Data display method and device based on organization authority and electronic equipment

By constructing an organizational permission model and field-level visibility policies, parsing user access requests, determining the effective permission set, and rendering expense documents, the problem of field/attachment-level control in enterprise expense control systems is solved, achieving fine-grained visibility control of sensitive information and improving data security.

CN121935936APending Publication Date: 2026-04-28BEIJING HESI HUIZHI INFORMATION TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING HESI HUIZHI INFORMATION TECHNOLOGY CO LTD
Filing Date
2026-01-15
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

Existing enterprise expense control and reimbursement systems struggle to achieve field/attachment level visibility control, resulting in poor data consistency, high maintenance costs, significant information leakage risks, and a lack of policy versioning and audit evidence chains.

Method used

The data display method based on organizational permissions constructs an organizational permission model and field-level visibility strategy, parses user access requests, determines the set of valid permissions, and renders expense documents based on visibility decisions. This achieves fine-grained visibility control of fields and attachments, including data filtering, de-identification, and secondary validation.

Benefits of technology

It achieves minimal visibility display of sensitive fields and attachments, reducing the risk of data leakage, minimizing data consistency discrepancies and maintenance costs, and supporting dynamic policy rendering and audit traceability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121935936A_ABST
    Figure CN121935936A_ABST
Patent Text Reader

Abstract

The invention provides a data display method and device based on organization permission and electronic equipment, and the method comprises the steps: obtaining an access request of a user for a fee receipt, and analyzing the access request based on a pre-constructed organization permission model to obtain an effective permission set of the user for the fee receipt; based on a pre-constructed field-level visibility strategy and the effective permission set, determining a visibility decision of the user on the field and / or the attachment of the expense document; and rendering the cost document based on the visibility decision, and displaying the rendered cost document to the user. According to the invention, fine-grained visibility control of sensitive fields and attachments in enterprise expense receipts can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data processing technology, and in particular to a data display method, apparatus, and electronic device based on organizational permissions. Background Technology

[0002] In corporate expense control and reimbursement systems, documents contain a large amount of sensitive information, such as specific amounts, supplier information, tax identification numbers, bank account numbers, and attachments such as contracts, acceptance documents, and travel itineraries. Actual business collaboration involves multiple roles, departments, projects, approval levels, and external collaborators. Different roles require different levels of information granularity. For example, a supervisor needs to review compliance but may not need to know the supplier's tax identification number; a project manager needs to focus on budgets and project attribution but does not need to see employees' private documents; and external collaborators should only see the necessary fields. However, most existing corporate expense control and reimbursement systems use document-level or page-level permissions, making it difficult to achieve field / attachment-level control. Summary of the Invention

[0003] In view of this, the purpose of the present invention is to provide a data display method, device and electronic device based on organizational permissions, which can realize fine-grained visibility control over sensitive fields and attachments in enterprise expense documents.

[0004] To achieve the above objectives, the technical solution adopted by the present invention is as follows: In a first aspect, the present invention provides a data display method based on organizational permissions, comprising: obtaining a user's access request for an expense document, and parsing the access request based on a pre-built organizational permission model to obtain a set of valid permissions for the user on the expense document; determining the user's visibility decision for fields and / or attachments of the expense document based on a pre-built field-level visibility strategy and the set of valid permissions; rendering the expense document based on the visibility decision, and displaying the rendered expense document to the user.

[0005] Optionally, before obtaining user access requests for expense documents, the process may include: standardizing the data structure of the expense documents, breaking them down into multiple fields and / or attachments, and determining the sensitivity level of each field and / or attachment; constructing an organizational permission model based on the enterprise's organizational structure, job levels, department affiliation, project affiliation, approval chain, data domain, external entities, and sensitivity levels; wherein, the organizational permission model includes each user's access permissions to expense documents and fields and / or attachments; access permissions are determined by user relationships, which include at least: organizational relationships, business relationships, and process relationships.

[0006] Optionally, the access request is parsed based on a pre-built organizational permission model to obtain a set of valid permissions for the user on the expense document. This includes: parsing the access request based on the pre-built organizational permission model to determine the ternary relationship between the access subject, the expense document, and the fields and / or attachments; determining the user's access permissions to the fields and / or attachments of the expense document based on the ternary relationship, and generating a set of valid permissions; wherein the set of valid permissions includes the fields and / or attachments that the user has access to.

[0007] Optionally, based on a pre-built field-level visibility policy and a set of valid permissions, the visibility decision of a user on fields and / or attachments of a expense document is determined, including: based on a pre-built field-level visibility policy, determining the visibility policy of fields and / or attachments that the user has access to; and adjusting the visibility policy of fields and / or attachments that the user has access to based on a preset policy priority, to obtain the visibility decision of fields and / or attachments that the user has access to.

[0008] Optionally, based on visibility decisions, the expense document is rendered and displayed to the user. This includes: for fields, based on visibility decisions, filtering and de-identifying the response data corresponding to fields that the user has access to, rendering the processed response data, and displaying the rendered expense document to the user; for attachments, based on visibility decisions, sending the target URL and access token of the attachment to the user, and verifying the user's access permissions based on the access token when the user downloads the attachment; wherein, the target URL and access token are valid for a first preset time period.

[0009] Optionally, it also includes: obtaining user access fee invoice behavior records and generating audit logs based on the behavior records; wherein, the audit logs include at least: access subject, fee invoice ID, field and / or attachment list, field-level visibility policy version, data anonymization method, client information, timestamp, and access IP.

[0010] Optionally, it also includes: obtaining a user's application for temporary access to the target field, and granting the user access to the target field for a second preset time after the application for temporary access is approved.

[0011] Secondly, the present invention provides a data display device based on organizational permissions, comprising: a permission parsing module, used to obtain a user's access request for an expense document, and parse the access request based on a pre-built organizational permission model to obtain a set of valid permissions for the user on the expense document; a visibility decision module, used to determine the visibility decision of the user's fields and / or attachments on the expense document based on a pre-built field-level visibility strategy and the set of valid permissions; and a rendering module, used to render the expense document based on the visibility decision and display the rendered expense document to the user.

[0012] Thirdly, the present invention provides an electronic device including a processor and a memory, the memory storing computer-executable instructions executable by the processor, the processor executing the computer-executable instructions to implement the steps of the method provided in any of the first aspects above.

[0013] Fourthly, the present invention provides a computer-readable storage medium storing a computer program, wherein the computer program, when executed by a processor, performs the steps of the method provided in any of the first aspects above.

[0014] This invention brings the following beneficial effects: The data display method, apparatus, and electronic device based on organizational permissions provided by this invention first obtain a user's access request for an expense document, and then parse the access request based on a pre-built organizational permission model to obtain the user's valid permission set for the expense document. Next, based on a pre-built field-level visibility strategy and the valid permission set, the visibility decision for the user's fields and / or attachments on the expense document is determined. Finally, based on the visibility decision, the expense document is rendered and displayed to the user. In this method, upon receiving a user's access request, the access request is parsed according to the pre-built organizational permission model to determine the user's valid permission set for the expense document (i.e., the fields / attachments the user has access to). Then, based on the pre-built field-level visibility strategy, the fields / attachments visible to the user are determined and rendered for display to the user. This ensures that sensitive fields in the expense document are displayed with minimal visibility to the user, avoiding unnecessary information exposure and reducing the risk of data leakage. Furthermore, based on the field-level visibility strategy, dynamic rendering enables differentiated display of expense documents, reducing problems such as poor data consistency caused by document splitting / copying.

[0015] Other features and advantages of the invention will be set forth in the description which follows, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention are realized and obtained in accordance with the structures particularly pointed out in the description, claims and drawings.

[0016] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description

[0017] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0018] Figure 1 A flowchart illustrating a data display method based on organizational permissions provided in an embodiment of the present invention; Figure 2 An example diagram illustrating a field-level visibility strategy provided in an embodiment of the present invention; Figure 3 Example diagram of another field-level visibility strategy provided in the embodiments of the present invention; Figure 4 A flowchart illustrating the visibility and anonymization of expense receipts provided in this embodiment of the invention; Figure 5 This is a schematic diagram of the structure of a data display device based on organizational permissions provided in an embodiment of the present invention; Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation

[0019] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0020] Currently, most existing enterprise expense control and reimbursement systems use document-level or page-level permissions, making it difficult to achieve field / attachment-level control. Common problems include: (1) The discrepancy display is achieved by copying documents and splitting documents, which leads to poor data consistency and high maintenance costs; (2) Front-end desensitization or hidden fields are easily intercepted by the interface and the plaintext is obtained; (3) Once the attachment link is leaked, it can be downloaded immediately, lacking secondary verification and watermark; (4) Lack of strategy versioning and audit evidence chain makes it impossible to trace who has viewed which sensitive fields.

[0021] Based on this, the present invention provides a data display method, device and electronic device based on organizational permissions, which can realize fine-grained visibility control over sensitive fields and attachments in enterprise expense documents.

[0022] To facilitate understanding of this embodiment, a data display method based on organizational permissions disclosed in this invention will first be described in detail. This method is applied to enterprise expense control, reimbursement, procurement, corporate payments, electronic archives, and other systems, and can be executed by electronic devices such as smartphones, computers, and tablets. See also Figure 1 The flowchart shown illustrates a data display method based on organizational permissions, indicating that the method mainly includes the following steps S101 to S103: Step S101: Obtain the user's access request for the expense document, and parse the access request based on the pre-built organizational permission model to obtain the user's valid permission set for the expense document.

[0023] In one implementation, when a user (employee, direct supervisor, project manager, finance, audit, procurement, legal, or external collaborator) accesses expense documents, the system, upon receiving the user's request, can parse the access request, determine the access subject and the expense document being accessed, and determine the user's access permissions to the expense document and its fields and / or attachments based on a pre-built organizational permission model, thereby obtaining the user's valid permission set for the expense document.

[0024] Step S102: Based on the pre-built field-level visibility policy and effective permission set, determine the user's visibility decision on fields and / or attachments of the expense document.

[0025] In one implementation, the field-level visibility policy includes at least: visible / invisible, read-only / editable, display method (plaintext / masked / range / summary), exportable / non-exportable, downloadable / non-downloadable, and whether decryption is allowed. Based on this, in this embodiment of the invention, after determining the user's valid permission set for the expense document, the field-level visibility policy engine can determine the user's field-level visibility policy for each field and / or attachment according to a predefined field-level visibility policy, thus obtaining the visibility decision for each field and / or attachment.

[0026] Step S103: Based on visibility decisions, render the expense document and display the rendered expense document to the user.

[0027] In one implementation, the response data is rendered and displayed to the user based on a visibility decision for each field and / or attachment.

[0028] The data display method based on organizational permissions provided in this embodiment of the invention can parse the access request according to a pre-built organizational permission model after receiving a user's access request, determine the user's valid permission set for expense documents (i.e., fields / attachments that the user has access to), and then determine the fields / attachments that the user can see according to a pre-built field-level visibility strategy. After rendering these fields / attachments, the method displays them to the user. This ensures that sensitive fields in expense documents are displayed with minimal visibility to the user, avoiding unnecessary information exposure and reducing the risk of data leakage. At the same time, based on the field-level visibility strategy, dynamic strategy rendering can achieve differentiated display of expense documents, reducing problems such as poor data consistency caused by document splitting / copying.

[0029] In one implementation, before obtaining the user's access request for the expense document, the method further includes: First, the expense documents are standardized by breaking them down into multiple fields and / or attachments, and the sensitivity level of each field and / or attachment is determined.

[0030] In practical implementation, the system standardizes the data structure of expense documents (including but not limited to: reimbursement / payment / purchase orders / invoices / contracts, etc.), breaking them down into main table fields, detail row fields, related entity fields (supplier / payee / invoice issuer), voucher fields (invoice tax number, account number), and attachment resources (images / files). Each field and attachment is labeled with a sensitivity level and category. For example: Amount: Commercially sensitive; Supplier Name: Commercially sensitive; Tax Number / Account Number: Individual / Legal Person Sensitive; Attachment: Highly Sensitive. Further classification is required based on type: L0 for public, L1 for internal, L2 for commercially sensitive, L3 for privacy / legal person sensitive, and L4 for highly sensitive (account number / contract / signature / ID card, etc.). Simultaneously, the system maintains field lineage, recording the field's origin (manual entry / synchronization / recognition / OCR) and change history.

[0031] Then, an organizational permission model is built based on the enterprise's organizational structure, job levels, department affiliation, project affiliation, approval process, data domain, external entities, and sensitivity levels.

[0032] In practice, the organizational permission model includes each user's access permissions to expense documents and fields and / or attachments; access permissions are determined by user relationships, which include at least: organizational relationships, business relationships, and process relationships.

[0033] Specifically, the system constructs an organizational permission model based on organizational structure, job level, department affiliation, project affiliation, approval chain, data domain (company / business unit / cost center / project), and external entities (supplier liaison / outsourcing), clarifying the access permissions of each user role to expense documents and their fields and / or attachments. In this embodiment of the invention, user access permissions can be determined by the superposition of multiple relationships, including: organizational relationships such as: same department, superior chain, cross-departmental collaboration; business relationships such as: project affiliation, cost center affiliation, budget responsible person; process relationships such as: approval node, countersigning / copying, audit spot checks; and privilege relationships such as: statutory or authorized access by finance / audit / legal departments. For example, assuming user role A belongs to finance and is in the approval node, then user role A's access permissions are the union of finance's access permissions and the approval node's access permissions.

[0034] In one implementation, for the aforementioned step S101, i.e., when parsing the access request based on the pre-built organizational permission model to obtain the user's valid permission set for the expense document, the following methods may be adopted, including but not limited to: First, parse the access request based on the pre-built organizational permission model to determine the ternary relationship between the access subject, the expense document, and the fields and / or attachments; then, based on the ternary relationship, determine the user's access permissions to the fields and / or attachments of the expense document, and generate a valid permission set; wherein, the valid permission set includes the fields and / or attachments that the user has access to.

[0035] In practical implementation, after receiving a user's access request, the system parses the access subject and the accessed expense list according to the access request, and loads the accessed expense list and the sensitivity levels of each field and / or attachment in the expense list; then, based on the pre-built organizational permission model, it determines the relationship of the access subject and the access permissions to the expense document, and further determines the access permissions to each field and / or attachment in the expense document, that is, it determines the ternary relationship of the access subject, expense document, and fields and / or attachments; finally, it generates the user's valid permission set for the fields and / or attachments of the expense document.

[0036] In one implementation, for the aforementioned step S102, i.e., when determining the user's visibility decision on fields and / or attachments of expense documents based on a pre-built field-level visibility policy and a set of valid permissions, the following methods may be adopted, including but not limited to: First, based on the pre-built field-level visibility policy, determine the visibility policy for fields and / or attachments that the user has access to; then, based on a preset policy priority, adjust the visibility policy for fields and / or attachments that the user has access to, to obtain the visibility decision for fields and / or attachments that the user has access to.

[0037] In practical implementation, the system expresses permission rules as field-level visibility policies, including: visible / invisible, read-only / editable, display method (plaintext / masked / range / summary), exportable / non-exportable, downloadable / non-downloadable, and whether decryption is allowed. Field-level visibility policies support inheritance and overriding, for example: see [link to documentation]. Figure 2 As shown, for the `amount` field, by default, employees can see all fields of their expense documents, but their supervisors can only see the amount range and supplier alias. Tax ID and attachments require secondary authorization. Finance can see the tax ID, but attachments must meet conditions such as "Audit Task ID" or "Approved." See also... Figure 3 As shown, for the taxId field, employees / supervisors are shown with a visible mask. Finance personnel can see the plaintext tax ID, while external personnel cannot.

[0038] Furthermore, the policy engine supports prioritization and conflict resolution. After determining the visibility policies for fields and / or attachments that a user has access to, if there are conflicting visibility decisions for the same user role regarding a certain field or attachment, the rejected policy takes precedence, the least visible policy takes precedence, or the policy priority is adjusted according to preset policy priorities. The final output is the visibility decision for each field / attachment. These visibility decisions include: field / attachment visibility, data anonymization methods, attachment export / download control methods, and conflict resolution methods.

[0039] In one implementation, for the aforementioned step S103, i.e., when rendering the expense document based on visibility decisions and displaying the rendered expense document to the user, the following methods may be used, including but not limited to: (1) For fields, based on visibility decisions, the response data corresponding to fields that the user has access to is filtered and desensitized, and the processed response data is rendered and the rendered expense document is displayed to the user.

[0040] In practice, the system performs field-level filtering and anonymized rendering of the response data for each field based on the visibility decision of the output, including but not limited to the following operations: Filtering: Fields are not returned or placeholders are returned; Mask: such as the first and last 4 digits of the tax ID number; Range-based display: Amounts are displayed as ranges (e.g., 1k-2k) or levels (low / medium / high). Coded representation: Suppliers are displayed as aliases / codes; Summary: For non-authorized roles, only summary rows are displayed for detail rows.

[0041] It should be noted that, in this embodiment of the invention, rendering is performed on the server side, thereby ensuring that unauthorized data does not leave the database or is distributed, and preventing data leakage.

[0042] (2) For attachments, based on visibility decisions, the target URL and access token of the attachment are sent to the user, and the user's access rights are verified based on the access token when the user downloads the attachment.

[0043] In practical implementation, the download of attachment resources is controlled using an access token + short-term URL + secondary verification method. Specifically, for access to attachments, a short-term access token (token, bound to viewerId / docId / attId / policy version / validity period) is generated, and a target URL is provided to the user (the target URL and access token are valid for a first preset time period). Simultaneously, a secondary verification is performed when the user downloads the attachment, verifying whether the token matches the current ctx. In this embodiment of the invention, highly sensitive attachments can be watermarked (name / employee ID / time / document number) and dynamically masked according to role (e.g., obscuring account names and signatures).

[0044] In one implementation, the method further includes: obtaining user access fee invoice behavior records and generating audit logs based on the behavior records; wherein the audit logs include at least: access subject, fee invoice ID, field and / or attachment list, field-level visibility policy version, data anonymization method, client information, timestamp, and access IP.

[0045] In practical implementation, the system can record every user's viewing behavior and generate audit logs, including: access subject, document ID, field / attachment list, policy version, anonymization method, client information, timestamp, access IP, and detection signals during export / download / screenshot (if any). For temporary decryption or unauthorized access requests, the system records the approval form / work order associated ID and decryption token usage, and retains evidence packages before and after the access, supporting post-event auditing and accountability. The evidence package includes: a summary of the policy calculation results, a comparison of fields before and after anonymization (visible only to the audit system), authorization links, and token usage links.

[0046] In one embodiment, the method further includes: obtaining a user's application for temporary access to the target field, and granting the user access to the target field for a second preset time after the application for temporary access is approved.

[0047] In practical implementation, when business needs require temporarily granting access to a certain field (e.g., audit sampling requires viewing all attachments), the system provides an exception authorization process, including: application - approval - authorization period - expiration and revocation, and can generate a minimum permission suggestion. Users can apply for temporary access to a target field and, upon approval, obtain access to that target field. This access is valid for a second preset period, after which the user's access to that field will be retrieved. Simultaneously, the system can track field access frequency and abnormal access (e.g., a large number of views of highly sensitive fields in a short period) during the access process, triggering risk control alarms for continuous governance.

[0048] For ease of understanding, this embodiment of the invention also provides a flowchart of the visibility and de-identification display of expense documents, see [link / reference]. Figure 4 As shown, the process first obtains the user's viewing request, including the access subject (viewer) and the accessed expense document ID (docId). Then, it loads the expense document data and sensitive tags, and parses the viewing request context, including the access subject's organization, project, and process relationships. Next, it calculates the visibility decisions for fields / attachments based on the strategy engine. For fields, it resolves conflicts in the visibility decisions: prioritizing DENY or minimizing visibility, and then renders the data on the server side, including filtering, masking, range parsing, aliasing, and summarizing, finally returning the view model. For attachments, it uses short-term tokens and secondary verification control, allowing for watermarking and dynamic masking during viewing and downloading. Furthermore, it audits and tracks every user viewing action, recording field / attachment exposure and strategy version.

[0049] The method provided in this invention, centered on an organizational permission model, a field-level policy engine, dynamic desensitization rendering, and audit traceability, enables differentiated display and access control of the same document at the field, attachment, and row levels without copying data or splitting documents. It also provides traceable logging for any viewing, decryption, exporting, or downloading behavior, thereby improving compliance issues related to displaying different sensitive fields across different roles. Specifically, sensitive fields are minimized based on role visibility, avoiding unnecessary information exposure and reducing the risk of data leakage; dynamic policy rendering achieves differentiated display, reducing the problems of poor data consistency and high maintenance costs caused by document splitting / copying; desensitization and field filtering are performed on the server side, combined with short-term attachment tokens and secondary verification, avoiding plaintext leakage caused by front-end hiding; the exposure range of fields / attachments and policy versions are both logged, enabling identification of who viewed which information and when, meeting audit and internal control requirements; and through access statistics and abnormal access detection, policies are continuously optimized, forming a closed loop of permission governance.

[0050] In addition to the data display method based on organizational permissions provided in the foregoing embodiments, this invention also provides a data display device based on organizational permissions, see [link to previous embodiment]. Figure 5 The diagram shown illustrates the structure of a data display device based on organizational permissions, indicating that the device mainly comprises the following parts: The permission parsing module 501 is used to obtain the user's access request for the expense document and parse the access request based on the pre-built organizational permission model to obtain the user's valid permission set for the expense document.

[0051] The visibility decision module 502 is used to determine the user's visibility decision on fields and / or attachments of expense documents based on a pre-built field-level visibility policy and a set of valid permissions.

[0052] The rendering module 503 is used to render expense documents based on visibility decisions and display the rendered expense documents to the user.

[0053] The data display device based on organizational permissions provided in this embodiment of the invention can parse the access request according to a pre-built organizational permission model after receiving a user's access request, determine the user's valid permission set for expense documents (i.e., fields / attachments that the user has access to), and then determine the fields / attachments that the user can see according to a pre-built field-level visibility strategy. After rendering these fields / attachments, the device is displayed to the user. This ensures that sensitive fields in expense documents are displayed with minimal visibility to the user, avoiding unnecessary information exposure and reducing the risk of data leakage. At the same time, based on the field-level visibility strategy, dynamic strategy rendering can achieve differentiated display of expense documents, reducing problems such as poor data consistency caused by document splitting / copying.

[0054] In one embodiment, the above-mentioned apparatus further includes: a model building module, used to perform data structure standardization processing on expense documents, decompose the expense documents into multiple fields and / or attachments, and determine the sensitivity level of each field and / or attachment; and to build an organizational permission model based on the enterprise's organizational structure, job level, department affiliation, project affiliation, approval chain, data domain, external subjects, and sensitivity level; wherein, the organizational permission model includes each user's access permissions to expense documents and fields and / or attachments; the access permissions are determined by the user relationships, which include at least: organizational relationships, business relationships, and process relationships.

[0055] In one implementation, the permission parsing module 501 is specifically used to: parse the access request based on a pre-built organizational permission model to determine the ternary relationship between the access subject, the expense document, and the fields and / or attachments; based on the ternary relationship, determine the user's access permissions to the fields and / or attachments of the expense document, and generate a valid permission set; wherein the valid permission set includes the fields and / or attachments that the user has access to.

[0056] In one implementation, the visibility decision module 502 is configured to: determine the visibility policy of fields and / or attachments that the user has access to based on a pre-built field-level visibility policy; and adjust the visibility policy of fields and / or attachments that the user has access to based on a preset policy priority, thereby obtaining a visibility decision for fields and / or attachments that the user has access to.

[0057] In one implementation, the rendering module 503 is specifically used to: for fields, based on visibility decisions, filter and de-identify the response data corresponding to fields that the user has access to, and render the processed response data to display the rendered bill to the user; for attachments, based on visibility decisions, send the target URL and access token of the attachment to the user, and verify the user's access rights based on the access token when the user downloads the attachment; wherein the target URL and access token are valid for a first preset time period.

[0058] In one embodiment, the above-mentioned apparatus further includes: an audit module, used to obtain user access fee invoice behavior records and generate audit logs based on the behavior records; wherein the audit logs include at least: access subject, fee invoice ID, field and / or attachment list, field-level visibility policy version, data anonymization method, client information, timestamp, and access IP.

[0059] In one embodiment, the above-mentioned device further includes: a temporary permission granting module, used to obtain a user's application for temporary permission granting of a target field, and after the application for temporary permission granting of a target field is approved, granting the user access to the target field for a second preset time.

[0060] It should be noted that the device provided in this embodiment of the invention has the same implementation principle and technical effects as the aforementioned method embodiment. For the sake of brevity, any parts not mentioned in the device embodiment can be referred to the corresponding content in the aforementioned method embodiment. The specific numerical values ​​provided in this embodiment are merely exemplary and are not intended to limit the scope of the invention.

[0061] This invention also provides an electronic device, specifically, the electronic device includes a processor and a storage device; the storage device stores a computer program, and the computer program, when run by the processor, executes the method described in any of the above embodiments.

[0062] Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. The electronic device 100 includes: a processor 60, a memory 61, a bus 62, and a communication interface 63. The processor 60, the communication interface 63, and the memory 61 are connected through the bus 62. The processor 60 is used to execute executable modules, such as computer programs, stored in the memory 61.

[0063] The memory 61 may include high-speed random access memory (RAM) or non-volatile memory, such as at least one disk storage device. Communication between this system network element and at least one other network element is achieved through at least one communication interface 63 (which can be wired or wireless), such as the Internet, wide area network, local area network, metropolitan area network, etc.

[0064] Bus 62 can be an ISA bus, PCI bus, or EISA bus, etc. The bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 6 The symbol is represented by a single double-headed arrow, but this does not mean that there is only one bus or one type of bus.

[0065] The memory 61 is used to store programs. After receiving an execution instruction, the processor 60 executes the program. The method executed by the device for defining the flow process disclosed in any of the foregoing embodiments of the present invention can be applied to the processor 60 or implemented by the processor 60.

[0066] Processor 60 may be an integrated circuit chip with signal processing capabilities. In implementation, each step of the above method can be completed by the integrated logic circuitry in the hardware of processor 60 or by instructions in software form. Processor 60 can be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it can also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this invention. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this invention can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules can reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. The storage medium is located in memory 61. Processor 60 reads the information in memory 61 and, in conjunction with its hardware, completes the steps of the above method.

[0067] The computer program product of the readable storage medium provided in the embodiments of the present invention includes a computer-readable storage medium storing program code. The instructions included in the program code can be used to execute the methods described in the foregoing method embodiments. For specific implementation, please refer to the foregoing method embodiments, which will not be repeated here.

[0068] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, essentially, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0069] Finally, it should be noted that the above-described embodiments are merely specific implementations of the present invention, used to illustrate the technical solutions of the present invention, and not to limit it. The scope of protection of the present invention is not limited thereto. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that any person skilled in the art can still modify or easily conceive of changes to the technical solutions described in the foregoing embodiments within the technical scope disclosed in the present invention, or make equivalent substitutions for some of the technical features; and these modifications, changes, or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be covered within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A data display method based on organizational permissions, characterized in that, include: Obtain the user's access request for the expense document, and parse the access request based on the pre-built organizational permission model to obtain the user's valid permission set for the expense document; Based on the pre-built field-level visibility policy and the set of valid permissions, the visibility decision of the user to the fields and / or attachments of the expense document is determined. Based on the visibility decision, the expense document is rendered and displayed to the user.

2. The method according to claim 1, characterized in that, Before obtaining the user's access request for the expense document, the following steps are also included: The expense document is subjected to data structure standardization processing, which decomposes the expense document into multiple fields and / or attachments, and determines the sensitivity level of each field and / or attachment; An organizational permission model is constructed based on the enterprise's organizational structure, job levels, department affiliation, project affiliation, approval chain, data domain, external entities, and the aforementioned sensitivity level. This organizational permission model includes each user's access permissions to expense documents and the aforementioned fields and / or attachments. These access permissions are determined by the relationships between the users, which at least include: organizational relationships, business relationships, and process relationships.

3. The method according to claim 1, characterized in that, The access request is parsed based on a pre-built organizational permission model to obtain the user's valid permission set for the expense document, including: The access request is parsed based on a pre-built organizational permission model to determine the ternary relationship between the access subject, the expense document, and the fields and / or attachments. Based on the ternary relationship, the user's access permissions to the fields and / or attachments of the expense document are determined, and a valid permission set is generated; wherein, the valid permission set includes the fields and / or attachments that the user has access to.

4. The method according to claim 3, characterized in that, Based on a pre-built field-level visibility policy and the set of valid permissions, the visibility decision for the user's fields and / or attachments on the expense document is determined, including: Based on a pre-built field-level visibility policy, determine the visibility policy for fields and / or attachments that the user has access to; Based on preset policy priorities, the visibility policy of fields and / or attachments that the user has access to is adjusted to obtain the visibility decision of fields and / or attachments that the user has access to.

5. The method according to claim 1, characterized in that, Based on the visibility decision, the expense document is rendered, and the rendered expense document is displayed to the user, including: For the field, based on the visibility decision, the response data corresponding to the field that the user has access to is filtered and de-identified, and the processed response data is rendered to display the rendered bill to the user. For the attachment, based on the visibility decision, the target URL and access token of the attachment are sent to the user, and when the user downloads the attachment, the user's access rights are verified based on the access token; wherein, the target URL and the access token are valid for a first preset time period.

6. The method according to claim 1, characterized in that, Also includes: Obtain the user's access behavior records for the expense document, and generate an audit log based on the behavior records; wherein, the audit log includes at least: access subject, expense document ID, field and / or attachment list, field-level visibility policy version, data anonymization method, client information, timestamp, and access IP.

7. The method according to claim 1, characterized in that, Also includes: Obtain the user's temporary permission request for the target field, and after the temporary permission request is approved, grant the user access to the target field for a second preset time.

8. A data display device based on organizational permissions, characterized in that, include: The permission parsing module is used to obtain the user's access request for the expense document, and parse the access request based on the pre-built organizational permission model to obtain the user's valid permission set for the expense document. The visibility decision module is used to determine the user's visibility decision on fields and / or attachments of the expense document based on a pre-built field-level visibility policy and the set of valid permissions. The rendering module is used to render the expense document based on the visibility decision and display the rendered expense document to the user.

9. An electronic device, characterized in that, The method includes a processor and a memory, the memory storing computer-executable instructions executable by the processor, the processor executing the computer-executable instructions to implement the steps of the method according to any one of claims 1 to 7.

10. A computer-readable storage medium storing a computer program thereon, characterized in that, The computer program is executed by the processor to perform the steps of the method described in any one of claims 1 to 7.