在 Google Workspace Studio 中建構及執行自動化流程時,系統預設會內建安全性和資料隱私權功能。Workspace Studio 採用最低權限身分識別模型,也就是說,自動化流程執行背景工作時,只會使用執行各項動作所需的最低權限,不會無限制地存取使用者的整個 Google 帳戶。
如要安全地設定自動化功能,並掌握貴機構資料的存取方式,請參閱本指南,瞭解流程中每個步驟所需的權限。本頁面提供每個流程步驟類型及其所需的開放授權 (OAuth) 範圍對應表。
OAuth 範圍對 Studio 使用體驗的影響
使用 Workspace Studio 時,OAuth 範圍會以以下方式影響工作流程的建構、執行和管理:
- 一次性授權:首次新增與 Google 服務 (例如 Gmail 或 Google 雲端硬碟) 互動的步驟時,系統會顯示 Google 登入提示。這樣一來,該步驟就能獲得特定範圍的授權,流程也能在背景獨立執行。
- 非同步背景執行:流程開啟後,會在 Google 基礎架構上非同步執行。即使您未主動登入,流程也只會使用您核准的特定範圍執行工作 (例如安排 Google 日曆活動或撰寫草稿)。
- 集中管理員監督:管理員可以在管理控制台的「代理程式存取權管理」設定中,查看機構內所有有效流程。您可以暫停特定流程或指定及限制個別 OAuth 範圍 (例如移除雲端硬碟存取權,但保留 Gmail 存取權),確保貴機構的資料安全。瞭解詳情
排解權限不足問題
如果流程無法執行,且活動記錄中顯示「權限不足」或「發生錯誤」訊息,請檢查下列事項:
- 重新授權流程:在「建立工具」中開啟流程,按一下「儲存變更」,然後按照授權方塊中的任何提示,重新整理過期或遺失的 OAuth 權杖。
- 情境感知存取權 (CAA) 封鎖:如果貴機構嚴格執行裝置或 IP 政策,有時可能會封鎖背景流程執行作業。確認核心 Workspace Studio 用戶端 ID 不受 CAA 限制。
流程步驟和必要 OAuth 範圍
下表列出標準 Workspace Studio 步驟,以及每個步驟在幕後執行時所需的 OAuth 範圍。
| 步驟名稱 | 設定和範圍 |
|---|---|
| Studio AI 步驟 | |
| AIP 基本功能 (詢問 Gemini、詢問 Gem、使用 Gemini 建立內容、Deep Research、摘要未讀郵件、擷取、決定、摘要) | https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/cloud_search.query |
| 一般和公用程式 | |
| 依時間表 | 不適用 |
| 傳送 Webhook | 不適用 - 外部第三方 |
| 檢查是否 | 不適用 - 內部邏輯 |
| 篩選清單 | 不適用 - 內部邏輯 |
| Gmail | |
| 收到電子郵件時 | https://www.googleapis.com/auth/gmail.readonly https://www.googleapis.com/auth/gmail.event_trigger https://www.googleapis.com/auth/workspace.workflows.trigger |
| 透過電子郵件通知我 | https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly |
| 傳送電子郵件 | https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly |
| 撰寫電子郵件草稿 | https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.readonly |
| 轉寄電子郵件 | https://www.googleapis.com/auth/gmail.send https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly |
| 草擬回覆內容 | https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly |
| 回覆電子郵件 | https://www.googleapis.com/auth/gmail.compose https://www.googleapis.com/auth/gmail.readonly |
| 新增或移除標籤 | https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly |
| 標示為已讀取或未讀取 | https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly |
| 加上或移除星號 | https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly |
| 封存 (或刪除) | https://www.googleapis.com/auth/gmail.modify https://www.googleapis.com/auth/gmail.readonly |
| Google Chat | |
| 有人加入聊天室時 | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces |
| 收到即時通訊訊息時 | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces |
| 有人提及我時 | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces |
| 有人加上表情符號回應時 | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces |
| 在 Chat 中通知我 | https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships |
| 傳送聊天室 | https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces.create https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships https://www.googleapis.com/auth/chat.spaces |
| 傳送給其他人 | https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships |
| 回覆訊息 | https://www.googleapis.com/auth/chat.messages.create https://www.googleapis.com/auth/chat.spaces https://www.googleapis.com/auth/chat.messages.readonly https://www.googleapis.com/auth/chat.spaces.readonly https://www.googleapis.com/auth/chat.memberships.app https://www.googleapis.com/auth/chat.memberships.readonly https://www.googleapis.com/auth/chat.memberships |
| Google 試算表 | |
| 工作表變更時 | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly |
| 新增列 | https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly |
| 更新列 | https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly |
| 清除多列資料 | https://www.googleapis.com/auth/spreadsheet https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly |
| 取得工作表內容 | https://www.googleapis.com/auth/spreadsheets https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly |
| Google 文件 | |
| 建立 Google 文件 | https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly |
| 新增到文件 | https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/documents https://www.googleapis.com/auth/drive.readonly |
| Google 日曆和 Tasks | |
| 由會議觸發 | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/calendar.events.readonly |
| 建立工作 | https://www.googleapis.com/auth/tasks |
| 建立活動 | https://www.googleapis.com/auth/calendar.events |
| 新增邀請對象 | https://www.googleapis.com/auth/calendar.events |
| Google 雲端硬碟 | |
| 在資料夾中新增項目時 | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly |
| 有人編輯檔案時 | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.metadata.readonly |
| 有人編輯資料夾中的項目時 | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly |
| 移動檔案 | https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly |
| 複製檔案 | https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly |
| 儲存附件 | https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly |
| 建立資料夾 | https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.metadata.readonly https://www.googleapis.com/auth/drive.readonly |
| Google Meet | |
| 會議筆記 | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/drive.meet.readonly https://www.googleapis.com/auth/meetings.space.created https://www.googleapis.com/auth/calendar.events.readonly https://www.googleapis.com/auth/meetings.space.readonly |
| Google 表單 | |
| 有人回覆表單時 | https://www.googleapis.com/auth/workspace.workflows.trigger https://www.googleapis.com/auth/forms.responses.readonly https://www.googleapis.com/auth/forms.body.readonly https://www.googleapis.com/auth/drive.readonly (僅適用於表單中的 DLP 檔案支援) |
| NotebookLM | |
| 新增來源至 NotebookLM | https://www.googleapis.com/auth/drive.readonly |
| 問問 NotebookLM | https://www.googleapis.com/auth/drive.readonly |