Multi-level authorization management system and method, electronic device and storage medium
The multi-level authorization management system solves the problems of high process error rate, chaotic document version and inconsistent access control in traditional bank authorization management. It realizes efficient collaborative management of processes and documents and clear traceability of approval trajectory, thereby improving the efficiency and security of bank compliance management.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA CONSTRUCTION BANK
- Filing Date
- 2026-01-08
- Publication Date
- 2026-06-05
AI Technical Summary
Traditional bank authorization management systems suffer from problems such as high error rates in process flow, chaotic document version management, inconsistent access control, and untraceable approval trajectories, resulting in low efficiency in compliance management.
A multi-level authorization management system is adopted, which drives process management, structured document parsing and management, dynamic permission control and process document association through predefined process node configuration, so as to realize bidirectional association between processes and documents and the generation of visual trajectories.
It improved the standardization and efficiency of process flow, ensured the structured nature of document management and the accuracy of access control, achieved clear traceability of approval trajectories, and enhanced the efficiency of bank compliance management and data security.
Smart Images

Figure CN122153856A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of data processing technology, and in particular to a multi-level authorization management system and method, electronic device and storage medium. Background Technology
[0002] The bank authorization management system is an important support for compliance management in the financial industry. Traditional authorization management relies on OA systems, manual approval and paper signing to cover the entire process of application, approval process, legal review and document archiving.
[0003] With the digital transformation of the banking industry, existing technologies mostly adopt decentralized process control and unstructured document management solutions, but they have obvious limitations: the lack of a standardized workflow engine and reliance on manual design of process logic lead to high error rates in node transitions and long development cycles; the lack of a unified standard for document parsing and unclear parsing rules make it difficult to effectively distinguish between tables and paragraphs in Word documents, resulting in chaotic version management and conflicts due to reliance on manual comparison; and the lack of a unified access control model with scattered verification logic, hard-coded visibility rules, and high error rates in access configuration. Summary of the Invention
[0004] This disclosure provides a multi-level authorization management system and method, electronic device, and storage medium. Its main objective is to at least partially address one of the technical problems in the related art.
[0005] According to a first aspect of this disclosure, a multi-level authorization management system is provided, comprising: The process management module is used to drive the authorization process to flow between different levels of organizations through predefined process node configurations; The document parsing and management module is used to parse the structured content of uploaded authorized documents and store and manage them by version. The access control module is used to dynamically control the query and operation permissions of authorized matters based on the user's organizational level and preset visibility rules; The process document association module is used to bidirectionally associate process approval events with document version changes and generate a visual approval trajectory.
[0006] According to a second aspect of this disclosure, a multi-level authorization management method is provided, comprising: Based on predefined process node configurations, the authorization process is driven to flow between different levels of organizations; Parse the structured content of the uploaded authorization document, and store and manage the parsed content in different versions; Based on the organizational level of the user and the preset visibility rules, dynamically control their query and operation permissions for authorized matters; Link process approval events with document version changes and generate a visual process approval trajectory.
[0007] According to a third aspect of this disclosure, an electronic device is provided, comprising: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method described in the second aspect above.
[0008] According to a fourth aspect of this disclosure, a non-transitory computer-readable storage medium is provided storing computer instructions, wherein the computer instructions are configured to cause the computer to perform the method described in the second aspect above.
[0009] According to a fifth aspect of this disclosure, a computer program product is provided, comprising a computer program that, when executed by a processor, implements the method described in the second aspect above.
[0010] The multi-level authorization management system and method, electronic devices, and storage media disclosed herein integrate predefined process node configuration-driven process management, structured parsing and version-based storage management of authorization documents, dynamic access control based on the user's organizational level and preset visibility rules, and bidirectional correlation and visual approval trajectory generation functions for process approval events and document version changes. Therefore, it can solve the problems in existing technologies caused by the lack of standardized workflow engines, the absence of unified standards for document parsing, inconsistent access control models, and the lack of effective correlation between processes and documents, such as high error rates in process flow, long development cycles, chaotic document versions, high error rates in access configuration, and untraceable approval trajectories. It achieves the technical effects of standardized and efficient process flow, structured and orderly document management, precise and compliant access control, and clear and traceable approval trajectories, thereby improving the efficiency of bank compliance management and data security.
[0011] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description
[0012] The accompanying drawings are provided to better understand this solution and do not constitute a limitation of this disclosure. Wherein: Figure 1 This is a schematic diagram of the structure of a multi-level authorization management system provided in an embodiment of the present disclosure; Figure 2This is a schematic diagram of another multi-level authorization management system provided in an embodiment of the present disclosure; Figure 3 A flowchart illustrating a multi-level authorization management method provided in this embodiment of the disclosure; Figure 4 A schematic block diagram of an example electronic device provided for embodiments of this disclosure. Detailed Implementation
[0013] The exemplary embodiments of this disclosure are described below with reference to the accompanying drawings, including various details of the embodiments to aid understanding, and should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this disclosure. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.
[0014] The following description, with reference to the accompanying drawings, describes a multi-level authorization management system and method, electronic device, and storage medium according to embodiments of the present disclosure.
[0015] Figure 1 This is a schematic diagram of the structure of a multi-level authorization management system provided in an embodiment of this disclosure.
[0016] like Figure 1 As shown, it includes: The process management module 11 is used to drive the authorization process to flow between different levels of organizations through predefined process node configurations.
[0017] In the embodiments of this disclosure, the process management module 11 aims to achieve standardized flow of authorization processes between multi-level institutions. Its core is to define the attributes, associated logic, and flow rules of each process node through predefined process node configurations. Based on this, the authorization process is driven to proceed in an orderly manner across different levels of institutions, ensuring consistency and controllability of process execution while also considering the flexibility to adapt to different business scenarios. As one implementation method, the process node configuration may include node definitions, sequence, flow conditions, and rollback rules. For example, it may preset nodes such as business department flow and multi-level approval, driving the process to flow according to rules between provincial branches, secondary branches, and grassroots outlets.
[0018] By driving the flow through standardized process node configuration, the drawbacks of traditional manual process logic design are avoided, the error rate of process flow is reduced, and the scalability and operational efficiency of the process are improved. It can efficiently adapt to the authorization business collaboration needs of multi-level institutions in the bank.
[0019] The document parsing and management module 12 is used to parse the structured content of uploaded authorized documents and store and manage them by version.
[0020] In the embodiments of this disclosure, the core of the document parsing and management module 12 lies in realizing the structured processing and full lifecycle version control of authorized documents. It identifies the structured content in uploaded authorized documents through specific parsing logic, clarifies the constituent units and relationships of the content, and establishes a standardized version management mechanism to differentiate, store, trace, and control different update states of the document, ensuring the integrity of the document content and the traceability of its versions. As one implementation method, parsing technology adapted to the document format can be used to extract structured information such as paragraphs and tables, and the document can be stored in different versions according to preset rules, supporting version query and management based on dimensions such as version number and time.
[0021] By using structured parsing and standardized version management, the problems of lack of unified standards and version chaos in traditional document parsing are solved, improving the accuracy and efficiency of document processing, ensuring clear traceability of authorized document versions, and adapting to the compliance requirements of document management in bank authorization business.
[0022] The access control module 13 is used to dynamically control the query and operation permissions of authorized matters based on the user's organizational level and preset visibility rules.
[0023] In the embodiments of this disclosure, the core of the access control module 13 lies in achieving precise and dynamic management of authorized matters. It first determines the user's organizational level, then combines this with preset visibility rules to construct a hierarchical, configurable access control logic. This logic dynamically allocates and verifies query and operation permissions for authorized matters in real time, ensuring that the granted permissions match the user's organizational level and business needs, balancing the rigor and flexibility of access control. As one implementation method, the visibility rules can include the definition of permission scope corresponding to different organizational levels. For example, based on the user's provincial branch, secondary branch, or grassroots branch level, preset rules dynamically open corresponding authorized matter query permissions and distinguish between editable and non-editable operation permissions.
[0024] By combining institutional hierarchy with visibility rules, dynamic access control solves the problems of inconsistent traditional access control models and high configuration error rates, improves the accuracy and compliance of access control, and effectively adapts to the access management needs of multi-level banking institutions.
[0025] The process document association module 14 is used to bidirectionally associate process approval events with document version changes and generate a visual approval trajectory.
[0026] In the embodiments of this disclosure, the core of the process document association module 14 lies in constructing a collaborative management and control mechanism for processes and documents. By establishing a unified association logic, it bidirectionally binds various approval events generated during the process approval process with version changes of authorized documents, enabling mutual traceability between approval actions and document version updates. Simultaneously, it generates an intuitive approval trajectory based on the associated data, clearly presenting the correspondence between process progress and document evolution. As one implementation method, a unique identifier (such as a process serial number or document version ID) can be used to establish the association mapping between the two. The visualized approval trajectory can include a sequential presentation of key information such as approval nodes, approval subjects, approval time, and corresponding document versions.
[0027] By establishing a two-way correlation between process approval events and document version changes, and generating a visual trajectory, the problem of disconnect between processes and documents and untraceable approval trajectories in the traditional model is solved. This enables collaborative traceability of processes and documents, and improves the auditability and compliance of authorized business.
[0028] The multi-level authorization management system disclosed herein integrates predefined process node configuration-driven process management, structured parsing and version-based storage management of authorization documents, dynamic access control based on the user's organizational level and preset visibility rules, and bidirectional correlation and visual approval trajectory generation functions for process approval events and document version changes. Therefore, it can solve the problems in existing technologies caused by the lack of standardized workflow engines, the absence of unified standards for document parsing, inconsistent access control models, and the lack of effective correlation between processes and documents, resulting in high error rates in process flow, long development cycles, chaotic document versions, high error rates in access configuration, and untraceable approval trajectories. It achieves the technical effects of standardized and efficient process flow, structured and orderly document management, precise and compliant access control, and clear and traceable approval trajectories, thereby improving the efficiency of bank compliance management and data security.
[0029] As a specific implementation of this disclosure, based on the basic solution, the process management module 11 is further defined to include: a workflow engine integration unit 111, used to integrate an external workflow engine into the system framework in the form of a service call; and a process definition and execution unit 112, used to start a process instance according to the process node configuration and drive the process task to flow between nodes.
[0030] Specifically, the workflow engine integration unit 111 (i.e., the functional unit used to interface external workflow engines with the system framework) pre-selects external workflow engines (such as Activiti, Flowable, etc.) that are adapted to the process characteristics of the financial industry. It establishes a communication link between the engine and the system framework through standardized API interfaces, and encapsulates the engine's process scheduling capabilities into system-callable service components using a service call model. This completes the registration, configuration, and permission verification of the engine services, ensuring compatibility and adaptation between the engine and the system framework. The process definition and execution unit 112 reads predefined process node configuration information (including node number, sequence, association, and flow rules), creates a process instance based on this configuration, assigns a unique process serial number, and drives the orderly flow of process tasks between nodes by calling the integrated workflow engine service and using parameters such as the next node number and fallback node number in the process node information table. Simultaneously, it synchronizes the process status to the process information table in real time, ensuring accurate recording and control of the process execution status.
[0031] By integrating mature external workflow engines through service call patterns, the complexity of self-developed process logic is avoided, and the efficiency and standardization of process development are improved. Process definition and execution units are based on configuration-driven flow, which ensures the consistency and controllability of process execution and effectively reduces the error rate of node flow.
[0032] As a specific implementation of this disclosure, based on the basic scheme, the document parsing and management module 12 is further defined as follows: a document structure parsing unit 121, used to identify paragraph and table structures in the document and extract their content and format information; and a version management unit 122, used to store the parsed document content according to its components and to maintain and retrieve historical versions based on version identifiers.
[0033] Specifically, the document structure parsing unit 121 (i.e., the functional unit for extracting structured information from the document) adopts parsing technologies such as Apache POI that are compatible with the .docx format. It uses the getParagraphs and getBodyElements methods of the XWPFDocument object to obtain the paragraph information and format of the uploaded authorized document, storing them in the corresponding collections. It iterates through the paragraph format collection; if a BodyElementType.TABLE format is identified, the corresponding paragraph index is recorded and marked as a table structure, then the table content and format parameters are extracted. For those not marked as tables, the paragraph text and format information such as font, color, and size are extracted, achieving accurate differentiation between paragraphs and table structures. The version management unit 122 associates each component of the parsed document (including paragraphs and tables) with version identifiers (such as version number, creation time, and modification time), storing them in the item version table and item version attachment table. It uses an incremental storage mode to save only the changed parts, while also establishing a version retrieval index to support querying historical versions based on dimensions such as version number and effective date, achieving full lifecycle maintenance of document versions.
[0034] By using specialized parsing technology to accurately identify document paragraph and table structures, the problem of difficulty in distinguishing structures in traditional parsing is solved; by storing documents by components and maintaining and retrieving them based on version identifiers, fine-grained management of document versions is achieved, reducing the risk of version conflicts and improving the efficiency of version tracing.
[0035] As a specific implementation of this disclosure, based on the basic scheme, the permission control module 13 is further defined to include: an organization level judgment unit 131, used to identify the coding level of the organization to which the user belongs; and a permission rule matching unit 132, used to dynamically generate data filtering conditions based on the organization code and a preset visibility flag field.
[0036] Specifically, the organization level judgment unit 131 (i.e. the functional unit used to identify the organization level to which the user belongs) receives the user number passed in from the front end, queries the user organization association data stored in the system, parses the coding structure of the organization to which the user belongs (such as the coding prefix length, level segment identifier, etc.), accurately determines whether the organization to which the user belongs is a provincial branch, a secondary branch, a grassroots branch or a headquarters department, and clarifies the organization coding rules and level attributes corresponding to each level. The permission rule matching unit 132 pre-reads the configuration information of fields such as the second-level row visibility flag (CST_VSBL_IND), county branch visibility flag (EBNKG_VBSBL_IND), and grassroots outlet visibility flag in the item version table. Based on the organization code level determined by the organization level judgment unit, it dynamically generates corresponding data filtering conditions. For example, for provincial-level users, it generates the filtering condition "organization number LIKE 'provincial-level code prefix%' and all level visibility flags are allowed", and for second-level users, it generates the filtering condition "organization number LIKE 'second-level row code prefix%' and second-level row and lower-level visibility flags are allowed", ensuring that data filtering accurately matches the user's organization level and visibility rules.
[0037] By accurately determining the hierarchy through parsing the organizational coding structure and dynamically generating filtering conditions by combining visible flag fields, data filtering is automated and precise. This avoids the rigidity of traditional hard-coded rules, reduces the error rate of permission configuration, and ensures that users at each level can only access data that meets their permissions.
[0038] As a specific implementation of this disclosure, based on the basic solution, the process document association module 14 is further defined as follows: a status driving unit 141, used to respond to process approval operations, update process status and drive the process to the next node; and a visualization generation unit 142, used to generate an approval trajectory view containing approval opinions and time based on process status and node information.
[0039] Specifically, the status-driven unit 141 (i.e., the functional unit used to respond to approval operations and drive process flow) receives approval data transmitted from the process approval interface in real time, including approval results, approval opinions, approver information, etc. Based on this data, it updates the process status (such as updating "pending" to "completed" or "returned"), approval time, and current node identifier in the process information table (SQXT_LC_INFO), and at the same time queries the next node number or rollback node number in the process node information table (SQXT_LC_NODE_INF). According to the approval result, it drives the process task to flow to the corresponding node and synchronously updates the process status identifier associated with the document version, ensuring real-time linkage between process status and document version changes. The visualization generation unit 142 reads data such as the approver's name, approval opinion, and approval time from the process information table, as well as the Chinese name and order of nodes from the process node information table. It then organizes the approval information in a chronological order according to the node sequence, and constructs a structured data set containing the node flow path, the approval subject of each node, the approval opinion, and the approval timestamp. Using view rendering technology, it transforms this set into an intuitive approval trajectory view, clearly presenting the complete flow of the process from initiation to the current node.
[0040] By using state-driven mechanisms, real-time synchronization of process and document states is achieved, ensuring the accuracy of their correlation. The visual view intuitively presents key approval information and workflow trajectory, solving the problem of difficulty in tracing traditional approval trajectories and improving the auditability and process transparency of authorization processes.
[0041] As a specific implementation of this disclosure, in addition to the basic solution, it further includes: a template filling module 15, which is used to dynamically fill business data into a specified position of a structured document template to generate the final authorization document.
[0042] Specifically, the template filling module 15 (the functional unit used to dynamically generate the final authorization document) pre-stores structured authorization (sub-authorization) templates. The templates include fillable fields related to the authorization matters (such as authorized person information, authorization level, authorization time, etc.) set at designated locations according to business logic, and bind corresponding business data field identifiers to each fillable field. This module extracts business data such as the matter number, authorized person's name, authorization time, level 5 to 10 matters, and department name by associating with the authorization matter table (SQXT_SX). It accurately matches the extracted business data with the field identifiers of the fillable fields in the template, automatically filling the corresponding business data into the designated locations in the template. Simultaneously, it renders the filled content according to the template's preset font, color, size, bold / italic formatting requirements, ultimately generating a structured authorization document that conforms to business specifications, and supports viewing and downloading the document.
[0043] By precisely binding structured templates with business data, dynamic filling is achieved, avoiding the tediousness and errors of manual entry and greatly improving the efficiency of generating authorization documents. Standardized templates and automatic format rendering ensure the standardization and uniformity of authorization documents, adapting to the compliance management needs of bank authorization business.
[0044] As a specific implementation of this disclosure, based on the basic scheme, the permission control module 13 further includes: an editing permission verification unit 133, which is used to verify whether the user has the permission to modify the content based on the organizational level and the visibility flag field when the user initiates an editing operation.
[0045] Specifically, the editing permission verification unit 133 (i.e., the functional unit used to verify user editing permissions) listens in real time for authorized item editing requests initiated by users, receives the user ID, the item ID to be edited, and the operation type information carried in the request, obtains the user's organization level by calling the judgment result of the organization level judgment unit 131, and simultaneously queries the authorized item table (SQXT_SX) for the corresponding allowed modification flag (PRMT_MOD_ACCND_IND) and the item version table (SQXT_VERSION_INF) for the visibility flag field. The verification logic is executed according to preset rules: if the user's organization is a provincial branch or at the same level as the secondary branch to which the item belongs, and the allowed modification flag is "modifiable" and the corresponding visibility flag is allowed, then the user is deemed to have editing permissions; if the user's organization is a third-level or lower-level branch, or the allowed modification flag is "unmodifiable", then the user is deemed not to have editing permissions. After successful verification, an instruction to allow editing is returned to the system; if the verification fails, a permission insufficient feedback message is generated and the editing operation is blocked, while a permission verification log is recorded.
[0046] Targeted permission verification is performed when a user initiates an editing operation, enabling real-time control of editing permissions. This avoids data chaos caused by unauthorized modifications, further improves the granularity of permission control, and ensures the integrity and security of authorized data.
[0047] Figure 3 This is a schematic diagram of a multi-level authorization management method provided in this embodiment.
[0048] like Figure 3 As shown, the method includes the following steps: Step 201: Based on the predefined process node configuration, drive the authorization process to flow between different levels of organizations.
[0049] Step 202: Parse the structured content of the uploaded authorization document, and store and manage the parsed content in different versions.
[0050] Step 203: Based on the organizational level to which the user belongs and the preset visibility rules, dynamically control their query and operation permissions for authorized matters.
[0051] Step 204: Associate the process approval event with the document version change and generate a visual process approval trajectory.
[0052] Specifically, in steps 201-204, step 201 is executed. Based on the predefined process node configuration (including node number, sequence, flow rules, rollback nodes, etc.), a process instance is started and a unique process serial number is assigned. The integrated workflow engine calls the process service, queries the next node or rollback node according to the process node information table, and drives the authorized process to flow orderly among preset nodes (such as business department flow, multi-level approval, etc.) at various levels of institutions such as provincial branches, secondary branches, and grassroots branches. At the same time, the process status and node identifier in the process information table are updated in real time. Next, step 202 is executed. The uploaded .docx format authorization document is parsed using Apache POI technology. The content and format information of paragraphs and tables are extracted through XWPFDocument objects. Version numbers, creation times, and other identifiers are associated with document components and stored in the item version table and item version attachment table. An incremental storage mode is used to maintain historical versions, and retrieval based on version number or effective date is supported. Then, step 203 is executed. By parsing the organization code structure corresponding to the user's operation number, the user's level is determined. Combined with the visibility flag field in the item version table, data filtering conditions (such as organization number prefix matching rules) are dynamically generated to precisely control the user's query scope for authorized items. At the same time, the operation permission is verified by linking the modification permission flag. Finally, step 204 is executed. By establishing the association between process approval events (including approval results, opinions, and time) and document version changes through the process serial number and document version ID, key data from the process information table and node information table are read, and after being organized chronologically according to the node order, a visual approval trajectory containing the approval subject, opinions, and timestamps is generated through view rendering technology.
[0053] By implementing standardized workflows, structured document parsing and version management, precise access control, and a coherent process of visual trajectory generation, the entire authorization process has been standardized and automated, significantly reducing human error rates and process redundancy, and improving business processing efficiency and compliance traceability.
[0054] It should be noted that the embodiments of this disclosure may include multiple steps. For ease of description, these steps are numbered, but these numbers are not a limitation on the execution time slots or execution order between the steps; these steps can be implemented in any order, and the embodiments of this disclosure do not limit this.
[0055] According to embodiments of this disclosure, this disclosure also provides an electronic device, a readable storage medium, and a computer program product.
[0056] Figure 4 A schematic block diagram of an example electronic device 300 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0057] like Figure 4 As shown, the electronic device 300 includes a computing unit 301, which can perform various appropriate actions and processes based on a computer program stored in ROM (Read-Only Memory) 302 or a computer program loaded from storage unit 308 into RAM (Random Access Memory) 303. The RAM 303 may also store various programs and data required for the operation of the electronic device 300. The computing unit 301, ROM 302, and RAM 303 are interconnected via a bus 304. An I / O (Input / Output) interface 305 is also connected to the bus 304.
[0058] Multiple components in electronic device 300 are connected to I / O interface 305, including: input unit 306, such as keyboard, mouse, etc.; output unit 307, such as various types of displays, speakers, etc.; storage unit 308, such as disk, optical disk, etc.; and communication unit 309, such as network card, modem, wireless transceiver, etc. Communication unit 309 allows electronic device 300 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0059] The computing unit 301 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 301 include, but are not limited to, CPUs (Central Processing Units), GPUs (Graphics Processing Units), various special-purpose AI (Artificial Intelligence) computing chips, various computing units running machine learning model algorithms, DSPs (Digital Signal Processors), and any suitable processor, controller, microcontroller, etc. The computing unit 301 performs the various methods and processes described above, such as multi-level authorization management methods. For example, in some embodiments, the multi-level authorization management method may be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 308. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 300 via ROM 302 and / or communication unit 309. When the computer program is loaded into RAM 303 and executed by the computing unit 301, one or more steps of the methods described above may be performed. Alternatively, in other embodiments, the computing unit 301 may be configured to perform the aforementioned multi-level authorization management method by any other suitable means (e.g., by means of firmware).
[0060] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, FPGAs (Field Programmable Gate Arrays), ASICs (Application-Specific Integrated Circuits), ASSPs (Application-Specific Standard Products), SOCs (System-on-Chips), CPLDs (Complex Programmable Logic Devices), computer hardware, firmware, software, and / or combinations thereof. These various implementations may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0061] The program code used to implement the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0062] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, RAM, ROM, EPROM (Electrically Programmable Read-Only Memory) or flash memory, optical fiber, CD-ROM (Compact Disc Read-Only Memory), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0063] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (Cathode-Ray Tube) or LCD (Liquid Crystal Display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0064] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include LANs (Local Area Networks), WANs (Wide Area Networks), the Internet, and blockchain networks.
[0065] Computer systems can include clients and servers. Clients and servers are generally geographically separated and typically interact via communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. A server can be a cloud server, also known as a cloud computing server or cloud host, a hosting product within the cloud computing service system that addresses the shortcomings of traditional physical hosts and VPS (Virtual Private Server) services, such as high management difficulty and weak business scalability. Servers can also be servers for distributed systems or servers incorporating blockchain technology.
[0066] It's important to note that artificial intelligence (AI) is the study of enabling computers to simulate certain human thought processes and intelligent behaviors (such as learning, reasoning, thinking, and planning). It encompasses both hardware and software technologies. AI hardware technologies generally include sensors, dedicated AI chips, cloud computing, distributed storage, and big data processing. AI software technologies primarily include computer vision, speech recognition, natural language processing, machine learning / deep learning, big data processing, and knowledge graph technologies.
[0067] The various numerical designations such as "first," "second," etc., used in this disclosure are merely for ease of description and are not intended to limit the scope of the embodiments of this disclosure, nor do they indicate a sequential order.
[0068] At least one of the features described in this disclosure can also be described as one or more, and multiple features can be two, three, four or more, and this disclosure does not impose any limitations. In the embodiments of this disclosure, for a technical feature, the technical features in that technical feature are distinguished by "first", "second", "third", "A", "B", "C" and "D", etc., and there is no sequential order or size order among the technical features described by "first", "second", "third", "A", "B", "C" and "D".
[0069] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this disclosure can be achieved, and this is not limited herein.
[0070] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.
Claims
1. A multi-level authorization management system, characterized in that, include: The process management module is used to drive the authorization process to flow between different levels of organizations through predefined process node configurations; The document parsing and management module is used to parse the structured content of uploaded authorized documents and store and manage them by version. The access control module is used to dynamically control the query and operation permissions of authorized matters based on the user's organizational level and preset visibility rules; The process document association module is used to bidirectionally associate process approval events with document version changes and generate a visual approval trajectory.
2. The system according to claim 1, characterized in that, The process management module includes: Workflow Engine Integration Unit, used to integrate external workflow engines into the system framework via service calls; The process definition and execution unit is used to start process instances according to the process node configuration and drive process tasks to flow between nodes.
3. The system according to claim 1, characterized in that, The document parsing and management module includes: The document structure parsing unit is used to identify paragraph and table structures in a document and extract their content and formatting information; The version management unit is used to store the parsed document content according to its components and to maintain and retrieve historical versions based on version identifiers.
4. The system according to claim 1, characterized in that, The access control module includes: The organization level determination unit is used to identify the coding level of the user's organization; The permission rule matching unit is used to dynamically generate data filtering conditions based on the organization code and the preset visibility flag field.
5. The system according to claim 1, characterized in that, The process document association module includes: The state-driven unit is used to respond to process approval operations, update the process status, and drive the process to the next node. The visualization generation unit is used to generate an approval trajectory view that includes approval comments and time based on the process status and node information.
6. The system according to any one of claims 1 to 5, characterized in that, Also includes: The template filling module is used to dynamically fill business data into specified locations in a structured document template to generate the final authorization document.
7. The system according to claim 4, characterized in that, The access control module also includes: The edit permission verification unit is used to verify whether a user has the right to modify an edit when the user initiates an edit operation, based on the user's organizational level and the visibility flag field.
8. A multi-level authorization management method, characterized in that, include: Based on predefined process node configurations, the authorization process is driven to flow between different levels of organizations; Parse the structured content of the uploaded authorization document, and store and manage the parsed content in different versions; Based on the organizational level of the user and the preset visibility rules, dynamically control their query and operation permissions for authorized matters; Link process approval events with document version changes and generate a visual process approval trajectory.
9. An electronic device, characterized in that, include: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method of claim 8.
10. A non-transitory computer-readable storage medium storing computer instructions, characterized in that, The computer instructions are used to cause the computer to perform the method according to claim 8.