Asynkron bakgrundskörning: När ett flöde har aktiverats körs det asynkront på Googles infrastruktur. Flödet utför uppgifter (som att schemalägga en kalenderhändelse eller skriva ett utkast) med endast de specifika omfattningar du har godkänt, även när du inte är aktivt inloggad.
  • Centraliserad administratörsövervakning: Som administratör kan du se alla aktiva flöden i din organisation med hjälp av inställningarna för agentåtkomsthantering i din administratörskonsol. Du kan pausa specifika flöden eller rikta in dig på och begränsa enskilda OAuth-omfång (som att ta bort Drive-åtkomst medan Gmail lämnas aktivt) för att skydda organisationens data. Läs mer

Felsök otillräckliga behörigheter

Om ett flöde inte körs och visar felmeddelandet "Otillräckliga behörigheter" eller "Något gick fel" i aktivitetsloggen, kontrollera följande:

  • Omauktorisera ditt flöde: Öppna flödet i Builder, klicka på Spara ändringar och följ alla anvisningar i auktoriseringsrutan för att uppdatera utgångna eller saknade OAuth-tokens.
  • Kontextmedveten åtkomst (CAA)-blockeringar: Om din organisation strikt tillämpar enhets- eller IP-policyer kan bakgrundsflödeskörningar ibland blockeras. Se till att det centrala Workspace Studio-klient-ID:t är undantaget från CAA-restriktioner.

Flödessteg och obligatoriska OAuth-omfattningar

Den här tabellen beskriver standardsteg i Workspace Studio och de OAuth-omfång som varje steg kräver för att köras bakom kulisserna.

Stegnamn Konfiguration och omfattning
Studio AI-steg
AIP-primitiver (Fråga Gemini, Fråga en Gem, Skapa med Gemini, Djupgående research, Sammanfatta olästa e-postmeddelanden, Extrahera, Besluta, Sammanfatta) https://www.googleapis.com/auth/drive
https://www.googleapis.com/auth/documents
https://www.googleapis.com/auth/spreadsheets
https://www.googleapis.com/auth/cloud_search.query
Allmänna och allmännyttiga tjänster
Enligt ett schema Ej tillämpligt
Skicka webhook Ej tillämpligt - Extern 3P
Kontrollera om Ej tillämpligt - Intern logik
Filtrera en lista Ej tillämpligt - Intern logik
Gmail
När jag får ett e-postmeddelande https://www.googleapis.com/auth/gmail.readonly https://www.googleapis.com/auth/gmail.event_trigger https://www.googleapis.com/auth/workspace.workflows.trigger
Meddela mig via e-post https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly
Skicka ett e-postmeddelande https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
Utkast till e-postmeddelande https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly
Vidarebefordra ett e-postmeddelande https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
Utkast till svar https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
Svara på ett e-postmeddelande https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
Lägg till eller ta bort etiketter https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
Markera läst eller oläst https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
Stjärna eller ta bort stjärnan https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
Arkivera (eller radera) https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
Google Chat
När någon går med i ett utrymme https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
När jag får ett chattmeddelande https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
När jag blir omnämnd https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
När en emoji-reaktion läggs till https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
Meddela mig i chatten https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships
Skicka chattutrymme https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces.create https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
Skicka till andra https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships
Svara på meddelande https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships
Google Kalkylark
När bladet ändras https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly
Lägg till en rad https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
Uppdatera rader https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
Rensa rader https://www.googleapis.com/auth/spreadsheet https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
Hämta arkets innehåll https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
Google Dokument
Skapa ett Google-dokument https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly
Lägg till i ett dokument https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly
Google Kalender och Uppgifter
Baserat på ett möte https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/calendar.events.readonly
Skapa uppgift https://www.googleapis.com/auth/tasks
Skapa händelse https://www.googleapis.com/auth/calendar.events
Lägg till gäster https://www.googleapis.com/auth/calendar.events
Google Drive
När ett objekt läggs till i en mapp https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly
När en fil redigeras https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
När ett objekt i en mapp redigeras https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly
Flytta fil https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
Kopiera fil https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
Spara bilagor https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
Skapa en mapp https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
Google Meet
När man antecknar möten https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.meet.readonly https://www.googleapis.com/auth/meetings.space.created https://www.googleapis.com/auth/calendar.events.readonly https://www.googleapis.com/auth/meetings.space.readonly
Google Formulär
När ett formulärsvar kommer in https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/forms.responses.readonly https://www.googleapis.com/auth/forms.body.readonly https://www.googleapis.com/auth/drive.readonly (endast för stöd för DLP-filer i Formulär)
NotebookLM
Lägg till källa till NotebookLM https://www.googleapis.com/auth/drive.readonly
Fråga NotebookLM https://www.googleapis.com/auth/drive.readonly