|
[https://www.googleapis.com/auth/drive.readonly](https://www.googleapis.com/auth/drive.readonly)
|
Grants Moveworks read-only access to files, folders, and shared drives. This enables ingestion of metadata and file content without the ability to modify or delete any data.
|
|
[https://www.googleapis.com/auth/admin.directory.user.readonly](https://www.googleapis.com/auth/admin.directory.user.readonly)
|
Allows Moveworks to read user information (e.g., names, emails, org units) to associate Drive permissions with actual users in your workspace.
|
|
[https://www.googleapis.com/auth/admin.directory.group.readonly](https://www.googleapis.com/auth/admin.directory.group.readonly)
|
Enables Moveworks to read Google Groups used in Drive ACLs (e.g., “[Engineering@company.com](mailto:Engineering@company.com)
”), ensuring proper permissions enforcement during search.
|
|
[https://www.googleapis.com/auth/admin.directory.group.member.readonly](https://www.googleapis.com/auth/admin.directory.group.member.readonly)
|
Provides visibility into group memberships so Moveworks can determine which users have access through nested group permissions.
|