Visual dynamic permission allocation method and device based on multiple dimensions
Through the multi-dimensional visualization of dynamic permission allocation method, permission tables are dynamically generated, which solves the problem of high complexity of permission allocation in large enterprises, realizes refined permission management and real-time information sharing, reduces operation and maintenance costs, and improves collaboration efficiency.
Patent Information
- Application Number
- CN202510484065.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-17
- Publication Date
- 2025-08-08
AI Technical Summary
In large enterprises, the traditional authority allocation system has high operation and maintenance costs and large adjustment workloads due to the large number of users and the large number of individualized management demands of units, making it difficult to realize real-time sharing and circulation of information, and the system operation and maintenance complexity is high.
The multi-dimensional visual dynamic permission allocation method is adopted to achieve flexible permission allocation through table form, dynamically generate multi-dimensional table display institutions, departments, table samples and permission relationships between users, dynamically filter the departments, table samples and operation permissions visible to users, and support drag, check and scope input operations, realizing refined management of permissions.
It reduces the complexity of permission allocation, improves the refinement and flexibility of management, realizes real-time sharing and circulation of information, reduces system operation and maintenance costs, and improves the collaboration efficiency between departments.
Smart Images

Figure CN120449137A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data management, and in particular to a multi-dimensional visual dynamic permission allocation method and device. Background Art
[0002] In recent years, as the market landscape continues to evolve, companies are increasingly driven by the need to explore more flexible and efficient management methods, a key element in supporting their long-term development. Against this backdrop, deeply integrating software applications into corporate development strategies and seamlessly integrating them with refined management philosophies is crucial.
[0003] In traditional software systems, the refinement of management concepts is mainly achieved through user authorization and role authorization in the authority allocation system. When the overall units and users of the enterprise are too large and the subordinate units have too many personalized management demands, it may be necessary to create roles in separate tables or grant permissions to each user, and the overall system operation and maintenance costs will increase exponentially. Specifically: the traditional conventional authority allocation system establishes users and roles in the system and assigns permissions to users or roles; taking the filling of reports in the system as an example, assuming that Group A has 10 secondary units, the number of departments and department permissions set up under each secondary unit are different, and 100 report samples are filled out during the overall annual report period.
[0004] According to the traditional authority allocation system, since users belong to specific departments under different units, if you want to allocate permissions based on the authority requirements in the table above, there are two ways:
[0005] 1) User-based authorization: Different users are given the ability to fill in or view different tables. Advantages: Authorization is based on individuals, and permissions are clearly assigned to each user. Disadvantages: The workload is enormous when there are a large number of users, or when there are subsequent changes such as new users, departures, or job transfers.
[0006] 2) Create roles on a 1:1 basis based on the number of tables and assign permissions to each role. Advantage: By assigning permissions based on roles, you can remove or add corresponding roles when users change. Disadvantage: If the number of tables is large, for example, 100, at least 100 roles must be created. Assuming each table is divided into reporting and viewing, 100 * 2 = 200 roles must be created.
[0007] To this end, the industry urgently needs an efficient authority allocation system to enhance seamless collaboration between departments and employees of system demanders, ensure real-time sharing and circulation of information, and improve operational efficiency. Summary of the Invention
[0008] The purpose of this application is to provide a multi-dimensional, visual, dynamic permission allocation method and device. This method, in the form of a table, enables flexible permission allocation and customized operation and maintenance, reduces the complexity of permission allocation, and improves the refinement, flexibility, and real-time nature of management. By implementing a top-down table with a different table for each unit, the multi-dimensional nature allows different units to display different departments and table templates, reducing the complexity of operation and maintenance.
[0009] To achieve the above-mentioned purpose, the multi-dimensional visual dynamic permission allocation method provided by the present application specifically includes: configuring department compilation rules according to the association relationship between institutions, departments, and forms and the permission allocation logic; dynamically displaying the permission association between institutions, departments, forms and users according to the department compilation rules to generate a dynamic multi-dimensional table; collecting permission data including the operation permissions of departments and forms and / or the affiliation between departments and users according to the specified collection table style; dynamically filtering the departments, forms and operation permissions visible to users during the execution of system functions according to the dynamic multi-dimensional table and the permission data.
[0010] In the above-mentioned multi-dimensional-based visual dynamic permission allocation method, optionally, the department compilation rules include a combination of one or more of the department view permission collection mode, the table sample view permission collection mode and the hybrid view permission collection mode; wherein, the department view permission collection mode is used to limit the department's operating permissions on the table sample; the table sample view permission collection mode is used to limit the department and user scope to which the table sample belongs; the hybrid view permission collection mode is used to dynamically generate permission rules in combination with the department view and the table sample view.
[0011] In the above-mentioned multi-dimensional-based visual dynamic permission allocation method, optionally, generating a dynamic multi-dimensional table by dynamically displaying the permission associations between institutions, departments, forms and users according to the department compilation rules also includes: dynamically adjusting the displayed departments and form scopes according to the institutional hierarchy through the dynamic multi-dimensional table, or configuring the permission association relationship by dragging, checking or range input, or updating the permission rules in real time and synchronizing them to one or more function combinations in the system function module.
[0012] In the above-mentioned multi-dimensional visual dynamic authority allocation method, optionally, the operation authority includes the superior unit viewing the subordinate unit data, the designated department leader viewing the data of all departments under the organization and / or the cross-organizational department viewing the subordinate unit data within a specified range.
[0013] In the above-mentioned multi-dimensional visual dynamic permission allocation method, optionally, the method further includes: dynamically generating a permission filtering chain based on the organization and department to which the user belongs; the filtering chain includes: determining the visible department range based on the organization associated with the user, filtering operable forms based on the association rules between departments and forms, and / or adjusting the read and write permissions of the final form based on the permission exception settings.
[0014] In the above-mentioned multi-dimensional visual dynamic permission allocation method, optionally, the operation permissions include batch importing the permission relationships of institutions, departments and users through multi-dimensional tables; and generating permission rules according to preset templates and associating them with business processes.
[0015] In the above-mentioned multi-dimensional-based visual dynamic permission allocation method, optionally, generating a dynamic multi-dimensional table by dynamically displaying the permission associations between institutions, departments, forms and users according to the department compilation rules also includes: dynamically grouping by institutional hierarchy, department type, and form classification through the multi-dimensional table; and quickly locating the target permission configuration item through keyword retrieval.
[0016] The present application also provides a multi-dimensional visual dynamic permission allocation device, which includes: a rule configuration module, a multi-dimensional table generation module, a permission collection module and a permission execution module; the rule configuration module is used to configure department compilation rules based on the association relationship between institutions, departments and forms and the permission allocation logic; the multi-dimensional table generation module is used to dynamically display the permission association between institutions, departments, forms and users according to the department compilation rules to generate a dynamic multi-dimensional table; the permission collection module is used to collect permission data including the operation permissions of departments and forms and / or the affiliation between departments and users according to a specified collection table style; the permission execution module is used to dynamically filter the departments, forms and operation permissions visible to users according to the dynamic multi-dimensional table and the permission data during the execution of system functions.
[0017] In the above-mentioned multi-dimensional visual dynamic permission allocation device, optionally, the multi-dimensional table generation module includes a control unit, which is used to dynamically fold or expand the department and table list according to the organizational hierarchy, distinguish the read and write permission status of the table by color marking, and / or use the integrated permission exception setting control to configure special permission scenarios.
[0018] In the above-mentioned multi-dimensional visual dynamic permission allocation device, optionally, the permission execution module includes a query unit, a filtering unit and a processing unit; the query unit is used to retrieve associated institutions and departments based on user identity; the filtering unit is used to generate an operable table range based on the association rules between departments and tables; the processing unit is used to adjust the final permission result in combination with the permission exception settings.
[0019] In the above-mentioned multi-dimensional visual dynamic authority allocation device, optionally, the device also includes a task management module and a dynamic update module; the task management module is used to bind the authority allocation task with the business process, and the business process includes at least one of budget preparation, report filling, and approval process; the dynamic update module is used to synchronize to the system function interface in real time when user permissions or department compilation rules change.
[0020] The present application also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the above-mentioned method when executing the computer program.
[0021] The present application also provides a computer-readable storage medium, which stores a computer program for executing the above method.
[0022] The present application also provides a computer program product, comprising a computer program / instruction, which implements the steps of the above method when executed by a processor.
[0023] The beneficial technical effects of this application are: based on a multi-dimensional visual dynamic authority allocation system, with the help of flexible and diverse display forms of multi-dimensional tables, in addition to meeting the basic flexible and dynamic authority allocation according to multiple dimensions of institutions, departments, and forms, it realizes the collaborative autonomy and thousands of companies and states of departments within each organization; because the overall interface is simple and easy to use, it can be directly handed over to customized operation and maintenance to reduce system maintenance costs, enhance seamless collaboration between departments and employees of system demanders, ensure real-time sharing and circulation of information, and improve operational efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] The drawings described herein are used to provide a further understanding of the present application, constitute a part of the present application, and do not constitute a limitation of the present application. In the drawings:
[0025] Figure 1 A flowchart of a multi-dimensional visual dynamic permission allocation method provided in one embodiment of the present application;
[0026] Figure 2 A logical diagram of department compilation rules provided in one embodiment of the present application;
[0027] Figure 3 A logical diagram of filtering visible departments provided in an embodiment of the present application;
[0028] Figure 4 A logical diagram of filtering a table based on departments and obtaining read and write permissions for a table provided in one embodiment of the present application;
[0029] Figure 5A A schematic diagram of the collection department and sample authority provided in one embodiment of the present application;
[0030] Figure 5B A schematic diagram of the relationship between the collection department and the user provided in one embodiment of the present application;
[0031] Figure 6A schematic diagram of the structure of a multi-dimensional visual dynamic permission allocation device provided in one embodiment of the present application;
[0032] Figure 7 A schematic diagram of the structure of an electronic device provided in one embodiment of the present application. DETAILED DESCRIPTION
[0033] The following will describe in detail the implementation methods of this application in conjunction with the accompanying drawings and examples, so that the application can fully understand how technical means are used to solve technical problems and achieve technical effects, and implement them accordingly. It should be noted that as long as there is no conflict, the various embodiments and the various features in each embodiment of this application can be combined with each other, and the resulting technical solutions are all within the scope of protection of this application.
[0034] Additionally, the steps shown in the flowcharts of the accompanying drawings may be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowcharts, in some cases the steps shown or described may be performed in an order different from that shown.
[0035] Please refer to Figure 1 As shown, the multi-dimensional visual dynamic permission allocation method provided by this application specifically includes:
[0036] S101 configures department compilation rules based on the relationship between institutions, departments, and forms, as well as the authority allocation logic;
[0037] S102 generates a dynamic multidimensional table based on the department compilation rules to dynamically display the authority associations among organizations, departments, table templates, and users;
[0038] S103 collects authority data including the operation authority of the department and the form and / or the affiliation between the department and the user according to the specified collection form;
[0039] S104 dynamically filters user-visible departments, table templates, and operation permissions according to the dynamic multidimensional table and the permission data during the execution of system functions.
[0040] In the above embodiment, this application establishes and provides a multi-dimensional visual dynamic permission allocation method based on the existing standard permission system. With the help of flexible and diverse display forms of multi-dimensional tables, the relationship between organizations, departments, tables, and users is configured through dynamically generated multi-dimensional tables to achieve flexible allocation of permissions, meet the needs of refined management and work collaboration between different units, departments, and employees. Ensure real-time sharing and circulation of information and improve operational efficiency. For details, please refer to Figure 2As shown, by enabling the department compilation rule setting, the filling and viewing rules between the specific task configuration agencies, departments, and forms, as well as the filling and viewing rules between agencies, departments and users, form the basic rule data of the authority system; then respond to the authority allocation rules during the opening and execution of specific functions of the entire system; the specific implementation method of each step will be described in detail in the subsequent embodiments, and will not be described in detail here.
[0041] In one embodiment of the present application, the department compilation rules include a combination of one or more of the department view permission collection mode, the table view permission collection mode and the hybrid view permission collection mode; wherein, the department view permission collection mode is used to limit the department's operating authority on the table; the table view permission collection mode is used to limit the department and user range to which the table belongs; the hybrid view permission collection mode is used to dynamically generate permission rules in combination with the department view and the table view. Afterwards, the department compilation permission maintenance table model and related multidimensional tables are automatically generated according to the selected collection table style, and the department editing permission collection task is added simultaneously. Based on the different permission collection table styles selected, the final generated models are slightly different, including department view permission collection, table view permission collection, and hybrid view permission collection.
[0042] In one embodiment of the present application, the operational permissions include the ability for a superior unit to view subordinate unit data, for a designated department head to view data for all departments within their organization, and / or for a cross-organizational department to view data for subordinate units within a specified scope. In another embodiment, the operational permissions include the ability to batch import organization, department, and user permission relationships via a multidimensional table; and the ability to generate permission rules based on pre-set templates and associate them with business processes.
[0043] Specifically, in actual work, the entire permission collection visualization device configuration interface uses flexible and diverse multi-dimensional tables to dynamically generate multi-dimensional tables based on the relationships between organizations, departments, and tables. Customers independently operate and collect relevant data to form a standardized permission system between organizations, departments, tables, and organizations, departments, and users. In actual projects, the compilation of response department permission filtering is divided into the following parts:
[0044] 1) Find the department under the organization according to the user (using exceptions);
[0045] 2) Determine the scope of the table based on the department;
[0046] 3) Determine the read and write permissions of the table range based on the department’s permission table.
[0047] In addition to following the above-mentioned regularized and relatively standard permission filtering method, the overall design process also needs to adapt to personalized and differentiated management models, such as: the superior unit views the data of the subordinate unit, the leader of the unit's finance department views the data of all departments under the unit, the superior unit's affiliated department views the data of the subordinate units within the affiliated scope, etc. These all require adaptation to permission exception settings; in addition, when the department compilation rule configuration is enabled, all places in the system that require read permissions, such as process approval and task monitoring, need to respond to the department compilation's visual dynamic permission allocation method.
[0048] In one embodiment of the present application, the method may also include: dynamically generating a permission filtering chain based on the organization and department to which the user belongs; the filtering chain includes: determining the visible department range based on the organization associated with the user, filtering operable forms based on the association rules between departments and forms, and / or adjusting the read and write permissions of the final form based on the permission exception settings.
[0049] For details, please refer to Figure 3 As shown, the process of filtering visible departments based on permissions is as follows:
[0050] First, the user logs in. After verifying the user's identity, the compilation function is opened to specify the task. Based on the user's identity, the display department's total department compilation and the detailed department configured in the permission table are determined, or the current logged-in user is determined to belong to an exception role for further analysis.
[0051] The following situations exist when determining that a user belongs to an exception role:
[0052] Make sure to enable exceptions at this level:
[0053] Determine whether the institution currently selected in the compilation table is the institution to which the exception user belongs or the regulatory agency itself; if so, display the department totals and detailed departments; if not, query the department compilation authority table based on the selected institution and return the department;
[0054] Make sure to enable the subordinate exceptions:
[0055] Determine whether the institution currently selected in the compilation table is the institution to which the exception user belongs or the subordinate of the regulatory agency; if so, display the department totals and detailed departments; if not, query the department compilation authority table based on the selected institution and return the department;
[0056] In determining the "Father Watches Son" situation:
[0057] If so, the department totals and the departments configured in the department establishment authority table are displayed; otherwise, the department establishment authority table is queried according to the organization selected by establishment and the department is returned.
[0058] Please refer to Figure 4 As shown in the figure, the process of filtering tables by department and obtaining read and write permissions for the tables is as follows:
[0059] First, log in as a user and open the agent query. The visible table range in the agent query is the visible table range of the reporting dimension. You can also open the compilation task and choose to switch departments, such as detailed departments or department totals.
[0060] When selecting department totals, determine whether the user is an exception user:
[0061] If yes, enter the summary node configuration table range judgment: if it is judged to be within the table range, directly display the summary node table range; if it is not within the table range, perform the final unit analysis; if it is within the final unit, display the sum of the visible table ranges of all detailed departments; if it is not, determine whether there is a detailed department; if so, display the sum of the visible table ranges of all corresponding detailed departments; if not, directly read the number of the subordinate organization department summary table; if the direct subordinate organization summary node has a table configured, read it directly; otherwise, read the full set of the direct subordinate organization detailed department tables;
[0062] If not, the parent-child judgment is performed. If not, the above-mentioned aggregate node configuration table range judgment is entered. If so, the display is determined according to the configured table range: the intersection of the full set of table ranges configured by the current user's institution\regulatory agency in the department compilation and the aggregate node table range, and the overall principle of vertical proximity to the institution; or, the full set of table ranges configured by the current user's institution\regulatory agency in the department compilation and the visible table range of the detailed department are intersected, and the overall principle of vertical proximity to the institution is followed.
[0063] When a detailed department is selected, the table range of the department's organization configuration is displayed.
[0064] In one embodiment of the present application, generating a dynamic multidimensional table based on the dynamic display of permission associations between institutions, departments, forms and users according to the department compilation rules also includes: dynamically adjusting the displayed departments and form ranges according to the institutional hierarchy through the dynamic multidimensional table, or configuring permission association relationships by dragging, checking or range input, or updating permission rules in real time and synchronizing them to one or more function combinations in the system function module; and, dynamically grouping by institutional hierarchy, department type, and form classification through the multidimensional table; and, quickly locating the target permission configuration item through keyword retrieval.
[0065] Specifically, in actual work, the characteristics of dynamic multi-dimensional tables can be used to dynamically display the scope of departments and forms based on the organizational hierarchy; during this period, users with different permissions can see different form data; users can also determine the relationship between permissions through operations such as dragging, checking, or range input, or when new needs arise, update permission rules in real time to facilitate flexible configuration of form display. Furthermore, users can also dynamically group based on different attribute types, such as organizational hierarchy, department type, and form classification, or use keyword retrieval to locate the target permission configuration location. This process can be configured using existing technology and will not be described in detail here.
[0066] On the whole, the multi-dimensional visual dynamic permission allocation method provided by this application can effectively realize the refined management of permissions. Taking the annual budget preparation as an example, the annual budget has more than 100 tables. If the report filling of each unit in the preparation process is completed by the financial department personnel, the task is arduous, time-consuming and labor-intensive. In actual work, it is necessary to split and allocate complex tasks to specific business departments, and everyone works together to fill in the reports. The specific configuration steps are that the system operation and maintenance personnel add the department main dimension to the annual budget task, include the annual budget task in the department preparation scope, and after release, the system automatically generates the organization, department, and user permission collection table ( Figure 5A and Figure 5B ), the customer will make more fine-grained authority divisions based on the management model and work arrangements of each unit, and in the final compilation process, the authority relationship maintained by the customer will be used to achieve refined authority management.
[0067] Therefore, through the form of tables, flexible allocation of permissions can be achieved. There is no need to allocate permissions one by one by user or role as in the past, which reduces the complexity of permission allocation and improves the refinement, flexibility, and real-time performance of management. Customized operation and maintenance of permissions is achieved through visualization, saving system operation and maintenance costs. The flexibility and real-time performance of operation and maintenance are improved. From top to bottom, each unit is different. With the help of multi-dimensional characteristics, the dynamic display of units, departments, and tables is achieved, eliminating unnecessary complex interference items and reducing the complexity of operation and maintenance. The permission system of the entire set of compilation tables is re-divided from the perspective of the department, and the department compilation collaboration and autonomy within each organization is achieved (they manage their own department distribution and department budget responsibilities, and department participants), realizing thousands of companies and thousands of situations.
[0068] Please refer to Figure 6As shown, the present application also provides a multi-dimensional visual dynamic permission allocation device, which includes: a rule configuration module, a multi-dimensional table generation module, a permission collection module and a permission execution module; the rule configuration module is used to configure department compilation rules based on the association relationship between institutions, departments and forms and the permission allocation logic; the multi-dimensional table generation module is used to dynamically display the permission association between institutions, departments, forms and users according to the department compilation rules to generate a dynamic multi-dimensional table; the permission collection module is used to collect permission data including the operation permissions of departments and forms and / or the affiliation between departments and users according to a specified collection table style; the permission execution module is used to dynamically filter the departments, forms and operation permissions visible to users according to the dynamic multi-dimensional table and the permission data during the execution of system functions.
[0069] In the above embodiment, the device further includes a task management module and a dynamic update module; the task management module is used to bind the authority allocation task to the business process, and the business process includes at least one of budget preparation, report filling, and approval process; the dynamic update module is used to synchronize in real time to the system function interface when the user authority or department compilation rules change. Specifically, in actual work, the task management module and the dynamic update module can provide a user management window to enable users to manage and update permissions and business processes in real time. Users can also split it into more and more detailed management windows according to actual needs. This application does not further limit this.
[0070] In another embodiment of the present application, the multidimensional table generation module includes a control unit, which is used to dynamically fold or expand the department and table list according to the organizational hierarchy, distinguish the read and write permission status of the table through color marking, and / or configure special permission scenarios using an integrated permission exception setting control. Furthermore, the permission execution module includes a query unit, a filtering unit, and a processing unit; the query unit is used to retrieve associated organizations and departments based on user identity; the filtering unit is used to generate an operable table range based on the association rules between departments and tables; and the processing unit is used to adjust the final permission result in combination with the permission exception setting. Since the principle of solving the problem of this device is similar to that of the multi-dimensional visual dynamic permission allocation method, the implementation of this device can refer to the implementation of the multi-dimensional visual dynamic permission allocation method, and the repeated parts will not be repeated.
[0071] The beneficial technical effects of this application are: based on a multi-dimensional visual dynamic authority allocation system, with the help of flexible and diverse display forms of multi-dimensional tables, in addition to meeting the basic flexible and dynamic authority allocation according to multiple dimensions of institutions, departments, and forms, it realizes the collaborative autonomy and thousands of companies and states of departments within each organization; because the overall interface is simple and easy to use, it can be directly handed over to customized operation and maintenance to reduce system maintenance costs, enhance seamless collaboration between departments and employees of system demanders, ensure real-time sharing and circulation of information, and improve operational efficiency.
[0072] The present application also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the above-mentioned method when executing the computer program.
[0073] The present application also provides a computer-readable storage medium, which stores a computer program for executing the above method.
[0074] The present application also provides a computer program product, comprising a computer program / instruction, which implements the steps of the above method when executed by a processor.
[0075] like Figure 7 As shown, the electronic device 600 may further include: a communication module 110, an input unit 120, an audio processor 130, a display 160, and a power supply 170. It is worth noting that the electronic device 600 does not necessarily have to include Figure 7 In addition, the electronic device 600 may also include all components shown in Figure 7 For components not shown, reference may be made to the prior art.
[0076] like Figure 7 As shown, the central processing unit 100 is sometimes also referred to as a controller or an operation control unit, and may include a microprocessor or other processor device and / or logic device. The central processing unit 100 receives inputs and controls the operations of various components of the electronic device 600 .
[0077] Memory 140 may be, for example, one or more of a cache, flash memory, hard drive, removable media, volatile memory, non-volatile memory, or other suitable devices. It may store the aforementioned failure-related information and may also store programs that execute the relevant information. The CPU 100 may execute the programs stored in memory 140 to implement information storage or processing.
[0078] The input unit 120 provides input to the CPU 100. The input unit 120 may be, for example, a keypad or touch input device. The power supply 170 is used to provide power to the electronic device 600. The display 160 is used to display objects such as images and text. The display may be, for example, an LCD display, but is not limited thereto.
[0079] The memory 140 may be a solid-state memory, such as a read-only memory (ROM), a random access memory (RAM), or a SIM card. Alternatively, it may be a memory that retains information even when power is off, can be selectively erased, and is provided with more data. Examples of such memory are sometimes referred to as EPROMs. The memory 140 may also be some other type of device. The memory 140 includes a buffer memory 141 (sometimes referred to as a buffer). The memory 140 may include an application / function storage unit 142 for storing application programs and function programs or processes for executing the operations of the electronic device 600 via the central processing unit 100.
[0080] The memory 140 may also include a data storage unit (data 143) for storing data, such as contacts, digital data, pictures, sounds, and / or any other data used by the electronic device. The driver storage unit (driver 144) of the memory 140 may include various driver programs for communication functions of the electronic device and / or for executing other functions of the electronic device (such as messaging applications, address book applications, etc.).
[0081] The communication module 110 is a transmitter / receiver 110 that transmits and receives signals via an antenna 111. The communication module (transmitter / receiver) 110 is coupled to the central processor 100 to provide input signals and receive output signals, which may be the same as in a conventional mobile communication terminal.
[0082] Based on different communication technologies, multiple communication modules 110 may be provided in the same electronic device, such as a cellular network module, a Bluetooth module, and / or a wireless local area network module. The communication module (transmitter / receiver) 110 is also coupled to a speaker 131 and a microphone 132 via an audio processor 130 to provide audio output via the speaker 131 and receive audio input from the microphone 132, thereby implementing common telecommunication functions. The audio processor 130 may include any suitable buffer, decoder, amplifier, etc. Furthermore, the audio processor 130 is also coupled to the central processing unit 100, enabling local recording via the microphone 132 and playback of stored audio via the speaker 131.
[0083] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0084] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0085] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0086] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps for the function specified in one or more boxes.
[0087] The specific embodiments described above further illustrate the purpose, technical solutions and beneficial effects of the present application. It should be understood that the above description is only a specific embodiment of the present application and is not intended to limit the scope of protection of the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should be included in the scope of protection of the present application.
Claims
1. A multi-dimensional visual dynamic authority allocation method, characterized in that: The method comprises: Configure department compilation rules based on the relationship between institutions, departments, and forms, as well as the authority allocation logic; Dynamically display the authority associations among institutions, departments, table templates and users according to the department compilation rules to generate dynamic multi-dimensional tables; Collect authority data including the operation authority of departments and tables and / or the affiliation between departments and users according to the specified collection table style; According to the dynamic multidimensional table and the permission data, the departments, table samples and operation permissions visible to the user are dynamically filtered during the execution of system functions.
2. The multi-dimensional visual dynamic permission allocation method according to claim 1 is characterized in that: The department compilation rules include one or more combinations of department view authority collection mode, table view authority collection mode and mixed view authority collection mode; Among them, the department view permission collection mode is used to limit the department's operating authority on the table sample; the table sample view permission collection mode is used to limit the department and user scope to which the table sample belongs; the mixed view permission collection mode is used to dynamically generate permission rules by combining the department view and the table sample view.
3. The multi-dimensional visual dynamic authority allocation method according to claim 1 is characterized in that: Generating a dynamic multidimensional table based on the department compilation rules to dynamically display the authority associations among institutions, departments, table templates, and users also includes: The dynamic multidimensional table is used to dynamically adjust the displayed departments and table sample ranges according to the organizational hierarchy, or to configure permission association relationships by dragging, checking, or range input, or to update permission rules in real time and synchronize them to one or more function combinations in the system function module.
4. The multi-dimensional visual dynamic authority allocation method according to claim 1 is characterized in that: The operation permissions include the superior unit viewing the data of the subordinate unit, the designated department leader viewing the data of all departments under the organization and / or the cross-organizational department viewing the data of the subordinate units within a specified range.
5. The multi-dimensional visual dynamic authority allocation method according to claim 1 is characterized in that: The method further comprises: Dynamically generate permission filtering chains based on the user's organization and department; The filtering chain includes: determining the visible department range according to the organization associated with the user, filtering the operable forms according to the association rules between departments and forms, and / or adjusting the read and write permissions of the final form according to permission exception settings.
6. The multi-dimensional visual dynamic authority allocation method according to claim 1 is characterized in that: The operation permissions include batch importing organization, department and user permission relationships through multi-dimensional tables; and generating permission rules based on preset templates and associating them with business processes.
7. The multi-dimensional visual dynamic authority allocation method according to claim 1 is characterized in that: Generating a dynamic multidimensional table based on the dynamic display of authority associations among institutions, departments, forms and users according to the department compilation rules also includes: dynamically grouping by institution level, department type and form classification through the multidimensional table; and quickly locating target authority configuration items through keyword retrieval.
8. A multi-dimensional visual dynamic authority allocation device, characterized in that: The device comprises: a rule configuration module, a multidimensional table generation module, a permission collection module and a permission execution module; The rule configuration module is used to configure department compilation rules based on the relationship between institutions, departments, and forms and the authority allocation logic; The multi-dimensional table generation module is used to generate a dynamic multi-dimensional table based on the department compilation rules to dynamically display the authority association between the organization, department, table sample and user; The authority collection module is used to collect authority data including the operation authority of the department and the form and / or the affiliation between the department and the user according to the specified collection form; The permission execution module is used to dynamically filter the departments, table samples and operation permissions visible to the user during the execution of system functions according to the dynamic multidimensional table and the permission data.
9. The multi-dimensional visual dynamic authority allocation device according to claim 8, characterized in that: The multidimensional table generation module includes a control unit, which is used to dynamically fold or expand the department and table list according to the organizational hierarchy, distinguish the read and write permission status of the table through color marking, and / or configure special permission scenarios using an integrated permission exception setting control.
10. The multi-dimensional visual dynamic authority allocation device according to claim 9, characterized in that: The permission execution module includes a query unit, a filtering unit and a processing unit; The query unit is used to retrieve the associated institutions and departments according to the user identity; The filtering unit is used to generate an operable table sample range based on the association rule between the department and the table sample; The processing unit is used to adjust the final permission result in combination with the permission exception setting.
11. The multi-dimensional visual dynamic authority allocation device according to claim 8, characterized in that: The device also includes a task management module and a dynamic update module; The task management module is used to bind the authority allocation task to the business process, and the business process includes at least one of budget preparation, report filling, and approval process; The dynamic update module is used to synchronize the system function interface in real time when user permissions or department compilation rules are changed.
12. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.
13. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.
14. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Authority visual configuration control method and device in an information system, terminal and storage medium
CN110443010A
Multi-dimensional data permission management system and method
CN110807201A
Multi-dimensionalauthority model design method for matrix management
CN112632492A
Data authority control system and method based on intelligent report platform
CN115270088A
Data authority management method, system and device based on organization and storage medium
CN119168501A