在 Google Workspace Studio 中构建和运行自动化流程时,系统默认会内置安全和数据隐私权保护功能。Workspace Studio 采用的是最低权限身份模型,这意味着自动化流程在运行后台任务时,只会使用执行每项操作所需的最低权限,而不会拥有对用户整个 Google 账号的广泛不受限的访问权限。
为了安全地配置自动化流程并随时了解组织数据的访问方式,请使用本指南来确定流程中每个步骤所需的权限。本页面提供了每个流程步骤类型及其所需的开放授权 (OAuth) 范围的对应关系。
OAuth 权限范围对您使用 Studio 的影响
使用 Workspace Studio 时,OAuth 权限范围会以以下方式影响您构建、运行和管理工作流的方式:
- 一次性授权:首次添加与 Google 服务(例如 Gmail 或 Google 云端硬盘)互动的步骤时,系统会显示 Google 登录提示。这会为相应步骤授权特定范围,以便流程可以在后台独立运行。
- 异步后台执行:开启流程后,流程会在 Google 的基础设施上异步运行。即使您未主动登录,该流程也只会使用您批准的特定范围来执行任务(例如安排日历活动或撰写草稿)。
- 集中式管理员监督:作为管理员,您可以在管理控制台中使用客服人员访问权限管理设置查看组织中的所有有效流程。您可以暂停特定流程或定位并限制各个 OAuth 范围(例如移除云端硬盘访问权限,同时保持 Gmail 处于有效状态),以确保组织的数据安全。了解详情
排查权限不足问题
如果某个流未运行,并且在活动日志中显示“权限不足”或“出了点问题”错误,请检查以下各项:
- 重新授权工作流:在构建器中打开工作流,点击保存更改,然后按照授权框中的任何提示刷新已过期或缺失的 OAuth 令牌。
- 情境感知访问权限 (CAA) 屏蔽:如果贵组织严格执行设备或 IP 政策,有时可能会屏蔽后台流程执行。确保核心 Workspace Studio 客户端 ID 不受 CAA 限制。
流程步骤和所需的 OAuth 范围
下表列出了标准的 Workspace Studio 步骤,以及每个步骤在后台运行所需的 OAuth 范围。
| 步骤名称 | 配置和范围 |
|---|---|
| Studio AI 步骤 | |
| AIP 原语(向 Gemini 提问、向 Gem 提问、使用 Gemini 创建内容、Deep Research、总结未读电子邮件、提取、决定、总结) | https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/cloud_search.query |
| 常规和实用工具 | |
| 按时间表 | 不适用 |
| 发送 webhook | 不适用 - 外部第三方 |
| 检查是否 | 不适用 - 内部逻辑 |
| 过滤列表 | 不适用 - 内部逻辑 |
| Gmail | |
| 当我收到电子邮件时 | https://www.googleapis.com/auth/gmail.readonly https://www.googleapis.com/auth/gmail.event_trigger https://www.googleapis.com/auth/workspace.workflows.trigger |
| 通过电子邮件通知我 | https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly |
| 发送电子邮件 | https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly |
| 撰写电子邮件 | https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly |
| 转发电子邮件 | https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly |
| 撰写回复草稿 | https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly |
| 回复电子邮件 | https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly |
| 添加或移除标签 | https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly |
| 标记为已读或未读 | https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly |
| 加星标或移除星标 | https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly |
| 归档(或删除) | https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly |
| Google Chat | |
| 有人加入聊天室时 | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces |
| 当我收到聊天消息时 | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces |
| 有人提及我时 | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces |
| 添加表情符号回应时 | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces |
| 在 Chat 中通知我 | https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships |
| 发送聊天室 | https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces.create https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces |
| 发送给他人 | https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships |
| 回复消息 | https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships |
| Google 表格 | |
| 当工作表发生更改时 | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly |
| 添加行 | https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly |
| 更新行 | https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly |
| 清除行 | https://www.googleapis.com/auth/spreadsheet https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly |
| 获取工作表内容 | https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly |
| Google 文档 | |
| 创建 Google 文档 | https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly |
| 添加到文档 | https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly |
| Google 日历和 Google Tasks | |
| 基于会议 | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/calendar.events.readonly |
| 创建任务 | https://www.googleapis.com/auth/tasks |
| 创建活动 | https://www.googleapis.com/auth/calendar.events |
| 添加邀请对象 | https://www.googleapis.com/auth/calendar.events |
| Google 云端硬盘 | |
| 当内容添加到文件夹时 | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly |
| 当文件被修改时 | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly |
| 当文件夹中的内容项被修改时 | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly |
| 移动文件 | https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly |
| 复制文件 | https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly |
| 保存附件 | https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly |
| 创建文件夹 | https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly |
| Google Meet | |
| 会议记录 | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.meet.readonly https://www.googleapis.com/auth/meetings.space.created https://www.googleapis.com/auth/calendar.events.readonly https://www.googleapis.com/auth/meetings.space.readonly |
| Google 表单 | |
| 当收到表单回复时 | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/forms.responses.readonly https://www.googleapis.com/auth/forms.body.readonly https://www.googleapis.com/auth/drive.readonly(仅用于表单中的 DLP 文件支持) |
| NotebookLM | |
| 向 NotebookLM 添加来源 | https://www.googleapis.com/auth/drive.readonly |
| 向 NotebookLM 提问 | https://www.googleapis.com/auth/drive.readonly |