4.8 KiB
4.8 KiB
Business Rules
Durable Rules
agent设计规范/business-adaptation-registry.mdis the cross-session business entry; each business maps user input, Skill/action, ERP flow, contracts, implementation, fixtures, and verification status.- Manual and AgentBus tasks share the same 18 machine routes, task-scoped parser mode snapshot, and organization automation rules.
- The platform exposes one fixed deployment scope, not an organization-management product. Accounts use
admin,team_lead, anduserroles. - Passwords must be non-empty but have no application-level length restriction. First login and administrator password reset do not force a subsequent password change; users may still change passwords voluntarily, administrators may reset them, and password changes revoke existing sessions according to the account lifecycle contract.
- Administrators always hold all 18 manual business routes. Team leads and ordinary users start with no task grants, require explicit administrator allowlists, and may use normal task APIs only for their own manual tasks.
- A known ungranted route or a non-unique/unresolved route for a non-administrator fails before parsing, plugin dispatch, or ERP execution. Authorization is rechecked for supplemental input, attachments, confirmation, automatic confirmation, and browser claim.
- Team leads may read all manual account work only through the platform-operations dashboard. The dashboard is aggregate-first across task, person, original input, final output, time, task type, and completion state, with business-facing drill-through. Internal attention or waiting-for-input states remain unchanged in task storage but are presented and filtered as “进行中”; the leadership view exposes no separate “待跟进” category. It is not an audit log and never renders technical payloads, internal identifiers, machine-shaped historical input, or technical failure text; this visibility does not grant cross-user task mutation, artifacts, SSE, global settings, audit administration, or AgentBus access.
- Creator and input-turn attribution are durable, business inputs remain encrypted at rest, denial audit excludes plaintext, and routine task removal uses archive/restore rather than physical purge.
- The two passenger-list import routes are Program-only and wait for exactly one
.xlsor.xlsxattachment before deterministic normalization. - Passenger workbooks must contain exactly one complete ERP-semantic header within rows 1–100. The header may be on row 1 or follow metadata, column order is arbitrary, and only the finite approved source/ERP aliases—including
NAME,证件号码,签发日, and身份证—are mapped. Unknown or unheaded data columns, duplicate semantic fields, multiple candidate headers, and non-passport identity data fail closed; the internal 13-column canonical TSV contract remains unchanged. - A WeChat attachment card is transport placeholder text, not file content. Only a structured
payload.attachments[]entry can resume a roster task; missing metadata fails before ingestion and leaves the original task inawaiting_attachmentinstead of creating a new task. - The trusted internal deployment accepts credential-free HTTPS roster attachment URLs whose host is internal, private/reserved IPv4/IPv6, or localhost. DNS pinning, redirect revalidation, download timeout, byte limits, declared-size checks, and optional SHA-256 verification remain mandatory.
- AgentBus attachment diagnostics may record stage, address count/family, status, byte count, code, outcome, and duration, but never URL, hostname, IP, file name, bytes, message text, or roster values.
- Passenger overwrite requires confirmation when target ERP rows are occupied; after
full_replace + confirmed=true, every attachment-specified sequence is written even when values are unchanged. - A single strict
领队row supplies leader contact; ambiguous, incomplete, duplicate, or structurally inconsistent leader data fails closed. - Shared-mother-plan
整团游客信息export is onlyshared_plan + visitor-list + tid-only; independent and concrete shared-child visitor lists remaindid+tid. - Real writes require unique resolution, exact page identity, ownership, write projection, explicit server response, and action-specific completion evidence.
- Current business capability and verification status come from active source/contracts and the lifecycle release gate, never from archive wording.
Open Questions
- Fresh authorized runtime read verification remains for the shared-mother-plan whole-visitor export branch.
- Authorized current-version ERP write verification remains for SGL/TWN and four independent-order headcount categories.
- One live internal attachment verification of the newly integrated roster-header path remains unperformed and requires separate task-mutation/channel authorization.
Last Reviewed
2026-09-02