ขอบเขต OAuth และสิทธิ์สำหรับขั้นตอนโฟลว์ของ Workspace Studio

เมื่อคุณสร้างและเรียกใช้โฟลว์อัตโนมัติใน Google Workspace Studio ระบบจะติดตั้งการรักษาความปลอดภัยและความเป็นส่วนตัวของข้อมูลไว้ให้โดยค่าเริ่มต้น Workspace Studio ใช้โมเดลข้อมูลประจำตัวที่มีสิทธิ์น้อยที่สุด ซึ่งหมายความว่าโฟลว์อัตโนมัติจะเรียกใช้ฟังก์ชันการทำงานเบื้องหลังโดยใช้สิทธิ์ขั้นต่ำที่จำเป็นในการดำเนินการแต่ละอย่างเท่านั้น แทนที่จะมีสิทธิ์เข้าถึงบัญชี Google ทั้งหมดของผู้ใช้แบบกว้างๆ และไม่จำกัด

หากต้องการกำหนดค่าระบบอัตโนมัติอย่างปลอดภัยและรักษาการมองเห็นวิธีเข้าถึงข้อมูลขององค์กร ให้ใช้คู่มือนี้เพื่อระบุสิทธิ์ที่จำเป็นสำหรับแต่ละขั้นตอนในโฟลว์ หน้านี้จะแสดงการแมปประเภทขั้นตอนของโฟลว์แต่ละประเภทและขอบเขตการให้สิทธิ์แบบเปิด (OAuth) ที่จำเป็น

วิธีที่ขอบเขต OAuth ส่งผลต่อการใช้ Studio

เมื่อคุณใช้ Workspace Studio ขอบเขต OAuth จะส่งผลต่อวิธีที่คุณสร้าง เรียกใช้ และจัดการโฟลว์ในลักษณะต่อไปนี้

  • การให้สิทธิ์แบบครั้งเดียว: ในครั้งแรกที่คุณเพิ่มขั้นตอนที่โต้ตอบกับบริการของ Google (เช่น Gmail หรือ Google ไดรฟ์) คุณจะได้รับข้อความแจ้งให้ลงชื่อเข้าใช้ Google ซึ่งจะให้สิทธิ์ขอบเขตที่เฉพาะเจาะจงสำหรับขั้นตอนนี้เพื่อให้โฟลว์ทำงานในเบื้องหลังได้อย่างอิสระ
  • การดำเนินการเบื้องหลังแบบไม่พร้อมกัน: หลังจากเปิดโฟลว์แล้ว โฟลว์จะทำงานแบบไม่พร้อมกันในโครงสร้างพื้นฐานของ Google โฟลว์จะทำงานต่างๆ (เช่น การกำหนดเวลากิจกรรมในปฏิทินหรือการเขียนฉบับร่าง) โดยใช้ขอบเขตที่เฉพาะเจาะจงที่คุณอนุมัติเท่านั้น แม้ว่าคุณจะไม่ได้ลงชื่อเข้าใช้อยู่ก็ตาม
  • การควบคุมดูแลของผู้ดูแลระบบแบบรวมศูนย์: ในฐานะผู้ดูแลระบบ คุณสามารถดูโฟลว์ที่ใช้งานอยู่ทั้งหมดในองค์กรได้โดยใช้การตั้งค่าการจัดการการเข้าถึงของ Agent ในคอนโซลผู้ดูแลระบบ คุณสามารถหยุดโฟลว์ที่เฉพาะเจาะจงชั่วคราว หรือกำหนดเป้าหมายและจำกัดขอบเขต OAuth แต่ละรายการ (เช่น การนำสิทธิ์เข้าถึงไดรฟ์ออกในขณะที่ยังคงเปิดใช้งาน Gmail ไว้) เพื่อรักษาข้อมูลขององค์กรให้ปลอดภัย ดูข้อมูลเพิ่มเติม

แก้ปัญหาเกี่ยวกับสิทธิ์ไม่เพียงพอ

หากโฟลว์ไม่ทำงานและแสดงข้อผิดพลาด "สิทธิ์ไม่เพียงพอ" หรือ "เกิดข้อผิดพลาด" ในบันทึกกิจกรรม ให้ตรวจสอบสิ่งต่อไปนี้

  • ให้สิทธิ์โฟลว์อีกครั้ง: เปิดโฟลว์ในเครื่องมือสร้าง คลิกบันทึกการเปลี่ยนแปลง แล้วทำตามข้อความแจ้งในช่องการให้สิทธิ์เพื่อรีเฟรชโทเค็น OAuth ที่หมดอายุหรือหายไป
  • การเข้าถึงแบบ Context-Aware (CAA) บล็อก: หากองค์กรของคุณบังคับใช้นโยบายอุปกรณ์หรือนโยบาย IP อย่างเข้มงวด ระบบอาจบล็อกการดำเนินการโฟลว์เบื้องหลังในบางครั้ง ตรวจสอบว่ารหัสไคลเอ็นต์หลักของ Workspace Studio ได้รับการยกเว้นจากข้อจำกัด CAA

ขั้นตอนของโฟลว์และขอบเขต OAuth ที่จำเป็น

ตารางนี้แสดงขั้นตอนมาตรฐานของ Workspace Studio และขอบเขต OAuth ที่แต่ละขั้นตอนต้องใช้ในการทำงานเบื้องหลัง

ชื่อขั้นตอน การกำหนดค่าและขอบเขต
ขั้นตอน AI ของ Studio
AIP Primitive (ขอความช่วยเหลือจาก Gemini, ขอความช่วยเหลือจาก Gem, สร้างด้วย Gemini, Deep Research, สรุปอีเมลที่ยังไม่อ่าน, แยก, ตัดสินใจ, สรุป) https://www.googleapis.com/auth/drive
https://www.googleapis.com/auth/documents
https://www.googleapis.com/auth/spreadsheets
https://www.googleapis.com/auth/cloud_search.query
ทั่วไปและยูทิลิตี้
ตามกำหนดเวลา ไม่มี
ส่งเว็บฮุค ไม่มี - บุคคลที่สามภายนอก
ตรวจสอบว่า ไม่มี - ตรรกะภายใน
กรองรายการ ไม่มี - ตรรกะภายใน
Gmail
เมื่อได้รับอีเมล https://www.googleapis.com/auth/gmail.readonly https://www.googleapis.com/auth/gmail.event_trigger https://www.googleapis.com/auth/workspace.workflows.trigger
แจ้งเตือนฉันทางอีเมล https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly
ส่งอีเมล https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
ร่างอีเมล https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly
ส่งต่ออีเมล https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
ร่างการตอบกลับ https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
ตอบกลับอีเมล https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
เพิ่มหรือนำป้ายกำกับออก https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
ทำเครื่องหมายว่าอ่านแล้วหรือยังไม่อ่าน https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
ติดดาวหรือยกเลิกการติดดาว https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
เก็บ (หรือลบ) https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
Google Chat
เมื่อมีผู้เข้าร่วมพื้นที่ทำงาน https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
เมื่อได้รับข้อความแชท https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
เมื่อมีคนพูดถึงฉัน https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
เมื่อเพิ่มรีแอ็กชันด้วยอีโมจิ https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
แจ้งเตือนฉันใน Chat https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships
ส่งพื้นที่แชท https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces.create https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
ส่งให้คนอื่น https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships
ตอบกลับข้อความ https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships
Google ชีต
เมื่อชีตมีการเปลี่ยนแปลง https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly
เพิ่มแถว https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
อัปเดตแถว https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
ล้างแถว https://www.googleapis.com/auth/spreadsheet https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
รับเนื้อหาของชีต https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
Google เอกสาร
สร้างเอกสารใน Google เอกสาร https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly
เพิ่มลงในเอกสาร https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly
Google ปฏิทินและ Tasks
อิงตามการประชุม https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/calendar.events.readonly
สร้างงาน https://www.googleapis.com/auth/tasks
สร้างกิจกรรม https://www.googleapis.com/auth/calendar.events
เพิ่มผู้เข้าร่วม https://www.googleapis.com/auth/calendar.events
Google ไดรฟ์
เมื่อเพิ่มรายการลงในโฟลเดอร์ https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly
เมื่อมีการแก้ไขไฟล์ https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
เมื่อมีการแก้ไขรายการในโฟลเดอร์ https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly
ย้ายไฟล์ https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
คัดลอกไฟล์ https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
บันทึกไฟล์แนบ https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
สร้างโฟลเดอร์ https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
Google Meet
เมื่อมีการจดบันทึกการประชุม https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.meet.readonly https://www.googleapis.com/auth/meetings.space.created https://www.googleapis.com/auth/calendar.events.readonly https://www.googleapis.com/auth/meetings.space.readonly
Google ฟอร์ม
เมื่อมีการส่งคำตอบของแบบฟอร์ม https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/forms.responses.readonly https://www.googleapis.com/auth/forms.body.readonly https://www.googleapis.com/auth/drive.readonly (เฉพาะสำหรับการรองรับไฟล์ DLP ใน Forms)
NotebookLM
เพิ่มแหล่งข้อมูลไปยัง NotebookLM https://www.googleapis.com/auth/drive.readonly
ขอความช่วยเหลือจาก NotebookLM https://www.googleapis.com/auth/drive.readonly