The invention belongs to the field of computer
data security, and particularly relates to a fine-grained permission
allocation method and
system based on organizations, and the method comprises the steps: constructing a first permission mapping relation
list through manageable objects corresponding to all organization nodes in a to-be-configured organization in a
database and all to-be-configured roles, and establishing a second permission mapping relation
list through each to-be-configured role and each operable service in the
database, so that a user permission model capable of accurately matching the operable service and the manageable object for the
user role can be established based on the first permission mapping relation
list and the second permission mapping relation list. Therefore, operable services and manageable objects with high fine
granularity can be adaptively matched for the target user. According to the method, permission updating of each operation item of the service operation
system can be completed only by modifying a part of the to-be-configured roles and the mapping relation between the operable services and the manageable objects, and the maintenance difficulty of the service operation
system using the method can be effectively reduced.