docs: integrate leadership dashboard definition
This commit is contained in:
1 parent
823d1cb630
commit
2bb5827867
9 files changed
+65
-6
No files matched your search
@@ -14,7 +14,7 @@
|
||||
| WeChat roster attachment | Strict transport envelope plus one structured `payload.attachments[]` entry | Existing `awaiting_attachment` task | Explicit conversation ID wins; otherwise strict `Conversation:` supplies the fallback. Placeholder text alone never creates a task. |
|
||||
| Internal attachment download | Credential-free HTTPS URL | Bounded in-memory workbook bytes | Internal/private DNS answers are allowed; the selected address is pinned, every redirect is revalidated, and URL/host/IP/bytes are omitted from logs. |
|
||||
| Operational diagnostics | Service, request, task, parser, AgentBus, attachment, database, and cleanup stages | Structured stdout/stderr and bounded Docker logs | Correlation identifiers, codes, outcomes, and durations only; no secrets or business payloads. |
|
||||
| Operations oversight | Manual task creator, encrypted instruction history, and readable outcome | Team-lead/administrator dashboard projection | Read-only who/instruction/result view; no parser/executor payloads or task mutation authority |
|
||||
| Platform operations oversight | Manual task creator, encrypted instruction history, and readable outcome | Team-lead/administrator leadership projection | Aggregate-first task/person/input/output/time/type/completion view with clickable business drill-through; no machine payloads, technical failure text, internal identifiers, or task mutation authority |
|
||||
| Confirmation export | ERP source file | Archived source plus mobile delivery artifact | Visitor XLS becomes real XLSX; other types prefer PDF |
|
||||
| Release | Editable source | `dist/release-manifest.json` and versioned artifacts | Manifest owns current hashes and filenames |
|
||||
|
||||
|
||||
@@ -21,7 +21,8 @@ Authenticated manual or AgentBus input is routed through task-scoped AI/Shadow/A
|
||||
|
||||
- AI/Program parsing and ERP resolution/execution share the final operation contract but do not share authority.
|
||||
- Platform envelope fields such as task ID, account identity, authorization revision, session, parser decision, confirmation, transport, and audit never enter the business operation.
|
||||
- The product is one fixed internal organization scope with three roles. Administrators manage accounts and all 18 manual routes; team leads and users are owner-scoped for normal tasks and require explicit per-route grants. Team leads additionally receive a dedicated read-only, manual-task-only operations dashboard.
|
||||
- The product is one fixed internal organization scope with three roles. Administrators manage accounts and all 18 manual routes; team leads and users are owner-scoped for normal tasks and require explicit per-route grants. Team leads additionally receive a dedicated read-only, manual-task-only platform-operations dashboard.
|
||||
- The leadership dashboard is an aggregate-first projection across task, person, original input, final output, time, task type, and completion state. Its drill-through stays business-facing; technical payloads, internal identifiers, machine-shaped historical input, and technical failure text remain in separate authorized audit/engineering surfaces.
|
||||
- Authorization is enforced in server and service paths, not by navigation visibility. A denied or unresolved non-admin business route stops before parsing, plugin dispatch, and ERP execution; creator authorization is rechecked at confirmation and browser claim.
|
||||
- Creator and manual input-turn attribution remain durable while business input stays encrypted at rest. Routine removal is reversible archive/restore; physical purge is not an operator capability.
|
||||
- Unknown, ambiguous, unverified, or post-write-uncertain states fail closed; automatic retries must not create duplicate writes.
|
||||
|
||||
Reference in new issue
Block a user