Workspace Studio 工作流程步驟的 OAuth 範圍和權限

在 Google Workspace Studio 中建構及執行自動化流程時,系統預設會內建安全性和資料隱私權功能。Workspace Studio 採用最低權限身分識別模型,也就是說,自動化流程執行背景工作時,只會使用執行各項動作所需的最低權限,不會無限制地存取使用者的整個 Google 帳戶。

如要安全地設定自動化功能,並掌握貴機構資料的存取方式,請參閱本指南,瞭解流程中每個步驟所需的權限。本頁面提供每個流程步驟類型及其所需的開放授權 (OAuth) 範圍對應表。

OAuth 範圍對 Studio 使用體驗的影響

使用 Workspace Studio 時,OAuth 範圍會以以下方式影響工作流程的建構、執行和管理:

  • 一次性授權:首次新增與 Google 服務 (例如 Gmail 或 Google 雲端硬碟) 互動的步驟時,系統會顯示 Google 登入提示。這樣一來,該步驟就能獲得特定範圍的授權,流程也能在背景獨立執行。
  • 非同步背景執行:流程開啟後,會在 Google 基礎架構上非同步執行。即使您未主動登入,流程也只會使用您核准的特定範圍執行工作 (例如安排 Google 日曆活動或撰寫草稿)。
  • 集中管理員監督:管理員可以在管理控制台的「代理程式存取權管理」設定中,查看機構內所有有效流程。您可以暫停特定流程或指定及限制個別 OAuth 範圍 (例如移除雲端硬碟存取權,但保留 Gmail 存取權),確保貴機構的資料安全。瞭解詳情

排解權限不足問題

如果流程無法執行,且活動記錄中顯示「權限不足」或「發生錯誤」訊息,請檢查下列事項:

  • 重新授權流程:在「建立工具」中開啟流程,按一下「儲存變更」,然後按照授權方塊中的任何提示,重新整理過期或遺失的 OAuth 權杖。
  • 情境感知存取權 (CAA) 封鎖:如果貴機構嚴格執行裝置或 IP 政策,有時可能會封鎖背景流程執行作業。確認核心 Workspace Studio 用戶端 ID 不受 CAA 限制。

流程步驟和必要 OAuth 範圍

下表列出標準 Workspace Studio 步驟,以及每個步驟在幕後執行時所需的 OAuth 範圍。

步驟名稱 設定和範圍
Studio AI 步驟
AIP 基本功能 (詢問 Gemini、詢問 Gem、使用 Gemini 建立內容、Deep Research、摘要未讀郵件、擷取、決定、摘要) https://www.googleapis.com/auth/drive
https://www.googleapis.com/auth/documents
https://www.googleapis.com/auth/spreadsheets
https://www.googleapis.com/auth/cloud_search.query
一般和公用程式
依時間表 不適用
傳送 Webhook 不適用 - 外部第三方
檢查是否 不適用 - 內部邏輯
篩選清單 不適用 - 內部邏輯
Gmail
收到電子郵件時 https://www.googleapis.com/auth/gmail.readonly https://www.googleapis.com/auth/gmail.event_trigger https://www.googleapis.com/auth/workspace.workflows.trigger 
透過電子郵件通知我 https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly
傳送電子郵件 https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
撰寫電子郵件草稿 https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly
轉寄電子郵件 https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
草擬回覆內容 https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
回覆電子郵件 https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly
新增或移除標籤 https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
標示為已讀取或未讀取 https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
加上或移除星號 https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
封存 (或刪除) https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly
Google Chat
有人加入聊天室時 https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
收到即時通訊訊息時 https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
有人提及我時 https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
有人加上表情符號回應時 https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
在 Chat 中通知我 https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships
傳送聊天室 https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces.create https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces
傳送給其他人 https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships
回覆訊息 https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships
Google 試算表
工作表變更時 https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly
新增列 https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
更新列 https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
清除多列資料 https://www.googleapis.com/auth/spreadsheet https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
取得工作表內容 https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
Google 文件
建立 Google 文件 https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly
新增到文件 https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly
Google 日曆和 Tasks
由會議觸發 https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/calendar.events.readonly 
建立工作 https://www.googleapis.com/auth/tasks
建立活動 https://www.googleapis.com/auth/calendar.events
新增邀請對象 https://www.googleapis.com/auth/calendar.events
Google 雲端硬碟
在資料夾中新增項目時 https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly
有人編輯檔案時 https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly
有人編輯資料夾中的項目時 https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly
移動檔案 https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
複製檔案 https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
儲存附件 https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
建立資料夾 https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly
Google Meet
會議筆記 https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.meet.readonly https://www.googleapis.com/auth/meetings.space.created https://www.googleapis.com/auth/calendar.events.readonly https://www.googleapis.com/auth/meetings.space.readonly
Google 表單
有人回覆表單時 https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/forms.responses.readonly https://www.googleapis.com/auth/forms.body.readonly https://www.googleapis.com/auth/drive.readonly (僅適用於表單中的 DLP 檔案支援)
NotebookLM
新增來源至 NotebookLM https://www.googleapis.com/auth/drive.readonly
問問 NotebookLM https://www.googleapis.com/auth/drive.readonly