Human resource archive filing management system

Through multi-dimensional classification and scenario-based dynamic permission control, combined with legal retention rules and distributed storage architecture, it solves the problems of single classification, static permissions, and storage performance bottlenecks in traditional human resources archive management systems, and achieves efficient and secure archive management upgrades.

CN120743852APending Publication Date: 2025-10-03SHENZHEN JUNRUN ARCHIVES DATA MANAGEMENT CO LTD

Patent Information

Application Number
CN202510908994.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-02
Publication Date
2025-10-03

AI Technical Summary

Technical Problem

The existing traditional human resources archive management system has a single classification dimension and lacks refined management of sensitivity levels and data formats; data verification is limited to verifying that fields are required, lacking time sequence and business logic verification; permission management is a static "role-permission" binding model, which is difficult to adapt to dynamic business scenarios and lacks privacy protection mechanisms; data cleaning relies on simple expiration time triggers and lacks priority identification of legal retention rules; the storage architecture is centrally deployed, with performance bottlenecks and security vulnerabilities, and data associations are not effectively sorted out.

Method used

A multi-dimensional classification processing module, encompassing lifecycle, sensitivity level, and morphology, enables refined management of archival data. Data integrity is ensured through field integrity, chronological order, and business logic verification. Scenario-based dynamic permission control is implemented, along with granular management based on user behavior analysis and intelligent cleanup based on legal retention rules. Distributed cloud storage clusters and local storage nodes are constructed to optimize storage architecture and retrieval paths.

Benefits of technology

It achieves refined governance of archive management, ensures data integrity and logical accuracy, dynamically adjusts permissions, meets data security and compliance requirements, optimizes access performance, improves decision-making data support capabilities, reduces labor costs, and builds digital human resource management competitiveness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120743852A_ABST
    Figure CN120743852A_ABST
Patent Text Reader

Abstract

The invention discloses a human resource archive filing management system, and relates to the technical field of data management, the system comprises an acquisition module, a processing module and a management module, the acquisition module acquires original archive data of employees, transmits the data to the processing module, classifies the original archive data according to a preset first rule, and stores the classified data to the management module; the first archive data is obtained, controlled and managed, a calling permission and a distribution strategy are generated, the first archive data is recognized through a preset second rule, second archive data is generated, corresponding processing is conducted according to the processing priority, a processing log is reserved, third archive data are obtained and transmitted to the management module, and the management module is used for managing the first archive data. A distributed cloud storage cluster and a local storage node are constructed, an overall storage architecture and a retrieval path of third archive data are optimized, archive management is refined through three-dimensional classification, data integrity is guaranteed through field-level verification and automatic completion, scene-based dynamic authority control safety is achieved, compliance risks are intelligently cleared and avoided, and efficiency is improved through mixed storage. And active management of archive management is promoted.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data management, and in particular to a human resources file archiving management system. Background Art

[0002] With the deepening of digital transformation, human resource file management is accelerating the transformation from traditional paper archiving to intelligent system management. Traditional paper file management has the disadvantages of low efficiency, easy damage and difficult retrieval, and cannot meet the company's needs for efficient processing of massive employee data. The development of artificial intelligence, big data and cloud computing technologies has brought new opportunities for file management. Intelligent systems can not only realize the automatic collection, classification and storage of file data, but also mine the value of data to assist decision-making. At the same time, in the context of stricter data security and privacy protection regulations, its advantages in authority control, data encryption and compliance auditing are significant, becoming a key tool for companies to improve human resource management efficiency and enhance competitiveness.

[0003] The existing traditional human resources file management system has defects. The classification dimension is single, and data is only divided according to the employee life cycle. There is a lack of refined management of sensitivity levels and data forms; data verification only stops at verifying the mandatory fields, and lacks time sequence and business logic verification; permission management is a static "role-permission" binding mode, which is difficult to adapt to dynamic business scenarios and lacks privacy protection mechanism; data cleaning relies on simple expiration time triggers and lacks priority identification of legal retention rules; the storage architecture is centrally deployed, with performance bottlenecks and security vulnerabilities, and data association relationships are not effectively sorted out. Summary of the Invention

[0004] The technical problems solved by the present invention are: the existing traditional human resources archive management system has defects, the classification dimension is single, and data is only divided according to the employee life cycle, lacking refined management of sensitivity levels and data forms; data verification only stays at the verification of field mandatory fields, lacks time sequence and business logic verification; permission management is a static "role-permission" binding mode, which is difficult to adapt to dynamic business scenarios and lacks privacy protection mechanism; data cleaning relies on simple expiration time triggering and lacks priority identification of legal retention rules; the storage architecture is centrally deployed, with performance bottlenecks and security vulnerabilities, and data association relationships are not effectively sorted out.

[0005] In order to solve the above technical problems, the present invention provides the following technical solutions: a human resources file archiving management system includes a collection module, a processing module and a management module;

[0006] The acquisition module is used to collect the original file data of employees and transmit it to the processing module;

[0007] The processing module is configured to classify and process the original archival data according to a preset first rule to obtain first archival data, control and manage the first archival data, and simultaneously generate access rights and allocation policies for the original archival data;

[0008] Identify the first archival data using a preset second rule to generate second archival data, process the second archival data accordingly according to a disposal priority, retain a processing log, obtain third archival data, and transmit the data to a management module;

[0009] The management module is used to build a distributed cloud storage cluster and local storage nodes to optimize the overall storage architecture and retrieval path of the third archive data.

[0010] As a preferred solution of the human resources file archiving management system described in the present invention, the original file data includes basic information data, position-related data, qualification certificate data, contract agreement data, salary and benefits data, and assessment and evaluation data.

[0011] As a preferred solution of the human resources file archiving management system of the present invention, the first rule specifically includes:

[0012] The original archival data is classified by dimension to obtain first archival data, specifically including:

[0013] The dimensions include life cycle dimension, sensitivity level dimension and morphology dimension;

[0014] Classifying the original archival data according to the life cycle dimension to obtain entry data, on-the-job data, and resignation data;

[0015] Classifying the original archival data according to the sensitivity level dimension to obtain public data, internal data and confidential data;

[0016] Classifying the original archival data according to morphological dimensions to obtain structured data, semi-structured data and unstructured data;

[0017] The first archival data includes onboarding data, on-the-job data, resignation data, public data, internal data, confidential data, structured data, semi-structured data, and unstructured data;

[0018] Performing integrity check on the first file data;

[0019] The integrity check includes field integrity verification, time sequence verification and business logic verification;

[0020] The field integrity verification is performed by verifying the existence of the set of required fields and verifying the compliance of the fields with format requirements;

[0021] The time sequence verification is to verify the time rationality of the field groups with a time sequence relationship;

[0022] The business logic verification performs correlation verification on the field groups that have business rule dependencies.

[0023] As a preferred solution of the human resources file archiving management system of the present invention, the verification processing mechanism specifically includes:

[0024] If the field integrity verification fails, a completion reminder is automatically generated and the first file data status is marked, and a countdown timer is started at the same time;

[0025] If the completion is not completed before the countdown ends, the editing permission of the first file data will be automatically locked, and only the specified condition administrator will be allowed to operate or the approval process of the direct supervisor will be triggered;

[0026] The approval process involves the immediate supervisor reviewing whether to waive the completion requirement and providing reasons;

[0027] If the time sequence verification fails, a time logic conflict warning is automatically triggered and the flow of the first file data is blocked;

[0028] If the business logic verification fails, the manual review process will be triggered, and after the review passes, it will enter the next processing stage.

[0029] As a preferred solution of the human resources file archiving management system of the present invention, wherein: the access authority and allocation strategy are generated based on the confidentiality level and requirements of the original file data;

[0030] The access permissions include scenario-based dynamic permission control, which includes adjusting the permission scope and permission recovery mechanism;

[0031] The scenario-based dynamic permission control opens the fields corresponding to the first file data based on the usage scenario, realizes granular permission management, and dynamically adjusts the permission scope through user behavior analysis;

[0032] The scenarios include employee onboarding, employee employment, employee departure, audit, and statistical analysis.

[0033] The granular authority management implements granular authority management with the field of the first archival data as the smallest unit, and independently sets authority for a single field of the first archival data;

[0034] Said permissions include viewing, modifying and deleting;

[0035] The allocation strategy includes a privacy protection strategy.

[0036] As a preferred solution of the human resources file archiving management system of the present invention, wherein: the user behavior analysis dynamically adjusts permissions based on a multi-dimensional mechanism;

[0037] The multiple dimensions include access frequency dimension, operation type dimension, and access period dimension;

[0038] The access frequency dimension is used to adjust the read permission based on the frequency of the number of times the user accesses the specific first archive data;

[0039] The operation type dimension is used to analyze the matching degree between the user operation behavior and the sensitivity level of the first archive data to control permissions;

[0040] The access period dimension is used to identify regular access time periods and to control access permissions during abnormal time periods;

[0041] A first-file data association mechanism that dynamically masks non-related fields based on user business scenarios, a permission recovery mechanism when positions change, and a privacy protection strategy for anonymizing first-file data;

[0042] The permission recovery mechanism automatically adjusts the access scope of the first file data based on the new position permission template when the user changes or resigns, and retains the historical operation log;

[0043] The privacy protection strategy includes anonymization processing of the first archive data, response to deletion requests, and usage purpose constraint mechanisms.

[0044] As a preferred solution of the human resources file archiving management system of the present invention, the first file data is identified by a preset second rule, and based on the validity period and importance level of the first file data, the portion of the first file data to be cleaned up is automatically marked as second file data, and a disposal priority is generated;

[0045] The validity period includes the validity period of employment materials, contract agreement, assessment and evaluation, and qualification certificate, and long-term validity;

[0046] The validity period determination rule automatically identifies the validity period information in the field of the first file data through a preset business rule engine;

[0047] For first-file data without a clear validity period, it will be treated as long-term validity by default;

[0048] The importance levels include high importance, medium importance and low importance;

[0049] The importance level determination rules automatically divide the levels according to the preset classification rule template and support administrators to customize the rules;

[0050] The high importance mentioned includes social security records and senior management records that are required to be retained by law;

[0051] The medium importance mentioned includes ordinary employee contracts and routine performance data;

[0052] Low importance includes non-sensitive training records that have expired.

[0053] As a preferred solution of the human resources file archiving management system of the present invention, the priority of the first file data is controlled and managed based on legal rules, specifically including:

[0054] If the fields of the first archival data match the preset legal retention rule library, the default validity period and importance level determination logic are forcibly overwritten to generate a fixed retention period according to the law;

[0055] Automatically adding a "High Importance - Legal Hold" tag to the first archival data through the tag management engine of the first archival data, and simultaneously triggering the permission management unit of the processing module to increase the access control level;

[0056] The handling priorities include high priority, medium priority and low priority. The specific rules are as follows:

[0057] The high priority triggers a cleanup process when the first archival data exceeds its validity period and its importance level is low, and does not involve a legal retention period;

[0058] The medium priority level triggers manual review and approval when the first archive data is close to the expiration date and the importance level is medium;

[0059] For the low priority, when the validity period of the first archive data is long-term and the importance level is high, a dedicated encryption storage node is used for storage, and the access control level is upgraded to confidential level authority management;

[0060] When the first archival data meets multiple priority conditions at the same time, it is judged in the order of legal retention period greater than high importance greater than medium importance greater than low importance, and a visual rule configuration interface is provided to support administrators to customize priority judgment logic and conflict resolution strategies.

[0061] As a preferred solution of the human resources file archiving management system of the present invention, wherein: according to the validity period, importance level and priority rule, the data to be cleaned is automatically marked as second file data, and a corresponding disposal priority is generated;

[0062] Destroying the second archive data according to the disposal priority, retaining a destruction log, and using the remaining valid data as third archive data, specifically includes:

[0063] Before destruction, the permission recovery process is automatically triggered to revoke the access rights of all users associated with the second archive data in batches;

[0064] The permission change history is recorded synchronously in the destruction log, including the permission revocation time, the users involved, the roles, the original access scope, and other information;

[0065] Synchronize the destruction log to the management module, and conduct retrospective query and compliance audit on the permission change history and destruction log through the built-in audit mechanism of the management module;

[0066] After the destruction operation is completed, the index and association relationship map of the second file data in the storage architecture are updated.

[0067] As a preferred solution of the human resources archive management system of the present invention, the construction of a distributed cloud storage cluster and local storage nodes to optimize the overall storage architecture and retrieval path of the third archive data specifically includes:

[0068] A hybrid storage architecture is used to store frequently accessed third-party archive data in local SSD nodes, and less frequently accessed historical data in a distributed cloud storage cluster.

[0069] Establish a storage load balancing mechanism to dynamically adjust the third-party file data distribution based on the node read and write pressure;

[0070] Synchronously write permission metadata when storing the third archival data, bind the third archival data access permission configuration to the physical storage location, and form an associated index table;

[0071] The cloud storage cluster is configured across multiple active data centers across regions, with local nodes deploying cache to optimize access speed;

[0072] Establishing a multi-level index system for the third archival data, creating classification indexes based on life cycle dimensions, sensitivity level dimensions, and morphology dimensions, and locating the target third archival data storage location through the classification indexes;

[0073] Constructing a data association relationship map by sorting out and storing the association relationships between the structured data, semi-structured data and unstructured data;

[0074] When accessing data across nodes, access permissions are verified through the associated index table.

[0075] The beneficial effects of the present invention are: significant improvement in the efficiency of human resources archive management through multi-dimensional innovation, three-dimensional classification realizes refined archive management, field-level verification and automatic completion mechanism ensure data integrity and logical accuracy, scenario-based dynamic permission control combined with user behavior analysis realizes field-level granularity management, dynamically reclaims permissions and strengthens privacy protection, meets data security and compliance requirements, intelligent cleanup mechanism based on legal retention rules, prioritizes mandatory retention of laws and regulations, avoids compliance risks, distributed hybrid storage architecture optimizes access performance, multi-level indexing and association graphs improve retrieval efficiency, and significantly improves the response speed of local cache of high-frequency data, realizing the overall upgrade of archive management from "passive archiving" to "active governance", effectively reducing labor costs, improving decision-making data support capabilities, and building a competitive barrier for human resources management in the digital age for enterprises. BRIEF DESCRIPTION OF THE DRAWINGS

[0076] Figure 1 A basic flow chart of a human resources file archiving management system provided by one embodiment of the present invention. DETAILED DESCRIPTION

[0077] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the drawings. It is obvious that the described embodiments are only part of the embodiments of the present invention, but not all of the embodiments.

[0078] Example 1, with reference to Figure 1 , as an embodiment of the present invention, provides a human resources file archiving management system, including a collection module, a processing module, and a management module;

[0079] The collection module is used to collect employees' original file data and transmit it to the processing module;

[0080] a processing module, configured to classify and process the original archival data according to a preset first rule to obtain first archival data, control and manage the first archival data, and simultaneously generate access permissions and allocation policies for the original archival data;

[0081] Identify the first file data using a preset second rule to generate second file data, process the second file data accordingly according to the disposal priority, retain a processing log, obtain third file data, and transmit it to the management module;

[0082] The management module is used to build a distributed cloud storage cluster and local storage nodes, and optimize the overall storage architecture and retrieval path of the third-party archive data.

[0083] In one embodiment, the three core modules of collection, processing and management are operated in coordination. The collection module collects the original archival data of employees through a standardized interface and transmits it to the processing module in real time. The processing module first classifies and processes the original data based on a preset first rule to generate structured first archival data, and simultaneously generates access permissions and privacy protection policies based on confidentiality levels and scenarios; then, through a preset second rule, the second archival data to be cleaned is identified according to the validity period, importance level and legal retention rules, and is destroyed or encrypted for storage according to high priority, medium priority and low priority. After retaining the processing log, the third archival data is formed. The management module adopts a hybrid architecture of distributed cloud storage clusters and local SSD nodes, dynamically allocates storage locations according to data access frequency, builds a multi-level index system and association relationship map, realizes efficient storage and millisecond-level retrieval of the third archival data, and strengthens data access control and compliance auditing by binding permission metadata to physical storage locations.

[0084] Original file data includes basic information data, position-related data, qualification certificate data, contract agreement data, salary and benefits data, and assessment and evaluation data.

[0085] The first rule specifically includes:

[0086] The original file data is classified by dimension to obtain the first file data, which specifically includes:

[0087] The dimensions include life cycle dimension, sensitivity level dimension and morphology dimension;

[0088] Classify the original archival data by life cycle dimension to obtain entry data, employment data and resignation data;

[0089] Classify the original archival data by sensitivity level to obtain public data, internal data and confidential data;

[0090] The original archival data is classified by morphological dimensions to obtain structured data, semi-structured data and unstructured data;

[0091] The first file data includes entry data, on-the-job data, resignation data, public data, internal data, confidential data, structured data, semi-structured data and unstructured data;

[0092] Performing integrity check on the first file data;

[0093] Integrity verification includes field integrity verification, time sequence verification, and business logic verification;

[0094] Field integrity verification, by verifying the existence of the set of required fields and verifying the compliance of fields with format requirements;

[0095] Time sequence verification: verify the time rationality of field groups with time sequence relationships;

[0096] Business logic validation: performs correlation validation on field groups with business rule dependencies.

[0097] In one embodiment, three-dimensional classification governance is implemented for the original archival data, including basic information, position data, qualification certificates, contract agreements, salary and benefits, and assessment and evaluation data. First, it is divided into entry data, on-the-job data, and resignation status data according to the life cycle dimension; it is simultaneously marked as public data (such as work badge information), internal data (such as general performance data), and confidential data (such as executive compensation) according to the sensitivity level; then it is divided into structured data (such as Excel salary spreadsheets), semi-structured data (such as formatted emails), and unstructured data (such as PDF contracts) according to the form, forming a nine-category first archival data matrix. After the classification is completed, a triple integrity check is performed, including field integrity verification, field integrity verification, existence verification based on a preset set of required fields (such as entry date and contract number), time sequence verification, and business logic verification. Field integrity verification performs format compliance verification on the ID card number and bank account number fields; time sequence verification, such as verifying whether the signing date of the labor contract is later than the entry date and whether the performance appraisal cycles overlap; business logic verification, such as checking the correlation between position change records and salary adjustment data. Verification rules allow administrators to customize field sets and timing logic through a visual interface to ensure accurate and compliant data logic.

[0098] The verification processing mechanism includes:

[0099] If the field integrity verification fails, a completion reminder will be automatically generated and the first file data status will be marked, and a countdown timer will be started;

[0100] If the completion is not completed before the countdown ends, the editing permission of the first file data will be automatically locked, and only the administrator with specified conditions will be allowed to operate or the approval process of the direct supervisor will be triggered;

[0101] The approval process involves the immediate supervisor reviewing whether to waive the completion requirement and providing reasons;

[0102] If the time sequence verification fails, a time logic conflict warning will be automatically triggered and the flow of the first file data will be blocked;

[0103] If the business logic verification fails, the manual review process will be triggered, and after the review passes, it will enter the next processing stage.

[0104] In one embodiment, the following processing is implemented for situations where field integrity verification fails: the system automatically generates a pop-up window with a completion reminder and marks the file status as "pending completion." A three-working-day countdown timer is simultaneously started, based on the company's standard data completion timeline. If completion is not completed by the end of the countdown, data editing permissions are automatically locked, allowing only system administrators to operate or triggering the approval process of the direct supervisor. The direct supervisor must review whether to waive the completion requirement and provide a written justification. Permission is unlocked after the waiver is approved.

[0105] When the time sequence verification fails, a red highlighted conflict warning will be triggered in real time, such as the prompt "the contract end date is earlier than the start date", and the first file data will be automatically blocked from entering the archiving or circulation link until the time sequence logic correction is completed.

[0106] When the business logic verification fails, a manual review task will be automatically pushed to the human resources specialist account. The review must be completed within 2 working days. The setting basis is based on the timeliness requirements of the business process. After the review is passed, the blockade will be lifted and the data will be allowed to enter the next processing stage.

[0107] Access permissions and allocation strategies are generated based on the confidentiality level and requirements of the original archival data;

[0108] Access permissions include scenario-based dynamic permission control, which includes adjusting permission scope and permission recovery mechanism;

[0109] Scenario-based dynamic permission control opens the fields corresponding to the first file data based on the usage scenario, realizes granular permission management, and dynamically adjusts the permission scope through user behavior analysis;

[0110] Scenarios include employee onboarding, employee employment, employee departure, audit, and statistical analysis.

[0111] Granular authority management: This implements granular authority management with the fields of the first archive data as the smallest unit, and independently sets authority for each field of the first archive data;

[0112] Permissions include viewing, modifying, and deleting;

[0113] The allocation strategy includes a privacy protection strategy.

[0114] In one embodiment, based on the confidentiality level (public / internal / confidential) of the original file data and business needs, a scenario-based dynamic permission management system is constructed. For the core scenarios of employee joining, employment, resignation, audit, and statistical analysis, the field permissions corresponding to the first file data are dynamically opened. For example, in the onboarding scenario, only the viewing permission of basic information fields (such as name and education) is opened to new employees. In the audit scenario, the read-only permission of contract agreement and salary and benefits fields is opened to the compliance department. The statistical analysis scenario opens the analysis permission of summary data fields according to the desensitization rules, so as to achieve accurate permission matching in different scenarios; a granular permission management mechanism is adopted, with a single field of the first file data as the smallest unit (such as ID number, bank account number, salary value), and the viewing, modification, and deletion permissions are independently configured. For example, employees in service can only modify non-sensitive fields such as contact number and emergency contact independently, and sensitive fields such as salary and performance are only available to human resources managers or direct supervisors. Core confidential fields (such as executive salary structure) are prohibited from being accessed by ordinary employees. Segment-level permission control implements the principle of minimizing data sharing; the dynamic permission adjustment mechanism optimizes the permission scope in real time based on user behavior analysis (access frequency, operation type, access time period), automatically monitors the frequency of user access to specific fields, triggers secondary authentication for abnormally high-frequency access to confidential fields, and temporarily reduces the permission scope; when an employee changes positions or leaves, the system automatically reclaims non-related field permissions based on the new position permission template (such as revoking access to customer resource fields after a sales position is transferred to a technical position), and fully records the permission change log to ensure that permission allocation is dynamically synchronized with business scenarios; the allocation strategy is deeply integrated with privacy protection rules, and irreversible anonymization is implemented for sensitive fields in the files of departing employees (such as bank account numbers, health data, and home addresses) (such as converting the full ID number to the "622202001267" format), strictly responding to the deletion request of the "Personal Information Protection Law"; at the same time, a usage purpose constraint mechanism is established to prohibit the allocation of field permissions that exceed business needs to unrelated personnel, blocking the risk of privacy leakage from the source of permissions.

[0115] User behavior analysis dynamically adjusts permissions based on a multi-dimensional mechanism;

[0116] Multiple dimensions include access frequency, operation type, and access period;

[0117] An access frequency dimension, used to adjust the read permission based on the frequency of the user's access to specific first archive data;

[0118] The operation type dimension is used to analyze the matching degree between user operation behavior and the sensitivity level of the first profile data in order to control permissions;

[0119] The access time dimension is used to identify regular access time periods and to control access permissions during abnormal time periods;

[0120] A first-file data association mechanism that dynamically masks non-related fields based on user business scenarios, a permission recovery mechanism when positions change, and a privacy protection strategy for anonymizing first-file data;

[0121] The permission recovery mechanism automatically adjusts the access scope of the primary file data based on the new position permission template when a user changes positions or leaves the company, and retains historical operation logs;

[0122] Privacy protection policy, including anonymization of first-file data, response to deletion requests, and usage purpose constraint mechanism.

[0123] In one embodiment, permissions are dynamically adjusted through a multi-dimensional user behavior analysis mechanism, which is specifically implemented as follows: based on the access frequency dimension, if a specific sensitive field (such as salary data) is accessed more than 5 times a day, the setting basis is the enterprise's anti-data abuse security policy, which automatically triggers secondary authentication (such as SMS verification code) and temporarily switches to read-only permissions until the access is ≤ 2 times for 3 consecutive days and the original permissions are restored; based on the operation type dimension, an "operation-sensitivity level" matching rule library is established. When ordinary employees perform modification operations on "confidential level" fields, the system automatically intercepts and requires submission of an approval form within 2 hours, which is set based on real-time business response requirements. It can only be executed and logged after approval; for the access time dimension, it is defined as 9:00-18:00 on weekdays. For regular time periods, the setting basis is the company's standard working hours. Access during abnormal time periods must be verified by fingerprint or face recognition, and records are synchronized to the security audit log. A real-time permission recovery mechanism is integrated. When an employee changes positions or leaves, non-related field permissions are immediately recovered based on the new position template. For example, if a sales position is transferred to a management position, the customer phone modification right will be revoked immediately, and the operation logs for the past three years will be retained. The setting basis is the compliance audit data retention requirements; in terms of privacy protection, the files of resigned employees will be kept for 30 days after the date of resignation. The setting basis is the minimum file retention period of the "Labor Contract Law", and fields such as ID number and bank account number are automatically irreversibly anonymized (such as replaced with "622202001267"), and applications for permissions beyond the scope are rejected by using the purpose constraint mechanism.

[0124] The first archival data is identified by a preset second rule, and based on the validity period and importance level of the first archival data, the portion of the first archival data that needs to be cleaned is automatically marked as second archival data, and a disposal priority is generated;

[0125] The validity period includes the validity period of the employment materials, the validity period of the contract agreement, the validity period of the assessment and evaluation, the validity period of the qualification certificate and long-term validity;

[0126] The validity period determination rule automatically identifies the validity period information in the field of the first file data through a preset business rule engine;

[0127] For first-file data without a clear validity period, it will be treated as long-term validity by default;

[0128] Importance levels include high importance, medium importance, and low importance;

[0129] Importance level determination rules, automatically divide levels according to preset classification rule templates, and support administrators to customize rules;

[0130] High importance includes social security records and senior management records that are required to be retained by law;

[0131] Medium importance includes ordinary employee contracts and routine performance data;

[0132] Low importance includes non-sensitive training records that have expired.

[0133] In one embodiment, the first file data is automatically identified and hierarchically managed by presetting a second rule engine: first, based on the validity period dimension, the business rule engine automatically scans the timeliness information in the field, and sets the entry materials to be kept for 3 years from the date of leaving the job. The setting is based on the enterprise personnel file management specifications, the contract agreement is kept for at least 2 years in accordance with the requirements of the "Labor Contract Law", and the assessment and evaluation data is retained for the employee's employment period + 1 year. The qualification certificate is automatically marked according to the expiration date. Data without a clear validity period is treated as long-term valid by default (such as employee resumes). At the same time, it is divided into three levels according to the importance level: high importance High-importance data (such as social security records and senior management appointment files that are required to be retained by law) must be permanently encrypted and stored in accordance with Article 74 of the Social Insurance Law. Medium-importance data (such as ordinary employee contracts and routine performance) are managed according to the standard retention period. Low-importance data (such as expired non-sensitive training records) will trigger a 90-day countdown cleanup from the expiration date. The setting is based on the enterprise data cleansing cycle standard, and supports administrators to customize validity period rules and importance level templates through a visual interface. It automatically adds a "high importance-legal retention" label to data that meets legal retention rules to ensure the compliance and flexibility of data cleansing policies.

[0134] Control and manage the priority of primary file data based on legal rules, including:

[0135] If the fields of the first archive data match the preset legal retention rule base, the default validity period and importance level judgment logic will be forcibly overwritten and a fixed retention period will be generated according to the regulations;

[0136] The tag management engine of the first archive data automatically adds a "High Importance - Legal Hold" tag to the first archive data, and simultaneously triggers the permission management unit of the processing module to increase the access control level;

[0137] The disposal priorities include high priority, medium priority, and low priority. The specific rules are as follows:

[0138] High priority: When the first archive data exceeds the validity period and the importance level is low, and it does not involve the legal retention period, the cleanup process is triggered;

[0139] Medium priority: When the first file data is close to the expiration date and the importance level is medium, manual review and approval is triggered;

[0140] Low priority: When the validity period of the first archive data is long-term and the importance level is high, a dedicated encrypted storage node is used for storage, and the access control level is upgraded to confidential level authority management;

[0141] When the first-file data meets multiple priority conditions at the same time, it is judged in the order of legal retention period greater than high importance greater than medium importance greater than low importance, and a visual rule configuration interface is provided to support administrators to customize priority judgment logic and conflict resolution strategies.

[0142] In one embodiment, a file data priority management system is constructed based on legal rules, and mandatory compliance control is achieved through a preset legal retention rule library. When the first file data field matches the rule library (such as social security records, senior executive appointment files and other legally retained data), the default validity period and importance level judgment logic are automatically overwritten, and a fixed retention period is generated according to regulations such as the "Social Insurance Law" and the "Labor Contract Law" (such as permanent retention of social security records). A "high importance-legal retention" label is added through the tag management engine, and the permission management unit is simultaneously triggered to upgrade the access control level to the confidential level (such as access only by the human resources director and the compliance department). The disposal priority is divided into three levels: high priority automatically triggers the cleanup process for data that has exceeded the validity period, is of low importance, and has no legal retention requirements (such as expired non-sensitive training records), and executes a 7-day countdown reminder before cleanup, which is set based on the company's data pre-cleaning notification convention; medium priority triggers a manual review and approval process for medium-importance data (such as ordinary employee performance records) that is close to the expiration date (such as 30 days before the contract expires, based on the company's contract management cycle) to confirm whether to extend the retention period or initiate the return. Long-term, high-importance data (such as the appointment records of key technical personnel) is automatically assigned to dedicated encrypted storage nodes using the AES-256 encryption algorithm (based on industry data security standards) and restricted to department heads and above. When data meets multiple priority criteria simultaneously, it is prioritized according to the order of "legal retention period > high importance > medium importance > low importance." For example, if an expired low-importance training record (triggering high-priority cleanup) is temporarily marked as medium importance due to litigation (triggering medium-priority review), the system will prioritize the high-priority rule and initiate the cleanup process. If the data is also marked as legally held, cleanup is immediately terminated and transferred to long-term encrypted storage. Furthermore, a visual rule configuration interface is provided. The left side allows users to adjust the priority order of "high importance, medium importance, low importance," and "legal hold." The condition editing pop-up window on the right allows users to set parameters such as validity period thresholds and importance criteria for different data types. The conflict resolution strategy module supports options such as "apply to the latest rule" and "execute by weighted rule" to ensure a balance between compliance and management flexibility.

[0143] Automatically mark the data to be cleaned as second-file data based on validity period, importance level and priority rules, and generate corresponding disposal priority;

[0144] The second archive data is destroyed according to the disposal priority, the destruction log is retained, and the remaining valid data is used as the third archive data, specifically including:

[0145] Before destruction, the permission recovery process is automatically triggered to revoke the access rights of all users associated with the second archive data in batches;

[0146] The permission change history is recorded synchronously in the destruction log, including the permission revocation time, the users involved, the roles, the original access scope, and other information;

[0147] Synchronize the destruction log to the management module, and use the built-in audit mechanism of the management module to conduct retrospective query and compliance audit on the permission change history and destruction log;

[0148] After the destruction operation is completed, the index and association relationship map of the second file data in the storage architecture are updated.

[0149] In one embodiment, based on the validity period, importance level and priority rules of the first archive data, an automated data cleaning and management system is constructed to automatically scan the data, mark the data that meets the cleaning conditions such as "overdue and low importance" as the second archive data, and classify them into high priority, medium priority and low priority (for example, high priority data must be processed within 72 hours, based on the enterprise data cleaning time limit standard). Before the destruction is executed, the permission recovery process is triggered to revoke the access rights of all related users (including ordinary employees, department heads and other roles) in batches; and the permission change information is recorded in detail in the destruction log, including the revocation time, the user account involved, the original access right, etc. Field range (such as salary data, training records), logs are synchronized to the management module in real time, and support traceability queries by date, user ID, data type and other conditions through the audit mechanism to meet the compliance audit requirements of the "Personal Information Protection Law"; when the second file data of different priorities are triggered to be destroyed at the same time, the system executes the destruction process in the order of "high priority greater than medium priority greater than low priority" to ensure that key data is processed first. After the destruction is completed, the index and association relationship map in the storage architecture are automatically updated to ensure the integrity and access smoothness of the third file data (that is, the remaining valid data), and avoid storage redundancy or permission configuration confusion due to data deletion.

[0150] Build a distributed cloud storage cluster and local storage nodes to optimize the overall storage architecture and retrieval path of third-party archive data, including:

[0151] A hybrid storage architecture is used to store frequently accessed third-party archive data in local SSD nodes, and less frequently accessed historical data in a distributed cloud storage cluster.

[0152] Establish a storage load balancing mechanism to dynamically adjust the third-party file data distribution based on the node read and write pressure;

[0153] Synchronously write permission metadata when the third archival data is stored, bind the third archival data access permission configuration with the physical storage location, and form an associated index table;

[0154] The cloud storage cluster is configured across multiple active-active data centers across regions, with cache deployed on local nodes to optimize access speed;

[0155] Establish a multi-level index system for third-party archive data, create classification indexes based on life cycle dimensions, sensitivity level dimensions, and morphology dimensions, and locate the target third-party archive data storage location through the classification index;

[0156] Build a data association relationship map by sorting out and storing the association relationships between structured data, semi-structured data, and unstructured data;

[0157] When accessing data across nodes, access permissions are verified through the associated index table.

[0158] In one embodiment, by constructing a hybrid architecture of distributed cloud storage clusters and local storage nodes, the efficiency of third-party archive data storage and retrieval is optimized, and a hot and cold data separation strategy is adopted. High-frequency data with an access frequency greater than or equal to 5 times within 30 days, which is set based on the enterprise data access activity analysis, is stored in the local SSD node, and the remaining low-frequency historical data is stored in the distributed cloud storage cluster; at the same time, a load balancing mechanism is deployed. When the read and write pressure of a node exceeds a threshold of 80% (based on: hardware performance safety redundancy standard), the data is automatically migrated to a node with lower pressure. When storing, the system binds data access permissions (such as viewing, modifying, and deleting) to the physical storage location, generates an associated index table, and ensures that permission verification is synchronized with data reading; the cloud storage cluster The cluster is deployed in multiple active data centers across regions to ensure high data availability. Redis cache is configured on local nodes, and the cache validity period is set to 24 hours. Based on the data update cycle, high-frequency data access is accelerated, and a three-level index system is constructed based on the data life cycle (creation, use, archiving), sensitivity level (public, internal, confidential), and form (documents, pictures, videos). For example, the target data storage location can be quickly located through the "confidentiality level-archiving period-document" label. In addition, the association relationship between structured data (database tables), semi-structured data (JSON logs), and unstructured data (files) is sorted out to generate a visual map. When accessing data across nodes, permissions are forcibly verified through the associated index table to prevent unauthorized access.

[0159] The present invention significantly improves the efficiency of human resource file management through dimensional innovation. Three-dimensional classification realizes refined file management. Field-level verification and automatic completion mechanism ensure data integrity and logical accuracy. Scenario-based dynamic permission control is combined with user behavior analysis to achieve field-level granularity management, dynamically reclaim permissions and strengthen privacy protection to meet data security and compliance requirements. The intelligent cleanup mechanism based on legal retention rules gives priority to mandatory retention of laws and regulations to avoid compliance risks. The distributed hybrid storage architecture optimizes access performance. Multi-level indexing and association graphs improve retrieval efficiency. The response speed of local caching of high-frequency data is significantly improved. The overall upgrade of file management from "passive archiving" to "active governance" is realized, which effectively reduces labor costs, improves decision-making data support capabilities, and builds a competitive barrier for human resource management in the digital age for enterprises.

[0160] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a fully hardware embodiment, a fully software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media containing computer-usable program code. The storage medium may be implemented by any type of volatile or non-volatile storage device, or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0161] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.

Claims

1. A human resources file archiving management system, characterized in that: Including acquisition module, processing module and management module; The acquisition module is used to collect the original file data of employees and transmit it to the processing module; The processing module is configured to classify and process the original archival data according to a preset first rule to obtain first archival data, control and manage the first archival data, and simultaneously generate access rights and allocation policies for the original archival data; Identify the first archival data using a preset second rule to generate second archival data, process the second archival data accordingly according to a disposal priority, retain a processing log, obtain third archival data, and transmit the data to a management module; The management module is used to build a distributed cloud storage cluster and local storage nodes to optimize the overall storage architecture and retrieval path of the third archive data.

2. The human resources file archiving management system according to claim 1, characterized in that: The original file data includes basic information data, position-related data, qualification certificate data, contract agreement data, salary and benefits data, and assessment and evaluation data.

3. The human resources file archiving management system according to claim 1, characterized in that: The first rule specifically includes: The original archival data is classified by dimension to obtain first archival data, specifically including: The dimensions include life cycle dimension, sensitivity level dimension and morphology dimension; Classifying the original archival data according to the life cycle dimension to obtain entry data, on-the-job data, and resignation data; Classifying the original archival data according to the sensitivity level dimension to obtain public data, internal data and confidential data; Classifying the original archival data according to morphological dimensions to obtain structured data, semi-structured data and unstructured data; The first archival data includes onboarding data, on-the-job data, resignation data, public data, internal data, confidential data, structured data, semi-structured data, and unstructured data; Performing integrity check on the first file data; The integrity check includes field integrity verification, time sequence verification and business logic verification; The field integrity verification is performed by verifying the existence of the set of required fields and verifying the compliance of the fields with format requirements; The time sequence verification is to verify the time rationality of the field groups with a time sequence relationship; The business logic verification performs correlation verification on the field groups that have business rule dependencies.

4. The human resources file archiving management system according to claim 3, characterized in that: The verification processing mechanism specifically includes: If the field integrity verification fails, a completion reminder is automatically generated and the first file data status is marked, and a countdown timer is started at the same time; If the completion is not completed before the countdown ends, the editing permission of the first file data will be automatically locked, and only the specified condition administrator will be allowed to operate or the approval process of the direct supervisor will be triggered; The approval process involves the immediate supervisor reviewing whether to waive the completion requirement and providing reasons; If the time sequence verification fails, a time logic conflict warning is automatically triggered and the flow of the first file data is blocked; If the business logic verification fails, the manual review process will be triggered, and after the review passes, it will enter the next processing stage.

5. The human resources file archiving management system according to claim 1, characterized in that: The access authority and allocation strategy are generated based on the confidentiality level and requirements of the original archival data; The access permissions include scenario-based dynamic permission control, which includes adjusting the permission scope and permission recovery mechanism; The scenario-based dynamic permission control opens the fields corresponding to the first file data based on the usage scenario, realizes granular permission management, and dynamically adjusts the permission scope through user behavior analysis; The scenarios include employee onboarding, employee employment, employee departure, audit, and statistical analysis. The granular authority management implements granular authority management with the field of the first archival data as the smallest unit, and independently sets authority for a single field of the first archival data; Said permissions include viewing, modifying and deleting; The allocation strategy includes a privacy protection strategy.

6. The human resources file archiving management system according to claim 5, characterized in that: The user behavior analysis dynamically adjusts permissions based on a multi-dimensional mechanism; The multiple dimensions include access frequency dimension, operation type dimension, and access period dimension; The access frequency dimension is used to adjust the read permission based on the frequency of the number of times the user accesses the specific first archive data; The operation type dimension is used to analyze the matching degree between the user operation behavior and the sensitivity level of the first profile data to control permissions; The access period dimension is used to identify regular access time periods and to control access permissions during abnormal time periods; A first-file data association mechanism that dynamically masks non-related fields based on user business scenarios, a permission recovery mechanism when positions change, and a privacy protection strategy for anonymizing first-file data; The permission recovery mechanism automatically adjusts the access scope of the first file data based on the new position permission template when the user changes or resigns, and retains the historical operation log; The privacy protection strategy includes anonymization processing of the first archive data, response to deletion requests, and usage purpose constraint mechanisms.

7. The human resources file archiving management system according to claim 1, characterized in that: Identifying the first archival data using a preset second rule, automatically marking the portion of the first archival data that needs to be cleaned as second archival data based on the validity period and importance level of the first archival data, and generating a disposal priority; The validity period includes the validity period of employment materials, contract agreement, assessment and evaluation, and qualification certificate, and long-term validity; The validity period determination rule automatically identifies the validity period information in the field of the first file data through a preset business rule engine; For first-file data without a clear validity period, it will be treated as long-term validity by default; The importance levels include high importance, medium importance and low importance; The importance level determination rules automatically divide the levels according to the preset classification rule template and support administrators to customize the rules; The high importance mentioned includes social security records and senior management records that are required to be retained by law; The medium importance mentioned includes ordinary employee contracts and routine performance data; Low importance includes non-sensitive training records that have expired.

8. The human resources file archiving management system according to claim 1, wherein: Controlling and managing the priority of the first archival data based on legal rules specifically includes: If the fields of the first archival data match the preset legal retention rule library, the default validity period and importance level determination logic are forcibly overwritten to generate a fixed retention period according to the law; Automatically adding a "High Importance - Legal Hold" tag to the first archival data through the tag management engine of the first archival data, and simultaneously triggering the permission management unit of the processing module to increase the access control level; The handling priorities include high priority, medium priority and low priority. The specific rules are as follows: The high priority triggers a cleanup process when the first archival data exceeds its validity period and its importance level is low, and does not involve a legal retention period; The medium priority level triggers manual review and approval when the first archive data is close to the expiration date and the importance level is medium; For the low priority, when the validity period of the first archive data is long-term and the importance level is high, a dedicated encryption storage node is used for storage, and the access control level is upgraded to confidential level authority management; When the first archival data meets multiple priority conditions at the same time, it is judged in the order of legal retention period greater than high importance greater than medium importance greater than low importance, and a visual rule configuration interface is provided to support administrators to customize priority judgment logic and conflict resolution strategies.

9. The human resources file archiving management system according to claim 8, characterized in that: Automatically mark the data to be cleaned as second archive data according to the validity period, importance level and priority rule, and generate a corresponding disposal priority; Destroying the second archive data according to the disposal priority, retaining a destruction log, and using the remaining valid data as third archive data, specifically includes: Before destruction, the permission recovery process is automatically triggered to revoke the access rights of all users associated with the second archive data in batches; The permission change history is recorded synchronously in the destruction log, including the permission revocation time, the users involved, the roles, the original access scope, and other information; Synchronize the destruction log to the management module, and conduct retrospective query and compliance audit on the permission change history and destruction log through the built-in audit mechanism of the management module; After the destruction operation is completed, the index and association relationship map of the second file data in the storage architecture are updated.

10. The human resources file archiving management system according to claim 3, characterized in that: The construction of a distributed cloud storage cluster and local storage nodes to optimize the overall storage architecture and retrieval path of the third archive data specifically includes: A hybrid storage architecture is used to store frequently accessed third-party archive data in local SSD nodes, and less frequently accessed historical data in a distributed cloud storage cluster. Establish a storage load balancing mechanism to dynamically adjust the third-party file data distribution based on the node read and write pressure; Synchronously write permission metadata when storing the third archival data, bind the third archival data access permission configuration to the physical storage location, and form an associated index table; The cloud storage cluster is configured across multiple active data centers across regions, with local nodes deploying cache to optimize access speed; Establishing a multi-level index system for the third archival data, creating classification indexes based on life cycle dimensions, sensitivity level dimensions, and morphology dimensions, and locating the target third archival data storage location through the classification indexes; Constructing a data association relationship map by sorting out and storing the association relationships between the structured data, semi-structured data and unstructured data; When accessing data across nodes, access permissions are verified through the associated index table.

Citation Information

Patent Citations

  • Enterprise archive informatization intelligent management system based on big data

    CN119884032A

  • Archive management system based on cloud archive library

    CN120011617A

  • Circulation system, method and device for archive management and storage medium

    CN120067048A

  • Data security encryption method and system for archive management

    CN120124084A

Cited By

  • Data resource processing method, equipment and medium

    CN120974247A

  • File information processing method and system based on digital security

    CN121118113A

  • An archive information processing method and system based on digital security

    CN121118113B

  • File sharing permission control method and system applied to file hosting management system

    CN121351138A

  • File sharing permission control method and system applied to file hosting management system

    CN121351138B