เมื่อคุณสร้างและเรียกใช้โฟลว์อัตโนมัติใน Google Workspace Studio ระบบจะติดตั้งการรักษาความปลอดภัยและความเป็นส่วนตัวของข้อมูลไว้ให้โดยค่าเริ่มต้น Workspace Studio ใช้โมเดลข้อมูลประจำตัวที่มีสิทธิ์น้อยที่สุด ซึ่งหมายความว่าโฟลว์อัตโนมัติจะเรียกใช้ฟังก์ชันการทำงานเบื้องหลังโดยใช้สิทธิ์ขั้นต่ำที่จำเป็นในการดำเนินการแต่ละอย่างเท่านั้น แทนที่จะมีสิทธิ์เข้าถึงบัญชี Google ทั้งหมดของผู้ใช้แบบกว้างๆ และไม่จำกัด
หากต้องการกำหนดค่าระบบอัตโนมัติอย่างปลอดภัยและรักษาการมองเห็นวิธีเข้าถึงข้อมูลขององค์กร ให้ใช้คู่มือนี้เพื่อระบุสิทธิ์ที่จำเป็นสำหรับแต่ละขั้นตอนในโฟลว์ หน้านี้จะแสดงการแมปประเภทขั้นตอนของโฟลว์แต่ละประเภทและขอบเขตการให้สิทธิ์แบบเปิด (OAuth) ที่จำเป็น
วิธีที่ขอบเขต OAuth ส่งผลต่อการใช้ Studio
เมื่อคุณใช้ Workspace Studio ขอบเขต OAuth จะส่งผลต่อวิธีที่คุณสร้าง เรียกใช้ และจัดการโฟลว์ในลักษณะต่อไปนี้
- การให้สิทธิ์แบบครั้งเดียว: ในครั้งแรกที่คุณเพิ่มขั้นตอนที่โต้ตอบกับบริการของ Google (เช่น Gmail หรือ Google ไดรฟ์) คุณจะได้รับข้อความแจ้งให้ลงชื่อเข้าใช้ Google ซึ่งจะให้สิทธิ์ขอบเขตที่เฉพาะเจาะจงสำหรับขั้นตอนนี้เพื่อให้โฟลว์ทำงานในเบื้องหลังได้อย่างอิสระ
- การดำเนินการเบื้องหลังแบบไม่พร้อมกัน: หลังจากเปิดโฟลว์แล้ว โฟลว์จะทำงานแบบไม่พร้อมกันในโครงสร้างพื้นฐานของ Google โฟลว์จะทำงานต่างๆ (เช่น การกำหนดเวลากิจกรรมในปฏิทินหรือการเขียนฉบับร่าง) โดยใช้ขอบเขตที่เฉพาะเจาะจงที่คุณอนุมัติเท่านั้น แม้ว่าคุณจะไม่ได้ลงชื่อเข้าใช้อยู่ก็ตาม
- การควบคุมดูแลของผู้ดูแลระบบแบบรวมศูนย์: ในฐานะผู้ดูแลระบบ คุณสามารถดูโฟลว์ที่ใช้งานอยู่ทั้งหมดในองค์กรได้โดยใช้การตั้งค่าการจัดการการเข้าถึงของ Agent ในคอนโซลผู้ดูแลระบบ คุณสามารถหยุดโฟลว์ที่เฉพาะเจาะจงชั่วคราว หรือกำหนดเป้าหมายและจำกัดขอบเขต OAuth แต่ละรายการ (เช่น การนำสิทธิ์เข้าถึงไดรฟ์ออกในขณะที่ยังคงเปิดใช้งาน Gmail ไว้) เพื่อรักษาข้อมูลขององค์กรให้ปลอดภัย ดูข้อมูลเพิ่มเติม
แก้ปัญหาเกี่ยวกับสิทธิ์ไม่เพียงพอ
หากโฟลว์ไม่ทำงานและแสดงข้อผิดพลาด "สิทธิ์ไม่เพียงพอ" หรือ "เกิดข้อผิดพลาด" ในบันทึกกิจกรรม ให้ตรวจสอบสิ่งต่อไปนี้
- ให้สิทธิ์โฟลว์อีกครั้ง: เปิดโฟลว์ในเครื่องมือสร้าง คลิกบันทึกการเปลี่ยนแปลง แล้วทำตามข้อความแจ้งในช่องการให้สิทธิ์เพื่อรีเฟรชโทเค็น OAuth ที่หมดอายุหรือหายไป
- การเข้าถึงแบบ Context-Aware (CAA) บล็อก: หากองค์กรของคุณบังคับใช้นโยบายอุปกรณ์หรือนโยบาย IP อย่างเข้มงวด ระบบอาจบล็อกการดำเนินการโฟลว์เบื้องหลังในบางครั้ง ตรวจสอบว่ารหัสไคลเอ็นต์หลักของ Workspace Studio ได้รับการยกเว้นจากข้อจำกัด CAA
ขั้นตอนของโฟลว์และขอบเขต OAuth ที่จำเป็น
ตารางนี้แสดงขั้นตอนมาตรฐานของ Workspace Studio และขอบเขต OAuth ที่แต่ละขั้นตอนต้องใช้ในการทำงานเบื้องหลัง
| ชื่อขั้นตอน | การกำหนดค่าและขอบเขต |
|---|---|
| ขั้นตอน AI ของ Studio | |
| AIP Primitive (ขอความช่วยเหลือจาก Gemini, ขอความช่วยเหลือจาก Gem, สร้างด้วย Gemini, Deep Research, สรุปอีเมลที่ยังไม่อ่าน, แยก, ตัดสินใจ, สรุป) | https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/cloud_search.query |
| ทั่วไปและยูทิลิตี้ | |
| ตามกำหนดเวลา | ไม่มี |
| ส่งเว็บฮุค | ไม่มี - บุคคลที่สามภายนอก |
| ตรวจสอบว่า | ไม่มี - ตรรกะภายใน |
| กรองรายการ | ไม่มี - ตรรกะภายใน |
| Gmail | |
| เมื่อได้รับอีเมล | https://www.googleapis.com/auth/gmail.readonly https://www.googleapis.com/auth/gmail.event_trigger https://www.googleapis.com/auth/workspace.workflows.trigger |
| แจ้งเตือนฉันทางอีเมล | https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly |
| ส่งอีเมล | https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly |
| ร่างอีเมล | https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly |
| ส่งต่ออีเมล | https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly |
| ร่างการตอบกลับ | https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly |
| ตอบกลับอีเมล | https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly |
| เพิ่มหรือนำป้ายกำกับออก | https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly |
| ทำเครื่องหมายว่าอ่านแล้วหรือยังไม่อ่าน | https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly |
| ติดดาวหรือยกเลิกการติดดาว | https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly |
| เก็บ (หรือลบ) | https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly |
| Google Chat | |
| เมื่อมีผู้เข้าร่วมพื้นที่ทำงาน | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces |
| เมื่อได้รับข้อความแชท | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces |
| เมื่อมีคนพูดถึงฉัน | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces |
| เมื่อเพิ่มรีแอ็กชันด้วยอีโมจิ | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces |
| แจ้งเตือนฉันใน Chat | https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships |
| ส่งพื้นที่แชท | https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces.create https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces |
| ส่งให้คนอื่น | https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships |
| ตอบกลับข้อความ | https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships |
| Google ชีต | |
| เมื่อชีตมีการเปลี่ยนแปลง | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly |
| เพิ่มแถว | https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly |
| อัปเดตแถว | https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly |
| ล้างแถว | https://www.googleapis.com/auth/spreadsheet https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly |
| รับเนื้อหาของชีต | https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly |
| Google เอกสาร | |
| สร้างเอกสารใน Google เอกสาร | https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly |
| เพิ่มลงในเอกสาร | https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly |
| Google ปฏิทินและ Tasks | |
| อิงตามการประชุม | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/calendar.events.readonly |
| สร้างงาน | https://www.googleapis.com/auth/tasks |
| สร้างกิจกรรม | https://www.googleapis.com/auth/calendar.events |
| เพิ่มผู้เข้าร่วม | https://www.googleapis.com/auth/calendar.events |
| Google ไดรฟ์ | |
| เมื่อเพิ่มรายการลงในโฟลเดอร์ | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly |
| เมื่อมีการแก้ไขไฟล์ | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly |
| เมื่อมีการแก้ไขรายการในโฟลเดอร์ | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly |
| ย้ายไฟล์ | https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly |
| คัดลอกไฟล์ | https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly |
| บันทึกไฟล์แนบ | https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly |
| สร้างโฟลเดอร์ | https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly |
| Google Meet | |
| เมื่อมีการจดบันทึกการประชุม | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.meet.readonly https://www.googleapis.com/auth/meetings.space.created https://www.googleapis.com/auth/calendar.events.readonly https://www.googleapis.com/auth/meetings.space.readonly |
| Google ฟอร์ม | |
| เมื่อมีการส่งคำตอบของแบบฟอร์ม | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/forms.responses.readonly https://www.googleapis.com/auth/forms.body.readonly https://www.googleapis.com/auth/drive.readonly (เฉพาะสำหรับการรองรับไฟล์ DLP ใน Forms) |
| NotebookLM | |
| เพิ่มแหล่งข้อมูลไปยัง NotebookLM | https://www.googleapis.com/auth/drive.readonly |
| ขอความช่วยเหลือจาก NotebookLM | https://www.googleapis.com/auth/drive.readonly |