GOOGLE WORKSPACE · FILES & DOCS
Read ranges, append rows, and update cells in their spreadsheets.
Each action is granted on its own. An agent allowed to read is not thereby allowed to write, and the scope beside each row is what the acting user must have connected for it to run at all.
Put Google Sheets behind one governed endpoint.
Same permissions, same audit trail, whatever else you connect next.