Information processing device, information processing method, and program
The information processing device addresses the blurring of stages in business collaboration by providing a preparatory area with restricted data generation until conditions are met, ensuring high-quality decision-making through controlled data transition.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- SPECIAL MEDICO CO LTD
- Filing Date
- 2026-06-05
- Publication Date
- 2026-07-24
AI Technical Summary
Conventional platforms for business matching and collaborative work often blur the boundary between the preparation and decision-making stages, leading to risks of immature discussions being mistakenly established as legally binding outcomes and unclear responsibility, making it difficult to ensure high-quality decision-making.
An information processing device that provides a preparatory area for information retrieval and hypothesis testing, restricting data generation functions until predetermined conditions such as mutual approval, objective setting, and termination conditions are met, and forming a logical connection channel only after these conditions are fulfilled.
This approach creates a 'safe zone' for exploration and experimentation without risking premature data generation, ensuring that only high-quality decisions are made with clear objectives and defined responsibilities, preventing unintended agreements and unclear discussions.
Smart Images

Figure 0007894674000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to an information processing apparatus capable of transferring data to a plurality of tenant environments respectively managed by a plurality of corporate entities, an information processing method executed by this information processing apparatus, and a program for causing a computer to function as the information processing apparatus.
Background Art
[0002] Conventionally, many platforms for supporting business matching and collaborative work between companies or individuals have been provided. These platforms play an important role in promoting communication between users and improving business efficiency.
[0003] For example, Patent Document 1 discloses a technique for supporting matching between a business operator and a partner candidate. Specifically, a system has been proposed that extracts tags using AI from new case information and partner candidate information and performs appropriate matching. In this system, case information, partner information, matching results, and even feedback evaluations are stored in a database and managed centrally on the platform.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] Conventionally, in platforms for supporting business matching and collaborative work between companies or individuals, it is common for users to be able to shift from communication such as chat to agreement formation at an arbitrary timing.
[0006] However, this conventional structure has a problem in that the boundary between the "preparation and consideration stage," which involves information gathering and hypothesis testing, and the "decision-making and agreement stage," which involves legal effects and responsibilities, tends to become blurred. For example, there is a risk of accidents occurring where immature discussions are mistakenly established as legally binding outcomes (unintended agreements due to operational errors or misunderstandings).
[0007] Furthermore, meetings often proceed without a clear purpose, where the prerequisites for consensus building (objectives and termination conditions) are established, or where responsibility remains unclear. This makes it difficult to systematically guarantee high-quality decision-making.
[0008] In view of the circumstances described above, at least some embodiments of the present invention aim to provide an information processing device, an information processing method, and a program that can provide a secure environment for information retrieval and hypothesis testing, while also enabling strict access control according to the phase and ensuring the quality of consensus building. [Means for solving the problem]
[0009] Information processing devices according to at least some embodiments of the present invention are An information processing device that provides information processing to users belonging to multiple tenant environments, The Area Management Department provides various areas of activity, A connection control unit that forms a logical connection channel between a first entity that manages the first tenant environment and a second entity that manages the second tenant environment, Equipped with, The aforementioned domain management unit provides a preparatory area for accumulating information or testing hypotheses as a preliminary step to the formation of the logical connection channel, and while providing communication functions with other tenants in the preparatory area, restricts the function of generating result data. The connection control unit forms the logical connection channel to which it is granted the authority to generate the result data, in response to transition requests from the first and second entities in the preparation area, provided that predetermined generation conditions, including mutual approval, objective setting, and termination condition definition, are met.
[0010] At least some embodiments of the present invention are information processing methods. An information processing method executed by an information processing device that provides information processing to users belonging to multiple tenant environments, As a preliminary step to the formation of a logical connection channel between a first entity managing the first tenant environment and a second entity managing the second tenant environment, a preparatory area for accumulating information or testing hypotheses is provided, and in the said preparatory area, communication functions with other tenants are provided while the function for generating result data is restricted. The steps include forming a logical connection channel to which the authority to generate the outcome data is granted, provided that predetermined generation conditions, including mutual approval, objective setting, and termination condition definition, are met in response to transition requests from the first and second entities in the preparation area, Includes.
[0011] Programs according to at least some embodiments of the present invention are A program for causing a computer to function as an information processing device that provides information processing to users belonging to multiple tenant environments, To the aforementioned computer, As a preliminary step to the formation of a logical connection channel between the first entity managing the first tenant environment and the second entity managing the second tenant environment, a preparatory area is provided for information storage or hypothesis testing, and within this preparatory area, a function is provided to restrict the function of generating result data while providing communication functions with other tenants. A function to form a logical connection channel to which the authority to generate the outcome data is granted, provided that predetermined generation conditions, including mutual approval, objective setting, and termination condition definition, are met in response to transition requests from the first and second entities in the preparation area. To make it happen. [Effects of the Invention]
[0012] According to at least some embodiments of the present invention, in the preparation area provided as a preliminary step before the formation of a logical connection channel, communication functions with other tenants are provided, while the functions for generating outcome data are restricted. This provides a "safe zone" in which users can explore and experiment with information without risk before formal agreements and outcome confirmations are made, and prevents immature, early-stage information from being mistakenly generated as official outcome data. Furthermore, a logical connection channel is only formed that grants the authority to generate outcome data after certain generation conditions, including mutual recognition, objective setting, and termination condition definition, have been met. This prevents situations where communication is initiated without a clear purpose or discussions take place without a defined consensus goal, enabling strict operation that systematically allows only high-quality decision-making activities. [Brief explanation of the drawing]
[0013] [Figure 1A] This is a block diagram showing the functional configuration of an information processing device according to one embodiment. [Figure 1B] This is a block diagram showing the functional configuration of an information processing device according to another embodiment. [Figure 2] This is a hardware configuration diagram of an information processing device according to one embodiment. [Figure 3] A model diagram showing the hierarchical structure and transition relationships of multiple activity areas in an information processing device according to one embodiment. [Figure 4] This is an example of a database structure (ER diagram) in an information processing device according to one embodiment. [Figure 5]It is an explanatory diagram showing gateway determination logic in a connection channel formation unit of an information processing apparatus according to an embodiment. [Figure 6] It is a diagram showing an example of a data structure of structured result data in an embodiment. [Figure 7] It is a flowchart showing special agreement channel generation and result confirmation processing in an information processing method according to an embodiment. [Figure 8] It is a sequence diagram showing attribution transfer processing and non-retaining processing of result data in an information processing method according to an embodiment. [Figure 9] It is a diagram showing a use case of two-party cooperation between a business office and an industrial physician. [Figure 10] It is a diagram showing a use case of three-party cooperation including a medical institution. [Figure 11] It is a learning ecosystem diagram by abstraction and reuse of result data. [Figure 12] It is an ecosystem diagram showing the recycling process of taking home, implementing, and publicly disclosing result data in an information processing apparatus according to an embodiment.
Embodiments for Carrying Out the Invention
[0014] Hereinafter, some embodiments of the present invention will be described with reference to the accompanying drawings. However, the dimensions, materials, shapes, relative arrangements, etc. of the components described as embodiments or shown in the drawings are not intended to limit the scope of the present invention, but are merely illustrative examples.
[0015] [System Configuration] <1. Outline of Functional Configuration> FIG. 1A is a block diagram showing the functional configuration of an information processing apparatus 10A (hereinafter also referred to as a market management server) according to an embodiment. FIG. 1B is a block diagram showing the functional configuration of an information processing apparatus 10B according to another embodiment.
[0016] As shown in Figures 1A and 1B, the information processing device 10 (10A, 10B) is connected to user terminals 20A and 20B via a communication network 90 such as the Internet. The information processing device 10 (10A, 10B) includes a region management unit 110, a connection channel formation unit 120, and a data control unit 130.
[0017] The information processing device 10 (10A, 10B) is configured to control the ownership of data to multiple tenant environments (T1, T2, ...) managed by multiple entities (e.g., corporate entities). Here, "tenant environment" refers to the computing environment managed by each legal entity (company, organization, sole proprietor, etc.). Figures 1A and 1B show multiple tenant environments, including a first tenant environment T1 managed by a first entity and a second tenant environment T2 managed by a second entity.
[0018] In the embodiment shown in Figure 1A, the tenant environments (T1, T2, ...) are external servers physically separate from the information processing device 10A (on-premise servers, cloud storage contracted by the corporation, SaaS environment, etc.). In this case, the information processing device 10A can output data (transfer data) to external servers, which are tenant environments (T1, T2, ...), via the communication network 90.
[0019] In contrast, in the embodiment shown in Figure 1B, the tenant environments (T1, T2, ...) are logically isolated within the information processing device 10B and are dedicated storage areas (so-called private tenant areas) where only the legal entity has exclusive access rights (management rights). In this case, the tenant environments (T1, T2, ...) are part of the storage area 140 of the information processing device 10B. The storage area 140 may include not only private tenant areas (tenant environments T1, T2, ...) set up for each legal entity, but also a shared area C that does not belong to any particular legal entity. The information processing device 10B is capable of internally outputting data from the shared area C to tenant environments (T1, T2, ...) which are private tenant areas. This internal data output includes not only data transfer from the shared area C to the private tenant area, but also the process of changing the data's ownership from the shared area C to the private tenant area through data authority delegation.
[0020] The connection channel formation unit 120 is an example of a "connection control unit" and has the function of forming a logical connection channel (for example, a special agreement channel 400 described later) based on conditions agreed upon between a first entity that manages the first tenant environment T1 and a second entity that manages the second tenant environment T2. Here, "logical connection channel" refers to any logical session or virtual space where information can be exchanged between entities, regardless of its name or UI form. This may include text chat rooms, video conferencing sessions, voice call lines, document sharing spaces, or metaverse spaces.
[0021] In a "logical connection channel" (for example, Special Agreement Channel 400), outcome data is generated as a result of activities involving multiple parties. Here, "outcome data" refers to all data generated in connection with activities in a logical connection channel, and this includes not only the final deliverables that have been agreed upon, but also activity history information (logs), communication records, draft data from the deliberation process, or records indicating that an agreement was not reached.
[0022] The data control unit 130 has the function of assigning result data generated by activities performed between entities on a logical connection channel to a storage area under the management of each tenant environment, and executing control to set the storage area associated with the channel within the information processing device 10 (for example, shared area C shown in Figure 1B) to a state where the actual result data is not held. The specific process of setting the actual result data to a state where it is not held includes, for example, deleting the actual result data or moving the actual result data to the tenant environment. In the embodiment shown in Figure 1A, the data control unit 130 transfers the result data in the logical connection channel to the tenant environment (T1 or T2), which is an external server, and deletes or moves the actual result data to the tenant environment so that no actual result data remains in the storage area of the information processing device 10A. In the embodiment shown in Figure 1B, the data control unit 130 may change the destination of the actual result data in the logical connection channel to a tenant environment (T1 or T2), which is a private tenant area, for example, by delegating authority. In this case, the actual result data becomes accessible and editable only by the first or second entity that manages the private tenant area (tenant environment T1 or T2), and the actual result data does not remain in the storage area (e.g., shared area C) within the information processing device 10B associated with the logical connection channel.
[0023] The domain management unit 110 provides multiple types of activity domains according to the depth of information (exploration, discussion, decision-making, implementation, etc.) and has the function of controlling user permissions (whether or not results can be produced, etc.) in each domain. The activity areas provided by the Area Management Department 110 will be described in detail later.
[0024] <2. Hardware Configuration> Figure 2 is a hardware configuration diagram of an information processing device according to one embodiment. In some embodiments, the information processing device 10 is realized by a server computer including a CPU (Central Processing Unit) 101, memory 102, storage 103, a communication interface (IF), etc., or by a cloud computing system in which these hardware resources are virtualized.
[0025] The various functional components of the information processing device 10, such as the load balancer 11, Web / App server group 12, asynchronous processing server 13, and DB cluster 14 shown in Figure 2, are realized by organically combining the aforementioned hardware resources. Specifically, the Web / App server group 12 and the asynchronous processing server 13 realize their processing functions when the CPU 101 reads the application program stored in the storage 103 into the memory 102 and executes it. Furthermore, the DB cluster 14 primarily uses storage 103 (such as HDDs and SSDs) as persistent data storage, while performing data writing and reading under the control of the database management system (DBMS) by the CPU 101. In a cloud computing environment, physical hardware resources such as CPU 101 and memory 102 may be managed as a resource pool and dynamically allocated to each functional component (11-14) of the information processing device 10 in units such as virtual machines (VMs) or containers.
[0026] The load balancer 11 receives HTTP / HTTPS requests sent from numerous user terminals 20A and 20B via the communication network 90 and functions as a gateway to distribute traffic to the appropriate Web / App server group 12 according to its operational status and load. It also performs SSL / TLS termination processing and is responsible for encrypting and decrypting the communication path, thereby providing a secure communication environment.
[0027] The Web / App server group 12 uses the resources of CPU 101 and memory 102 to execute application programs and outputs API responses in HTML, CSS, JavaScript, or JSON format to the web browsers or native applications of user terminals 20A and 20B, thereby providing user interfaces (UI) for each activity area (e.g., performance disclosure area, preparation area, special agreement channel, etc.). Specifically, the Web / App server group 12 functions as a domain management unit 110. When it receives a screen display request from a user, it determines the user's tenant and permission level, and dynamically generates and returns screen data that includes only permitted operation buttons (e.g., the result generation button). This enables UI-level function restrictions and permission management.
[0028] Furthermore, the Web / App server group 12 may also have "tenant isolation middleware" running, positioned between the application layer and the database layer. This middleware verifies the authentication token (e.g., JWT) included in every request and strictly verifies whether the data the requesting user is trying to access belongs to the tenant environment (T1 or T2) to which the user belongs. This makes it possible to achieve a multi-tenant environment (see Figure 1B) in which data for each legal entity is logically completely isolated, even though they physically share a single DB cluster 14.
[0029] The asynchronous processing server 13 works in cooperation with the Web / App server group 12 to realize the functions of the connection control unit (connection channel formation unit 120), particularly the real-time consensus formation process in the "special agreement channel 400". The asynchronous processing server 13 establishes persistent connection sessions with each user terminal participating in the channel using technologies such as WebSocket and long polling. This means that any expression of intent (such as pressing an agreement button or electronically signing) or data input operation performed by one party is immediately synchronized as a push notification on the other party's screen. This real-time capability ensures the simultaneity of "agreement made here and now," supporting the smooth generation of results.
[0030] The DB cluster 14 is a storage system that stores structured data (RDB) and document-format data (NoSQL), and reads and writes data in response to queries from the Web / App server group 12. The Web / App server group 12, acting as the data control unit 130, writes the result data to a temporary or shared area on the DB cluster 14 once the result data is finalized in the special agreement channel. Subsequently, upon receiving a retrieve instruction (output request) from a user or an event that triggers such an instruction, it reads the data from the DB cluster 14 and executes a process to output it to the target tenant environment (external server or internal private area). Furthermore, after the output is complete, it issues an update query to the DB cluster 14 to delete the actual result data or activate the non-retention flag (is_archived), thereby achieving a non-retention state on the platform.
[0031] <3. Hierarchical structure of activity areas> Figure 3 is a model diagram showing the hierarchical structure and transition relationships of multiple activity areas in an information processing device according to one embodiment. In some embodiments, as shown in Figure 3, the domain management unit 110 provides users in each tenant environment with multiple types of activity domains based on three parameters: "information depth (exploration, discussion, decision, implementation, learning)", "disclosure scope (public, limited, individual)", and "time axis (permanent, limited time)", each with a different combination of these parameters. The domain management unit 110 provides the activity domains through the provision of user interfaces (UIs) for each activity domain by the Web / App server group 12. Based on the definition of each domain, the domain management unit 110 implements function restrictions and permission management at the UI level.
[0032] In the embodiment shown in Figure 3, the area management unit 110 provides the following six types of activity areas to users in each tenant environment.
[0033] (1) Area for disclosing results 111 (results board) Parameters: [Depth: Exploration] × [Range: Public] × [Time: Permanent] Function: This platform publishes metadata (summaries, numerical results, etc.) of previously generated performance data, and visualizes reliability information. Control: In this domain, no function for generating new output data is provided; only viewing and searching functions are available.
[0034] (2) Area 112 (Market Board) where application guidelines are presented. Parameters: [Depth: Exploration] × [Range: Public] × [Time: Permanent] Function: This is a platform for posting job postings (project cards) in a standardized format linked to a specific purpose ID (e.g., joint development, recruitment, industrial physician request, etc.). Controls: Free text chat (casual conversation) functionality is restricted, and only standardized matching requests based on purpose IDs are permitted.
[0035] (3) Preparation and Examination Area 220 (Knowledge Thread / Hypothesis Examination Room) Parameters: [Depth: Discussion] × [Scope: Public or Limited] × [Time: Permanent or Limited] Function: This is a platform for asynchronous comment posting, document sharing, risk assessment simulations, and other activities during the initial stages after matching. Control (Safe Zone): This area functions as a "safe zone" where formal consensus building does not take place. The area management unit 110 intentionally restricts the generation of outcome data objects (agreement packages) for users active in this area. Specifically, the generation of outcome data objects is restricted by not displaying UI parts for outcome generation on the web application screen, or by not granting access permissions to the relevant API (returning "403 Forbidden"). This prevents immature discussions from being mistakenly recognized as legally binding outcomes.
[0036] (4) Special Agreement Channel 400 (Token Room) Parameters: [Depth: Determined] × [Range: Limited (Parties Only)] × [Time: Time Limit] Function: This is a dedicated decision-making space that is generated only after passing through the gateway described later. Control: Only within this domain, the domain management unit 110 grants the user the real-time consultation function, the electronic signature function, and the authority to generate result data objects (commit authority).
[0037] (5) Implementation Area 115 (Operational DB / Implementation Board) Parameters: [Depth: Implementation] × [Range: Individual (within tenant)] × [Time: Permanent] Function: This is a platform for distributing the collected output data and for managing tasks and recording execution results within each tenant. Control: Communication with external tenants is blocked, and the confidentiality of internal information is protected.
[0038] (6) Learning and Inheritance Domain 116 (Decision Archive) Parameters: [Depth: Learning] × [Range: Public or Limited] × [Time: Permanent] Function: This is a place to store and reference past decision-making logic (success / failure turning points, preconditions, points to note, etc.) as an abstract model that disregards personal information and raw data. Control: Direct access to specific case data is prohibited; only structured knowledge templates are provided.
[0039] In Figure 3, "gateway" refers to a systemic barrier (logical gate) for transitioning from (3) preparation / examination area 220 to (4) special agreement channel 400. While typical chat tools allow users to seamlessly transition from "conversation" to "agreement" at any time, the embodiment shown in Figure 3 establishes a clear boundary (gateway) between these two areas. The connection channel formation unit 120 prohibits the creation of an instance of the special agreement channel 400 (a space with outcome generation authority) unless it systematically verifies that all three conditions—"mutual acknowledgment (Ack)," "setting of purpose ID (Purpose)," and "definition of termination conditions (Exit Criteria)"—have been entered and that both parties have agreed to them in response to a transition request from the user. This structure physically eliminates the occurrence of "meetings without a purpose" and "agreements with unclear responsibility."
[0040] <4. Data Structure> Figure 4 shows an example of a database structure (ER diagram) in an information processing device according to one embodiment. In the example shown in Figure 4, DB cluster 14 stores the following four tables.
[0041] <4-1. Area Management Table 141 (Rooms)> The area management table 141 is a table that manages the state of all "spaces" within the system. The area management table 141 has, for example, the following columns: room_id: A unique identifier for the area. Type: This indicates the type of activity area (Achievements, Market, Preparation, TokenRoom, Implementation, Learning) of the six activity areas shown in Figure 3 (Achievements Publication Area 111, Application Guidelines Presentation Area 112, Preparation / Consideration Area 220, Special Agreement Channel 400, Implementation Area 115, Learning / Inheritance Area 116). Based on this type value, the area management unit 110 switches the set of permissions to apply. gateway_status: Indicates the gateway's status (Pending, Cleared). Until this status is Cleared, the record for Special Agreement Channel 400 (Type=TokenRoom) will not be created (or become Active). purpose_id / exit_criteria: The required purpose and exit criteria for a token room. valid_until: The expiration date of the token room. This is a required field for token rooms.
[0042] <4-2. Participant Permissions Table 142 (Room_Participants)> The participant permission table 142 is a table that manages the roles and permissions of users in each domain. The participant permission table 142 has a one-to-many relationship with the domain management table 141 mentioned above. The participant permission table 142 has, for example, the following columns. Role: Role (Owner, Guest, Observer, Doctor, HR, etc.). permissions: Bit flags indicating specific operational permissions. For example, the "Result Generation Bit (Can_Commit_Outcome)" is set to "True (1)" only for token room participants, and fixed to "False (0)" for preparation area participants. The Web / App server group 12 refers to this bit when rendering the screen to control the display / hide of the result confirmation button.
[0043] <4-3. Outcome Data Table 143> The results data table 143 is a table that stores the finalized results packages. data_body: The actual output (JSON object or PDF binary). export_rules: Rules for forwarding and reusing. is_archived: Non-retention flag. After the data control unit 130 completes the data assignment process to the tenant environment, this flag becomes "True", and the actual results are deleted or the system's reference to them is locked.
[0044] <4-4. Decision Structure Table 144 (Guidance_Nodes)> The decision structure table 144 is a table used in the learning and inheritance domain 116 described in Figure 3. Rather than a log of specific "who did what," it stores abstract decision nodes such as "under these conditions, A should be selected" or "there is a risk of B," which are used to assist the AI when generating the next special agreement channel.
[0045] [Connection channel generation logic] Referring to Figure 5, the gateway determination process performed by the connection channel formation unit 120 and its implementation on the Web application will be described in detail. Figure 5 is an explanatory diagram showing the gateway determination logic in the connection channel formation unit of an information processing device according to one embodiment.
[0046] In some embodiments, as shown in Figure 5, the transition to the special agreement channel 400 (token room) is initiated by activities in the "preparation / consideration area 220 (knowledge thread)". As shown in Figure 5, the UI of the preparation / consideration area 220 includes a "Request" button 222 for sending connection requests to other entities and an "Approve" button 224 for approving connection requests from other entities. A special agreement channel 400 may be generated based on conditions such as mutual approval between the first and second entities using these action buttons.
[0047] In some embodiments, the connection channel formation unit 120 prohibits the special agreement channel 400 if any one of the predetermined generation conditions (gateway conditions), including mutual recognition, purpose setting, and termination condition definition, is not met in response to connection requests from the first and second entities. In the embodiment shown in Figure 5, the connection channel formation unit 120 determines whether the gateway conditions (mutual approval, purpose setting, and termination conditions) are met when both the "request" button 222 is pressed by the first entity and the "approval" button 224 is pressed by the second entity.
[0048] In other embodiments not shown, the UI flow enforces agreements regarding gateway conditions such as objective setting and termination conditions between the parties, thereby simplifying the determination by the connection channel formation unit 120 as to whether or not a special agreement channel 400 can be formed. In this case, the connection channel formation unit 120 may form a special agreement channel 400 by going through a gateway determination process in the following procedure.
[0049] (Request submission phase) First, the Web / App server group 12 displays the UI components for setting conditions (for example, the "condition setting modal window") included in the UI of the preparation / consideration area 220 (knowledge thread) to user terminals 20A and 20B.
[0050] Before pressing the "Request" button 222, the user must select and enter the following required items in the UI component for setting conditions. • Purpose: Select one of the predefined options (e.g., "Conclude a joint development agreement," "Notify of job offer," "Conduct a return-to-work assessment"). • Exit Criteria: Define the goal of the agreement (e.g., "Completion of electronic signatures by both parties," "Issuance of a PDF of the agreement").
[0051] After selecting and entering these required items, the user of the first entity presses the "Request" button 222, which sends a "Conditional Connection Request" from the first entity to the Web / App server group 12. In the area management table 141 (Rooms) on the DB cluster 14, gateway_status is recorded as "Pending".
[0052] (Approval and Channel Generation Phase) Next, the asynchronous processing server 13 sends real-time notifications (push notifications or on-screen info bar displays) to the user terminals of the second entity participating in the same preparation / examination area 220.
[0053] The notification includes a message such as, "We have received a request from the first entity to create a consensus-building room for the purpose of 'return-to-work assessment'," along with a link to the relevant screen in Preparation / Consideration Area 220. The user follows the link to access Preparation / Consideration Area 220, reviews the content of the request from the first entity, and presses the "Approve" button 224 (and "Reject" button) displayed on the UI.
[0054] The connection channel formation unit 120 determines that mutual approval of the special agreement channel 400, including the setting of objectives and termination conditions, has been established when the second entity presses the "Approve" button 224, and forms the special agreement channel 400. Specifically, the connection channel formation unit 120 updates the gateway_status to "Cleared" in the area management table 141 (Rooms) on the DB cluster 14, generates a new instance (URL) of the special agreement channel 400, and automatically transitions both screens to that channel.
[0055] In this procedure, by forcing the first entity to input objective settings and termination conditions as part of the UI flow before pressing the "Request" button 222, the occurrence of the "Approve" button 224 press event by the second entity signifies the fulfillment of the gateway conditions (mutual approval, objective setting, and termination conditions). Therefore, the connection channel formation unit 120 can immediately form the special agreement channel 400 in response to the "Approve" button 224 press event by the second entity.
[0056] [Results standard structure] Figure 6 shows an example of the data structure of structured output data 500 in one embodiment. In some embodiments, the output data is not simply a text-based meeting transcript, but is generated as a "structured data object" encapsulated as a unit that can be reused and automatically processed in subsequent systems (implementation domains). The output data as a "structured data object" (structured output data) is described in a format such as JSON.
[0057] In the embodiment shown in Figure 6, the structured outcome data 500 includes a decision / conclusion block 510, a next action block 520, a transfer / sharing control block 530, and an authenticity assurance block 540.
[0058] (1. Judgment / Conclusion Block 510) The decision-making block 510 stores the core information of the decision-making process, which was finalized within the special agreement channel 400, in a machine-readable format. For example, in the use case of collaboration with industrial physicians, the following fields are included: • employment_decision (Employment Classification Determination): A determination result code such as "Normal work permitted," "Restricted work," "Leave of absence," or "Requires medical consultation." • Restrictions (Work Restrictions): An array of data indicating specific restrictions such as "No overtime," "No night shifts," "No lifting heavy objects," and "No driving." • rationale_summary (basis for judgment): A summary of the medical and legal grounds that led to the judgment. Because this data is structured, it is possible to automatically update the work status of employee master data in the tenant environment where the data is taken (e.g., HR system) or to link restriction flags (e.g., overtime lock) to the attendance management system.
[0059] (2. Next action block 520) The next action block 520 stores the task definition that should be executed based on the agreement. • next_actions (next action definition): An array of objects that define "Who," "Due Date," and "Task." For example, a task might be defined as "The HR person will prepare a referral letter to a medical institution within two weeks." The data control unit 130 or the tenant's system analyzes this field and automatically generates specific ToDo items on the implementation area (task management board). This prevents agreements from being left unfinished and ensures reliable fulfillment (implementation).
[0060] (3. Transfer / Sharing Control Block 530) The transfer and sharing control block 530 stores security rules (transfer rule information) related to the retrieval and retrieval of data. The transfer rule information stored in the transfer and sharing control block 530 may include definitions of destinations to which data can be transferred or whether it can be reused.
[0061] The transfer / sharing control block 530 includes, for example, the following fields: • export_rules (transfer rules): A list of tenant IDs that are permitted to take the output package (transfer ownership). This also includes a flag indicating whether the package can be reused. • share_policy (sharing scope policy): Defines the granularity of viewing permissions within a tenant. For example, the results of an industrial physician consultation may contain sensitive personal information (such as disease names). Therefore, in share_policy, detailed control rules can be defined, such as "disclose all items to HR personnel" but "disclose only 'suitability for employment' and 'considerations' to on-site supervisors, and mask disease names." The data control unit 130 and the tenant-side display system automatically mask (conceal) information according to the viewer's role in accordance with this policy.
[0062] (4. Authenticity Assurance Block 540) Authenticity assurance block 540 includes, for example, the following fields: • Signatures (digital signatures): Digital signatures and timestamps using the private keys of the participants (first and second entities). • Version (version control): Version information when supplements (corrections) have been made. As a result, it is cryptographically guaranteed as to "when and by whom the data taken home was finalized," and tampering detection becomes possible.
[0063] [Processing Flow] Referring to the flowchart of FIG. 7, a series of processing procedures from the generation of the special agreement channel 400 to the finalization of the result data, which are executed by the information processing apparatus 10 (mainly the connection channel forming unit 120 and the data control unit 130), will be described in detail. FIG. 7 is a flowchart showing the generation of a special agreement channel and the result finalization process in an information processing method according to an embodiment.
[0064] As shown in FIG. 7, in S101, the system receives a connection request from the user. In S102, the above-described gateway determination is performed, and if there is a lack of conditions, the process branches to S103 to reject the generation. When the conditions are satisfied, in S104, a special agreement channel 400 (token room) is generated, and a result generation function (such as a confirmation button on the UI) is activated. In S105, when an agreement formation operation (such as an electronic signature) is performed between the parties, in S106, a structured result data object is generated and temporarily saved. Hereinafter, each of steps S101 to S106 will be described in detail.
[0065] <S101 (Receiving a Connection Request)> In the preparation / deliberation area 220 (such as a chat screen), a "transition request to the agreement formation phase" is received from the user terminal 20A of the first subject (S101). When the Web / App server group 12 receives this request, it expands the "purpose ID (purpose_id)" and "end condition (exit_criteria)" included in the request parameters in the memory, and creates a temporary record in the area management table 141 (Rooms) of the DB cluster 14.
[0066] <S102 (Gateway Determination)> The connection channel formation unit 120 refers to the status on the database and determines whether all of the following three conditions are satisfied (AND condition) (S102). Condition 1. Confirmation of input of purpose and conditions: The required fields are not empty. Condition 2. Approval from the other party (Ack): Asynchronous notification is sent to the user terminal 20B of the second entity, and an "approval action (pressing the 'approve' button 224)" has been received for this. Condition 3. Permission check: The user who made the request is a role (e.g., personnel administrator, industrial doctor) with "decision-making authority" in the tenant.
[0067] <S103 (Rejection / block of generation)> In the determination of S102 above, if any one of the conditions is missing (e.g., the other party rejected, or insufficient authority), the system interrupts the transition process (S103). At this time, an error message (e.g., "Consent from the other party has not been obtained") is displayed on the UI, and the user is kept in the preparation / consideration area 220. This reliably prevents the generation of a channel in a state where the premise for consent formation is not met.
[0068] <S104 (Generation of special consent channel)> When the gateway conditions are satisfied, the connection channel formation unit 120 creates a new record (Type = TokenRoom; special consent channel 400) in the area management table 141 (Rooms) and sets the status to "active". At the same time, the participant permission table 142 (Room_Participants) is updated, and only for the users participating in the channel, the outcome generation permission bit (can_commit_outcome) is rewritten to "True (1)". As a result, an "outcome confirmation button" and an "electronic signature panel" are dynamically rendered (displayed) on the screen of the user terminal.
[0069] <S105 (Consent formation and signature)> Within the generated special agreement channel 400, final confirmation among the parties is conducted. When the user performs a "confirmation (signature)" operation, the system generates an electronic signature for the hash value of the agreement content using the private key of each user. In the example of industry-doctor collaboration, the confirmation of medical findings by the industrial doctor and the confirmation signature by the company's responsible person correspond to this.
[0070] <S106 (Generation of Result Package)> Triggered by the completion of the two-way signature, the data control unit 130 generates the structured result data 500 (e.g., in JSON format) shown in FIG. 6. Specifically, the judgment results input on the screen are mapped to each field of the judgment conclusion block 510, the tasks to be performed next are mapped to each field of the next action block 520, and transfer rules are assigned to the transfer / share control block 530, and then persisted in the result data table 143. At this point, the data still exists in the storage area associated with the special agreement channel 400 within the information processing apparatus 10, but the preparation for the next process of "data retrieval process (see FIG. 8)" is completed.
[0071] [Details of Output (Transfer of Attribution) of Result Data and Non-Retention Processing] Referring to the sequence diagram of FIG. 8, the details of the output (transfer of attribution) of the result data and the non-retention processing will be described. FIG. 8 is a sequence diagram showing the transfer of attribution processing and non-retention processing of result data in an information processing method according to an embodiment.
[0072] In the example shown in FIG. 8, the transfer of attribution processing of the result data is led by the data control unit 130 (Web / App server group 12), and is a transaction process between the storage area associated with the special agreement channel 400 in the DB cluster 14 and the tenant environments T (T1, T2,...).
[0073] <1. Retrieval Request (Export Request)> After the output data is finalized, a request to output the output data is sent from the tenant environment (corporate system) or the user terminal. For example, if the tenant environment T (T1, T2, ...) shown in Figure 1A is an external server, the output request for outcome data may be a POST request to the API endpoint of the information processing device 10 (e.g., api / outcomes / {id} / export). This request includes the target outcome ID and authentication token.
[0074] <2. Permission verification (check export_rules)> Upon receiving the request, the information processing device 10 reads the record from the results data table 143 (Outcomes) and analyzes the transfer rule information (export_rules field in Figure 4, or the transfer / sharing control block 530 in Figure 6). Specifically, it verifies whether the requesting tenant ID is included in the "allowed_targets" list and whether the data has not already been archived (is_archived=True). This verification process prevents unauthorized data extraction and duplicate data retrieval by third parties.
[0075] <3. Data Attribution Control> If the verification is successful, the data control unit 130 assigns the actual output data (JSON object and signed PDF, etc.) to an area under the control of the requester. • For external tenants: Send an HTTPS POST request to the Webhook URL specified by the other system. • In the case of an internal private area: Data is INSERT (replicated) to an implementation area table (such as Tenant_Tasks) dedicated to that tenant, located within the same DB cluster 14. With the completion of this data attribution process, the "ownership" of the data is transferred from the platform (shared space) to each tenant (individual space).
[0076] <4. Non-retention process (Delete / Archive)> After confirming the successful completion of the output ("HTTP 200 OK" or "DB commit"), the data control unit 130 may execute the following "non-retention logic". Specifically, it performs one or a combination of the following update operations on the outcome data table 143 (Outcomes). • Logical deletion: Set the is_archived flag to True to prevent referencing from applications. • Physical deletion: Overwrites the contents of the data_body column with NULL or dummy data. • Discard encryption key: If the data is encrypted, discard the decryption key from memory and storage.
[0077] <5. Retention of metadata only> Even after the above processing, the actual data (contents) of the results does not exist within the information processing device 10, but only metadata such as outcome_id, purpose_id, created_at, and signatures (hash value) is retained. This allows the platform to provide proof of fact (audit logs) that "an agreement definitely existed," even though the contents are "invisible (not retained)," and to provide performance data for future matching (see Figure 11).
[0078] [Examples of application to industrial physician collaboration systems] Next, with reference to Figures 9 to 11, an example of applying the information processing device 10 with the above configuration to an "industrial physician collaboration system" will be described. The industrial physician collaboration system in this application example is designed to reconcile a company's "duty of care for safety" and "data sovereignty," with the first entity defined as the "company (operator)" and the second entity as the "industrial physician (external expert)." Furthermore, different roles exist within the company tenant: "business site (workplace)" and "head office (human resources and labor)."
[0079] <Use Case 1: Two-party collaboration under headquarters control> Figure 9 is a diagram illustrating a use case for two-party collaboration between a business establishment and an industrial physician, showing the system processing flow in collaboration between the business establishment and the industrial physician. In the example shown in Figure 9, the system prohibits direct requests to the industrial physician based solely on on-site judgment. Instead, the flow involves an internal review by headquarters and mutual approval (gateway) with the industrial physician before a special agreement channel 400 can be formed. The following explains the collaboration flow between the first entity (business establishment and human resources / labor management) and the second entity (industrial physician) as shown in Figure 9.
[0080] (1) Preparation and consideration area (event understanding phase): In S201, the on-site staff member at the business site accesses the web application from a user terminal and inputs events such as "occurrence of a high-stress employee" or "desire to return to work" into the UI of the preparation / consideration area 220. This stage is the event assessment phase, and the domain management department 110, in the preparation and review area 220, only allows on-site personnel to input "report forms," and does not provide any functions for connecting to industrial physicians or generating results. As a result, only pure factual reports that do not include medical judgments are accumulated. When event data is entered into preparation / review area 220, a notification is sent to the user terminal of the head office's HR department, and the internal review phase begins.
[0081] (2) Internal review and external connection requests: In S202, a person in charge of human resources at headquarters accesses preparation / review area 220, reviews the report content, and determines whether an "industrial physician consultation is necessary" in light of internal standards and legal standards. If the head office HR staff determines that it is necessary, a "connection request" is sent from the head office terminal to the industrial physician, who is the second party, via S203. At this time, following the UI flow, the HR staff enters required items such as "purpose setting (e.g., return-to-work assessment)", "necessary documents (attendance data, etc.)", and "termination conditions" before pressing the "request" button 222. As a result of the "Request" button 222 being pressed, a notification is sent to the second entity (industrial physician).
[0082] (3) Formation of request approval and special agreement channels: Upon receiving the notification, the second party (industrial physician) will then proceed with scheduling and other necessary arrangements before clicking the "Approve" button 224. In S204, the connection channel formation unit 120 deems that an agreement has been reached between the first entity and the second entity, and forms a "special agreement channel 400 (token room)".
[0083] (4) Communication through the special agreement channel (medical evaluation phase): Only through Special Agreement Channel 400 are industrial physicians granted the authority to "create opinion reports (output generation)." Industrial physicians conduct online interviews on Special Agreement Channel 400 and input "employment classification (normal / restricted / leave of absence)" and "considerations" from a medical standpoint into structured data. In S205, once the industrial physician's electronic signature and the employer's confirmation signature are completed, the output data (industrial physician's opinion package) is finalized.
[0084] (5) Output and Implementation (Employment Measures Phase): In S206, the finalized output data is immediately output (data transferred) from the information processing device 10 to the company's "human resources management DB (implementation area)". Although the physical entities on the platform are not retained (deleted), the company's system will initiate implementation processes such as "automatic issuance of work restriction notices" and "task creation for follow-up interviews" based on the retrieved structured data (next_actions).
[0085] <Use Case 2: Three-party collaboration including medical institutions> Figure 10 illustrates a use case for tripartite collaboration involving a medical institution, showing an extended flow in which a medical institution (specialist) participates as a third party when more specialized judgment is required. If the industrial physician determines that "the opinion of a specialist is needed," a participant (third party) will be added to the special agreement channel. The point to note here is the export rules information for transferring outcome data. While medical institutions provide expert opinions, the destination of the generated outcome data (employment assessment results) is fixed to the "company (first entity)." Therefore, the data control unit 130 rejects "take-away requests" from medical institution terminals and only allows output to corporate tenants. This prevents the dispersion of information even as the number of stakeholders increases and centralizes corporate management responsibility (ownership).
[0086] [Ecosystem: Decision support through learning and inheritance domains] Figure 11 shows a learning ecosystem through the abstraction and reuse of output data. In the embodiment shown in Figure 11, the information processing device 10 does not retain "individual raw data (personal information)," but has the function of accumulating the "logical structure of judgment (knowledge)" extracted from the outcome data by the extraction engine 600.
[0087] The information processing device 10 performs abstraction processing on the result data using the extraction engine 600 immediately before the result data is deleted. The extraction engine 600 may be an internal engine (CPU 101) of the information processing device 10, or an external engine (such as an AI model on the cloud). The extraction engine 600 extracts "Guidance Nodes" from the outcome data of the case, excluding personal information. For example, it records only the logical pattern in the "Learning and Inheritance Domain" where, under the conditions of "over 80 hours of overtime" and "insomnia," a judgment of "prohibition from work" was made, and that this was "successful (successful return to work)."
[0088] The next time a similar case occurs (e.g., an interview with an employee working long hours) and a new special agreement channel 400 is generated, the information processing device 10 will refer to the learning and inheritance area 116. Furthermore, the system displays a guide on the industrial physician's input screen stating, "In similar past cases, 'work restrictions' were selected in 90% of cases," along with a draft of the opinion statement. This allows even inexperienced industrial physicians to make high-quality judgments by utilizing the collective intelligence (knowledge) of the entire platform, while ensuring complete privacy as no specific past employee data can be accessed.
[0089] [Ecosystem and Performance Cycle] Figure 12 is an ecosystem diagram illustrating the recirculation process for data acquisition, implementation, and public disclosure of results in an information processing device according to one embodiment. The example shown in Figure 12 illustrates a cyclical structure in which the generated and retrieved output data is not treated as "disposable," but rather reused as a "template" for new matching through the following two phases.
[0090] <Performance Feedback Phase> As shown by the arrow (performance FB) pointing from the implementation area 115 to the performance publication area 111 in Figure 12, after the work is completed in each tenant environment, the performance metadata is fed back to the platform. Specifically, the information processing device 10 collects statistical information such as task completion status and required time in the implementation area. In this process, sensitive information such as individual names and specific medical conditions are completely excluded, and only abstracted information such as "Case type: Return to work determination," "Time to completion: 14 days," and "Agreement status: Amicable resolution" is published in the performance disclosure area 111.
[0091] <Attribute Inheritance Phase> In Figure 12, the dotted arrow (attribute inheritance) that runs vertically through the center of the figure is explained. This is a function that accelerates new consensus building, starting from past success stories. When a user with a problem refers to a similar past success story (abstracted information) in the results disclosure area 111, selects it, and makes a connection request, the connection channel formation unit 120 performs the following processing. 1. Parameter inheritance: Attribute information such as "Purpose ID," "Exit Criteria," and "Required Documents List" used in selected past cases is read and copied (inherited) as the initial settings for the newly generated Special Agreement Channel 400. 2. Presentation of the draft: The structure of the outcome data agreed upon in past cases (such as the set of items for employment restrictions) will be presented as a "decision draft" within the new Special Agreement Channel 400. This eliminates the need for users to negotiate terms from scratch, allowing them to quickly generate high-quality results using proven, successful templates. This cycle strengthens the collective intelligence of the entire ecosystem the more the system is used.
[0092] The characteristic configurations of the information processing apparatus, information processing method, and program according to some of the embodiments described above can be summarized as follows.
[0093] [1] An information processing apparatus (10) according to at least some embodiments of the present invention is An information processing device (10) capable of controlling the ownership of data in multiple tenant environments (T) managed by multiple legal entities, A connection control unit (e.g., connection channel formation unit 120) that forms a logical connection channel (e.g., special agreement channel 400) accessible to the first entity and the second entity, based on conditions agreed upon between the first entity managing the first tenant environment (T1) and the second entity managing the second tenant environment (T2), A data control unit (130) performs a process to assign the result data generated by the activities performed in the logical connection channel to the storage area (140) under the management of the first tenant environment (T1) and the second tenant environment (T2), respectively. Equipped with, The data control unit (130), in conjunction with the attribute process, executes control to set the actual result data in a non-retaining state in the storage area (140) within the information processing device (10) associated with the logical connection channel.
[0094] In some embodiments of the present invention, "assigning" the result data to a storage area (140) under the management of each tenant environment T (T1, T2…) is not merely a physical act of replicating or storing the data itself, but also includes the concept of transferring exclusive management rights (ownership) of the data from the platform to each tenant entity, or the concept of a state transition involving a change in the managing entity. Specifically, "ownership" encompasses all processes involving the transfer of control over data, including not only the act of "outputting (transmitting / forwarding)" data from an information processing device to a physically different external server (tenant environment) via a network and placing it under the control of the recipient, but also the act of "outputting (moving / writing)" data from a shared area to a specific private tenant area within the same information processing device, thereby revoking access rights from others or platform operators and changing the managing entity. In this specification, when we refer to data "transfer," it should be interpreted as a broad ownership transfer process that includes not only the physical transmission of data via a network, but also the logical movement (delegation of authority) of data within the information processing device as described above.
[0095] Furthermore, in some embodiments of the present invention, "placing the actual data of the results in a non-retained state" is not limited to physically erasing the data completely from storage or storage media within the information processing device. For example, it broadly includes the concept of transitioning the data to a state where platform operators or other users cannot recover or reuse the actual data through normal operations, such as by activating a logical deletion flag (is_archived, etc.), severing reference links in the database, or destroying encryption keys for data decryption. This makes it possible to achieve effective separation of data sovereignty and reduction of information leakage risk while suppressing the processing load on the system.
[0096] According to the configuration described in [1] above, the result data generated in the logical connection channel formed based on the conditions agreed upon between the first entity and the second entity is assigned to a storage area under the management of each entity's tenant environment, and in conjunction with this assignment process, control is performed to set the storage area associated with the channel within the information processing device (platform) to a state where the actual result data is not held. This prevents the accumulation of actual performance data on the platform, allowing each entity to establish "data sovereignty" by owning and managing data within its own controlled environment. Consequently, it avoids data lock-in by platform operators and fundamentally reduces the risk of information leakage from the platform side.
[0097] [2] In some embodiments, in the configuration of [1] above, The data control unit (130) is configured to hold only the metadata of the result data in the storage area (140) within the information processing device (10) associated with the logical connection channel, in conjunction with the process of assigning the data.
[0098] In the configuration described in [2] above, the data control unit retains only the metadata of the result data in the storage area of the information processing device associated with the logical connection channel, even after the actual result data is no longer held. This makes it possible to maintain and provide value-added platform functions such as searching and referencing results using metadata (such as whether results were achieved, attributes, and summaries) while ensuring the security of highly confidential physical data.
[0099] [3] In some embodiments, in the configuration of [1] or [2] above, The connection control unit is configured to prohibit the formation of the logical connection channel if any one of the predetermined generation conditions, including mutual approval, purpose setting, and termination condition definition, is not met in response to connection requests from the first and second entities.
[0100] According to the configuration described in [3] above, the formation of a logical connection channel is prohibited if any of the predetermined generation conditions, including mutual recognition, objective setting, and termination condition definition, are not met. This prevents situations where communications are initiated without a clear purpose or where discussions take place without a defined goal (termination condition) for reaching a consensus, enabling strict operation that systematically allows only high-quality decision-making activities.
[0101] [4] In some embodiments, in any of the configurations described in [1] to [3] above, The aforementioned information processing device (10) The domain management unit (110) further provides users belonging to the aforementioned multiple tenant environments (T) with multiple types of activity domains that have different combinations of information depth, scope of disclosure, and disclosure period. The domain management unit (110) provides a preparation area (e.g., preparation / examination area 220) for accumulating information or testing hypotheses as a preliminary step to the formation of the logical connection channel. In the aforementioned preparation area, communication functions with other tenants are provided, while the function for generating the aforementioned result data is restricted.
[0102] According to the configuration described in [4] above, a preparatory area is provided for accumulating information and testing hypotheses, as a preliminary step to a logical connection channel (a place where results can be generated). In this preparatory area, communication with other tenants is permitted, but the function of generating result data is restricted. This provides a "safe zone (sandbox)" where users can explore and experiment with information without risk before formal agreements and outcome confirmations involving accountability are made. It also prevents immature, still-developing information from being mistakenly generated as official outcome data.
[0103] [5] In some embodiments, in the configuration of [4] above, The connection control unit is configured not to grant permission to generate the result data in the preparation area (for example, the preparation / examination area 220).
[0104] In the above [5], the configuration is such that in the preparation area, the connection control unit does not grant the authority to generate the result data itself. This ensures that, regardless of user interface errors or other operational mistakes, the system's internal access control logic reliably prevents the generation of results during the preparation phase, thereby enabling more robust and appropriate activity control according to the phase.
[0105] [6] In some embodiments, in any of the configurations [1] to [5] above, The aforementioned outcome data includes, in addition to the agreed conclusion data, transfer rule information that defines the destination to which the outcome data can be transferred or whether it can be reused. When the data control unit (130) receives a request to transfer the result data, it refers to the transfer rule information and determines whether or not the transfer is to a tenant environment (T) with legitimate authority.
[0106] According to the configuration described in [6] above, the output data itself contains transfer rule information that defines its transfer destinations and whether it can be reused, and the data control unit refers to this rule to determine whether or not it can be transferred. This allows for strict and automatic security controls to prevent the data from being leaked to inappropriate tenants or used for unintended secondary purposes when exporting results data, based on rules tied to the data itself, rather than being arbitrarily operated by the platform.
[0107] [7] In some embodiments, in any of the configurations described in [1] to [6] above, The information processing device (10) is The domain management unit (110) further provides users belonging to the aforementioned multiple tenant environments (T) with multiple types of activity domains that have different combinations of information depth, scope of disclosure, and disclosure period. The aforementioned domain management unit (110) provides a performance disclosure domain (111) that publishes metadata of the aforementioned performance data generated in the past, and a recruitment guidelines presentation domain (112) that presents collaboration needs. The connection control unit is configured such that, when a connection request is made starting from the performance data selected in the performance disclosure area (111), it inherits the attribute information contained in the performance data as the purpose setting for the newly generated logical connection channel, or generates and presents a connection candidate that inherits the attribute information.
[0108] According to the configuration described in [7] above, when performance data is selected in the performance disclosure area where metadata of past performance data is published, its attribute information is either inherited as the objective setting for a new logical connection channel, or connection candidates that have inherited the attribute information are presented. This makes it possible to efficiently form future collaborations and matches based on past successful results (achievements). Users can avoid the hassle of setting conditions from scratch, and can achieve highly accurate matches (ecosystem cycle) based on past results.
[0109] [8] Information processing methods according to at least some embodiments of the present invention are An information processing method executed by an information processing device (10) capable of controlling the ownership of data for multiple tenant environments (T) managed by multiple legal entities, Step (S104) of forming a logical connection channel accessible to the first entity and the second entity, based on conditions agreed upon between the first entity managing the first tenant environment (T1) and the second entity managing the second tenant environment (T2), Step (S205) of assigning the result data generated by the activities performed in the logical connection channel to the storage area (140) under the management of the first tenant environment (T1) and the second tenant environment (T2), respectively. In conjunction with the process of assigning the data, the process includes the step (S205) of setting the actual result data in a non-retaining state in the storage area (140) within the information processing device (10) associated with the logical connection channel, Includes.
[0110] According to the method described in [8] above, the result data generated in a logical connection channel formed based on conditions agreed upon between the first entity and the second entity is assigned to a storage area under the management of each entity's tenant environment, and in conjunction with this assignment process, control is performed to make the storage area associated with the channel within the information processing device (platform) not retain the actual result data. This prevents the accumulation of actual performance data on the platform, allowing each entity to establish "data sovereignty" by owning and managing data within its own controlled environment. Consequently, it avoids data lock-in by platform operators and fundamentally reduces the risk of information leakage from the platform side.
[0111] [9] Programs according to at least some embodiments of the present invention A program for causing a computer to function as an information processing device (10) capable of controlling the ownership of data in multiple tenant environments (T) managed by multiple legal entities, To the aforementioned computer, A function to form a logical connection channel accessible to the first entity and the second entity, based on conditions agreed upon between the first entity managing the first tenant environment (T1) and the second entity managing the second tenant environment (T2), A function that performs a process to assign the result data generated by the activities performed in the logical connection channel to the storage area (140) under the management of the first tenant environment (T1) and the second tenant environment (T2), respectively. A function that, in conjunction with the process of assigning the data, executes control to set the actual result data to a non-retaining state in the storage area (140) within the information processing device (10) associated with the logical connection channel, To make it happen.
[0112] According to the program described in [9] above, the result data generated in a logical connection channel formed based on conditions agreed upon between the first and second entities is assigned to a storage area under the management of each entity's tenant environment, and in conjunction with this assignment process, control is performed to set the storage area associated with the channel within the information processing device (platform) to a state where the actual result data is not held. This prevents the accumulation of actual performance data on the platform, allowing each entity to establish "data sovereignty" by owning and managing data within its own controlled environment. Consequently, it avoids data lock-in by platform operators and fundamentally reduces the risk of information leakage from the platform side. [Explanation of Symbols]
[0113] 10(10A,10B): Information Processing Device 11: Load balancer 12: Web / App Server Group 13: Asynchronous Processing Server 14: DB cluster 20A, 20B: User terminals 90: Communication Network 101: CPU 102: Memory 103: Storage 110: Area Management Department 111: Area for disclosing achievements 112: Recruitment requirements presentation area 115: Implementation Area 116: Learning and Inheritance Domain 120: Connection channel forming section 130: Data Control Unit 140: Storage area 141: Area Management Table 142: Participant Permissions Table 143: Results Data Table 144: Decision Structure Table 220: Preparation and Consideration Areas 400: Special Agreement Channel 500: Structured outcome data 510: Judgment / Conclusion Block 520: Next action block 530: Transfer and sharing control block 540: Authenticity Assurance Block 600: Extraction Engine T(T1,T2): Tenant environment
Claims
1. An information processing device that provides information processing to users belonging to multiple tenant environments, The Area Management Department provides various areas of activity, A connection control unit that forms a logical connection channel between a first entity that manages the first tenant environment and a second entity that manages the second tenant environment, Equipped with, The aforementioned domain management unit provides a preparatory area for accumulating information or testing hypotheses as a preliminary step to the formation of the logical connection channel, and in the aforementioned preparatory area, it provides communication functions with other tenants while restricting the function of generating result data. The connection control unit, in response to transition requests from the first and second entities in the preparation area, forms the logical connection channel to which it is granted the authority to generate the result data, provided that predetermined generation conditions, including mutual approval, objective setting, and termination condition definition, are met. Information processing device.
2. The area management unit restricts the function of generating the result data by hiding the UI parts for generating the result data or by not granting access rights to the API for generating the result data to users who are active in the preparation area. The information processing apparatus according to claim 1.
3. The aforementioned outcome data is generated as a structured data object that includes conclusion data determined in the logical connection channel, next action definition data defining tasks to be performed based on the conclusions indicated by the conclusion data, and transfer / sharing control data defining the transfer destination or viewing scope policy for the outcome data. The information processing apparatus according to claim 1 or 2.
4. The domain management unit expands the output data generated in the logical connection channel and further provides an implementation area for task management and recording of execution results within each tenant environment. In the aforementioned implementation area, communication with other tenants is blocked. The information processing apparatus according to claim 1 or 2.
5. The information processing device further comprises an extraction engine that abstracts personal information from the outcome data determined in the logical connection channel, extracts the logical structure of the judgment, and stores it as an abstraction model. When a new logical connection channel is created, the domain management unit presents a draft of a decision based on similar past cases, using the accumulated abstraction model. The information processing apparatus according to claim 1 or 2.
6. The aforementioned domain management unit further provides a performance disclosure domain that publishes metadata of the aforementioned performance data generated in the past, When the connection control unit receives a transition request based on past performance data selected in the performance disclosure area, it reads the objective settings and termination condition definitions used in the past performance data and inherits them as initial settings for the newly generated logical connection channel. The information processing apparatus according to claim 1 or 2.
7. An information processing method executed by an information processing device that provides information processing to users belonging to multiple tenant environments, As a preliminary step to the formation of a logical connection channel between a first entity managing the first tenant environment and a second entity managing the second tenant environment, a preparatory area is provided for information storage or hypothesis testing, and while the preparatory area provides communication functions with other tenants, it restricts the function of generating result data. The steps include forming a logical connection channel to which the authority to generate the outcome data is granted, provided that predetermined generation conditions, including mutual approval, objective setting, and termination condition definition, are met in response to transition requests from the first and second entities in the preparation area, including Information processing methods.
8. A program for causing a computer to function as an information processing device that provides information processing to users belonging to multiple tenant environments, To the aforementioned computer, As a preliminary step to the formation of a logical connection channel between the first entity managing the first tenant environment and the second entity managing the second tenant environment, a preparatory area is provided for information storage or hypothesis testing, and within this preparatory area, a function is provided to restrict the function of generating result data while providing communication functions with other tenants. A function to form a logical connection channel to which the authority to generate the outcome data is granted, provided that predetermined generation conditions, including mutual approval, objective setting, and termination condition definition, are met in response to transition requests from the first and second entities in the preparation area. A program to achieve this.