A dynamic permission management method, device and storage medium
By intercepting user account change processes, retrieving business data and management entity sets, identifying inheriting users and updating permissions, the problem of low efficiency in organizational tree permission management is solved, dynamic permission management is realized, complex cross-domain management scenarios are supported, and the continuity and efficiency of business management are improved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- GUANGDONG KETYOO INTELLIGENT TECH CO LTD
- Filing Date
- 2026-04-10
- Publication Date
- 2026-07-21
AI Technical Summary
In existing technologies, permission management systems based on organizational trees require deep recursive traversal of the entire organizational tree when personnel relationships change. This results in high computational complexity, low efficiency in permission management, and hinders the smooth handover of business resources when users leave or change positions, thus affecting business management.
By intercepting user account change processes, retrieving business data and management entity sets, identifying inheriting users, and updating permissions through business management entity set transfer methods, the strong binding between users and the organizational tree is removed, thus achieving dynamic permission management.
It eliminates the need for deep recursive traversal of the entire organizational tree, improving the efficiency of access control, ensuring business continuity, supporting complex cross-domain management scenarios, and reducing management costs and system performance consumption.
Smart Images

Figure CN122433100A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular to a dynamic permission management method, device and storage medium. Background Technology
[0002] In business channel management, companies need to maintain both the internal administrative organizational hierarchy and the external channel network of distributors and stores, which often leads to situations such as one person holding multiple positions, cross-regional management, store transfers, and handover upon resignation.
[0003] Most business management channel management systems based on related technologies use a single organizational tree for permission management, attaching users to the organizational tree to achieve a strong binding between users and the organizational tree. When personnel relationships change (such as employee transfers or departures), the permission management system based on the organizational tree needs to perform a deep recursive traversal of the entire organizational tree to recalculate the boundaries of business management channel permissions. The computational complexity increases exponentially, resulting in low permission management efficiency. Summary of the Invention
[0004] This application provides a dynamic permission management method, device, and storage medium to solve the technical problem in related technologies where permission management systems based on organizational trees require deep recursive traversal of the entire organizational tree to recalculate the permission boundaries of business management channels, resulting in exponentially increasing computational complexity and low permission management efficiency. This method eliminates the need for deep recursive traversal of the entire organizational tree, effectively improving permission management efficiency.
[0005] In a first aspect, embodiments of this application provide a dynamic permission management method, including: If an account change for the first user is detected, the account change process for the first user will be intercepted. Retrieve the first user's first business data and the first business management entity set, wherein the first business management entity set is used to record the first user's first business management channel scope; the first user's functional permissions for the first business management channel they are responsible for are determined based on the assigned role and / or position. Determine the successor user, and update the successor user's second business data and second business management entity set based on the first business data and the first business management entity set; the second business management entity set is used to record the successor user's second business management channel scope, and the successor user's functional permissions for the second business management channel they are responsible for are determined based on the assigned role and / or position.
[0006] In a second aspect, embodiments of this application provide a dynamic permission management device, including a change interception module, a data retrieval module, and an inheritance processing module, wherein: The change interception module is used to intercept the account change process of the first user when an account change of the first user is detected. The data retrieval module is used to retrieve the first user's first business data and the first business management entity set, wherein the first business management entity set is used to record the first user's first business management channel scope; the first user's functional permissions for the first business management channel they are responsible for are determined based on the assigned role and / or position. The inheritance processing module is used to determine the inheriting user, and update the second business data and the second business management entity set of the inheriting user according to the first business data and the first business management entity set; the second business management entity set is used to record the scope of the second business management channel of the inheriting user, and the functional permissions of the inheriting user to the second business management channel he / she is responsible for are determined based on the assigned role and / or position.
[0007] In a third aspect, embodiments of this application provide a dynamic access control device, including: a memory and one or more processors; The memory is used to store one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the dynamic permission management method as described in the first aspect.
[0008] In a fourth aspect, embodiments of this application provide a storage medium for storing computer-executable instructions, which, when executed by a computer processor, are used to perform the dynamic permission management method as described in the first aspect.
[0009] This application embodiment intercepts the account change process of a first user upon detecting an account change, retrieves the first user's first business data and first business management entity set, wherein the first business management entity set records the first user's first business management channel scope, and the first user's functional permissions for the first business management channel are determined based on the assigned role and / or position. A successor user is determined, and the successor user's second business data and second business management entity set are updated according to the first business data and first business management entity set. The second business management entity set records the successor user's second business management channel scope, and the successor user's functional permissions for the second business management channel are determined based on the assigned role and / or position. By decoupling the business management channel from the organizational tree, the business management channel and user are no longer strongly bound to the organizational tree. When a user account change occurs, a deep recursive traversal of the entire organizational tree is not required; dynamic updates of business management channel permissions can be achieved through the transfer of the business management entity set, effectively improving the efficiency of permission management. Attached Figure Description
[0010] Figure 1 This is a flowchart of a dynamic permission management method provided in an embodiment of this application; Figure 2 This is a schematic diagram of a tissue tree structure provided in an embodiment of this application; Figure 3 This is a flowchart of another dynamic permission management method provided in the embodiments of this application; Figure 4 This is a schematic diagram of the structure of a dynamic permission management device provided in an embodiment of this application; Figure 5 This is a schematic diagram of the structure of a dynamic permission management device provided in an embodiment of this application. Detailed Implementation
[0011] To make the objectives, technical solutions, and advantages of this application clearer, specific embodiments of this application will be described in further detail below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are merely for explaining this application and not for limiting it. It should also be noted that, for ease of description, only the parts relevant to this application are shown in the drawings, not all of them. Before discussing exemplary embodiments in more detail, it should be mentioned that some exemplary embodiments are described as processes or methods depicted as flowcharts. Although the flowcharts describe operations (or steps) as sequential processes, many of these operations can be performed in parallel, concurrently, or simultaneously. Furthermore, the order of the operations can be rearranged. The process can be terminated when its operation is completed, but additional steps not included in the drawings may also be present. The above processes can correspond to methods, functions, procedures, subroutines, subroutines, etc.
[0012] The dynamic permission management method provided in this application can be applied to comprehensive digital marketing management platforms for the broader retail sector (including but not limited to mini-programs, store workbenches, channel management platforms, and operational decision-making platforms), cross-channel / cross-organizational customer relationship management systems for medium and large enterprises, and franchised or directly operated store network systems requiring frequent personnel deployment. In related business management channel (e.g., sales channel) permission management solutions, the organizational structure based on an organizational tree is strongly bound to the business management channel, resulting in a lack of flexibility in permission management. A single administrative organizational tree cannot support complex scenarios such as cross-regional management (e.g., different managers simultaneously responsible for business management channels in different regions) or temporary management (e.g., someone else temporarily managing a business management channel due to staff departures or changes). For example, if a regional director needs to temporarily manage a distributor in another province, adding a virtual node or migrating the affiliation in the organizational tree would disrupt the company's administrative structure, leading to extremely high management costs. Furthermore, when management relationships change (such as employee reassignment or large-scale management scope adjustments), traditional business management channel permission management requires deep recursive traversal of the entire organizational tree branch or the whole organizational tree to recalculate permission boundaries. This results in exponentially increasing computational complexity, severely consuming system performance and even causing query blocking. Moreover, when an employee's departure status is detected or an account is manually deleted / disabled by an administrator, the employee's affiliation node in the organizational tree is typically severed. The business resources (e.g., customer resources), unassigned business records (e.g., sales records), and unclosed task instructions bound to that employee become ownerless, leading to errors in upstream indicator statistical reports and broken performance allocation, severely impacting business management. Based on this, this application provides a dynamic permission management method to solve the above-mentioned technical problems.
[0013] Figure 1 A flowchart of a dynamic permission management method provided in an embodiment of this application is given. The dynamic permission management method provided in this embodiment of the application can be executed by a dynamic permission management device, which can be implemented by hardware and / or software and integrated into a dynamic permission management device (e.g., a server).
[0014] The following description uses a dynamic permission management device to implement a dynamic permission management method as an example. (Reference) Figure 1 This dynamic permission management method includes: S110: If an account change is detected for the first user, the account change process for the first user is intercepted.
[0015] In one embodiment, user accounts of multiple pre-recorded users are monitored. Different users correspond to different business data and business management entity sets. The system determines whether any users have experienced account changes. This application identifies users among the pre-recorded users whose account changes occurred due to resignation or handover requiring the transfer of customer channels with other users. Users who inherit the business data and business management entity set of the first user are identified as inheriting users. These users can be staff members of the internal management system or personnel from external channels (e.g., distributors, store managers, and sales staff from external channels).
[0016] The business management entity set (including a first business management entity set and a second business management entity set) provided in this application is used to record the scope of a user's business management channels, that is, the scope of the business management channels that the user is responsible for. The business management entity set can be recorded through business management channel identifiers. A business management channel can be one or more combinations of business area (e.g., distributor area), business store (e.g., distributor store), distributor, store manager, and store employee. Correspondingly, the business management channel identifier can be one or more combinations of business area number (e.g., distributor number), business store number (e.g., distributor store number), distributor number, store manager number, and store employee number, where the number can be the corresponding ID information. For example, for regional manager A, who is responsible for store A, store B, and distributor C, and whose corresponding business management channel identifiers are A1, B2, and C3 respectively, then his corresponding business management entity set can be represented as: [A1, B2, C3].
[0017] The business data provided in this application (including first business data and second business data) are business assets owned by the user. Optionally, the business data can be one or more combinations of the user's pending settlement performance, customer resources to be followed up, and unfinished business tasks (such as marketing tasks). Pending settlement performance can be understood as performance data generated by the user but not yet financially settled, such as unrealized earnings like commissions and bonuses corresponding to achieved sales performance. Customer resources to be followed up can be understood as customer information that the user is responsible for maintaining but has not yet completed conversion or service loop, including key business relationships such as potential customers and interested customers. Unfinished business tasks can be understood as marketing activities or tasks that the user is currently executing but have not yet completed, such as unfinished promotional activities, marketing tasks, and customer maintenance tasks. In one embodiment, the business data and business management entity set can be stored in a preset storage location (such as a preset database).
[0018] The account changes provided in this application can be due to the departure of the first user or the need for the first user to adjust their business responsibilities (e.g., transferring all or part of the business management channels they are responsible for). In one embodiment, when the management platform performs an account change for the first user (e.g., when an administrator performs an account change operation for the first user due to the departure of the first user or a business change, in which case the management platform will issue a departure signal or perform a cancellation action), an account change process for the first user is initiated. This account change process will perform account change operations for the first user, such as deleting or updating the first user's first business data and the first business management entity set.
[0019] For example, when an account change for the first user is detected, the account change process for the first user is intercepted, freezing the account change process for the first user and activating the account change confirmation workflow for the first user. Under the account change confirmation workflow, the business data and business management entity set are transferred from the first user to the successor user.
[0020] S120: Retrieve the first user's first business data and the first business management entity set.
[0021] For example, the first user's first business data and the first business management entity set are retrieved from a preset storage location. The first business management entity set is used to record the first user's first business management channel range, and the first business management channel range recorded in the first business management entity set can be used to reflect the range of data that the first user can manage (e.g., which business management channels, distributors, stores, etc., data can be managed).
[0022] The functional permissions of the first user to the first business management channel under their responsibility provided in this application can be determined based on the assigned role and / or position. The functional permissions of the first user to the first business management channel under their responsibility can be understood as the permissions to perform specific operations or access specific functional modules.
[0023] S130: Determine the inheriting user, and update the second business data and second business management entity set of the inheriting user based on the first business data and the first business management entity set.
[0024] For example, a successor user is determined to take over the first user's first business data and first business management entity set. There can be one or more successor users. The successor user can be designated by the first user's superior (e.g., a supervisor), designated by the first user, or designated according to a preset successor user determination strategy. After determining the successor user, the successor user's second business data and second business management entity set can be updated based on the first business data and first business management entity set. The second business management entity set records the successor user's second business management channel scope, which reflects the scope of data the successor user can manage (e.g., which business management channels, distributors, stores, etc., data they can manage).
[0025] The functional permissions of the successor user for the second business management channel they are responsible for, as provided in this application, can be determined based on the assigned role and / or position. These permissions can be understood as the ability to perform specific operations or access specific functional modules. After the first business data and the first business management entity set are transferred to the successor user, they are added to the successor user's second business data and second business management entity set. At this point, the scope of business data and business management channels managed by the successor user increases. Even if an account change operation is performed on the first user, the first user's first business data and first business management entity set are no longer in an ownerless state. Deleting the first user from the organizational tree will not affect the continuation of related businesses. The successor user can take over the first user's first business data and first business management entity set, effectively ensuring business continuity.
[0026] In one embodiment, different roles and / or positions can be pre-configured with different functional permissions. For example, after creating a login account for a user (including the first user and successor users), the user's login account and related basic information (such as name, department, etc.) can be encapsulated into an independent digital identity. Roles and / or positions can be assigned to the user, and a business management entity set can be created for the user based on their data permissions and business affiliation. For example, assigning a regional manager position to a user grants them the functional operation permissions corresponding to that position, such as viewing regional sales data and managing subordinate stores. Based on the user's business management entity set and the assigned role and / or position, the scope of data the user can manage can be determined, as well as the operations that can be performed on that scope based on the management method of the manageable data. This application achieves functional permission allocation by assigning roles and / or positions, which decouples the user's affiliation from the administrative organization (organizational tree), facilitating flexible adjustment of the permission scope according to business needs. Optionally, the assignment of a user's role and / or position can be triggered by the first user or the user's superior user.
[0027] In one embodiment, such as Figure 2 As shown in the provided organizational tree structure diagram, this application can divide the organizational tree into an internal organizational tree and an external channel tree. Optionally, different internal organizational nodes in the internal organizational tree can be mapped to digital identities corresponding to different internal personnel, realizing the association between different internal organizational nodes and different users. Similarly, different external channel organizations in the external channel tree can be mapped to digital identities corresponding to different external channels, realizing the association between different external channel nodes and different users. Specifically, different internal organizational nodes in the internal organizational tree can be mapped to one or more external channel nodes in the external channel tree based on the business management entity set corresponding to the digital identity. In this case, the user corresponding to the internal organizational node in the internal organizational tree has the permission to access the relevant data of the external channel node and its subordinate nodes recorded in the business management entity set. Furthermore, different external channel nodes in the external channel tree can also be mapped to one or more other external channel nodes in the external channel tree based on the business management entity set corresponding to the digital identity. In this case, the user corresponding to the external channel node in the external channel tree has the permission to access the relevant data of the external channel node and its subordinate nodes recorded in the business management entity set.
[0028] Figure 2 The diagram illustrates an internal organizational branch in an internal organizational tree and an external channel branch in an external channel tree. Within the internal organizational branch, the internal organizational nodes, from top to bottom, are associated with the group headquarters, offline sales centers, sales directors, sales regions, senior regional managers, regional managers, and channel sales / retail business positions. Similarly, within the external channel branch, the external channel nodes, from top to bottom, are associated with the sales regions, regions, distributor organizations, stores, store managers, and store staff. The business management entity set of the sales region in the internal organizational tree records the sales region identifier of the sales region in the external channel tree, meaning the sales region in the internal organizational tree has access to the relevant data of the sales region and its subordinate nodes in the external channel tree. Likewise, the business management entity set of the regional manager in the internal organizational tree records the distributor organization identifier of the distributor organization in the external channel tree, meaning the regional manager in the internal organizational tree has access to the relevant data of the distributor organization and its subordinate nodes in the external channel tree. Compared to the single data structure in related technologies that directly attaches users to static organizational tree nodes, this application establishes a multi-dimensional, interwoven, and separate data structure consisting of digital identity, role definition, functional positions, and business management entity sets. This decouples the administrative affiliation of personnel from the sales channels they are responsible for, enabling cross-level concurrent management data affiliation mapping to be directly associated through a flattened business management entity set without moving the administrative nodes of the organizational tree. Furthermore, it allows for the addition or deletion of the concurrent management scope of different personnel at any time without changing the organizational tree structure.
[0029] In one possible embodiment, the dynamic permission management method provided in this application, after updating the second business data and second business management entity set of the inherited user based on the first business data and the first business management entity set, can also remove the interception of the account change process to perform account change operations on the first user through the account change process. Specifically, performing account change operations on the first user can be deleting part or all of the transferred first business data and first business management entity set of the first user in a preset storage location, removing the first user from the organizational tree, or canceling the first user's account. A pre-emptive account change process interception is set up above the underlying account cancellation interface. When an employee account change signal is captured, a full asset scan for confirmation of rights and targeted transfer and merger are triggered to ensure the continuity of indicators and performance.
[0030] The above describes a method that intercepts the account change process of a first user upon detecting such an account change. It retrieves the first user's first business data and first business management entity set. The first business management entity set records the first user's first business management channel scope. The first user's functional permissions for the first business management channel are determined based on assigned roles and / or positions. The method then identifies the successor user and updates the successor user's second business data and second business management entity set based on the first business data and first business management entity set. The second business management entity set records the successor user's second business management channel scope. The successor user's functional permissions for the second business management channel are determined based on assigned roles and / or positions. By decoupling business management channels from the organizational tree, business management channels and users are no longer strongly bound to the organizational tree. When a user account change occurs, a deep recursive traversal of the entire organizational tree is unnecessary. Dynamic updates of business management channel permissions can be achieved through the transfer of business management entity sets, effectively improving permission management efficiency.
[0031] Based on the above embodiments, Figure 3 A flowchart of another dynamic permission management method provided in an embodiment of this application is given, which is a concretization of the above-described dynamic permission management method. (Reference) Figure 3 This dynamic permission management method includes: S210: If an account change is detected for the first user, the account change process for the first user is intercepted.
[0032] S220: Retrieve the first user's first business data and the first business management entity set.
[0033] S230: Obtain the load bandwidth information and service area affiliation of multiple candidate users, and determine the successor user from multiple candidate users based on the load bandwidth information and service area affiliation.
[0034] For example, after intercepting the account change process of the first user, an inheritance designation request is sent to the preset management user, requesting the preset management user to designate an inheritor user for the first user based on the inheritance designation request, and determining the inheritor user designated by the preset management user based on the inheritance designation request.
[0035] In one embodiment, upon receiving an inheritance designation request, a pre-defined management user can select one or more users from a pool of users as successor users and send the designated successor users to the dynamic access control device. The pre-defined management user can be the parent user of the first user or a pre-set system loss prevention administrator. For example, a pop-up window and to-do information can be pushed to the parent user or the designated system loss prevention administrator, requesting the pre-defined management user to designate one or more successor users. This application ensures smooth operation of the business by sending an inheritance designation request to the pre-defined management user, allowing the pre-defined management user to determine the appropriate successor users.
[0036] In one possible embodiment, after intercepting the account change process of the first user, load bandwidth information and business region affiliation of multiple candidate users can be obtained. Based on the first user's first business data, first business management entity set, load bandwidth information, and business region affiliation, one or more candidate users whose load bandwidth information and business region affiliation better match the first business data and first business management entity set to be transferred can be identified as candidate successor users. The load bandwidth information can be used to reflect the candidate user's current business volume and the total business volume it can handle. The business region affiliation can be used to reflect the candidate user's region or area affiliation. The business region affiliation can be determined based on the candidate user's pre-set region affiliation information or based on the region affiliation corresponding to each business management channel in the candidate user's business management entity set. For example, if the current business volume plus the allocated first business data does not exceed the total business volume it can handle, and the business region affiliation matches the region or area affiliation corresponding to the first business management entity set, the corresponding candidate user can be identified as a candidate successor user. In one embodiment, the load bandwidth information and business region affiliation provided in this application can be one or more combinations of the corresponding user's current store size, daily activity level, and historical conversion metrics.
[0037] Optionally, the first service data, the first service management entity set, load bandwidth information, and service area affiliation can be sent to the trained candidate successor user determination model. The candidate successor user determination model analyzes and processes the first service data, the first service management entity set, load bandwidth information, and service area affiliation to obtain one or more candidate users as candidate successor users.
[0038] In one embodiment, after determining one or more candidate successor users, a succession designation request can be sent to a preset management user based on the one or more candidate successor users. The preset management user can designate one or more candidate successor users as successor users from among the one or more candidate successor users indicated in the succession designation request. In another embodiment, after receiving a succession designation request based on one or more candidate successor users, the preset management user can determine the successor user from among the one or more candidate successor users indicated in the succession designation request, or it can determine the successor user from among users other than the candidate successor users. This application determines candidate successor users from multiple candidate users based on load bandwidth information and service area affiliation. The preset management user can designate the successor user based on the candidate successor users. This improves the efficiency of successor user determination while balancing the service volume of the successor user and the affiliation scope of the inherited service, thus determining the successor user more rationally.
[0039] S240: Update the second business data and the second business management entity set of the inheriting user based on the first business data and the first business management entity set.
[0040] In one possible embodiment, the dynamic permission management method provided in this application, updating the second business data and the second business entity set of the inheriting user based on the first business data and the first business management entity set, may include: S241: Determine the completed first business data and the first business data in progress from the first business data.
[0041] S242: Perform inheritance annotation processing on the completed first business data, and add the ongoing first business data to the second business data of the inheriting user.
[0042] S243: Based on the difference set algorithm, update the second business management entity set of the inheriting user according to the first business management entity set.
[0043] For example, completed first business data and ongoing first business data are determined in the first user's first business data. Completed first business data can be statistical reports and performance data that have occurred and are frozen, while ongoing first business data can be tasks in progress, responsible customer data, etc. Further, the determined completed first business data undergoes inheritance labeling (e.g., adding a label "First user has been inherited by successor user" to the first business data), locking the completed first business data based on the principle of historical invariance, thus implementing snapshot naming processing for the completed first business data. The determined ongoing first business data is added to the successor user's second business data, and the first business management entity set is added to the successor user's second business management entity set. The successor user can execute unfinished tasks of the first user based on the transferred first business data, take over customer data previously managed by the first user, and manage external channels previously managed by the first user based on the transferred first business management entity set. Further, based on a difference set algorithm, the successor user's second business management entity set is updated according to the first business management entity set. Among them, the difference set algorithm can update the second business management entity set based on the differences generated by the second business management entity set of the inheriting user after the first business management entity set is transferred to the inheriting user.
[0044] This application achieves more refined inheritance processing of the first business data and the first business management entity set by performing inheritance annotation processing on the completed first business data, adding the ongoing first business data to the second business data of the inheriting user, and updating the second business management entity set of the inheriting user according to the first business management entity set based on the difference set algorithm. This accurately preserves and transfers the first business data and the first business management entity set, thereby improving the quality of dynamic permission management.
[0045] In one possible embodiment, the dynamic permission management method provided in this application is based on a difference set algorithm, which updates the second business management entity set of the inheriting user according to the first business management entity set. This may include: determining difference data for the first entity set based on the difference set algorithm; updating the permission mapping table of the business management channel according to the difference data of the first entity set, wherein the permission mapping table records the mapping relationship from the business management channel to the responsible user; and generating a first access control list for the inheriting user based on the updated permission mapping table when responding to a first data request for the inheriting user, thereby generating the updated second business management entity set.
[0046] For example, based on the difference set algorithm, difference data of the first entity set is determined according to the first business management entity set. This difference data reflects the changes in business management channels that occur in the second business management entity set of the inheriting user after the first business management entity set is transferred. Further, the permission mapping table of the business management channels is updated according to the determined difference data of the first entity set. For example, if the difference data reflects that the inheriting user has added a new business management channel to be managed, the inheriting user is added to the permission mapping table of that business management channel; if the difference data reflects that the first user has reduced the number of business management channels to be managed, the first user is deleted from the permission mapping table of that business management channel. In one embodiment, the permission mapping table and the business management channels can have a one-to-many relationship or a one-to-one relationship. For example, a permission mapping table can simultaneously record the mapping relationships between multiple business management channels and users, or it can record the mapping relationship between one business management channel and one user.
[0047] In one embodiment, the business management entity set can be recorded using an access control list (ACL), which records the business management channels a user is responsible for. When a user needs to access or modify data under a specific business management channel, it can be determined whether the user's ACL contains the corresponding business management channel identifier. If the ACL contains the identifier, the user is allowed to access or modify the data under that channel; otherwise, access or modification is denied. In another embodiment, a user can initiate a data request for themselves or other users. This request can be a data viewing request or a data creation / deletion / modification request. Upon receiving a data request, the scope of business management channels the user is responsible for can be determined based on the ACL.
[0048] In one embodiment, upon responding to a first data request for an inheriting user, a first access control list for the inheriting user can be generated based on the updated permission mapping table, thereby generating an updated second business management entity set. The user initiating the first data request for the inheriting user can be either the inheriting user or another user (e.g., the inheriting user's supervisor). The permission mapping table provided in this application can be used to record the mapping relationship from business management channels to responsible users. For example, if the permission mapping table records users A1, A2, and A3 corresponding to business management channel S1, then users A1, A2, and A3 all possess functional permissions for business management channel S1. The permission mapping table corresponding to business management channel S1 can be represented as [User A1, User A2, User A3]. When the first entity set difference data reflects the inheritance of business management channel S1, which is managed by the first user A3, to the inheriting user A4, the permission mapping table for business management channel S1 will be updated to [User A1, User A2, Inheriting User A4].
[0049] Assume that the first access control list (ACL) for inheriting user A4 before the update is [S2, S3], the permission mapping table for business management channel S2 is [inheriting user A4, user A5, user A6], and the permission mapping table for business management channel S3 is [inheriting user A4, user A7, user A8]. Upon receiving the first data request for inheriting user A4, the ACL [S1, S2, S3] for inheriting user A4 can be generated based on the permission mapping table for business management channel S1 [user A1, user A2, inheriting user A4], the permission mapping table for business management channel S2 [inheriting user A4, user A5, user A6], and the permission mapping table for business management channel S3 [inheriting user A4, user A7, user A8]. This results in the updated second business management entity set [S1, S2, S3].
[0050] This application updates the permission mapping table of the business management channel based on the difference data of the first entity set, and generates the first access control list of the inherited user based on the updated permission mapping table when responding to the first data request for the inherited user, thereby generating the updated second business management entity set. By using the permission mapping table as an inverted data permission index, the permission mapping table can be updated only when account changes occur, without having to update the access control list extensively based on the differences of the entity set. This greatly reduces the recursive operations when updating the access control list in the database and reduces computational overhead.
[0051] In one possible embodiment, the dynamic permission management method provided in this application is based on the difference set algorithm. The method for determining the difference data of the first entity set according to the first business management entity set may be: determining a new second business management entity set according to the first business management entity set and the second business management entity set; and determining the entity set increment data and entity set decrement data according to the second business management entity set before the update and the new second business management entity set.
[0052] For example, a new second business management entity set is determined based on the first business management entity set and the second business management entity set. For instance, the first business management channel recorded in the first business management entity set is added to the second business management entity set (i.e., the second business management entity set before the update) to obtain the new second business management entity set.
[0053] The first entity set difference data provided in this application can be represented by entity set incremental data and entity set decrement data. Entity set incremental data can be understood as data used to add new business management channels. For example, the entity set incremental data is obtained by subtracting the business management channel identifiers that are the same as those in the previous business management entity set from the new business management entity set; that is, entity set incremental data = new business management entity set - previous business management entity set. Entity set decrement data can be understood as data used to remove business management channels. For example, the entity set decrement data is obtained by subtracting the business management channel identifiers that are the same as those in the new business management entity set from the previous business management entity set; that is, entity set decrement data = previous business management entity set - new business management entity set. This application determines the entity set incremental data and entity set decrement data based on the first and second business management entity sets, accurately determining the changes in the business management channels managed by the second business management entity set inheriting the user, and more accurately updating the permission mapping table.
[0054] In one embodiment, updating the permission mapping table of the business management channel based on the difference data of the first entity set can be done by: adding a mapping relationship from the business management channel to the inheriting user in the permission mapping table of the business management channel based on the incremental data of the entity set, and deleting a mapping relationship from the business management channel to the inheriting user in the permission mapping table of the business management channel based on the decrement data of the entity set.
[0055] For example, the incremental data of the entity set reflects the addition of business management channels by inherited users, and a new mapping relationship from the corresponding business management channel to the inherited user is added to the permission mapping table corresponding to these business management channels. Conversely, the incremental data of the entity set reflects the reduction of business management channels by inherited users, and the mapping relationship from the corresponding business management channel to the inherited user is deleted from the permission mapping table corresponding to these business management channels. This application updates the permission mapping table of business management channels based on the incremental and reduced data of the entity set, accurately updating the permission mapping table according to the changes in the business management channels managed by the inherited user.
[0056] In one possible embodiment, the dynamic permission management method provided in this application may further include: upon detecting a change in the personal account of a second user, determining third entity set difference data based on the personal account change; updating the permission mapping table of the business management channel according to the third entity set difference data, wherein the permission mapping table records the mapping relationship from the business management channel to the responsible user; and generating a second access control list for the second user based on the updated permission mapping table when responding to a second data request for the second user.
[0057] The second user can be a user whose account changes due to a change in position (e.g., a promotion leading to a change in the business management channels they are responsible for) or a change in authority (e.g., the addition or deletion of business management channels), requiring them to update customer channels within their personal scope. For example, when a change in the second user's personal account is detected, third entity set difference data is determined based on this change. This third entity set difference data can be used to reflect the changes in business management channels that will occur in the second user's third business management entity set after the change in their personal account.
[0058] Furthermore, the permission mapping table of the business management channel is updated based on the aforementioned determined third entity set difference data. For example, if the third entity set difference data reflects that the second user has added a business management channel to be responsible for, the second user is added to the permission mapping table of that business management channel; if the third entity set difference data reflects that the second user has reduced the number of business management channels to be responsible for, the second user is deleted from the permission mapping table of that business management channel.
[0059] In one embodiment, when responding to a second data request for a second user, a second access control list for the second user can be generated based on the updated permission mapping table, thereby generating an updated third business management entity set for the second user. The user initiating the second data request for the second user can be the second user or another user (e.g., the second user's supervisor). For example, if the permission mapping table records users B1, B2, and the second user B3 corresponding to business management channel S2, then users B1, B2, and the second user B3 all have functional permissions for business management channel S2. The permission mapping table corresponding to business management channel S2 can be represented as [User B1, User B2]. When the difference data in the third entity set reflects that the second user B3 has newly taken charge of business management channel S1, the permission mapping table for business management channel S1 will be updated to [User B1, User B2, Second User B4].
[0060] Assume that the second access control list (QC) for user B4 before the update is [S2, S3], the permission mapping table for business management channel S2 is [User B4, User B5, User B6], and the permission mapping table for business management channel S3 is [User B4, User B7, User B8]. Upon receiving a second data request for user B4, the second QC for user B4 can be generated based on the permission mapping table for business management channel S1 [User B1, User B2, User B4], the permission mapping table for business management channel S2 [User B4, User B5, User B6], and the permission mapping table for business management channel S3 [User B4, User B7, User B8]. This results in the updated third business management entity set [S1, S2, S3].
[0061] This application updates the permission mapping table of the business management channel based on the difference data of the third entity set, and generates a second access control list for the second user based on the updated permission mapping table when responding to a second data request for the second user, thereby generating an updated third business management entity set. This achieves the updating of the business management entity set when personal accounts change. Furthermore, by using the permission mapping table as an inverted data permission index, the permission mapping table only needs to be updated when an account changes, without needing to update the access control list extensively based on the differences of the entity set. This greatly reduces the recursive operations when updating the database access control list and reduces computational overhead.
[0062] The above describes a method that intercepts the account change process of a first user upon detecting such an account change. It retrieves the first user's first business data and first business management entity set. The first business management entity set records the first user's first business management channel scope. The first user's functional permissions for the first business management channel are determined based on assigned roles and / or positions. The method then identifies the successor user and updates the successor user's second business data and second business management entity set based on the first business data and first business management entity set. The second business management entity set records the successor user's second business management channel scope. The successor user's functional permissions for the second business management channel are determined based on assigned roles and / or positions. By decoupling business management channels from the organizational tree, business management channels and users are no longer strongly bound to the organizational tree. When a user account change occurs, a deep recursive traversal of the entire organizational tree is unnecessary. Dynamic updates of business management channel permissions can be achieved through the transfer of business management entity sets, effectively improving permission management efficiency. Meanwhile, by decoupling the administrative organizational tree from external sales channels, it supports the smooth operation of mixed models such as direct operation, distribution, and agency management. It can seamlessly manage different store collections across regions and provinces, breaking the rigid constraints of traditional organizational trees. It proactively intercepts the forced triggering of the closed-loop process of employee departure inheritance, solving the problems of unclaimed performance, unclaimed customers, and incorrect downstream reports caused by the abrupt suspension of departing employees, thus ensuring the security and continuity of the enterprise's underlying data. Moreover, for large retail systems with a large number of stores, refreshing permissions after the transfer of management personnel is a heavy system burden. This application replaces the traditional recursive tree depth traversal strategy with a lightweight local recalculation based on difference sets, avoiding the performance fluctuations caused by a full refresh of the user's first access control list, achieving second-level rapid permission self-healing, and improving permission management efficiency.
[0063] Figure 4 A schematic diagram of a dynamic permission management device provided in an embodiment of this application is given. (Reference) Figure 4 The dynamic permission management device includes a change interception module 41, a data retrieval module 42, and an inheritance processing module 43.
[0064] The system includes the following components: A change interception module 41, used to intercept the account change process of the first user upon detecting an account change; a data retrieval module 42, used to retrieve the first user's first business data and first business management entity set, wherein the first business management entity set records the first user's first business management channel scope; the first user's functional permissions for the first business management channel are determined based on assigned roles and / or positions; and an inheritance processing module 43, used to determine the inheriting user and update the inheriting user's second business data and second business management entity set according to the first business data and the first business management entity set; the second business management entity set records the inheriting user's second business management channel scope, and the inheriting user's functional permissions for the second business management channel are determined based on assigned roles and / or positions.
[0065] The above describes a method that intercepts the account change process of a first user upon detecting such an account change. This method retrieves the first user's first business data and first business management entity set. The first business management entity set records the first user's first business management channel scope. The first user's functional permissions for the first business management channel are determined based on assigned roles and / or positions. The method then determines the successor user and updates the successor user's second business data and second business management entity set based on the first business data and first business management entity set. The second business management entity set records the successor user's second business management channel scope. The successor user's functional permissions for the second business management channel are determined based on assigned roles and / or positions. By decoupling business management channels from the organizational tree, business management channels and users are no longer strongly bound to the organizational tree. When a user account change occurs, a deep recursive traversal of the entire organizational tree is unnecessary. Dynamic updates of business management channel permissions can be achieved through the transfer of business management entity sets, effectively improving permission management efficiency.
[0066] In one possible embodiment, the inheritance processing module 43 updates the second business data and the second business management entity set of the inheriting user based on the first business data and the first business management entity set, including: The completed first business data and the ongoing first business data are identified from the first business data. The completed first business data is marked with inheritance annotation, and the ongoing first business data is added to the second business data of the inheriting user; Based on the difference set algorithm, the second business management entity set of the inherited user is updated according to the first business management entity set.
[0067] In one possible embodiment, the inheritance processing module 43 updates the second business management entity set of the inheriting user based on the difference set algorithm, according to the first business management entity set, including: Based on the difference set algorithm, the difference data of the first entity set is determined according to the first business management entity set; Update the permission mapping table of the business management channel according to the difference data of the first entity set, wherein the permission mapping table records the mapping relationship from the business management channel to the responsible user; In response to the first data request for the inherited user, a first access control list for the inherited user is generated based on the updated permission mapping table, thereby generating an updated second business management entity set.
[0068] In one possible embodiment, the inheritance processing module 43 determines the first entity set difference data based on the first business management entity set using a difference set algorithm, including: Based on the first set of business management entities and the second set of business management entities, a new set of second business management entities is determined; The incremental data and decremental data of the entity set are determined based on the second business management entity set before the update and the new second business management entity set.
[0069] In one possible embodiment, the inheritance processing module 43 updates the permission mapping table of the business management channel based on the difference data of the first entity set, including: Based on the incremental data of the entity set, a new mapping relationship from the business management channel to the inherited user is added to the permission mapping table of the business management channel; based on the decrement data of the entity set, a mapping relationship from the business management channel to the inherited user is deleted from the permission mapping table of the business management channel.
[0070] In one possible embodiment, the inheritance processing module 43 determines the inheritance user, including: Obtain the load bandwidth information and service area affiliation of multiple candidate users, and determine the successor user from the multiple candidate users based on the load bandwidth information and service area affiliation.
[0071] In one possible embodiment, the dynamic permission management device further includes an interception and de-interception module. The interception and de-interception module is used to de-intercept the account change process after the inheritance processing module 43 updates the second business data and the second business management entity set of the inherited user according to the first business data and the first business management entity set, and then performs an account change operation on the first user through the account change process.
[0072] In one possible embodiment, the dynamic permission management device further includes a personal change response module, which is configured to: upon detecting a change in the personal account of a second user, determine third entity set difference data based on the personal account change; update the permission mapping table of the business management channel according to the third entity set difference data, wherein the permission mapping table records the mapping relationship from the business management channel to the responsible user; and upon responding to a second data request for the second user, generate a second access control list for the second user based on the updated permission mapping table.
[0073] It is worth noting that in the embodiments of the above-mentioned dynamic permission management device, the various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be achieved; in addition, the specific names of each functional unit are only for easy differentiation and are not used to limit the protection scope of the embodiments of this application.
[0074] This application also provides a dynamic permission management device, which can integrate the dynamic permission management apparatus provided in this application. Figure 5 This is a schematic diagram of the structure of a dynamic access control device provided in an embodiment of this application. (Reference) Figure 5 The dynamic permission management device includes: an input device 53, an output device 54, a memory 52, and one or more processors 51; the memory 52 is used to store one or more programs; when one or more programs are executed by one or more processors 51, the one or more processors 51 implement the dynamic permission management method provided in the above embodiments. The input device 53, output device 54, memory 52, and processors 51 can be connected via a bus or other means. Figure 5 Taking the example of a connection between China and Israel via a bus.
[0075] The memory 52, as a computing device readable storage medium, can be used to store software programs, computer-executable programs, and modules, such as program instructions / modules corresponding to the dynamic permission management method provided in any embodiment of this application (e.g., the change interception module 41, data retrieval module 42, and inheritance processing module 43 in the dynamic permission management device). The memory 52 may primarily include a program storage area and a data storage area. The program storage area may store the operating system and at least one application program required for a function; the data storage area may store data created based on the use of the device, etc. Furthermore, the memory 52 may include high-speed random access memory and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other non-volatile solid-state storage device. In some instances, the memory 52 may further include memory remotely located relative to the processor 51, and these remote memories can be connected to the device via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0076] Input device 53 can be used to receive input digital or character information, and to generate key signal inputs related to user settings and function control of the device. Output device 54 may include display devices such as a display screen.
[0077] The processor 51 executes various functional applications and data processing of the device by running software programs, instructions and modules stored in the memory 52, thereby realizing the dynamic permission management method described above.
[0078] The dynamic permission management device, equipment, and computer provided above can be used to execute the dynamic permission management method provided in any of the above embodiments, and have corresponding functions and beneficial effects.
[0079] This application embodiment also provides a storage medium for storing computer-executable instructions. When executed by a computer processor, the computer-executable instructions are used to execute the dynamic permission management method provided in the above embodiment. The dynamic permission management method includes: intercepting the account change process of the first user when an account change is detected; retrieving the first user's first business data and a first business management entity set, wherein the first business management entity set is used to record the first user's first business management channel scope; the first user's functional permissions for the first business management channel are determined based on the assigned role and / or position; determining a successor user, and updating the successor user's second business data and a second business management entity set according to the first business data and the first business management entity set; the second business entity set is used to record the successor user's second business management channel scope, and the successor user's functional permissions for the second business channel are determined based on the assigned role and / or position.
[0080] Storage medium – any type of memory device or storage device. The term “storage medium” is intended to include: mounting media, such as CD-ROMs, floppy disks, or magnetic tape devices; computer system memory or random access memory, such as DRAM, DDR RAM, SRAM, EDO RAM, Rambus RAM, etc.; non-volatile memory, such as flash memory, magnetic media (e.g., hard disks or optical storage); registers or other similar types of memory elements, etc. Storage media may also include other types of memory or combinations thereof. Furthermore, storage media may reside in a first computer system in which a program is executed, or may reside in a different second computer system connected to the first computer system via a network (such as the Internet). The second computer system can provide program instructions to the first computer for execution. The term “storage medium” can include two or more storage media that may reside in different locations (e.g., in different computer systems connected via a network). Storage media may store program instructions (e.g., specifically implemented as a computer program) executable by one or more processors.
[0081] Of course, the computer-executable instructions provided in the embodiments of this application are not limited to the dynamic permission management method provided above, but can also perform related operations in the dynamic permission management method provided in any embodiment of this application.
[0082] The dynamic permission management device, equipment, and storage medium provided in the above embodiments can execute the dynamic permission management method provided in any embodiment of this application. For technical details not described in detail in the above embodiments, please refer to the dynamic permission management method provided in any embodiment of this application.
[0083] The above description is merely a preferred embodiment and the technical principles employed in this application. This application is not limited to the specific embodiments provided herein, and various obvious changes, readjustments, and substitutions that can be made by those skilled in the art will not depart from the scope of protection of this application. Therefore, although this application has been described in detail through the above embodiments, this application is not limited to the above embodiments, and may include many other equivalent embodiments without departing from the concept of this application, the scope of which is determined by the scope of the claims.
Claims
1. A dynamic permission management method, characterized in that, include: If an account change for the first user is detected, the account change process for the first user will be intercepted. Retrieve the first user's first business data and the first business management entity set, wherein the first business management entity set is used to record the first user's first business management channel scope; the first user's functional permissions for the first business management channel they are responsible for are determined based on the assigned role and / or position. Determine the successor user, and update the successor user's second business data and second business management entity set based on the first business data and the first business management entity set; the second business management entity set is used to record the successor user's second business management channel scope, and the successor user's functional permissions for the second business management channel they are responsible for are determined based on the assigned role and / or position.
2. The dynamic permission management method according to claim 1, characterized in that, The step of updating the second business data and the second business management entity set of the inheriting user based on the first business data and the first business management entity set includes: The completed first business data and the ongoing first business data are identified from the first business data. The completed first business data is marked with inheritance annotation, and the ongoing first business data is added to the second business data of the inheriting user; Based on the difference set algorithm, the second business management entity set of the inherited user is updated according to the first business management entity set.
3. The dynamic permission management method according to claim 2, characterized in that, The step of updating the second business management entity set of the inheriting user based on the difference set algorithm includes: Based on the difference set algorithm, the difference data of the first entity set is determined according to the first business management entity set; Update the permission mapping table of the business management channel according to the difference data of the first entity set, wherein the permission mapping table records the mapping relationship from the business management channel to the responsible user; In response to the first data request for the inherited user, a first access control list for the inherited user is generated based on the updated permission mapping table, thereby generating an updated second business management entity set.
4. The dynamic permission management method according to claim 3, characterized in that, The method of determining the first entity set difference data based on the difference set algorithm includes: Based on the first set of business management entities and the second set of business management entities, a new set of second business management entities is determined; The incremental data and decremental data of the entity set are determined based on the second business management entity set before the update and the new second business management entity set.
5. The dynamic permission management method according to claim 4, characterized in that, The step of updating the permission mapping table of the business management channel based on the difference data of the first entity set includes: Based on the incremental data of the entity set, a new mapping relationship from the business management channel to the inherited user is added to the permission mapping table of the business management channel; based on the decrement data of the entity set, a mapping relationship from the business management channel to the inherited user is deleted from the permission mapping table of the business management channel.
6. The dynamic permission management method according to claim 1, characterized in that, The determination of the inheriting user includes: Obtain the load bandwidth information and service area affiliation of multiple candidate users, and determine the successor user from the multiple candidate users based on the load bandwidth information and service area affiliation.
7. The dynamic permission management method according to claim 1, characterized in that, After updating the second business data and the second business management entity set of the inheriting user based on the first business data and the first business management entity set, the method further includes: Remove the block on the account change process and perform an account change operation on the first user through the account change process.
8. The dynamic permission management method according to claim 1, characterized in that, Also includes: Upon detecting changes to the personal account of a second user, the third entity set difference data is determined based on the changes to the personal account. The permission mapping table of the business management channel is updated according to the difference data of the third entity set, wherein the permission mapping table records the mapping relationship from the business management channel to the responsible user; In response to a second data request for the second user, a second access control list for the second user is generated based on the updated permission mapping table.
9. A dynamic access control device, characterized in that, include: Memory and one or more processors; The memory is used to store one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the dynamic permission management method as described in any one of claims 1-8.
10. A storage medium for storing computer-executable instructions, characterized in that, The computer-executable instructions, when executed by a computer processor, are used to perform the dynamic permission management method as described in any one of claims 1-8.