OA office system account authority management method

By obtaining the role change approval process in the OA office system in real time and using the role account permission mapping table, the office account permissions are automatically adjusted, which solves the problems of frequent operations and errors in traditional permission management, and efficient and accurate permission management is achieved.

CN120354398APending Publication Date: 2025-07-22CHINA YANGTZE POWER
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510441055.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-09
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

Traditional office account permission management is frequently operated in enterprises, has a large workload and is prone to errors, and it is impossible to adjust permissions in a timely manner.

Method used

By obtaining the role change approval process in the OA office system in real time, using the pre-built role account permission mapping table, the role permissions of the office account are automatically adjusted, and permission allocation without manual operation is achieved.

Benefits of technology

It realizes automatic adjustment of permissions according to role changes, reduces manual operations, improves the accuracy and work efficiency of permission allocation, and enhances the security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120354398A_ABST
    Figure CN120354398A_ABST
Patent Text Reader

Abstract

The invention provides an OA office system account authority management method, and relates to the technical field of account authority management, and the method comprises the steps: obtaining a role change approval process submitted by an office account in an OA office system in real time; determining role change information of the office account based on the role change approval process; under the condition that the role change approval process passes, the role permission of the office account is adjusted based on role change information and a pre-constructed role account permission mapping table, and the role account permission mapping table is used for representing the relation between the role and the role permission; the authority of the corresponding office account can be automatically adjusted according to the role change approval process of the OA office system, manual operation is not needed, and authority distribution is accurate.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of account permission management, and particularly to a method for managing account permissions in an OA office system. Background Art

[0002] In modern enterprise organizations, the OA office system plays an important role by providing convenient workflow and permission management functions to assist internal business activities. However, as the scale and complexity of enterprises increase, the roles played by relevant personnel in the enterprise are constantly changing, and the permissions of their office accounts need to be adjusted according to the changes in their roles. Traditionally, the generation of permissions for office accounts usually involves manual operations, which are frequent, labor-intensive, and prone to errors in the permission allocation of office accounts. Summary of the Invention

[0003] In view of the above problems, the present invention provides a method for managing account permissions in an OA office system, which solves the technical problems that the generation of permissions for traditional office accounts usually involves manual operations, which are frequent, labor-intensive, and prone to errors in the permission allocation of office accounts. It can automatically adjust the permissions of the corresponding office accounts according to the role change approval process in the OA office system without manual operation, and the permission allocation is accurate.

[0004] An embodiment of the present invention provides a method for managing account permissions in an OA office system, including:

[0005] Obtaining in real time the role change approval process submitted by an office account in the OA office system;

[0006] Based on the role change approval process, determining the role change information of the office account;

[0007] When the role change approval process is passed, based on the role change information and a pre-constructed role-account permission mapping table, adjusting the role permissions of the office account, where the role-account permission mapping table is used to represent the relationship between roles and role permissions.

[0008] In some embodiments, it includes:

[0009] Identifying the text information of the role change approval process and determining the deleted role or / and added role of the office account;

[0010] Based on the deleted role or / and added role of the office account, the operation time node, and the ID of the office account, generating the role change information of the office account.

[0011] In some embodiments, it includes:

[0012] When the role change approval process is passed, obtain the operation time nodes of the deleted role or / and the newly added role from the role change information;

[0013] When the time node reaches the operation time nodes of the deleted role or / and the newly added role, based on the pre-constructed role account permission mapping table, adjust the role permissions of the office account.

[0014] In some embodiments, the roles include temporary roles and long-term roles.

[0015] In some embodiments, it includes:

[0016] When the role is a temporary role, based on the pre-constructed role account permission mapping table, adjust the role permissions of the office account, and assign a playing time period to the role permissions, where the role permissions become effective at the start node of the playing time period and become invalid at the end node of the playing time period.

[0017] In some embodiments, it includes:

[0018] When the OA office system receives a permission request initiated by an office account, the OA office system determines whether the login terminal of the office account is the target terminal;

[0019] If the login terminal of the office account is not the target terminal, the OA office system refuses to execute the permission request;

[0020] If the login terminal of the office account is the target terminal, obtain the identity identifier of the target terminal, and send an identity verification request based on the identity identifier;

[0021] If the identity verification request of the target terminal fails, the OA office system refuses to execute the permission request;

[0022] If the identity verification request of the target terminal is successful, the OA office system executes the permission request.

[0023] In some embodiments, it includes:

[0024] When the OA office system receives a permission request initiated by an office account, determine whether the permission request is within the scope of the office account permissions;

[0025] If the permission request is within the scope of the office account permissions, the OA office system determines whether the login terminal of the office account is the target terminal;

[0026] If the permission request is not within the scope of the office account permissions, the OA office system feeds back a refusal to execute message to the login terminal.

[0027] In some embodiments, it includes:

[0028] Obtain the separation approval process submitted by an office account in the OA office system;

[0029] Based on the separation approval process, determine the separation time node of the office account;

[0030] In the case where the separation approval process is passed, cancel the office account after the time node reaches the separation time node.

[0031] Compared with the prior art, the present invention has the following beneficial effects:

[0032] By obtaining in real time the role change approval process submitted by an office account in the OA office system; based on the role change approval process, determining the role change information of the office account; in the case where the role change approval process is passed, based on the role change information and a pre-constructed role-account permission mapping table, adjusting the role permissions of the office account, where the role-account permission mapping table is used to represent the relationship between roles and role permissions; it can automatically adjust the permissions of the corresponding office account according to the role change approval process of the OA office system without manual operation, and the permission allocation is accurate. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] The following further describes the embodiments of the present invention with reference to the drawings:

[0034] Figure 1 It is a schematic implementation flow diagram of an OA office system account permission management method provided by an embodiment of the present invention;

[0035] Figure 2 It is a schematic composition structure diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0036] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the drawings. The described embodiments should not be construed as limitations on the present invention. All other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0037] In the following description, reference is made to "some embodiments", which describe a subset of all possible embodiments. However, it can be understood that "some embodiments" can be the same subset or different subsets of all possible embodiments, and can be combined with each other without conflict.

[0038] If descriptions similar to "first / second / third" appear in the application documents, the following description shall be added. In the following description, the terms "first / second / third" involved are only used to distinguish similar objects and do not represent a specific order for the objects. Understandably, "first / second / third" can be interchanged in a specific order or sequence when permitted, so that the embodiments of the present invention described herein can be implemented in an order other than that illustrated or described herein.

[0039] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this invention belongs. The terms used herein are for the purpose of describing embodiments of the present invention only and are not intended to limit the present invention.

[0040] Based on the problems existing in the related art, embodiments of the present invention provide a method for managing account permissions in an OA office system. The execution subject of the management method can be an electronic device. The electronic device can be various types of terminals such as a laptop computer, a tablet computer, a desktop computer, a set-top box, a mobile device (e.g., a mobile phone, a portable music player, a personal digital assistant, a dedicated messaging device, a portable gaming device), or can also be implemented as a server. The server can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or can also be a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, Content Delivery Network (CDN), and big data and artificial intelligence platforms.

[0041] In some embodiments, the functions implemented by the management method provided by the embodiments of the present invention can be realized by a processor of an electronic device calling program code, where the program code can be stored in a computer storage medium.

[0042] Embodiments of the present invention provide a method for managing account permissions in an OA office system. Figure 1 It is a schematic diagram of the implementation process of a method for managing account permissions in an OA office system provided by embodiments of the present invention. As Figure 1 shown, it includes:

[0043] Step S1: Real-time obtain the role change approval process submitted by an office account in the OA office system.

[0044] In the embodiments of the present invention, the role change approval process submitted by an office account in the OA office system is automatically pulled through a pre-configured API interface. There is no need for manual and irregular checking for new role change approval processes, and the real-time performance of processing is high.

[0045] Step S2: Determine the role change information of the office account based on the role change approval process;

[0046] In some embodiments, step S2 includes:

[0047] Step S21: Identify the text information of the role change approval process and determine the deleted role and / or newly added role of the office account;

[0048] Step S22: Generate the role change information of the office account based on the deleted role and / or newly added role of the office account, the operation time node, and the ID of the office account.

[0049] In the embodiments of the present invention, the semantic recognition model constructed in advance can be used to perform semantic recognition on the text information of the role change approval process, so as to determine the deleted role and / or newly added role of the office account. When the deleted role and / or newly added role of the office account is determined, the deleted role and / or newly added role is used as the role change information of the office account. The role change information includes the deleted role and / or newly added role, the operation time node of the deleted role and / or newly added role, and the ID of the office account, etc., which is convenient for subsequent processing through the role change information.

[0050] Step S3: When the role change approval process passes, adjust the role permissions of the office account based on the role change information and the pre-constructed role-account permission mapping table, where the role-account permission mapping table is used to represent the relationship between roles and role permissions.

[0051] In some embodiments, step S3 includes:

[0052] Step S31: When the role change approval process passes, obtain the operation time node of the deleted role and / or newly added role from the role change information;

[0053] Step S32: When the time node reaches the operation time node of the deleted role and / or newly added role, adjust the role permissions of the office account based on the pre-constructed role-account permission mapping table.

[0054] In the embodiments of the present invention, the approval process for role change passing refers to the completion of the approval. In the case where the approval process for role change passes, based on the ID of the office account, the corresponding role change information is determined. From the obtained role change information, the operation time nodes of the deleted role or / and the added role and the deleted role or / and the added role are obtained, and then based on the deleted role or / and the added role and the operation time nodes of the deleted role or / and the added role, a permission adjustment task is created. One permission adjustment task corresponds to one deleted role or / and one added role. When the time node reaches the operation time node of the deleted role or / and the added role, the pre-constructed role-account permission mapping table is called to delete or / and add the role permissions of the office account. The role permissions of the office account will not be adjusted before the operation time node reaches, so as to avoid affecting work by adjusting the role permissions of the office account in advance. It can automatically adjust the role permissions of the office account according to the role change approval process submitted by the office account in the OA office system.

[0055] In summary, by obtaining in real time the role change approval process submitted by the office account in the OA office system; based on the role change approval process, determining the role change information of the office account; in the case where the role change approval process passes, based on the role change information and the pre-constructed role-account permission mapping table, adjusting the role permissions of the office account, wherein the role-account permission mapping table is used to represent the relationship between the role and the role permissions; it can automatically adjust the permissions of the corresponding office account according to the role change approval process of the OA office system without manual operation, and the permission allocation is accurate.

[0056] In some embodiments, the role includes a temporary role and a long-term role.

[0057] In the embodiments of the present invention, the temporary role is a position engaged in short-term work. Exemplarily, a member of a certain project team will be disbanded after the project ends. The long-term role is a position engaged in long-term work. Exemplarily, a technical staff in a certain technical department, a salesperson in a certain sales department, etc., and the department will exist for a long time.

[0058] In some embodiments, it includes:

[0059] Step S10: In the case where the role is a temporary role, based on the pre-constructed role-account permission mapping table, adjust the role permissions of the office account, and assign a playing time period to the role permissions, where the role permissions take effect at the start node of the playing time period and become invalid at the end node of the playing time period.

[0060] In an embodiment of the present invention, a temporary role belongs to a role added to an office account. The operation time nodes of the temporary role include an effective operation time node and an expiration operation time node. The playing time period of the temporary role can be obtained through the effective operation time node and the expiration operation time node. Based on a pre-constructed role-account permission mapping table, the role permissions of the office account are adjusted, and a playing time period is assigned to the role permissions. The role permissions become effective at the start node of the playing time period and expire at the end node of the playing time period. It is possible not to initiate a role change approval process, saving the process and improving work efficiency.

[0061] In some embodiments, it includes:

[0062] Step S101: When the OA office system receives a permission request initiated by an office account, the OA office system determines whether the login terminal of the office account is a target terminal;

[0063] Step S102: If the login terminal of the office account is not the target terminal, the OA office system refuses to execute the permission request;

[0064] Step S103: If the login terminal of the office account is the target terminal, obtain the identity identifier of the target terminal and send an identity verification request based on the identity identifier;

[0065] Step S104: If the identity verification request of the target terminal fails, the OA office system refuses to execute the permission request;

[0066] Step S105: If the identity verification request of the target terminal is successful, the OA office system executes the permission request.

[0067] In an embodiment of the present invention, when the OA office system receives a permission request initiated by an office account, it is necessary to determine whether the login terminal of the office account is a target terminal. The target terminal refers to the ID in the white list of the OA office system. When the login terminal of the office account is not the target terminal, the OA office system refuses to execute the permission request. When the login terminal of the office account is the target terminal, obtain the identity identifier of the target terminal and send an identity verification request based on the identity identifier. The identity verification request can be face recognition. Determine whether it is the person corresponding to the office account through face recognition. If the identity verification request fails, the OA office system refuses to execute the permission request. If the identity verification request is successful, the OA office system executes the permission request. It can effectively improve the security of the OA office system.

[0068] In some embodiments, it includes:

[0069] S1011: When the OA office system receives a permission request initiated by an office account, determine whether the permission request is within the scope of the office account's permissions;

[0070] S1012: If the permission request is within the scope of the office account's permissions, then the OA office system determines whether the login terminal of the office account is the target terminal;

[0071] S1013: If the permission request is not within the scope of the office account's permissions, then the OA office system feeds back a rejection execution message to the login terminal.

[0072] In the embodiment of the present invention, when the OA office system receives a permission request initiated by an office account, it determines whether the permission request is within the scope of the office account's permissions and filters the permission request, which can quickly process unauthorized requests.

[0073] In some embodiments, it includes:

[0074] Step S201: Obtain the separation approval process submitted by the office account in the OA office system;

[0075] Step S202: Based on the separation approval process, determine the separation time node of the office account;

[0076] Step S203: In the case where the separation approval process is passed, cancel the office account after the time node reaches the separation time node.

[0077] In the embodiment of the present invention, the separation approval process submitted by the office account in the OA office system is automatically pulled through the pre-configured API interface. There is no need for manual and irregular checking for new separation approval processes. In the case where the separation approval process is passed, the office account is cancelled after the time node reaches the separation time node. It can timely cancel the office accounts of separated personnel and improve the security of the OA office system.

[0078] It should be noted that in the embodiments of the present invention, if the above management method is implemented in the form of software function modules and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the embodiments of the present invention, in essence, or the part that contributes to the prior art can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), magnetic disks, or optical discs that can store program codes. In this way, the embodiments of the present invention are not limited to any specific combination of hardware and software.

[0079] Correspondingly, an embodiment of the present invention provides a storage medium, on which a computer program is stored, and is characterized in that when the computer program is executed by a processor, it implements the steps in the management method provided in the above embodiments.

[0080] An embodiment of the present invention provides an electronic device; Figure 2 is a schematic diagram of the composition structure of the electronic device provided in the embodiment of the present invention, as Figure 2 shown, the electronic device 400 includes: a processor 401, at least one communication bus 402, a user interface 403, at least one external communication interface 404, and a memory 405. Among them, the communication bus 402 is configured to implement connection communication between these components. Among them, the user interface 403 may include a display screen, and the external communication interface 404 may include a standard wired interface and a wireless interface. The processor 401 is configured to execute the program of the management method stored in the memory to implement the steps in the management method provided in the above embodiments.

[0081] It should be pointed out here that: the descriptions of the above storage medium and electronic device embodiments are similar to the descriptions of the above method embodiments and have beneficial effects similar to those of the method embodiments. For the technical details not disclosed in the embodiments of the storage medium and device of the present invention, please refer to the descriptions of the method embodiments of the present invention for understanding.

[0082] In several embodiments provided by the present invention, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined, or can be integrated into another system, or some features can be ignored, or not executed. In addition, the coupling, direct coupling, or communication connection between the displayed or discussed components can be through some interfaces. The indirect coupling or communication connection of devices or units can be electrical, mechanical, or other forms.

[0083] The units described above as separate components may or may not be physically separated. The components displayed as units may or may not be physical units. They can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0084] In addition, each functional unit in the embodiments of the present invention can be all integrated in a processing unit, or each unit can be separately used as a unit, or two or more units can be integrated in a unit. The above-mentioned integrated units can be implemented in the form of hardware, or in the form of hardware plus software functional units.

[0085] Those of ordinary skill in the art can understand that all or part of the steps to implement the above method embodiments can be completed by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps including the above method embodiments. The aforementioned storage medium includes various media that can store program codes, such as removable storage devices, read-only memory (ROM, Read Only Memory), magnetic disks, or optical discs.

[0086] Alternatively, if the above-mentioned integrated units of the present invention are implemented in the form of software functional modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the embodiments of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a controller to execute all or part of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media that can store program codes, such as removable storage devices, ROM, magnetic disks, or optical discs.

[0087] As described above, it is only the implementation mode of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims described above.

Claims

1. A method for managing account permissions in an OA office system, characterized in that, Including: Obtaining in real time the role change approval process submitted by an office account in the OA office system; Determining the role change information of the office account based on the role change approval process; When the role change approval process is passed, adjusting the role permissions of the office account based on the role change information and a pre-constructed role-account permission mapping table, where the role-account permission mapping table is used to represent the relationship between roles and role permissions.

2. The OA office system account permission management method according to claim 1, characterized in that Including: Identifying the text information of the role change approval process and determining the deleted role and / or newly added role of the office account; Generating the role change information of the office account based on the deleted role and / or newly added role of the office account, the operation time node, and the ID of the office account.

3. A method for managing account permissions in an OA office system according to claim 2, characterized in that, Including: When the role change approval process is passed, obtaining the operation time node of the deleted role and / or newly added role from the role change information; When the time node reaches the operation time node of the deleted role and / or newly added role, adjusting the role permissions of the office account based on the pre-constructed role-account permission mapping table.

4. A method for managing account permissions in an OA office system according to claim 1, characterized in that, The roles include temporary roles and long-term roles.

5. A method for managing account permissions in an OA office system according to claim 4, characterized in that, Including: When the role is a temporary role, adjusting the role permissions of the office account based on a pre-constructed role-account permission mapping table and assigning a playing time period to the role permissions, where the role permissions become effective at the start node of the playing time period and become invalid at the end node of the playing time period.

6. The OA office system account privilege management method according to claim 1, characterized in that Including: When the OA office system receives a permission request initiated by an office account, the OA office system determines whether the login terminal of the office account is the target terminal; If the login terminal of the office account is not the target terminal, the OA office system refuses to execute the permission request; If the login terminal of the office account is the target terminal, obtaining the identity identifier of the target terminal and sending an identity verification request based on the identity identifier; If the identity verification request of the target terminal fails, the OA office system refuses to execute the permission request; If the identity verification request of the target terminal is successful, the OA office system executes the permission request.

7. A method for managing account permissions in an OA office system according to claim 6, characterized in that Including: When the OA office system receives a permission request initiated by an office account, determining whether the permission request is within the scope of the office account's permissions; If the permission request is within the scope of the office account's permissions, the OA office system determines whether the login terminal of the office account is the target terminal; If the permission request is not within the scope of the office account's permissions, the OA office system feeds back a refusal to execute message to the login terminal.

8. A method for managing account permissions in an OA office system according to claim 1, characterized in that Including: Obtaining the separation approval process submitted by an office account in the OA office system; Determining the separation time node of the office account based on the separation approval process; When the separation approval process is passed, canceling the office account after the time node reaches the separation time node.