WO2019020118A1 - 管理系统中即时通讯账号的管理方法 - Google Patents

管理系统中即时通讯账号的管理方法 Download PDF

Info

Publication number
WO2019020118A1
WO2019020118A1 PCT/CN2018/097673 CN2018097673W WO2019020118A1 WO 2019020118 A1 WO2019020118 A1 WO 2019020118A1 CN 2018097673 W CN2018097673 W CN 2018097673W WO 2019020118 A1 WO2019020118 A1 WO 2019020118A1
Authority
WO
WIPO (PCT)
Prior art keywords
role
instant messaging
messaging account
user
employee
Prior art date
Application number
PCT/CN2018/097673
Other languages
English (en)
French (fr)
Inventor
陈达志
Original Assignee
成都牵牛草信息技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority to PE2020000089A priority Critical patent/PE20200330A1/es
Priority to KR1020207005657A priority patent/KR20200029590A/ko
Priority to AU2018308527A priority patent/AU2018308527A1/en
Priority to JP2020503024A priority patent/JP7164091B2/ja
Priority to MX2020000995A priority patent/MX2020000995A/es
Priority to CA3070871A priority patent/CA3070871A1/en
Priority to EP18838566.0A priority patent/EP3661119A4/en
Priority to EA202090406A priority patent/EA202090406A1/ru
Application filed by 成都牵牛草信息技术有限公司 filed Critical 成都牵牛草信息技术有限公司
Priority to BR112020001648-9A priority patent/BR112020001648A2/pt
Priority to US16/633,546 priority patent/US20200304440A1/en
Publication of WO2019020118A1 publication Critical patent/WO2019020118A1/zh
Priority to PH12020500118A priority patent/PH12020500118A1/en
Priority to CONC2020/0000844A priority patent/CO2020000844A2/es
Priority to ZA2020/00540A priority patent/ZA202000540B/en

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L51/00User-to-user messaging in packet-switching networks, transmitted according to store-and-forward or real-time protocols, e.g. e-mail
    • H04L51/04Real-time or near real-time messaging, e.g. instant messaging [IM]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L51/00User-to-user messaging in packet-switching networks, transmitted according to store-and-forward or real-time protocols, e.g. e-mail
    • H04L51/58Message adaptation for wireless communication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • H04L63/105Multiple levels of security
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/20Network architectures or network communication protocols for network security for managing network security; network security policies in general

Definitions

  • the invention relates to a method for managing an instant messaging account in a management system such as ERP and CRM.
  • Role-based access control is one of the most researched and matured database rights management mechanisms in recent years. It is considered to be an ideal candidate to replace traditional mandatory access control (MAC) and autonomous access control (DAC). Traditional autonomous access control has high flexibility but low security. Forced access control is highly secure but too restrictive. Role-based access control combines both ease of management and reduces the complexity, cost, and probability of errors. Therefore, it has been greatly developed in recent years.
  • the basic idea of role-based access control (RBAC) is to divide different roles according to different functional positions in the enterprise organization view, encapsulate the access rights of database resources in roles, and indirectly access database resources by being assigned different roles.
  • the role-based permission control mechanism can manage the access rights of the system simply and efficiently, which greatly reduces the burden and cost of the system rights management, and makes the system rights management more in line with the business management specifications of the application system.
  • the traditional role-based user rights management adopts the "role-to-user one-to-many” association mechanism, and the "role” is group/class nature, that is, one role can simultaneously correspond to/associate multiple users, and the role is similar to the post/
  • the concept of position/work type the authorization of user rights under this association mechanism is basically divided into the following three forms: 1.
  • the role (class/group/post/work type) is authorized (a role can be associated with multiple users), the user obtains the permission through the role, and the authority authority is the group/class nature role; As shown in Figure 3, the above two methods are combined.
  • both 2 and 3 need to authorize the role of the class/group nature, and the way of authorization through the role of class/group/post/work type has the following disadvantages: 1.
  • the above two processing methods not only require a long time for the role authorization in the case of a large number of role permissions, but also are easy to make mistakes, the user is cumbersome and troublesome to operate, and is also prone to errors resulting in loss to the system user.
  • the employee/user's form operation permissions change either the employee/user is removed from the role or the role is added to meet the job requirements.
  • the defect of the first method is the same as the above-mentioned "direct authorization to the user" method.
  • the new role involves the creation, association, and authorization of the role. Especially in the case of a large number of roles and a large number of users associated with the role, it is difficult to remember which users are associated with the role.
  • Instant messaging is an important communication tool for internal and external enterprises.
  • the commonly used instant messaging software includes QQ, WeChat, MSN, Fetion, etc.
  • instant messaging accounts such as QQ are usually directly assigned to people.
  • the user the following problems exist in the use process: A. If an employee has multiple positions in the enterprise, an effective work handover cannot be achieved when leaving the company or adjusting the post.
  • Zhang San is a sales engineer in the sales department of the Building Materials Division and a sales engineer in the sales department of the Aircraft Division. Zhang San is now leaving the sales engineer position of the Aircraft Division to be replaced by Li Si.
  • Zhang San’s QQ cannot be directly used by Li Si, because there are still many building materials customers on Zhang San’s QQ who need to contact and follow up.
  • Li Si Only let Li Si re-use a new QQ to add aircraft customers (adding customers needs the consent of the other party, not only increasing the workload will make the work lag, but also the customer may not know who the adder refuses, thus affecting the work), On the one hand, it is easy to leave a bad impression on customers. On the other hand, Li Si does not understand the past communication with the aircraft customers before Zhang San (message record), and the aircraft customers are likely to continue to contact Zhang San. It is easy to disclose confidential information of aircraft customers.
  • Li Si will be able to see the QQ news records and new news of building materials customers (Li Si just took over the sales of the Aircraft Division) and easily leaked building materials.
  • the confidential information of the class customers only take over the sales work of the building materials division, and can not take over the QQ of Zhang San, because after taking over, they will see the QQ message records and new news of the aircraft customers.
  • Subsequent messages may be sent to the QQ, and subsequent messages will continue to be known to salespeople who should not know.
  • the above is already a good situation. If the QQ used by the financial staff and the QQ used by the R&D personnel are related to the sales personnel after multiple associations, the confidential information of the research and development or the confidential financial information will be associated with the current information. Sales personnel know that it is easy to cause sensitive information to leak, which may cause serious losses to the company.
  • the employee A is in charge of the production supervisor and the post-sales supervisor. Now he is no longer in charge of the production supervisor (the employee's instant messaging account cannot be replaced by the replacement, because it also contains the post-sales supervisor's job-related communication information), if it is re-produced If the supervisor's successor assigns a new instant messaging account, then it is also necessary to notify the communication contact one by one (for example, equipment maintenance personnel, subcontractors, etc.), which not only has a large workload but also causes additional work for the other party, and the employee A It is also possible to receive subsequent production-type communication messages (for example, the sender of the information does not know that employee A is no longer in charge of production supervisor).
  • the communication contact one by one for example, equipment maintenance personnel, subcontractors, etc.
  • the object of the present invention is to overcome the deficiencies of the prior art and provide a management method for an instant messaging account in a management system, which binds a character-type instant messaging account to a role, and the employee (at the time of employment) obtains the role associated with the user.
  • Role-based instant messaging account When the employee leaves the company, the system administrator (or the corresponding administrator) directly cancels the association between the user and the role of the employee. The employee immediately loses the right to use the instant messaging account of the role. The risk of leakage of confidential information of the enterprise; when the employee is transferred, the system administrator (or the corresponding administrator) directly cancels the association between the employee (the user corresponding to the employee) and the original role, and then associates the new role to automatically obtain the new one.
  • the role-specific role of the instant messaging account can achieve seamless docking, to ensure that the user's instant messaging account is updated in a timely manner, there will be no delay or omission of the communication account handover, will not affect the normal use of the communication account, and also circumvented The risk of disclosure of confidential information.
  • a method for managing an instant messaging account in a management system comprising the following steps:
  • the character-associated instant messaging account is associated with the role.
  • a character-type instant messaging account can only be associated with one role, and one role can only be associated with one role-specific instant messaging account;
  • the role of the instant messaging account associated with all the roles associated with the user is the role of the user and/or the employee corresponding to the user. .
  • Step (3) may be performed after step (1), before step (2), or after step (2).
  • the role-specific instant messaging account associated with the role cannot be replaced; or, when a role-specific instant messaging account is associated with the role and the role-specific instant messaging account is used, the role is associated. The role of the instant messaging account cannot be replaced.
  • the method for managing an instant messaging account further includes: selecting one or more roles as supervisory roles, and setting a supervised role for each supervised role, respectively, and supervising the user associated with the role or the corresponding employee of the user can all corresponding to the supervised role
  • the character-associated instant messaging account associated with the supervised role operates, and the operations include viewing the communication content.
  • the instant messaging account management method further includes: associating a personal instant messaging account for the user/employee, and at the same time, one user/employee can only associate with one personal instant messaging account, and a personal instant messaging account can only be associated with one user/ Employees; the user and employee described in this application have a one-to-one relationship, that is, one user corresponds to one employee, and one employee corresponds to one user. After the corresponding relationship between the user and the employee is established, the user corresponding to the employee cannot be Other employees correspond.
  • the personal instant messaging account associated with the user/employee cannot be replaced; or, when the user/employee is associated with a personal instant messaging account and uses the personal instant messaging After the account number, the personal instant messaging account associated with the user/employee cannot be replaced.
  • the personal instant messaging account associated with the user is used as the personal instant messaging account of the employee corresponding to the user.
  • the personal instant messaging account associated with the employee is used as the personal instant messaging account of the user corresponding to the employee.
  • the method for managing an instant messaging account further includes: selecting one or more roles as supervisory roles, and setting a supervised role for each supervised role, respectively: the user associated with the supervised role or the corresponding employee of the user can correspond to the supervised role All of the users of the supervised role are associated with the personal nature of the instant messaging account; or the user associated with the supervised role or the corresponding employee of the user can instantly associate the personal characteristics of the employee associated with all supervised roles corresponding to the supervised role
  • the communication account is operated.
  • the character-based instant messaging account is an account of an instant messaging program in the system or an account of an instant messaging software provided by a third party
  • the personalized instant messaging account is an instant messaging provided by an account of the instant messaging program or a third party in the system.
  • Software account number is an account of an instant messaging program in the system or an account of an instant messaging software provided by a third party
  • the personalized instant messaging account is an instant messaging provided by an account of the instant messaging program or a third party in the system.
  • the beneficial effects of the present invention are as follows: (1)
  • the present invention provides a management method for an instant messaging account in a management system, which binds a character-type instant messaging account to a role, and the employee (at the time of employment) passes the role associated with the user. Obtain a character-based instant messaging account.
  • the system administrator or the corresponding administrator
  • the employee is automatically lost the right to use the instant messaging account of the role. Avoid the risk of disclosure of confidential information; when the employee is transferred, the system administrator (or the corresponding administrator) directly cancels the association between the employee (the user corresponding to the employee) and the original role, and then automatically associates the new role with the new role.
  • the role-specific instant messaging account corresponding to the new role can realize seamless docking, ensuring that the instant messaging account used by the user is updated in time, and there will be no lag or omission in the communication account handover, which will not affect the normal use of the communication account by the employee, and also avoid The risk of disclosure of confidential information.
  • the role of the role "production worker 1" associated with the instant messaging account is QQ number 123456, when the user corresponding to the employee Zhang San is associated with "production worker 1", then Zhang San uses the QQ number 123456, when Zhang San leaves the company, the system
  • the administrator or the corresponding administrator
  • Zhang San automatically loses the use right of QQ number 123456, avoiding the delay of QQ handover and causing "production worker 1" Relevant confidential information was leaked to Zhang San; when the new employee Li Si succeeded Zhang San’s work, the user corresponding to Li Si was directly associated with “production worker 1”, and Li Si automatically obtained the role of “production worker 1”.
  • Example of adjustment The employee Zhang San has to transfer from the production department to the after-sales department.
  • the system administrator cancels the association between the user corresponding to Zhang San and the original role “production worker 1”, and then associates with the new role of the after-sales department “after-sales service personnel 3 "Zhang San automatically obtained the role of the "after-sales service personnel 3" role corresponding to the role of the nature of the QQ number 987654.
  • the present invention associates a character-type instant messaging account for each role, and assigns a corresponding role-type instant messaging account to the employee while assigning the job number or work, and does not need to separately assign an instant messaging account to the employee.
  • the present invention associates a character-type instant messaging account for each role, and assigns a corresponding role-type instant messaging account to the employee while assigning the job number or work, and does not need to separately assign an instant messaging account to the employee.
  • there is no lag in the distribution of instant messaging accounts of the character nature which reduces the workload of instant messaging account allocation.
  • the role-specific instant messaging account associated with the role A and the role B is automatically assigned to the employee A, and there is no need to separately assign the instant messaging account to the employee A.
  • the character-associated instant messaging account associated with the role is assigned to other personnel, and is not assigned to the person who is not responsible for the role of the role, because the role of the invention is the job number/work
  • the role of the nature of the tag ensures that the instant messaging account will not be leaked to unrelated personnel during the process of replacing the user.
  • the user corresponding to the employee A is associated with the two roles of the electric appliance salesperson 1 and the software salesperson. Since the employee A resigns (the employee resigns: the electric appliance salesperson 1 and the software salesperson 1 are canceled corresponding to the employee A) If the user is associated, the user corresponding to the employee A or the employee A automatically loses the “right to use the instant messaging account associated with the role of the salesperson 1 and the instant messaging account associated with the software salesperson 1”.
  • Member 1 is associated with the user corresponding to employee B (employee B obtains the role of the electric salesperson 1 associated with the instant messaging account), and the software salesperson 1 is associated with the employee corresponding to the employee C (employee C obtains the role of the software salesperson 1 Communication account), then employee B can only obtain the information related to the sales of the appliance through the role-specific communication account corresponding to “Electricity Salesperson 1”, and cannot access the information related to software sales. Similarly, employee C can only pass “software sales”. The role-based communication account corresponding to member 1" obtains software sales related information, and cannot be contacted with electrical sales. Related information.
  • the character-associated instant messaging account is associated with the role according to the work content, and the contact on the communication account does not have to worry about the content of the message being unknown to the unrelated person when sending the message, because the role is the current nature of the instant messaging account.
  • the user is now responsible for the relevant work.
  • the role of role A is to perform attendance statistics
  • role A is associated with instant messaging account X
  • employee A becomes the current user of instant messaging account X
  • employee A is currently
  • the work content must include the attendance statistics.
  • the contact on the instant messaging account X sends the attendance related message to the instant messaging account X, the attendance message will not be seen by the unrelated person.
  • role A is associated with instant messaging account X
  • role A cannot be associated with other instant messaging accounts
  • instant messaging account X cannot be associated with other roles.
  • the user associated with the supervisor role or the employee corresponding to the user has the right to view the communication content (or the right of the user associated with the supervised role or the instant messaging account of the employee corresponding to the user if the supervisory role is authorized. View the communication content of the instant messaging account associated with the supervised role), so that the supervisors at the higher level can supervise and manage the work of their subordinates (or corresponding roles).
  • employee A For example, if employee A is late, his supervisor is not deducted because of the excellent performance of employee A. You can send a message to employee A's personal instant messaging account. Don't worry about the employee being taken over after the employee is resigned or transferred. The employees of the work saw that it had a negative impact on the company.
  • the role of the application is a one-to-one relationship to the user.
  • One role can only be associated with a unique user at the same time, and one user is associated with one or more roles.
  • Permissions that is, users gain access to their associated roles
  • the role's permission changes are much less than the user permissions in the traditional mechanism.
  • the number of roles of the nature of the independent body is small. Although the employee turnover is large, the change of the post number/station number is small (even if there is no change in a certain period of time, that is, the role does not change), This will greatly simplify the user's rights management and reduce the overhead of the system.
  • Zhang San due to Zhang San’s resignation or transfer, Zhang San will no longer work as a “buyer 3”, and Zhang will cancel the association with “Purchaser 3”; Li Si will take over as “Purchaser”. 3"
  • the role of this role only need to associate Li Si with the role, then Li Si automatically obtained the role of "Purchase 3" (because the role has been authorized according to the role of the role) and role-specific communication account .
  • the traditional authority management mechanism defines the role as a group, a job type (post), a class, etc.
  • the role is a one-to-many relationship with the user. In the actual system use process, because the user is often required in the operation process.
  • the permissions are adjusted. For example, when the employee permissions are changed, the permissions of an employee associated with the role change. We cannot change the permissions of the entire role because of the change of the individual employee permissions, because the role is also associated with other permissions. Unchanged employees. So in response to this situation, either create a new role to satisfy the employee whose permissions have changed, or directly authorize (disengage the role) from the employee based on the permission requirements.
  • the above two processing methods not only require a long time for the role authorization in the case of a large number of role permissions, but also are easy to make mistakes, the user is cumbersome and troublesome to operate, and is also prone to errors resulting in loss to the system user.
  • the role since the role is an independent individual, the role permission can be changed to achieve the goal.
  • the method of the present application seems to increase the workload when the system is initialized, it can be made by copying or the like to make the role or authorization more efficient than the traditional group/class nature, because the group/class role is not considered.
  • the application scheme will make the permission setting clear and clear; especially after the system is used for a period of time (the user/role authority changes dynamically), the application scheme can greatly improve the system usage for the system user.
  • the efficiency of the rights management makes the dynamic authorization simpler, more convenient, clearer and clearer, and improves the efficiency and reliability of the permission setting.
  • the traditional group/class role authorization method is error-prone, and the method of the present application greatly reduces the probability of authorization error, because the method of the present application only needs to consider the role as an independent individual, without considering the traditional method to associate the role of the group. What are the commonalities of multiple users? Even if the authorization error occurs, it only affects the user associated with the role, while the traditional group-based role affects all users associated with the role. Even if a permission authorization error occurs, the correction method of the present application is simple and short, and the traditional group-type role needs to consider the commonality of all users associated with the role when correcting the error, and not only the modification when there are many function points. Troublesome, complicated, very error-prone, and in many cases only new roles can be created.
  • the method of the present application is as follows: the transferred user associates several roles.
  • the user When adjusting the post, the user is first unlinked from the role in the original department (the canceled roles can be re-associated to other users), and then Associate users with roles in the new department. The operation is simple and will not go wrong.
  • FIG. 1 is a schematic diagram of a manner in which a system directly authorizes a user in the background art
  • FIG. 2 is a schematic diagram of a manner in which a system authorizes a group/class role in the background art
  • FIG. 3 is a schematic diagram of a manner in which a system directly authorizes a user and authorizes a group/class role role in the background art
  • FIG. 4 is a schematic diagram of a manner in which a system authorizes a user through an independent individual role
  • FIG. 5 is a flowchart of a management method according to an embodiment of the present invention.
  • a method for managing an instant messaging account in a management system includes the following steps: creating a system role, as shown in FIG. 4, the roles are independent individuals, not groups/classes, and the same During a time period, a role can only be associated with a unique user, and a user is associated with one or more roles; one user corresponds to one employee, one employee corresponds to one user, and the employee determines (acquires) permissions through the role associated with the corresponding user.
  • the employee and the user are in a one-to-one relationship and are bound for life. After the user corresponds to the employee, the user belongs to the employee, and the user can no longer associate with other employees; if the employee leaves the job, the user cannot correspond to other employees. After the employee re-joins, the employee still uses the original user.
  • the character-associated instant messaging account is associated with the role (for a role, further, it can also be understood as: according to the working content of the role in the management system, an instant messaging account is associated with the role as the role.
  • Character nature instant messaging account character nature instant messaging account
  • character nature instant messaging account is the instant number of the job number / station number.
  • a role-based instant messaging account can only be associated with one role, and a role can only be associated with a role-based instant messaging account; when it is necessary to replace a character-based instant messaging account for a role, cancel the role and the original character nature instant messaging
  • the association of the account, the role is associated with the new role-specific instant messaging account.
  • the character-based instant messaging account is an account of an instant messaging program (software) in the system (ie, an instant messaging account, an instant messaging account in the system; in this case, an instant messaging account/role-like instant messaging account is also created) Step), and / or the account of the instant messaging software provided by the third party (ie: instant messaging account, such as qq number, micro signal, etc.).
  • the role-specific instant messaging account associated with all the roles associated with the user is the instant messaging account of the role of the user and/or the employee corresponding to the user.
  • the invention binds a role-based instant messaging account to a role, and the employee obtains the role-specific instant messaging account through the corresponding user-associated role.
  • the system administrator or the corresponding administrator directly cancels the user corresponding to the employee.
  • the retired employee In association with the role, the retired employee automatically loses the right to use the instant messaging account of the role to avoid the risk of disclosure of confidential information; when the employee is transferred, the system administrator (or the corresponding administrator) directly cancels the employee and
  • the association of the original character, and then associated with the new role can automatically obtain the role-specific instant messaging account corresponding to the new character, which can realize seamless docking, ensure that the instant messaging account used by the user is updated in time, and there is no lag in communication account handover or Missing, will not affect the normal use of communication accounts by employees, and also avoid the risk of leakage of confidential information.
  • the role of the role "production worker 1" associated with the instant messaging account is QQ number 123456, when the user corresponding to the employee Zhang San is associated with "production worker 1", then Zhang San uses the QQ number 123456, when Zhang San leaves the company, the system
  • the administrator or the corresponding administrator
  • Zhang San automatically loses the use right of QQ number 123456, avoiding the delay of QQ handover and causing "production worker 1" Relevant confidential information was leaked to Zhang San; when the new employee Li Si succeeded Zhang San’s work, the user corresponding to Li Si was directly associated with “production worker 1”, and Li Si automatically obtained the role of “production worker 1”.
  • Example of adjustment The employee Zhang San has to transfer from the production department to the after-sales department.
  • the system administrator cancels the association between the user corresponding to Zhang San and the original role “production worker 1”, and then associates with the new role of the after-sales department “after-sales service personnel 3 "Zhang San automatically obtained the role of the "after-sales service personnel 3" role corresponding to the role of the nature of the QQ number 987654.
  • the character-associated instant messaging account associated with the role is assigned to other personnel, and is not assigned to the person who is not responsible for the role of the role, because the role of the invention is the nature of the post number/station number.
  • the role ensures that the instant messaging account will not be leaked to unrelated personnel during the process of replacing the user.
  • the user corresponding to the employee A is associated with the electric appliance salesperson 1 and the software salesperson 1. Since the employee A resigns, the electric appliance salesperson 1 is associated with the employee corresponding to the employee B, and the software salesperson 1 is associated with the user corresponding to the employee C, then Employee B can only obtain the information related to the sales of the appliance through the role-specific communication account corresponding to the “Electronic Salesperson 1”, and cannot access the information related to the software sales. Similarly, the employee C can only pass the “software salesperson 1”. The role-specific communication account obtains information related to software sales, and cannot access information related to sales of electrical appliances.
  • the character-associated instant messaging account is associated with the role, and the contact on the communication account does not have to worry about the content of the message being unknown to the unrelated person when sending the message, because the current user of the role of the instant messaging account is now Inevitably responsible for related work.
  • the role of role A is to perform attendance statistics
  • role A is associated with instant messaging account X
  • employee A becomes the current user of instant messaging account X
  • employee A is currently
  • the work content must include the attendance statistics. After the contact on the instant messaging account X sends the attendance related message to the instant messaging account X, the attendance message will not be seen by the unrelated person.
  • a method for managing an instant messaging account in a management system includes the following steps: creating a system role, as shown in FIG. 4, the roles are independent individuals, not groups/classes, and the same During the time period, a role can only be associated with a unique user, and a user is associated with one or more roles; according to the work content of the role in the management system, the character-associated instant messaging account is associated with the character. At the same time, a role-specific instant messaging account can only be associated.
  • a role can only be associated with a role-specific instant messaging account; establish an association between the user and the role, for any user, the role of the role associated with all the roles associated with the user instant messaging account as the user and / Or the instant messaging account of the role of the employee corresponding to the user.
  • the role-specific instant messaging account associated with the role cannot be replaced; or, when a role-specific instant messaging account is associated with the role and the role-specific instant messaging account is used. After that, the role-specific instant messaging account associated with the role cannot be replaced. That is, the character and role nature instant messaging account is bound for life. If the role is disabled, the corresponding role-based instant messaging account can no longer be associated with other roles, but the user associated with the supervisory role corresponding to the role or the employee corresponding to the user. The character instant messaging account can still be operated. After the role is re-enabled, the role still uses the character-associated instant messaging account that was originally associated.
  • role A is associated with instant messaging account X
  • role A cannot be associated with other instant messaging accounts
  • instant messaging account X cannot be associated with other roles.
  • the method for managing an instant messaging account further includes: selecting one or more roles as supervisory roles, respectively setting a supervised role for each supervised role, and supervising the user associated with the role or corresponding to the user
  • the employee can operate the role-specific instant messaging account associated with all supervised roles corresponding to the supervisory role, including viewing the communication content.
  • the communication content If the communication content is not viewed by the user associated with the supervised role, the communication content still displays the unviewed status, but displays the viewing record of the supervised role, such as the supervised role of the operation, the user associated with the supervised role, and the employee corresponding to the user. , operation time, operation content, etc.
  • the method for managing an instant messaging account further includes: selecting one or more roles as supervisory roles, and setting a supervised role for each supervisory role, respectively: supervising the user or the user associated with the role
  • the corresponding employee can operate the personal-type instant messaging account of the user associated with all the supervised roles corresponding to the supervised role; or the supervised role-associated user or the corresponding employee of the user can be able to supervise all the supervised roles corresponding to the supervised role
  • the personal nature of the employee corresponding to the associated user is operated by the instant messaging account.
  • the user associated with the supervised role has the authority to view the communication content of the instant messaging account of the user/employee associated with the supervised role, so that the superior supervisor can supervise and manage the work of his subordinates.
  • the method for managing an instant messaging account further includes: associating a personal instant messaging account for the user/employee (for a user/employee, further, it can also be understood as: for the user/employee) Associate an instant messaging account as the personal instant messaging account of the user/employee.
  • a personal instant messaging account can only be associated with one user/employee.
  • the personal instant messaging account is an account of an instant messaging program (software) in the system (ie, an instant messaging account, an instant messaging account in the system; in this case, an instant messaging account/personal instant messaging account is also created). Step), and / or the account of the instant messaging software provided by the third party (ie: instant messaging account, such as qq number, micro signal, etc.).
  • the personal instant messaging account associated with the user/employee will be suspended.
  • the personal instant messaging account will not be assigned to other employees/users, ensuring the communication message content of the personal instant messaging account. Not leaked, but the employee's superior supervisor can still operate the personal instant messaging account if authorized. If the employee returns to the company after leaving the company, the original personal instant messaging account of the employee is automatically used again for the employee and/or the corresponding user of the employee (the personal instant messaging account is always associated with the user once it is associated with the user) The status of the association cannot be changed; the personal instant messaging account is always associated with the employee once it is associated and cannot be changed).
  • the personal instant messaging account associated with the user/employee cannot be replaced; or, when the user/employee is associated with a personal instant messaging account and uses the personal instant messaging After the account number, the personal instant messaging account associated with the user/employee cannot be replaced.
  • the personal instant messaging account associated with the user is used as the personal instant messaging account of the employee corresponding to the user.
  • the personal instant messaging account associated with the employee is used as the personal instant messaging account of the user corresponding to the employee.
  • employee A For example, if employee A is late, his supervisor is not deducted because of the excellent performance of employee A. You can send a message to employee A's personal instant messaging account. Don't worry about the employee being taken over after the employee is resigned or transferred. The employees of the work saw that it had a negative impact on the company.
  • the role must select a department. Once the role is selected, the role belongs to the department. The name of the role is unique under the department. The role number is unique in the system. The role is authorized according to the work content of the role.
  • the user needs to adjust the posts across departments, it also includes a user cross-department management process, which includes: (1) canceling the association between the user and the role in the original department; and (2) associating the user with the role in the new department.
  • the user automatically obtains the corresponding rights of the instant messaging account associated with the role.
  • the instant messaging account management of the present application adopts an independent individual role, and the following analysis is performed on the advantages of authorizing the user through the independent individual role: the user determines through the association with the role ( Obtain the permission. If you want to modify the user's permissions, you can adjust the permissions owned by the role to achieve the purpose of changing the permissions of the user associated with the role. Once a user associates a role, that user has all the operational privileges for that role.
  • the role of the role to the user is one-to-one (when the role is associated with a user, other users can no longer associate the role; if the role is not associated with the user, it can be selected by other users; that is, a role can be And can only be associated by one user).
  • a user's relationship to a role is one-to-many (one user can associate multiple roles at the same time).
  • Role definition The role does not have the nature of group/class/category/post/job/work, but a non-collection nature, the role is unique, the role is an independent independent entity; in the enterprise application is equivalent Job number (The job number here is not a post, one post may have multiple employees at the same time, and one job number can only correspond to one employee at the same time).
  • a company system can create the following roles: general manager, deputy general manager 1, deputy general manager 2, Beijing sales manager, Beijing sales manager, Beijing sales manager, Shanghai sales engineer 1, Shanghai sales Engineer 2, Shanghai Sales Engineer 3, Shanghai Sales Engineer 4, Shanghai Sales Engineer 5...
  • general manager deputy general manager 1, deputy general manager 2, Beijing sales manager, Beijing sales manager, Shanghai sales engineer 1, Shanghai sales Engineer 2, Shanghai Sales Engineer 3, Shanghai Sales Engineer 4, Shanghai Sales Engineer 5...
  • Zhang San serves as the company's deputy general manager 2, and also serves as a sales manager in Beijing, then Zhang The three roles to be associated are Deputy General Manager 2 and Beijing Sales Manager. Zhang San has the rights to these two roles.
  • roles are group/class/post/position/work type, and one role can correspond to multiple users.
  • the concept of "role" in this application is equivalent to the post number/station number, and is similar to the role in the film and television drama: a character can only be played by one actor at the same time (childhood, juvenile, middle-aged). And an actor may be decorated with multiple angles.
  • the role After the role is created, you can associate the role in the process of creating the user, or you can associate it at any time after the user is created. After the user associates the role, the relationship with the role can be released at any time, and the relationship with other roles can be established at any time.
  • the composition of the character is: post name + post number.
  • workshop production workers 1, workshop production workers 2, workshop production workers 3... roles are independent individuals, equivalent to the concept of job number and station number, different from the role in the traditional authority management system, the concept of role in the traditional system It is the group/class nature of the position/position/work type.
  • the following example shows the relationship between employees, users and roles after the employee Zhang San enters a company: 1. New entry: The employee is newly hired, and directly associates the role of the corresponding job number/station number for the user (employee). Yes, for example: Zhang San joined the company (the company assigned a three-user for Zhang San), the job content is in the sales department, responsible for the sales of refrigerator products in Beijing area (the corresponding role is to sell the sales engineer under the 5 "This role", Zhang San users directly select the "sales engineer 5" role association.
  • Zhang also arranged for Zhang San to be responsible for the sales of regional TV products in Beijing (the corresponding role is to sell the role of “Sales Engineer 8” under the Ministry of Sales) and concurrently as the head of the after-sales department (corresponding to the after-sales department)
  • the three users added the roles of “sales engineer 8” under the sales department and “sales department supervisor 1” under the after-sales department.
  • Zhang San employees associated three roles, respectively.
  • Zhang San users have the authority of these three roles.
  • Zhang San serves as the post-sales manager (corresponding to the role of “after-sales manager” in the after-sales department) and no longer take up other jobs. Then Zhang San user is associated with the role of “after-sales manager” in the after-sales department, and cancels the three roles previously associated (Sales Engineer 5 under Sales, Sales Engineer 8 and “After Sales Manager 1” under the after-sales department) At this time, Zhang San users only have the authority of the role of “after-sales manager” under the after-sales department.
  • This application authorizes the role of the nature of the post number/station number, and the user determines the (acquired) authority by associating the role, and the control of the user authority is realized by a simple user-role relationship. It makes the permission control simple, easy to operate, clear and clear, and greatly improves the authorization efficiency and authorization reliability.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Computing Systems (AREA)
  • Theoretical Computer Science (AREA)
  • Bioethics (AREA)
  • General Health & Medical Sciences (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Health & Medical Sciences (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)
  • Information Transfer Between Computers (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

本发明公开了一种管理系统中即时通讯账号的管理方法,包括:创建系统角色,角色是独立的个体;根据管理系统中角色的工作内容为角色关联角色性质即时通讯账号,同一时段,一个角色性质即时通讯账号只能关联一个角色、一个角色只能关联一个角色性质即时通讯账号;建立用户和角色之间的关联关系,以用户所关联的所有角色关联的角色性质即时通讯账号作为该用户和/或该用户对应的员工的角色性质即时通讯账号。本发明员工通过对应的用户关联的角色获得角色性质即时通讯账号,员工离职时,取消该员工对应的用户与角色的关联,则离职员工自动失去权限,避免企业机密信息泄露的风险;员工调岗时,能够实现无缝对接,不会出现通讯账号交接滞后或遗漏。

Description

管理系统中即时通讯账号的管理方法 技术领域
本发明涉及一种ERP、CRM等管理系统中即时通讯账号的管理方法。
背景技术
基于角色的访问控制(RBAC)是近年来研究最多、思想最成熟的一种数据库权限管理机制,它被认为是替代传统的强制访问控制(MAC)和自主访问控制(DAC)的理想候选。传统的自主访问控制的灵活性高但是安全性低,强制访问控制安全性高但是限制太强;基于角色的访问控制两者兼具,不仅易于管理而且降低了复杂性、成本和发生错误的概率,因而近年来得到了极大的发展。基于角色的访问控制(RBAC)的基本思想是根据企业组织视图中不同的职能岗位划分不同的角色,将数据库资源的访问权限封装在角色中,用户通过被赋予不同的角色来间接访问数据库资源。
在大型应用系统中往往都建有大量的表和视图,这使得对数据库资源的管理和授权变得十分复杂。由用户直接管理数据库资源的存取和权限的收授是十分困难的,它需要用户对数据库结构的了解非常透彻,并且熟悉SQL语言的使用,而且一旦应用系统结构或安全需求有所变动,都要进行大量复杂而繁琐的授权变动,非常容易出现一些意想不到的授权失误而引起的安全漏洞。因此,为大型应用系统设计一种简单、高效的权限管理方法已成为系统和系统用户的普遍需求。
基于角色的权限控制机制能够对系统的访问权限进行简单、高效的管理,极大地降低了系统权限管理的负担和代价,而且使得系统权限管理更加符合应用系统的业务管理规范。
然而,传统基于角色的用户权限管理均采用“角色对用户一对多”的关联机制,其“角色”为组/类性质,即一个角色可以同时对应/关联多个用户,角色类似于岗位/职位/工种等概念,这种关联机制下对用户权限的授权基本分为以下三种形式:1、如图1所示,直接对用户授权,缺点是工作量大、操作频繁且麻烦;当发生员工变动(如调岗、离职等),该员工涉及到的所有权限必须要作相应调整,特别是对于公司管理人员,其涉及到的权限多,权限调整的工作量大、繁杂,容易出错或遗漏,影响企业的正常运营,甚至造成不可预估的损失。
2、如图2所示,对角色(类/组/岗位/工种性质)进行授权(一个角色可以关联多个用户),用户通过角色获得权限,权限授权主体是组/类性质角色;3、如图3所示,以上两种方式结合。
以上的表述中,2、3均需要对类/组性质的角色进行授权,而通过类/组/岗位/工种性质的角色进行授权的方式有以下缺点:1、用户权限变化时的操作难:在实际的系统使用过程中,经常因为在运营过程中需要对用户的权限进行调整,比如:在处理员工权限变化时,角色关联的某个员工权限发生变化,我们不能因该个别员工权限的变化而改变整个角色的权限,因为该角色还关联了其他权限未变的员工。因此为了应对该种情况,要么创建新角色来满足该权限发生变化的员工,要么对该员工根据权限需求直接授权(脱离角色)。以上两种处理方式,在角色权限较多的情况下对角色授权不仅所需时间长,而且容易犯错,使用方操作起来繁琐又麻烦,也容易出错导致对系统使用方的损失。
员工/用户的表单操作权限发生变化时,要么员工/用户脱离角色,要么新增角色来满足工作要求。第一种方式的缺陷同上述“直接对用户授权”方式的缺陷。第二种方式,新增角色便涉及到角色的新建、关联、授权工作,特别在角色多、角色关联的用户也多的情况下,角色具体关联了哪些用户是很难记住的。
2、要长期记住角色包含的具体权限难:若角色的权限功能点比较多,时间一长,很难记住角色的具体权限,更难记住权限相近的角色之间的权限差别,相近角色的权限也很容易混淆;若要关联新的用户,无法准确判断应当如何选择关联。
3、因为用户权限变化,则会造成角色创建越来越多(若不创建新角色,则会大幅增加直接对用户的授权),更难分清各角色权限的具体差别。
4、调岗时,若要将被调岗用户的很多个权限分配给另外几个用户承担,则处理时必须将被调岗用户的这些权限区分开来,分别再创建角色来关联另外几个用户,这样的操作不仅复杂耗时,而且还很容易发生错误。
即时通讯是各企事业单位对内、对外的重要交流沟通工具,目前常用的即时通讯软件包括QQ、微信、MSN、飞信等,传统企业管理模式中即时通讯账号如QQ号通常直接被分配给人或用户,使用过程中存在以下问题:A、若某员工在企业中有多个岗位,离职或调岗时无法实现有效的工作交接。例如,张三是建材事业部销售一部的销售工程师,同时也是飞机事业部销售一部的销售工程师,张三现在要卸任飞机事业部销售一部的销售工程师一职,由李四接任该职位,但无法将张三的QQ直接交由李四使用,因为张三的QQ上还有很多建材类客户需要其联系和跟进。只有让李四重新使用一个新的QQ去添加飞机类客户(添加客户需要对方的同意,不仅增加工作量还会让工作滞后,还可能客户不清楚添加者是谁而拒绝,从而影响工作),这样做一方面容易给客户留下不好的印象,另一方面李四也不了解张三之前与飞机类客户的过往沟通情况(消息记录),而且飞机类客户很可能会继续联系张三,容易泄露飞机类客户的机密信息。
B、若张三离职,由李四接手张三的QQ,则李四将能看到建材类客户的QQ消息记录及新消息(李四只是接手了飞机事业部的销售工作),容易泄露建材类客户的机密信息;同样的,只是接手建材事业部销售工作的人,也不能接手张三的QQ,因为接手后将会看到飞机类客户的QQ消息记录及新消息。
C、因为QQ是分配给人,而QQ没有被终身固定捆绑给某个人或用户,都是由人为操作将QQ分配给谁使用(人为的为员工关联/分配QQ缺点明显:在长时间的反复不断分配过程中,很容易出现员工分配QQ后,员工和QQ两者各自对应的工作范围有很大偏差、甚至错误,但又使用了,甚至使用了较长或很长一段时间,则会给后续工作造成很大困扰和麻烦、以及不可估量的损失),在分配过程中,极易发生企业机密信息的泄露。举例:有一个QQ,最初被分配给销售员张三使用(张三负责建材行业的销售),张三因为离职或其他原因没有使用该QQ了,该QQ又被分配给销售员李四使用(李四负责飞机行业的销售),李四不再使用后又分配给负责软件行业的销售员王五使用……如此循环,则一个QQ中的来往消息可能涉及了公司全部行业的客户,而公司是按行业来划分销售员市场范围的,不是销售员负责行业的市场是禁止其获取任何信息的,以上问题已经足够严重,更严重的是:非自己负责行业的客户之前是该QQ在联系,之后可能会将后续的消息发往该QQ,则后续消息也将不断地被不该知道的销售员知道。以上已经是比较好的情况了,若是将财务人员使用过的QQ、研发人员使用过的QQ经过多次关联后,关联给了销售人员,研发的机密信息或机密的财务信息都会被现在关联的销售人员知晓,极易导致敏感信息外泄,可能会对公司造成严重的损失。
D、员工入职、调岗时,每次都需要为员工关联即时通讯账号,工作量大(还可能关联错误);而且重新为员工关联即时通讯账号存在一定的滞后,会影响相关工作的正常开展。例如,员工甲由生产主管调为销售主管时,在将员工甲现有的即时通讯账号交接给其接替者后,如果不为员工甲关联新的即时通讯账号,那么员工甲此时没有即时通讯账号将无法开展相应的工作;如果不将员工甲现有的即时通讯账号交接给其接替者,那么该接替者无法了解此前的业务相关通讯信息,不利于工作的开展。又例如,员工甲任职生产主管和售后主管两个职位,现在不再任职生产主管(员工甲的即时通讯账号不能给接替者,因为里面还包含售后主管的工作相关通讯信息),如果重新为生产主管的接替者分配一个新的即时通讯账号,那么还需要逐个通知通讯联系人(例如,设备维修人员、委外生产商等),不仅工作量大而且给对方造成了额外的工作,而且员工甲还可能接收到后续的生产类通讯消息(比如信息发送者不知道员工甲没有再任职生产主管)。再例如,员工甲由生产主管调为销售主管时,在将员工甲现有的即时通讯账号交接给其接替者后没有立即为员工甲分配新的即时通讯账号,那么在此期间员工甲无法通过即时通讯账号处理工作,不利于工作的正常开展。
技术问题
本发明的目的在于克服现有技术的不足,提供一种管理系统中即时通讯账号的管理方法,为一个角色绑定一个角色性质即时通讯账号,员工(入职时)通过对应的用户关联的角色获得角色性质即时通讯账号,员工离职时,直接由系统管理员(或相应管理员)取消该员工对应的用户与角色的关联,则该离职员工自动失去了使用该角色性质即时通讯账号的权限,避免企业机密信息泄露的风险;员工调岗时,直接由系统管理员(或相应管理员)取消该员工(该员工对应的用户)与原角色的关联,再关联新的角色即可自动获得该新角色对应的角色性质即时通讯账号,能够实现无缝对接,保证用户所使用即时通讯账号得到及时更新,不会出现通讯账号交接滞后或遗漏,不会影响员工对通讯账号的正常使用,也规避了机密信息泄露的风险。
技术解决方案
本发明的目的是通过以下技术方案来实现的:管理系统中即时通讯账号的管理方法,包括以下步骤:
(1)创建系统角色,所述角色是独立的个体,而非组/类,同一时段,一个角色只能关联唯一的用户,而一个用户关联一个或多个角色;
(2)根据管理系统中角色的工作内容为角色关联角色性质即时通讯账号,同一时段,一个角色性质即时通讯账号只能关联一个角色、一个角色只能关联一个角色性质即时通讯账号;
(3)建立用户和角色之间的关联关系,对任意一个用户,以该用户所关联的所有角色关联的角色性质即时通讯账号作为该用户和/或该用户对应的员工的角色性质即时通讯账号。
步骤(3)可以在步骤(1)之后、步骤(2)之前执行,也可以在步骤(2)之后执行。
当为角色关联一个角色性质即时通讯账号后,该角色关联的角色性质即时通讯账号不能被更换;或,当为角色关联一个角色性质即时通讯账号且使用该角色性质即时通讯账号后,该角色关联的角色性质即时通讯账号不能被更换。
当需要为某个角色更换角色性质即时通讯账号时,取消该角色与原角色性质即时通讯账号的关联,将该角色与新的角色性质即时通讯账号进行关联。
即时通讯账号的管理方法还包括:选择一个或多个角色为监督角色,分别为每个监督角色设置被监督角色,则监督角色关联的用户或该用户对应的员工能够对该监督角色对应的所有被监督角色关联的角色性质即时通讯账号进行操作,所述的操作包括查看通讯内容。
即时通讯账号的管理方法还包括:为用户/员工关联一个个人性质即时通讯账号,同一时段,一个用户/员工只能关联一个个人性质即时通讯账号,一个个人性质即时通讯账号只能关联一个用户/员工;本申请所述的用户与员工为一对一的关系,即一个用户对应一个员工,一个员工对应一个用户,用户与员工的对应关系建立后将一直对应,被员工对应了的用户不能被其他员工对应。
当为用户/员工关联一个个人性质即时通讯账号后,该用户/员工关联的个人性质即时通讯账号不能被更换;或,当为用户/员工关联一个个人性质即时通讯账号且使用该个人性质即时通讯账号后,该用户/员工关联的个人性质即时通讯账号不能被更换。
当为用户关联一个个人性质即时通讯账号时,以该用户关联的个人性质即时通讯账号作为该用户对应的员工的个人性质即时通讯账号。
当为员工关联一个个人性质即时通讯账号时,以该员工关联的个人性质即时通讯账号作为该员工对应的用户的个人性质即时通讯账号。
即时通讯账号的管理方法还包括:选择一个或多个角色为监督角色,分别为每个监督角色设置被监督角色,则:监督角色关联的用户或该用户对应的员工能够对该监督角色对应的所有被监督角色关联的用户的个人性质即时通讯账号进行操作;或,监督角色关联的用户或该用户对应的员工能够对该监督角色对应的所有被监督角色关联的用户对应的员工的个人性质即时通讯账号进行操作。
所述的角色性质即时通讯账号为系统中即时通讯程序的账号或第三方提供的即时通讯软件的账号,所述的个人性质即时通讯账号为系统中即时通讯程序的账号或第三方提供的即时通讯软件的账号。
有益效果
本发明的有益效果是:(1)本发明提供了一种管理系统中即时通讯账号的管理方法,为一个角色绑定一个角色性质即时通讯账号,员工(入职时)通过对应的用户关联的角色获得角色性质即时通讯账号,员工离职时,直接由系统管理员(或相应管理员)取消该员工对应的用户与角色的关联,则该离职员工自动失去了使用该角色性质即时通讯账号的权限,避免企业机密信息泄露的风险;员工调岗时,直接由系统管理员(或相应管理员)取消该员工(该员工对应的用户)与原角色的关联,再关联新的角色即可自动获得该新角色对应的角色性质即时通讯账号,能够实现无缝对接,保证用户所使用即时通讯账号得到及时更新,不会出现通讯账号交接滞后或遗漏,不会影响员工对通讯账号的正常使用,也规避了机密信息泄露的风险。
离职举例:角色“生产工人1”关联的角色性质即时通讯账号是QQ号123456,员工张三对应的用户关联“生产工人1”时,则由张三使用QQ号123456,张三离职时,系统管理员(或相应管理员)直接取消张三对应的用户与“生产工人1”这一角色的关联,则张三自动失去了QQ号123456的使用权限,避免QQ交接滞后导致“生产工人1”相关机密信息泄露给张三;新入职员工李四接替张三的工作时,直接让李四对应的用户关联“生产工人1”,则李四自动获得了“生产工人1”这一角色对应角色性质QQ号123456的使用权限,无需再为李四重新分配新的QQ,操作简单快捷,大大减少了工作量;且接任工作的李四能够查看之前张三与该QQ联系人的消息记录,交接效果好,便于工作开展,使用方便。
调岗举例:员工张三要从生产部调岗到售后部,系统管理员取消张三对应的用户与原角色“生产工人1”的关联,再关联到售后部的新角色“售后服务人员3”,张三则自动获得了“售后服务人员3”这一角色对应角色性质QQ号987654的使用权限。
(2)本发明为每个角色关联一个角色性质即时通讯账号,在为员工分配岗位号或工作的同时为其分配了相应的角色性质即时通讯账号,无需再单独为该员工分配即时通讯账号,且在离职、调岗、入职等情况下不存在角色性质即时通讯账号分配的滞后性,减少了即时通讯账号分配的工作量。
例如,为员工甲对应的用户关联角色A、角色B后,则角色A和角色B关联的角色性质即时通讯账号自动分配给员工甲,无需再单独为员工甲分配即时通讯账号。
(3)在某个员工调岗或辞职后,将角色关联的角色性质即时通讯账号分配给其他人员时,不会分配给不负责该角色工作内容的人员,因为本发明角色是岗位号/工位号性质角色,保证了即时通讯账号在更换使用者的过程中通讯消息不会泄露给不相关人员。
例如,员工甲对应的用户关联着电器销售员1、软件销售员1两个角色,由于员工甲辞职(员工甲辞职:电器销售员1、软件销售员1两个角色被取消与员工甲对应的用户的关联,则员工甲或员工甲对应的用户自动的失去了“电器销售员1关联的角色性质即时通讯账号和软件销售员1关联的角色性质即时通讯账号”的使用权),将电器销售员1关联给员工乙对应的用户(员工乙获取电器销售员1关联的角色性质即时通讯账号)、软件销售员1关联给员工丙对应的用户(员工丙获取软件销售员1关联的角色性质即时通讯账号),那么员工乙只能通过“电器销售员1”对应的角色性质通讯账号获得电器销售相关信息,而无法接触到与软件销售相关的信息,同理,员工丙只能通过“软件销售员1”对应的角色性质通讯账号获得软件销售相关信息,而无法接触到与电器销售相关的信息。
(4)本发明中根据工作内容为角色关联角色性质即时通讯账号,该通讯账号上的联系人在发送消息时也不用担心消息内容被不相关的人员知晓,因为该角色性质即时通讯账号的当前使用者现在必然在负责相关工作。例如,角色A 的工作内容是进行考勤统计,角色A关联了即时通讯账号X,那么将角色A关联给员工甲对应的用户后,员工甲成为即时通讯账号X的当前使用者,而员工甲当前的工作内容必然包括进行考勤统计,即时通讯账号X上的联系人在向即时通讯账号X发送考勤相关消息后,该考勤消息不会被不相关人员看到。
(5)当为角色关联一个角色性质即时通讯账号后,该角色关联的角色性质即时通讯账号不能被更换,使得与该角色的工作内容相关的消息都收集在该通讯账号上,无需担心中途进行即时通讯账号更换。
例如,角色A关联了即时通讯账号X,那么角色A不能再关联其他即时通讯账号,即时通讯账号X也不能再关联其他角色。
(6)监督角色关联的用户或该用户对应的员工,在监督角色授权了的情况下,有权查看被监督角色关联的用户或该用户对应的员工的即时通讯账号的通讯内容(或有权查看被监督角色关联的即时通讯账号的通讯内容),便于上级主管人员对自己的下属(或相应角色)的工作进行监督和管理。
(7)为用户/员工设置个人性质即时通讯账号,用于收发用户/员工的私密信息,实现了工作即时通讯账号(角色性质即时通讯账号处理工作方面的即时通讯信息)和私人即时通讯账号(个人性质即时通讯账号处理个人方面的即时通讯信息)的分离,由于用户/员工的个人性质即时通讯账号不会被分配给其他员工/用户(个人性质即时通讯账号一旦关联员工或用户将一直关联,不可更换),无需担心由于工作变动进行通讯账号交接导致自己的私密信息泄露的问题。
例如,员工甲迟到,其主管因为员工甲的业绩优异未扣工资,可以向员工甲的个人性质即时通讯账号发送一条消息进行说明,不用担心员工甲离职或调岗后这则消息被接手员工甲工作的员工看到,给公司带来负面影响。
(8)本申请角色对用户是一对一的关系,同一时段一个角色只能关联唯一的用户,一个用户关联一个或多个角色,这样做的好处是,只要将用户关联到角色即可获得权限(即用户获得其关联的角色的权限),而且角色的权限变更比传统机制中的用户权限变更要少得多。独立体性质(岗位号/工位号性质)的角色数量变化小,虽然员工流动大,但岗位号/工位号的变化小(甚至在一定时段内是没有变化的,即角色没有变化),这样将极大简化用户的权限管理,减少系统的开销。
(9)动态管理、入职调岗等的操作简单方便,效率高,可靠性高:入职/离职/调岗在权限管理中的应用简单,当员工/用户发生变化时不用重新设置权限,用户只需取消或关联角色即可:不再任职该角色的用户就取消该角色关联,接手任职该角色的用户关联该岗位号的角色,关联该角色的用户自动就获得了该角色的角色性质通讯账号和操作权限,无需对角色进行重新授权,极大地提高了系统设置的效率、安全性和可靠性。
举例:因张三用户离职或调岗等原因,张三不再做“采购员3”这个角色的工作,则将张三取消与“采购员3”的关联;另外李四接手做“采购员3”这个角色的工作,只需将李四关联该角色,则李四自动获得了“采购员3”这个角色的权限(因为已根据角色的工作内容对角色进行了授权)和角色性质通讯账号。
(10)传统的权限管理机制将角色定义为组、工种(岗位)、类等性质,角色对用户是一对多的关系,在实际的系统使用过程中,因为在运营过程中经常需要对用户的权限进行调整,比如:在处理员工权限变化的时候,角色关联的某个员工的权限发生变化,我们不能因该个别员工权限的变化而改变整个角色的权限,因为该角色还关联了其他权限未变的员工。因此为了应对该种情况,要么创建新角色来满足该权限发生变化的员工,要么对该员工根据权限需求直接授权(脱离角色)。以上两种处理方式,在角色权限较多的情况下对角色授权不仅所需时间长,而且容易犯错,使用方操作起来繁琐又麻烦,也容易出错导致对系统使用方的损失。
但在本申请的方法下,因为角色是一个独立的个体,则可以选择改变角色权限即可达到目的。本申请的方法,虽然看起来在系统初始化时会增加工作量,但可以通过复制等方法,使其创建角色或授权的效率高于传统组/类性质的角色,因为不用考虑组/类性质角色在满足关联用户时的共通性,本申请方案会让权限设置清晰,明了;尤其是在系统使用一段时间后(用户/角色权限动态变化),该申请方案能为系统使用方大幅度提高系统使用中的权限管理效率,使动态授权更简单,更方便,更清晰、明了,提高权限设置的效率和可靠性。
(11)传统组/类性质的角色授权方法容易出错,本申请方法大幅降低了授权出错的几率,因为本申请方法只需考虑作为独立个体的角色,而不用考虑传统方法下关联该组性质角色的多个用户有哪些共通性。即使授权出错也只影响关联到该角色的那一个用户,而传统以组性质的角色则会影响关联到该角色的所有用户。即使出现权限授权错误,本申请的修正方法简单、时间短,而传统以组性质的角色在修正错误时需要考虑关联到该角色的所有用户的权限共通性,在功能点多的情况下不仅修改麻烦、复杂,非常容易出错,且很多情况下只能新创建角色才能解决。
(12)在传统以组为性质的角色授权方法下,若角色的权限功能点比较多,时间一长,很难记住角色的具体权限,更难记住权限相近的角色之间的权限差别,若要关联新的用户,无法准确判断应当如何选择关联。本申请方法的角色本身就具有岗位号/工位号的性质,选择一目了然。
(13)调岗时,若要将被调岗用户的很多个权限分配给另外几个用户承担,则处理时必须将被调岗用户的这些权限区分开来,分别再创建角色来关联另外几个用户,这样的操作不仅复杂耗时,而且还很容易发生错误。
本申请方法则为:被调岗用户关联了几个角色,在调岗时,首先取消用户与原部门内的角色的关联(被取消的这几个角色可以被重新关联给其他用户),然后将用户与新部门内的角色进行关联即可。操作简单,不会出错。
附图说明
图1为背景技术中系统直接对用户进行授权的方式示意图;
图2为背景技术中系统对组/类性质角色进行授权的方式示意图;
图3为背景技术中系统对用户直接授权和对组/类性质角色授权相结合的方式示意图;
图4为本发明系统通过独立个体性质角色对用户进行授权的方式示意图;
图5为本发明一种实施例的管理方法流程图。
本发明的实施方式
下面结合附图进一步详细描述本发明的技术方案,但本发明的保护范围不局限于以下所述。
【实施例1】如图5所示,管理系统中即时通讯账号的管理方法,包括以下步骤:创建系统角色,如图4所示,所述角色是独立的个体,而非组/类,同一时段,一个角色只能关联唯一的用户,而一个用户关联一个或多个角色;一个用户对应一个员工,一个员工对应一个用户,员工通过其对应的用户关联的角色确定(获得)权限。员工和用户相互均为1对1关系且终身绑定,用户对应员工后,则该用户归属于该员工,用户不能再关联其他的员工;若该员工离职,该用户也不能对应其他的员工,员工再次入职后,该员工还是使用原来的用户。
根据管理系统中角色的工作内容为角色关联角色性质即时通讯账号(针对一个角色,进一步的,也可理解为:根据管理系统中该角色的工作内容为该角色关联一个即时通讯账号作为该角色的角色性质即时通讯账号),角色性质即时通讯账号是岗位号/工位号性质的即时通讯账号。同一时段,一个角色性质即时通讯账号只能关联一个角色、一个角色只能关联一个角色性质即时通讯账号;当需要为某个角色更换角色性质即时通讯账号时,取消该角色与原角色性质即时通讯账号的关联,将该角色与新的角色性质即时通讯账号进行关联。
所述的角色性质即时通讯账号为系统中即时通讯程序(软件)的账号(即:即时通讯账号,系统中的即时通讯账号;这种情况下还包括创建即时通讯账号/角色性质即时通讯账号的步骤),和/或第三方提供的即时通讯软件的账号(即:即时通讯账号,比如qq号、微信号等)。
建立用户和角色之间的关联关系,对任意一个用户,以该用户所关联的所有角色关联的角色性质即时通讯账号作为该用户和/或该用户对应的员工的角色性质即时通讯账号。
本发明为一个角色绑定一个角色性质即时通讯账号,员工通过对应的用户关联的角色获得角色性质即时通讯账号,员工离职时,直接由系统管理员(或相应管理员)取消该员工对应的用户与角色的关联,则该离职员工自动失去了使用该角色性质即时通讯账号的权限,避免企业机密信息泄露的风险;员工调岗时,直接由系统管理员(或相应管理员)取消该员工与原角色的关联,再关联新的角色即可自动获得该新角色对应的角色性质即时通讯账号,能够实现无缝对接,保证用户所使用即时通讯账号得到及时更新,不会出现通讯账号交接滞后或遗漏,不会影响员工对通讯账号的正常使用,也规避了机密信息泄露的风险。
离职举例:角色“生产工人1”关联的角色性质即时通讯账号是QQ号123456,员工张三对应的用户关联“生产工人1”时,则由张三使用QQ号123456,张三离职时,系统管理员(或相应管理员)直接取消张三对应的用户与“生产工人1”这一角色的关联,则张三自动失去了QQ号123456的使用权限,避免QQ交接滞后导致“生产工人1”相关机密信息泄露给张三;新入职员工李四接替张三的工作时,直接让李四对应的用户关联“生产工人1”,则李四自动获得了“生产工人1”这一角色对应角色性质QQ号123456的使用权限,无需再为李四重新分配新的QQ,操作简单快捷,大大减少了工作量;且接任工作的李四能够查看之前张三与该QQ联系人的消息记录,交接效果好,便于工作开展,使用方便。
调岗举例:员工张三要从生产部调岗到售后部,系统管理员取消张三对应的用户与原角色“生产工人1”的关联,再关联到售后部的新角色“售后服务人员3”,张三则自动获得了“售后服务人员3”这一角色对应角色性质QQ号987654的使用权限。
在某个员工调岗或辞职后,将角色关联的角色性质即时通讯账号分配给其他人员时,不会分配给不负责该角色工作内容的人员,因为本发明角色是岗位号/工位号性质角色,保证了即时通讯账号在更换使用者的过程中通讯消息不会泄露给不相关人员。
例如,员工甲对应的用户关联着电器销售员1、软件销售员1,由于员工甲辞职,将电器销售员1关联给员工乙对应的用户、软件销售员1关联给员工丙对应的用户,那么员工乙只能通过“电器销售员1”对应的角色性质通讯账号获得电器销售相关信息,而无法接触到与软件销售相关的信息,同理,员工丙只能通过“软件销售员1”对应的角色性质通讯账号获得软件销售相关信息,而无法接触到与电器销售相关的信息。
本发明中根据工作内容为角色关联角色性质即时通讯账号,该通讯账号上的联系人在发送消息时也不用担心消息内容被不相关的人员知晓,因为该角色性质即时通讯账号的当前使用者现在必然在负责相关工作。例如,角色A 的工作内容是进行考勤统计,角色A关联了即时通讯账号X,那么将角色A关联给员工甲对应的用户后,员工甲成为即时通讯账号X的当前使用者,而员工甲当前的工作内容必然包括进行考勤统计,即时通讯账号X上的联系人在向即时通讯账号X发送考勤相关消息后,该考勤消息不会被不相关人员看到。
【实施例2】如图5所示,管理系统中即时通讯账号的管理方法,包括以下步骤:创建系统角色,如图4所示,所述角色是独立的个体,而非组/类,同一时段,一个角色只能关联唯一的用户,而一个用户关联一个或多个角色;根据管理系统中角色的工作内容为角色关联角色性质即时通讯账号,同一时段,一个角色性质即时通讯账号只能关联一个角色、一个角色只能关联一个角色性质即时通讯账号;建立用户和角色之间的关联关系,对任意一个用户,以该用户所关联的所有角色关联的角色性质即时通讯账号作为该用户和/或该用户对应的员工的角色性质即时通讯账号。
本实施例中,当为角色关联一个角色性质即时通讯账号后,该角色关联的角色性质即时通讯账号不能被更换;或,当为角色关联一个角色性质即时通讯账号且使用该角色性质即时通讯账号后,该角色关联的角色性质即时通讯账号不能被更换。即角色与角色性质即时通讯账号终生绑定,若角色被停用,则对应的角色性质即时通讯账号也不能再关联给其他角色,但该角色对应的监督角色关联的用户或该用户对应的员工仍然能够对该角色性质即时通讯账号进行操作。角色重新启用后,该角色还是使用原来关联的角色性质即时通讯账号。
当为角色关联一个角色性质即时通讯账号后,该角色关联的角色性质即时通讯账号不能被更换,使得与该角色的工作内容相关的消息都收集在该通讯账号上,无需担心中途进行即时通讯账号更换。
例如,角色A关联了即时通讯账号X,那么角色A不能再关联其他即时通讯账号,即时通讯账号X也不能再关联其他角色。
【实施例3】本实施例中,即时通讯账号的管理方法还包括:选择一个或多个角色为监督角色,分别为每个监督角色设置被监督角色,则监督角色关联的用户或该用户对应的员工能够对该监督角色对应的所有被监督角色关联的角色性质即时通讯账号进行操作,所述的操作包括查看通讯内容。
如果不是被监督角色关联的用户自己查看的通讯内容,则该通讯内容还是显示未查看状态,但是显示监督角色的查看记录,如进行操作的监督角色、监督角色关联的用户及该用户对应的员工、操作时间、操作内容等。
如果要删除角色性质即时通讯账号的通讯内容,必须经过监督角色(或相应管理者)的同意和确认,这样可以保障有用通讯内容不被恶意删除。
【实施例4】本实施例中,即时通讯账号的管理方法还包括:选择一个或多个角色为监督角色,分别为每个监督角色设置被监督角色,则:监督角色关联的用户或该用户对应的员工能够对该监督角色对应的所有被监督角色关联的用户的个人性质即时通讯账号进行操作;或,监督角色关联的用户或该用户对应的员工能够对该监督角色对应的所有被监督角色关联的用户对应的员工的个人性质即时通讯账号进行操作。
监督角色关联的用户在授权了的情况下,有权限查看被监督角色关联的用户/员工的即时通讯账号的通讯内容,便于上级主管人员对自己的下属的工作进行监督和管理。
【实施例5】本实施例中,即时通讯账号的管理方法还包括:为用户/员工关联一个个人性质即时通讯账号(针对一个用户/员工,进一步的,也可理解为:为该用户/员工关联一个即时通讯账号作为该用户/员工的个人性质即时通讯账号),同一时段,一个用户/员工只能关联一个个人性质即时通讯账号,一个个人性质即时通讯账号只能关联一个用户/员工。
所述的个人性质即时通讯账号为系统中即时通讯程序(软件)的账号(即:即时通讯账号,系统中的即时通讯账号;这种情况下还包括创建即时通讯账号/个人性质即时通讯账号的步骤),和/或第三方提供的即时通讯软件的账号(即:即时通讯账号,比如qq号、微信号等)。
用户/员工离职后,该用户/员工关联的个人性质即时通讯账号将被暂停使用,该个人性质即时通讯账号不会被分配给其他员工/用户,保证了该个人性质即时通讯账号内通讯消息内容不被泄露,但是该员工的上级主管在被授权了的情况下仍然可以对该个人性质即时通讯账号进行操作。若该员工离职后又回到该公司,则将该员工原来的个人性质即时通讯账号再次自动给该员工和/或该员工对应的用户使用(个人性质即时通讯账号与用户一旦关联,则一直处于关联状态,不能更改;个人性质即时通讯账号与员工一旦关联,则一直处于关联状态,不能更改)。
当为用户/员工关联一个个人性质即时通讯账号后,该用户/员工关联的个人性质即时通讯账号不能被更换;或,当为用户/员工关联一个个人性质即时通讯账号且使用该个人性质即时通讯账号后,该用户/员工关联的个人性质即时通讯账号不能被更换。
当为用户关联一个个人性质即时通讯账号时,以该用户关联的个人性质即时通讯账号作为该用户对应的员工的个人性质即时通讯账号。当为员工关联一个个人性质即时通讯账号时,以该员工关联的个人性质即时通讯账号作为该员工对应的用户的个人性质即时通讯账号。
为用户/员工设置个人性质即时通讯账号,用于收发用户/员工的私密信息,实现了工作通讯账号(角色性质即时通讯账号:用于该账号对应工作范围的工作性质的信息沟通)和私人通讯账号(个人性质即时通讯账号:用于个人性质的信息沟通)的分离,由于用户/员工的个人性质即时通讯账号不会被分配给其他员工/用户,无需担心由于工作变动进行通讯账号交接导致自己的私密信息泄露的问题。
例如,员工甲迟到,其主管因为员工甲的业绩优异未扣工资,可以向员工甲的个人性质即时通讯账号发送一条消息进行说明,不用担心员工甲离职或调岗后这则消息被接手员工甲工作的员工看到,给公司带来负面影响。
本申请中,角色必须选择一个部门,角色一旦选择部门后则该角色归属于该部门,该角色的名称在部门下唯一,角色的编号在系统中唯一,根据角色的工作内容对角色进行授权。
如果用户需要跨部门调岗,还包括一个用户跨部门调岗管理步骤,具体包括:(1)取消用户与原部门内的角色的关联;(2)将用户与新部门内的角色进行关联,用户自动获得该角色关联的即时通讯账号的相应权限。
上述实施例中,如图4所示,本申请即时通讯账号管理采用独立个体性质角色,以下对通过独立个体性质角色对用户进行授权所具备的优势进行分析:用户通过其与角色的关联确定(获得)权限,如果要修改用户的权限,通过调整角色所拥有的权限以达到改变关联了该角色的用户的权限的目的。一旦用户关联角色后,该用户就拥有了该角色的所有操作权限。
角色对用户的关系为一对一(该角色与一个用户关联时,其他用户则不能再关联该角色;若该角色未被用户关联,则可以被其他用户选择关联;即同一时段,一个角色能且只能被一个用户关联)。用户对角色的关系为一对多(一个用户可以同时关联多个角色)。
角色的定义:角色不具有组/类/类别/岗位/职位/工种等性质,而是一个非集合的性质,角色具有唯一性,角色是独立存在的独立个体;在企事业单位应用中相当于岗位号(此处的岗位号非岗位,一个岗位同时可能有多个员工,而同一时段一个岗位号只能对应一个员工)。
举例:某个公司系统中可创建如下角色:总经理、副总经理1、副总经理2、北京销售一部经理、北京销售二部经理、北京销售三部经理、上海销售工程师1、上海销售工程师2、上海销售工程师3、上海销售工程师4、上海销售工程师5……用户与角色的关联关系:若该公司员工张三任职该公司副总经理2,同时任职北京销售一部经理,则张三需要关联的角色为副总经理2和北京销售一部经理,张三拥有了这两个角色的权限。
传统角色的概念是组/类/岗位/职位/工种性质,一个角色能够对应多个用户。而本申请“角色”的概念相当于岗位号/工位号,也类同于影视剧中的角色:一个角色在同一时段(童年、少年、中年……)只能由一个演员来饰演,而一个演员可能会分饰多角。
在创建角色之后,可以在创建用户的过程中关联角色,也可以在用户创建完成后随时进行关联。用户关联角色后可以随时解除与角色的关联关系,也可以随时建立与其他角色的关联关系。
所述角色的构成为:岗位名+岗内编号。例如:车间生产工人1、车间生产工人2、车间生产工人3……角色是独立个体,相当于岗位号、工位号的概念,不同于传统权限管理体系中的角色,传统体系中角色的概念是岗位/职位/工种等的组/类性质。
以下举例员工张三进入某公司后,员工、用户与角色之间的关系为:1、新入职:员工新入职,直接为该用户(员工)选择相应的岗位号/工位号的角色进行关联即可,例:张三入职公司(公司为张三分配了一个张三用户),工作内容是在销售一部,负责北京区域冰箱产品的销售(对应的角色是销售一部下的“销售工程师5”这个角色),则张三用户直接选择“销售工程师5”这个角色关联即可。
2、增加职位:张三工作一段时间后,公司还安排张三负责北京区域电视产品的销售(对应的角色是销售一部下的“销售工程师8”这个角色)并兼任售后部主管(对应售后部主管1这个角色),则张三用户再增加关联销售一部下的“销售工程师8”和售后部下的“售后部主管1”这两个角色,此时,张三员工关联了三个角色,分别为销售一部下的“销售工程师5”、“销售工程师8”和售后部下的“售后部主管1”,张三用户则拥有了这三个角色的权限。
3、减少职位:又过了一段时间,公司决定让张三任职售后部经理(对应售后部下“售后部经理”这个角色),且不再兼任其他工作。则张三用户关联售后部下“售后部经理”这个角色,同时取消此前关联的三个角色(销售一部下的“销售工程师5”、“销售工程师8”和售后部下的“售后部主管1”),此时,张三用户只拥有售后部下“售后部经理”这个角色的权限。
4、角色权限的调整(针对角色本身所拥有的权限的调整):如公司决定增加售后部经理的权限,则只需增加对售后部经理这个角色的授权即可,则张三用户因为售后部经理这个角色的权限增加了,张三用户的权限也增加了。
5、离职:一年后,张三离职了,则取消张三用户与售后部下“售后部经理”这个角色的关联即可。
举例:公司在动态的经营中,职员的入职、离职是经常持续发生的,但岗位号/工位号的变化非常少(甚至在一定时期内是没有变化的)。
传统授权方法:在系统功能点多的情况下,以传统的组/类性质的角色进行授权,不仅授权工作量大,繁杂,而且很容易出错,甚至出错了在短时间内都不容易发现,容易对系统使用方造成损失。
本申请授权方法:本申请是对岗位号/工位号性质的角色进行授权,用户关联角色而确定(获得)权限,则对用户权限的控制,通过简单的用户-角色的关联关系来实现,让权限控制变得简单、易操作,清晰明了,大幅度提高了授权效率和授权可靠性。
以上所述仅是本发明的优选实施方式,应当理解本发明并非局限于本文所披露的形式,不应看作是对其他实施例的排除,而可用于各种其他组合、修改和环境,并能够在本文所述构想范围内,通过上述教导或相关领域的技术或知识进行改动。而本领域人员所进行的改动和变化不脱离本发明的精神和范围,则都应在本发明所附权利要求的保护范围内。

Claims (10)

  1. 管理系统中即时通讯账号的管理方法,其特征在于,包括以下步骤:
    在系统中创建角色,所述角色是独立的个体,而非组/类,同一时段,一个角色只能关联唯一的用户,而一个用户关联一个或多个角色;
    根据管理系统中角色的工作内容为角色关联角色性质即时通讯账号,同一时段,一个角色性质即时通讯账号只能关联一个角色、一个角色只能关联一个角色性质即时通讯账号;
    建立用户和角色之间的关联关系,对任意一个用户,以该用户所关联的所有角色关联的角色性质即时通讯账号作为该用户和/或该用户对应的员工的角色性质即时通讯账号。
  2. 根据权利要求1所述的管理系统中即时通讯账号的管理方法,其特征在于:当为角色关联一个角色性质即时通讯账号后,该角色关联的角色性质即时通讯账号不能被更换;
    或,当为角色关联一个角色性质即时通讯账号且使用该角色性质即时通讯账号后,该角色关联的角色性质即时通讯账号不能被更换。
  3. 根据权利要求1所述的管理系统中即时通讯账号的管理方法,其特征在于:当需要为某个角色更换角色性质即时通讯账号时,取消该角色与原角色性质即时通讯账号的关联,将该角色与新的角色性质即时通讯账号进行关联。
  4. 根据权利要求1所述的管理系统中即时通讯账号的管理方法,其特征在于:即时通讯账号的管理方法还包括:选择一个或多个角色为监督角色,分别为每个监督角色设置被监督角色,则监督角色关联的用户或该用户对应的员工能够对该监督角色对应的所有被监督角色关联的角色性质即时通讯账号进行操作,所述的操作包括查看通讯内容。
  5. 根据权利要求1所述的管理系统中即时通讯账号的管理方法,其特征在于:即时通讯账号的管理方法还包括:为用户/员工关联一个个人性质即时通讯账号,同一时段,一个用户/员工只能关联一个个人性质即时通讯账号,一个个人性质即时通讯账号只能关联一个用户/员工。
  6. 根据权利要求5所述的管理系统中即时通讯账号的管理方法,其特征在于:当为用户/员工关联一个个人性质即时通讯账号后,该用户/员工关联的个人性质即时通讯账号不能被更换;
    或,当为用户/员工关联一个个人性质即时通讯账号且使用该个人性质即时通讯账号后,该用户/员工关联的个人性质即时通讯账号不能被更换。
  7. 根据权利要求5所述的管理系统中即时通讯账号的管理方法,其特征在于:当为用户关联一个个人性质即时通讯账号时,以该用户关联的个人性质即时通讯账号作为该用户对应的员工的个人性质即时通讯账号。
  8. 根据权利要求5所述的管理系统中即时通讯账号的管理方法,其特征在于:当为员工关联一个个人性质即时通讯账号时,以该员工关联的个人性质即时通讯账号作为该员工对应的用户的个人性质即时通讯账号。
  9. 根据权利要求5所述的管理系统中即时通讯账号的管理方法,其特征在于:即时通讯账号的管理方法还包括:选择一个或多个角色为监督角色,分别为每个监督角色设置被监督角色,则:
    监督角色关联的用户或该用户对应的员工能够对该监督角色对应的所有被监督角色关联的用户的个人性质即时通讯账号进行操作;
    或,监督角色关联的用户或该用户对应的员工能够对该监督角色对应的所有被监督角色关联的用户对应的员工的个人性质即时通讯账号进行操作。
  10. 根据权利要求1所述的管理系统中即时通讯账号的管理方法,其特征在于:所述的角色性质即时通讯账号为系统中即时通讯程序的账号或第三方提供的即时通讯软件的账号。
PCT/CN2018/097673 2017-07-28 2018-07-27 管理系统中即时通讯账号的管理方法 WO2019020118A1 (zh)

Priority Applications (13)

Application Number Priority Date Filing Date Title
EP18838566.0A EP3661119A4 (en) 2017-07-28 2018-07-27 PROCEDURE FOR ADMINISTERING AN INSTANT MESSAGING ACCOUNT IN AN ADMINISTRATIVE SYSTEM
AU2018308527A AU2018308527A1 (en) 2017-07-28 2018-07-27 Method for managing instant messaging account in management system
JP2020503024A JP7164091B2 (ja) 2017-07-28 2018-07-27 管理システム内のインスタントメッセージアカウントの管理方法
MX2020000995A MX2020000995A (es) 2017-07-28 2018-07-27 Procedimiento para gestionar cuenta de mensajeria instantanea en un sistema de gestion.
CA3070871A CA3070871A1 (en) 2017-07-28 2018-07-27 Method for managing instant messaging account in management system
PE2020000089A PE20200330A1 (es) 2017-07-28 2018-07-27 Procedimiento para gestionar cuenta de mensajeria instantanea en un sistema de gestion
EA202090406A EA202090406A1 (ru) 2017-07-28 2018-07-27 Способ управления учетной записью для мгновенного обмена сообщениями в системе управления
KR1020207005657A KR20200029590A (ko) 2017-07-28 2018-07-27 관리 시스템 중의 인스턴트 메시징 계정의 관리 방법
BR112020001648-9A BR112020001648A2 (pt) 2017-07-28 2018-07-27 método para gerenciar a conta de mensagens instantâneas no sistema de gerenciamento
US16/633,546 US20200304440A1 (en) 2017-07-28 2018-07-27 Method for managing instant messaging account in management system
PH12020500118A PH12020500118A1 (en) 2017-07-28 2020-01-16 Method for managing instant messaging account in management system
CONC2020/0000844A CO2020000844A2 (es) 2017-07-28 2020-01-24 Procedimiento para gestionar cuenta de mensajería instantánea en un sistema de gestión
ZA2020/00540A ZA202000540B (en) 2017-07-28 2020-01-27 Method for managing instant messaging account in management system

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201710633373.6 2017-07-28
CN201710633373.6A CN107302540A (zh) 2017-07-28 2017-07-28 管理系统中即时通讯账号的管理方法

Publications (1)

Publication Number Publication Date
WO2019020118A1 true WO2019020118A1 (zh) 2019-01-31

Family

ID=60133735

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2018/097673 WO2019020118A1 (zh) 2017-07-28 2018-07-27 管理系统中即时通讯账号的管理方法

Country Status (15)

Country Link
US (1) US20200304440A1 (zh)
EP (1) EP3661119A4 (zh)
JP (1) JP7164091B2 (zh)
KR (1) KR20200029590A (zh)
CN (2) CN107302540A (zh)
AU (1) AU2018308527A1 (zh)
BR (1) BR112020001648A2 (zh)
CA (1) CA3070871A1 (zh)
CO (1) CO2020000844A2 (zh)
EA (1) EA202090406A1 (zh)
MX (1) MX2020000995A (zh)
PE (1) PE20200330A1 (zh)
PH (1) PH12020500118A1 (zh)
WO (1) WO2019020118A1 (zh)
ZA (1) ZA202000540B (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112311822A (zh) * 2019-07-29 2021-02-02 腾讯科技(深圳)有限公司 一种目标信息重分配方法、装置、设备和存储介质

Families Citing this family (13)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107465672A (zh) * 2017-07-28 2017-12-12 成都牵牛草信息技术有限公司 系统中用户/员工获取邮箱账号的方法
CN107302540A (zh) * 2017-07-28 2017-10-27 成都牵牛草信息技术有限公司 管理系统中即时通讯账号的管理方法
CN107360083A (zh) * 2017-07-29 2017-11-17 成都牵牛草信息技术有限公司 根据角色间的通讯关系预设即时通讯账号联系人及预设通讯录的方法
CN110351178A (zh) * 2018-04-02 2019-10-18 深圳市六度人和科技有限公司 一种信息监管方法及装置
CN108965109B (zh) * 2018-06-27 2021-08-31 腾讯科技(深圳)有限公司 一种即时通讯控制方法、装置及存储介质
CN109800943A (zh) * 2018-12-11 2019-05-24 广州市飞元信息科技有限公司 一种岗位管理方法、系统和协作方法
CN109510758B (zh) * 2019-02-14 2019-05-17 紫光云数科技有限公司 会话建立方法、终端及系统
CN110297849B (zh) * 2019-05-22 2023-09-01 中国平安财产保险股份有限公司 员工不相容权限筛选方法、装置、计算机设备及存储介质
CN110889669A (zh) * 2019-11-14 2020-03-17 上海易点时空网络有限公司 适用于离职账户的内部系统管理方法及装置、存储介质
CN111445210B (zh) * 2020-03-27 2023-10-20 咪咕文化科技有限公司 账号清理方法、装置、电子设备及存储介质
CN111666539B (zh) * 2020-05-06 2023-07-28 深圳思为科技有限公司 一种房地产资源管理方法、装置、服务器及存储介质
CN111984993B (zh) * 2020-08-06 2024-02-13 武汉华中时讯科技有限责任公司 一种账号下角色与非私密信息流关联的方法
CN115774501A (zh) * 2021-09-07 2023-03-10 北京字跳网络技术有限公司 交互方法、装置和电子设备

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20100042600A1 (en) * 2008-08-13 2010-02-18 Orr Robert L Role-based contact list manager
CN103475712A (zh) * 2013-09-10 2013-12-25 北京思特奇信息技术股份有限公司 基于云计算实现多企业多通讯录自动关联的方法及系统
CN104363163A (zh) * 2014-11-03 2015-02-18 北京金和软件股份有限公司 一种创建自动生成树状通讯目录的即时通信app的方法
CN107302540A (zh) * 2017-07-28 2017-10-27 成都牵牛草信息技术有限公司 管理系统中即时通讯账号的管理方法
CN107360083A (zh) * 2017-07-29 2017-11-17 成都牵牛草信息技术有限公司 根据角色间的通讯关系预设即时通讯账号联系人及预设通讯录的方法

Family Cites Families (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2005228059A (ja) 2004-02-13 2005-08-25 Hitachi Software Eng Co Ltd アカウント管理システム及びその方法
CN101159053A (zh) 2007-11-23 2008-04-09 金蝶软件(中国)有限公司 一种资源分配方法及系统
JP2009238191A (ja) 2008-03-28 2009-10-15 Mitsubishi Electric Corp Webアプリケーションシステム
US8914452B2 (en) * 2012-05-31 2014-12-16 International Business Machines Corporation Automatically generating a personalized digest of meetings
CN102904797B (zh) * 2012-09-21 2015-07-15 上海量明科技发展有限公司 即时通信中交互信息记录的实现方法及系统
CN104050401B (zh) * 2013-03-12 2018-05-08 腾讯科技(深圳)有限公司 用户权限管理方法及系统
US20160266733A1 (en) * 2015-03-11 2016-09-15 Case Global, Inc. Event and staff management systems and methods
WO2017177077A2 (en) * 2016-04-08 2017-10-12 Cloud Knox, Inc. Method and system to detect discrepancy in infrastructure security configurations from translated security best practice configurations in heterogeneous environments
CN106228059A (zh) * 2016-07-22 2016-12-14 南京航空航天大学 基于三员管理和拓展的角色访问控制方法

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20100042600A1 (en) * 2008-08-13 2010-02-18 Orr Robert L Role-based contact list manager
CN103475712A (zh) * 2013-09-10 2013-12-25 北京思特奇信息技术股份有限公司 基于云计算实现多企业多通讯录自动关联的方法及系统
CN104363163A (zh) * 2014-11-03 2015-02-18 北京金和软件股份有限公司 一种创建自动生成树状通讯目录的即时通信app的方法
CN107302540A (zh) * 2017-07-28 2017-10-27 成都牵牛草信息技术有限公司 管理系统中即时通讯账号的管理方法
CN107360083A (zh) * 2017-07-29 2017-11-17 成都牵牛草信息技术有限公司 根据角色间的通讯关系预设即时通讯账号联系人及预设通讯录的方法

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP3661119A4 *

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112311822A (zh) * 2019-07-29 2021-02-02 腾讯科技(深圳)有限公司 一种目标信息重分配方法、装置、设备和存储介质
CN112311822B (zh) * 2019-07-29 2022-11-25 腾讯科技(深圳)有限公司 一种目标信息重分配方法、装置、设备和存储介质

Also Published As

Publication number Publication date
EP3661119A1 (en) 2020-06-03
MX2020000995A (es) 2021-01-08
PE20200330A1 (es) 2020-02-13
JP7164091B2 (ja) 2022-11-01
PH12020500118A1 (en) 2020-09-14
EP3661119A4 (en) 2021-06-02
BR112020001648A2 (pt) 2020-07-21
EA202090406A1 (ru) 2020-05-08
JP2020529653A (ja) 2020-10-08
CN109167755B (zh) 2021-06-04
KR20200029590A (ko) 2020-03-18
CO2020000844A2 (es) 2020-05-05
AU2018308527A1 (en) 2020-03-12
CN109167755A (zh) 2019-01-08
ZA202000540B (en) 2021-02-24
CA3070871A1 (en) 2019-01-31
US20200304440A1 (en) 2020-09-24
CN107302540A (zh) 2017-10-27

Similar Documents

Publication Publication Date Title
WO2019020118A1 (zh) 管理系统中即时通讯账号的管理方法
WO2019024831A1 (zh) 根据角色间的通讯关系预设即时通讯账号联系人及预设通讯录的方法
CN108764833B (zh) 工作流审批节点按部门设置审批角色的方法
WO2018196876A1 (zh) 基于角色对用户一对一的工作流控制方法和系统
WO2018214890A1 (zh) 工作流审批节点按角色设置审批角色的方法
WO2019007260A1 (zh) 表单字段值操作权限授权方法
WO2019007292A1 (zh) 基于角色的表单操作权限授权方法
WO2019015656A1 (zh) 一种系统派工方法
WO2018192557A1 (zh) 基于角色对用户的一对一的权限授权方法和系统
US11303650B2 (en) Method for authorizing permission to operate content of mailbox account and instant messaging account in system
WO2019015539A1 (zh) 一种表单数据操作权限授权方法
WO2019019981A1 (zh) 系统中用户在信息交流单元的权限的设置方法
WO2019029501A1 (zh) 统计列表操作权限授权方法
WO2019029649A1 (zh) 对使用者进行审批流程及其审批节点授权的方法
US11563746B2 (en) Method for configuring operating time period for mailbox content and instant messaging content in system
WO2019011162A1 (zh) 快捷功能设置方法
JP7178014B2 (ja) システム中にユーザー/従業員がメールボックスアカウントを取得する方法
WO2019019980A1 (zh) 论坛管理方法
WO2019024899A1 (zh) 监察审批操作、授权操作及表单操作的方法
WO2019029502A1 (zh) 系统中对授权操作者进行授权的方法
OA19299A (en) Method for managing instant messaging account in management system.
EA044374B1 (ru) Способ управления учетной записью для мгновенного обмена сообщениями в системе управления

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 18838566

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 2020503024

Country of ref document: JP

Kind code of ref document: A

ENP Entry into the national phase

Ref document number: 3070871

Country of ref document: CA

NENP Non-entry into the national phase

Ref country code: DE

REG Reference to national code

Ref country code: BR

Ref legal event code: B01A

Ref document number: 112020001648

Country of ref document: BR

ENP Entry into the national phase

Ref document number: 20207005657

Country of ref document: KR

Kind code of ref document: A

ENP Entry into the national phase

Ref document number: 2018838566

Country of ref document: EP

Effective date: 20200228

ENP Entry into the national phase

Ref document number: 2018308527

Country of ref document: AU

Date of ref document: 20180727

Kind code of ref document: A

ENP Entry into the national phase

Ref document number: 112020001648

Country of ref document: BR

Kind code of ref document: A2

Effective date: 20200124