Data authority control method and system based on auditing node and terminal
By creating approval processes and database tables in the data permission control system and establishing the correspondence between approval nodes and data, the problem of cumbersome data permission control operations in the existing technology is solved, precise control of the data access rights of auditors is achieved, and data security and approval efficiency are enhanced.
Patent Information
- Application Number
- CN202510030189.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-08
- Publication Date
- 2025-05-06
AI Technical Summary
In the prior art, data permission control operations are cumbersome, and the data access rights of auditors cannot be accurately controlled, resulting in low data security and low approval efficiency.
By creating an approval process and database table, obtaining the unique identification of the approval node and data, establishing a correspondence relationship, and dynamically controlling data permissions.
It realizes detailed division and dynamic adjustment of the data access scope of different auditors during the approval stage, ensuring that each auditor only obtains data information within its scope of responsibility, thereby enhancing the security of data and the efficiency of the approval process.
Smart Images

Figure CN119939627A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data authority control, and in particular to a data authority control method, system, terminal and computer-readable storage medium based on audit nodes. Background Art
[0002] The importance of data permissions is becoming increasingly prominent in modern enterprises, becoming the cornerstone for maintaining data security, promoting efficient business operations, and ensuring compliance.
[0003] Data permissions are the first line of defense to ensure data security. In the data-driven era, corporate data contains sensitive information, customer privacy, and core business secrets. Once leaked or abused, it will cause immeasurable losses to the company. By accurately setting data permissions, companies can limit the scope of access to data and prevent unauthorized access and leakage, thereby effectively protecting data security and maintaining corporate reputation and customer trust. Secondly, the reasonable setting of data permissions helps improve business efficiency. In a complex business environment, different departments and positions have different needs for data. Through reasonable data permissions, companies can ensure that employees can quickly and accurately obtain the required data when needed to support business decisions and operations. It can not only improve work efficiency, but also promote information sharing and cooperation across departments.
[0004] At present, the commonly used data permission control methods include role-based data permission control, personnel-based data permission control, and data category-based data permission control. For example, personnel-based data permission control usually requires configuring the correspondence between personnel and their visible data first. For example, if personnel A is configured to only view data D1 and data D2, when personnel A views the data, according to the configured correspondence, it can be seen that personnel A can only view data D1 and D2, and cannot view data D3. The logic of the other two data permission control methods is also the same. For the approval process of dynamically obtaining personnel (the so-called dynamic means that the approver of a certain node in the approval process may be the leader of the department to which the submitter of the approval process belongs, or all personnel in the same department can review the node), this permission control method is more cumbersome to handle, and it is necessary to regularly pay attention to the addition of personnel to the approval process. At the same time, manual inspection of permission configuration information is prone to omissions. For example, at a certain node in the approval process, data D1 can only be reviewed by a designated person A1. In this case, not only the review node information needs to be configured for the person, but also the data permissions of person A1 and data D1 need to be configured to ensure the visibility of data D1 to person A1. If the review node subsequently changes person A1 to person A2, the relevant configuration of person A1 needs to be repeated, which is cumbersome.
[0005] Therefore, the prior art still needs to be improved and developed. Summary of the invention
[0006] The main purpose of the present invention is to provide a data permission control method, system, terminal and computer-readable storage medium based on audit nodes, aiming to solve the problems in the prior art that the control operations for data permissions are cumbersome, the data access rights allocated by auditors cannot be accurately controlled, resulting in low data security and low approval efficiency.
[0007] To achieve the above object, the present invention provides a data authority control method based on an audit node, the data authority control method based on an audit node comprising the following steps:
[0008] Create an approval process according to the business demand target, and when the business demand is created, obtain the approval node unique identifiers of multiple approval nodes in the approval process;
[0009] Create a data table in the database, save all approval node unique identifiers and all data unique identifiers in the data table, and set one approval node unique identifier to correspond to one or more data unique identifiers;
[0010] When it is detected that the approver performs data approval or data viewing operations, if the approver has approval authority in the approval process, the target approval node unique identifier corresponding to the approver is obtained, and one or more corresponding target data unique identifiers are obtained from the data table according to the corresponding relationship;
[0011] According to one or more unique identifiers of the target data, corresponding data records are obtained in the data table, and the data within the visible range of the approval personnel is displayed.
[0012] Optionally, the data authority control method based on the review node, wherein the step of creating a data table in a database, storing all approval node unique identifiers and all data unique identifiers in the data table, and setting one approval node unique identifier to correspond to one or more data unique identifiers, specifically includes:
[0013] Create a data table in the database, obtain the approval node unique identifiers of multiple approval nodes when the approval process is established, and obtain the visible data range of each approval node according to specific business rules to obtain the data unique identifier;
[0014] One of the approval node unique identifiers is set to correspond to one or more of the data unique identifiers, and a corresponding relationship between the approval node unique identifier and the data unique identifier is obtained and stored in the data table.
[0015] Optionally, in the data permission control method based on audit nodes, the business rules include mapping the corresponding relationship between data and audit nodes according to labels.
[0016] Optionally, the data authority control method based on the audit node, wherein the corresponding data record is obtained in the data table according to one or more unique identifiers of the target data, and the data within the visible range of the approval personnel is displayed, and then further includes:
[0017] If the approver is obtained dynamically, multiple people are added to the same approval node for review, or the approver is modified due to business changes, directly add or replace the corresponding reviewer information in the configuration information of the corresponding review node.
[0018] Optionally, the data authority control method based on the review node, wherein if the reviewer is dynamically acquired, multiple reviewers are added to the same review node, or the reviewer is modified due to business changes, the corresponding reviewer information in the configuration information of the corresponding review node is directly added or replaced, and the previous method also includes:
[0019] Add the auditor information of the corresponding auditors in the configuration information of all audit nodes in advance.
[0020] Optionally, in the data permission control method based on the audit node, the dynamic acquisition is to obtain the approval participation of the leader of the upper-level department according to the department to which the data approval submitter belongs.
[0021] Optionally, in the data authority control method based on review nodes, one of the review nodes needs to review one or more pieces of data.
[0022] In addition, to achieve the above-mentioned purpose, the present invention also provides a data authority control system based on an audit node, wherein the data authority control system based on an audit node comprises:
[0023] An approval process creation module is used to create an approval process according to a business demand target, and when the business demand is created, obtain the approval node unique identifiers of multiple approval nodes in the approval process;
[0024] A corresponding relationship setting module, used to create a data table in the database, save all approval node unique identifiers and all data unique identifiers in the data table, and set one approval node unique identifier to correspond to one or more data unique identifiers;
[0025] A data approval module is used to, when detecting that an approval officer performs data approval or data viewing operations, obtain a target approval node unique identifier corresponding to the approval officer if the approval officer has approval authority in the approval process, and obtain one or more corresponding target data unique identifiers from the data table according to the corresponding relationship;
[0026] The data display module is used to obtain corresponding data records in the data table according to one or more unique identifiers of the target data, and to display the data within the visible range of the approval personnel.
[0027] In addition, to achieve the above-mentioned purpose, the present invention also provides a terminal, wherein the terminal includes: a memory, a processor, and a data permission control program based on an audit node stored in the memory and executable on the processor, and when the data permission control program based on the audit node is executed by the processor, the steps of the data permission control method based on the audit node as described above are implemented.
[0028] In addition, to achieve the above-mentioned purpose, the present invention also provides a computer-readable storage medium, wherein the computer-readable storage medium stores a data permission control program based on an audit node, and when the data permission control program based on an audit node is executed by a processor, the steps of the data permission control method based on an audit node as described above are implemented.
[0029] In the present invention, an approval process is created according to a business demand target. When the business demand is created, the approval node unique identifiers of multiple approval nodes in the approval process are obtained; a data table is created in a database, all approval node unique identifiers and all data unique identifiers are saved in the data table, and one approval node unique identifier is set to correspond to one or more data unique identifiers; when it is detected that the approval personnel performs data approval or data viewing operations, if the approval personnel has approval authority in the approval process, the target approval node unique identifier corresponding to the approval personnel is obtained, and one or more target data unique identifiers are obtained from the data table according to the corresponding relationship; the corresponding data records are obtained in the data table according to one or more target data unique identifiers, and the data within the visible range of the approval personnel is displayed. The present invention realizes the detailed division and dynamic adjustment of the data range that different reviewers can access and operate in the approval stage by combining the authority management logic with the approval process. By using the data processing algorithm and the authority verification mechanism, it can ensure that each reviewer only obtains the necessary data information within his or her scope of responsibility, thereby enhancing the data security, compliance and efficiency of the approval process. At the same time, when the approver changes, the transfer and handover of data authority can be completed with minimal modification cost. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] Figure 1 It is a flow chart of a preferred embodiment of the data authority control method based on the audit node of the present invention;
[0031] Figure 2 It is a schematic diagram of the process of accurately controlling the data access rights assigned by the auditor in a preferred embodiment of the data authority control method based on the audit node of the present invention;
[0032] Figure 3 It is a structural diagram of a preferred embodiment of the data authority control system based on the audit node of the present invention;
[0033] Figure 4 It is a structural diagram of a preferred embodiment of the terminal of the present invention. DETAILED DESCRIPTION
[0034] In order to make the purpose, technical solution and advantages of the present invention clearer and more specific, the present invention is further described in detail below with reference to the accompanying drawings and examples. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0035] The data authority control method based on the audit node described in the preferred embodiment of the present invention is as follows: Figure 1 and Figure 2 As shown, the data authority control method based on the audit node includes the following steps:
[0036] Step S10: Create an approval process according to the business demand target. After the business demand is created, obtain the approval node unique identifiers of multiple approval nodes in the approval process.
[0037] Specifically, in the process of implementing business needs (i.e. obtaining business need goals), the logic of creation, update and circulation of approval process instances are mature. Then, the unique identifier of the approval node (set to node_uk) after the approval process is created is easy to obtain. The unique identifier of the approval node is obtained here for subsequent use.
[0038] Among them, an approval process may include N review nodes (N≥1). In the business system, each review node must have its own unique code, which can be used as the approval node's unique identification node_uk; after an approval process is created, in general, the review nodes of the approval process will be completely determined, and one of the approval nodes needs to review one or more pieces of data.
[0039] Step S20: Create a data table in the database, save all approval node unique identifiers and all data unique identifiers in the data table, and set one approval node unique identifier to correspond to one or more data unique identifiers.
[0040] Specifically, a data table (t) is created in the database, and when the approval process is established, the approval node unique identifiers (node_uk) of multiple approval nodes are obtained, and according to specific business rules (for example, mapping the corresponding relationship between data and the approval node according to the label), the visible data range of each of the approval nodes is obtained to obtain the data unique identifier (data_uk), wherein the data unique identifier (data_uk) in the database can be the primary key ID of the row of data, or the encoding of the data (the encoding here must be globally unique); one of the approval node unique identifiers (node_uk) is set to correspond to one or more of the data unique identifiers (data_uk), and the corresponding relationship between the approval node unique identifier (node_uk) and the data unique identifier (data_uk) is obtained and stored in the data table (t), and the corresponding relationship between the approval node unique identifier node_uk and the data unique identifier data_uk is formed in the data table (t) (set as rel).
[0041] Since there may be one or more approval data in an approval process, a certain approval node needs to review one or more data (such as financial review reimbursement form), that is, one node_uk can correspond to one or more data_uk.
[0042] Step S30: When it is detected that the approver performs data approval or data viewing operations, if the approver has approval authority in the approval process, obtain the target approval node unique identifier corresponding to the approver, and obtain the corresponding one or more target data unique identifiers from the data table according to the corresponding relationship.
[0043] Specifically, when the approver is approving or viewing data, if the approver has the authority to approve in the approval process, the approval node unique identifier node_uk corresponding to the approver can be obtained, and the data unique identifier data_uk can be obtained from the data table (t) according to the corresponding relationship rel through node_uk.
[0044] Among them, the approver refers to the person who can log in to the business system. After certain data is submitted, the person needs to approve the submitted data. For example, an employee submits two expense reports in the business system. Due to the different amounts of the expense reports, the large expense report needs to be approved by person A, while the small expense report needs to be reviewed by person B. The approver here refers to person A or B, that is, the process approver.
[0045] Step S40: Obtain corresponding data records in the data table according to one or more unique identifiers of the target data, and display the data within the visible range of the approval personnel.
[0046] Specifically, when the data unique identifier data_uk is known, the corresponding data record can be obtained, thereby displaying the data within the visible range of the approval personnel.
[0047] Furthermore, in actual business, there are cases where the approval personnel are dynamically obtained (for example, the department leader's participation in the approval is obtained based on the department to which the submitter (the triggerer of the approval process) belongs), multiple people are allowed to review the same approval node, and the approval personnel need to be modified due to business changes, etc., and the corresponding reviewer information in the configuration information of the corresponding review node is directly added or replaced.
[0048] The present invention can meet the above business scenario changes, and only needs to process the corresponding approval node according to the actual situation. In general, the configuration information of the review node contains the reviewer of the node (that is, the reviewer information of the corresponding reviewer is added in advance in the configuration information of all review nodes). Here, it means that when the reviewer changes, the corresponding reviewer information in the configuration information of the review node can be directly replaced. The modification here is determined by the approval process specifically implemented by each business system.
[0049] That is, as long as the unique identifier of the approval node node_uk does not change, there is no need to process data permissions additionally, which can effectively reduce the risks brought by human manipulation of data permissions. At the same time, it ensures the consistency of data permissions and makes it easy to achieve precise control of data permissions in the approval process.
[0050] In the present invention, in a business system with an approval process, approvers of different review levels can have different data permissions. For example, a specialist can only query part of the data, while a department leader can view all the data. Through the present invention, the approval node unique identifier node_uk can be obtained when the approval process is established, and the visible data range of the review node can be obtained according to specific business rules (such as mapping the corresponding relationship between data and the review node according to the label), and the data unique identifier data_uk can be obtained, so that the corresponding relationship rel between the approval node unique identifier node_uk and the data unique identifier data_uk can be saved in the data table (t).
[0051] When any approver is approving, if the approver has approval authority, the unique identification node_uk of the approval node corresponding to the approver can be obtained. At this time, the data range visible to the operator can be obtained through the corresponding relationship rel according to the unique identification node_uk of the approval node, thereby realizing data permission control based on the review node.
[0052] If the reviewer corresponding to a certain review node changes, since the data table (t) stores the correspondence between the review node and the data, you only need to modify the configuration information of the approval process to complete the perfect replacement of data permissions.
[0053] If the auditor of a certain audit node needs to be obtained dynamically, for example, in the scenario where the corresponding supervisor participates in the approval based on the department to which the submitter belongs, since the data table (t) stores the correspondence between the audit node and the data, the supervisor only needs to automatically obtain the corresponding audit node identifier during approval, and can obtain the corresponding data within the data authority range based on the correspondence relationship rel.
[0054] The present invention can effectively solve the problem of accurately controlling the data access rights allocated to auditors in the approval process management system. By combining the authority management logic with the approval process, it realizes the detailed division and dynamic adjustment of the data range that different auditors can access and operate in the approval stage. By using data processing algorithms and authority verification mechanisms, it can ensure that each auditor only obtains the necessary data information within the scope of his or her responsibilities, thereby enhancing the security, compliance and efficiency of the approval process of the data. At the same time, when the approver changes, the transfer and handover of data permissions can be completed with extremely small modification costs.
[0055] The advantage of the present invention is that in a system with approval process management, it can accurately control the data access rights assigned by reviewers, effectively reduce the number of changes in manually assigned data permissions, reduce the frequency of errors, and meet the data permission control requirements in scenarios such as changes in reviewers and dynamic acquisition of reviewers.
[0056] Furthermore, if Figure 3 As shown, based on the above-mentioned data authority control method based on the audit node, the present invention also provides a data authority control system based on the audit node, wherein the data authority control system based on the audit node includes:
[0057] An approval process creation module 51 is used to create an approval process according to a business requirement target, and when the business requirement is created, obtain the approval node unique identifiers of multiple approval nodes in the approval process;
[0058] The corresponding relationship setting module 52 is used to create a data table in the database, save all approval node unique identifiers and all data unique identifiers in the data table, and set one approval node unique identifier to correspond to one or more data unique identifiers;
[0059] The data approval module 53 is used for, when it is detected that the approval personnel performs data approval or data viewing operations, if the approval personnel has approval authority in the approval process, obtaining the target approval node unique identifier corresponding to the approval personnel, and obtaining one or more corresponding target data unique identifiers from the data table according to the corresponding relationship;
[0060] The data display module 54 is used to obtain corresponding data records in the data table according to one or more unique identifiers of the target data, and to display the data within the visible range of the approval personnel.
[0061] Furthermore, if Figure 4 As shown, based on the above-mentioned audit node-based data authority control method and system, the present invention also provides a terminal accordingly, and the terminal includes a processor 10, a memory 20 and a display 30. Figure 4 Only some components of the terminal are shown, but it should be understood that it is not required to implement all of the components shown, and more or fewer components may be implemented instead.
[0062] The memory 20 may be an internal storage unit of the terminal in some embodiments, such as a hard disk or memory of the terminal. The memory 20 may also be an external storage device of the terminal in other embodiments, such as a plug-in hard disk, a smart memory card (Smart Media Card, SMC), a secure digital (SecureDigital, SD) card, a flash card (Flash Card), etc. equipped on the terminal. Further, the memory 20 may also include both an internal storage unit of the terminal and an external storage device. The memory 20 is used to store application software and various types of data installed in the terminal, such as the program code of the installation terminal, etc. The memory 20 may also be used to temporarily store data that has been output or is to be output. In one embodiment, a data authority control program 40 based on an audit node is stored on the memory 20, and the data authority control program 40 based on the audit node can be executed by the processor 10, thereby realizing the data authority control method based on the audit node in the present application.
[0063] In some embodiments, the processor 10 may be a central processing unit (CPU), a microprocessor or other data processing chip, used to run the program code or process data stored in the memory 20, such as executing the audit node-based data authority control method.
[0064] In some embodiments, the display 30 may be an LED display, a liquid crystal display, a touch-sensitive liquid crystal display, an OLED (Organic Light-Emitting Diode) touch device, etc. The display 30 is used to display information on the terminal and to display a visual user interface. The processor 10, the memory 20, and the display 30 of the terminal communicate with each other via a system bus.
[0065] In one embodiment, when the processor 10 executes the audit node-based data authority control program 40 in the memory 20, the following steps are implemented:
[0066] Create an approval process according to the business demand target, and when the business demand is created, obtain the approval node unique identifiers of multiple approval nodes in the approval process;
[0067] Create a data table in the database, save all approval node unique identifiers and all data unique identifiers in the data table, and set one approval node unique identifier to correspond to one or more data unique identifiers;
[0068] When it is detected that the approver performs data approval or data viewing operations, if the approver has approval authority in the approval process, the target approval node unique identifier corresponding to the approver is obtained, and one or more corresponding target data unique identifiers are obtained from the data table according to the corresponding relationship;
[0069] According to one or more unique identifiers of the target data, corresponding data records are obtained in the data table, and the data within the visible range of the approval personnel is displayed.
[0070] The step of creating a data table in a database, storing all approval node unique identifiers and all data unique identifiers in the data table, and setting one approval node unique identifier to correspond to one or more data unique identifiers, specifically includes:
[0071] Create a data table in the database, obtain the approval node unique identifiers of multiple approval nodes when the approval process is established, and obtain the visible data range of each approval node according to specific business rules to obtain the data unique identifier;
[0072] One of the approval node unique identifiers is set to correspond to one or more of the data unique identifiers, and a corresponding relationship between the approval node unique identifier and the data unique identifier is obtained and stored in the data table.
[0073] The business rules include mapping the corresponding relationship between data and audit nodes according to labels.
[0074] The step of acquiring corresponding data records in the data table according to one or more unique identifiers of the target data and displaying the data within the visible range of the approval personnel may further include:
[0075] If the approver is obtained dynamically, multiple people are added to the same approval node for review, or the approver is modified due to business changes, directly add or replace the corresponding reviewer information in the configuration information of the corresponding review node.
[0076] Wherein, if the reviewer is dynamically acquired, multiple reviewers are added to the same review node, or the reviewer is modified due to business changes, the corresponding reviewer information in the configuration information of the corresponding review node is directly added or replaced, and the previous one also includes:
[0077] Add the auditor information of the corresponding auditors in the configuration information of all audit nodes in advance.
[0078] Among them, the dynamic acquisition is to obtain the participation of the leaders of the upper-level department in the approval based on the department to which the data approval submitter belongs.
[0079] Among them, one of the approval nodes needs to review one or more pieces of data.
[0080] The present invention also provides a computer-readable storage medium, wherein the computer-readable storage medium stores a data authority control program based on an audit node, and when the data authority control program based on an audit node is executed by a processor, the steps of the data authority control method based on an audit node as described above are implemented.
[0081] In summary, the present invention provides a data authority control method, system, terminal and computer-readable storage medium based on review nodes, the method comprising: creating an approval process according to a business demand target, and when the business demand is created, obtaining approval node unique identifiers of multiple approval nodes in the approval process; creating a data table in a database, saving all approval node unique identifiers and all data unique identifiers in the data table, and setting one approval node unique identifier to correspond to one or more data unique identifiers; when it is detected that the approver performs data approval or data viewing operations, if the approver has approval authority in the approval process, obtaining the target approval node unique identifier corresponding to the approver, and obtaining the corresponding one or more target data unique identifiers from the data table according to the corresponding relationship; obtaining corresponding data records in the data table according to one or more target data unique identifiers, and displaying the data within the visible range of the approver. The present invention combines the authority management logic with the approval process to achieve detailed division and dynamic adjustment of the data scope that different reviewers can access and operate during the approval stage. By utilizing data processing algorithms and authority verification mechanisms, it can ensure that each reviewer only obtains the necessary data information within the scope of his or her responsibilities, thereby enhancing data security, compliance and the efficiency of the approval process. At the same time, when the approver changes, the transfer and handover of data permissions can be completed with extremely small modification costs.
[0082] It should be noted that, in this article, the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or terminal including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or terminal. In the absence of further restrictions, an element defined by the sentence "includes a ..." does not exclude the existence of other identical elements in the process, method, article or terminal including the element.
[0083] Of course, those skilled in the art can understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing related hardware (such as a processor, a controller, etc.) through a computer program, and the program can be stored in a computer-readable storage medium that can be read by a computer, and the program can include the processes of the above-mentioned method embodiments when executed. The computer-readable storage medium can be a memory, a disk, an optical disk, etc.
[0084] It should be understood that the application of the present invention is not limited to the above examples. For ordinary technicians in this field, improvements or changes can be made based on the above description. All these improvements and changes should fall within the scope of protection of the claims attached to the present invention.
Claims
1. A data authority control method based on audit nodes, characterized in that: The data authority control method based on the audit node includes: Create an approval process according to the business demand target, and when the business demand is created, obtain the approval node unique identifiers of multiple approval nodes in the approval process; Create a data table in the database, save all approval node unique identifiers and all data unique identifiers in the data table, and set one approval node unique identifier to correspond to one or more data unique identifiers; When it is detected that the approver performs data approval or data viewing operations, if the approver has approval authority in the approval process, the target approval node unique identifier corresponding to the approver is obtained, and one or more corresponding target data unique identifiers are obtained from the data table according to the corresponding relationship; According to one or more unique identifiers of the target data, corresponding data records are obtained in the data table, and the data within the visible range of the approval personnel is displayed.
2. The data authority control method based on audit nodes according to claim 1 is characterized in that: The step of creating a data table in a database, storing all approval node unique identifiers and all data unique identifiers in the data table, and setting one approval node unique identifier to correspond to one or more data unique identifiers, specifically includes: Create a data table in the database, obtain the approval node unique identifiers of multiple approval nodes when the approval process is established, and obtain the visible data range of each approval node according to specific business rules to obtain the data unique identifier; One of the approval node unique identifiers is set to correspond to one or more of the data unique identifiers, and a corresponding relationship between the approval node unique identifier and the data unique identifier is obtained and stored in the data table.
3. The data authority control method based on audit nodes according to claim 2 is characterized in that: The business rules include mapping the corresponding relationship between data and audit nodes according to labels.
4. The data authority control method based on audit nodes according to claim 1 is characterized in that: The step of obtaining corresponding data records in the data table according to one or more unique identifiers of the target data and displaying the data within the visible range of the approval personnel further includes: If the approver is obtained dynamically, multiple people are added to the same approval node for review, or the approver is modified due to business changes, directly add or replace the corresponding reviewer information in the configuration information of the corresponding review node.
5. The data authority control method based on audit nodes according to claim 4 is characterized in that: If the reviewer is dynamically acquired, multiple reviewers are added to the same review node, or the reviewer is modified due to business changes, the corresponding reviewer information in the configuration information of the corresponding review node is directly added or replaced, which also includes: Add the auditor information of the corresponding auditors in the configuration information of all audit nodes in advance.
6. The data authority control method based on audit nodes according to claim 4 is characterized in that: The dynamic acquisition is to obtain the participation of the leaders of the upper-level departments in the approval based on the department to which the data approval submitter belongs.
7. The data authority control method based on audit nodes according to claim 1 is characterized in that: One of the approval nodes needs to review one or more pieces of data.
8. A data authority control system based on audit nodes, characterized in that: The data authority control system based on the audit node includes: An approval process creation module is used to create an approval process according to a business demand target, and when the business demand is created, obtain the approval node unique identifiers of multiple approval nodes in the approval process; A corresponding relationship setting module, used to create a data table in the database, save all approval node unique identifiers and all data unique identifiers in the data table, and set one approval node unique identifier to correspond to one or more data unique identifiers; A data approval module is used to, when detecting that an approval officer performs data approval or data viewing operations, obtain a target approval node unique identifier corresponding to the approval officer if the approval officer has approval authority in the approval process, and obtain one or more corresponding target data unique identifiers from the data table according to the corresponding relationship; The data display module is used to obtain corresponding data records in the data table according to one or more unique identifiers of the target data, and to display the data within the visible range of the approval personnel.
9. A terminal, characterized in that: The terminal includes: a memory, a processor, and a data permission control program based on an audit node stored in the memory and executable on the processor. When the data permission control program based on an audit node is executed by the processor, the steps of the data permission control method based on an audit node as described in any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a data authority control program based on an audit node, and when the data authority control program based on an audit node is executed by a processor, the steps of the data authority control method based on an audit node as described in any one of claims 1-7 are implemented.