权限边界

按角色、字段和动作说明可见性。

角色边界

角色可看不可看边界
ROLE_MANAGER团队员工摘要、测评状态、脱敏画像answer_payload、完整干部结论、薪酬、人事动作profile/risk_tags masked; actions gated
ROLE_BOSS全局汇总、组织风险、高潜/风险分布未脱敏个人敏感字段、完整 answer_payloaddashboard summary only
ROLE_HRBP员工 portfolio、运营状态、风险跟进、audit/rollback 入口permission rule apply、business-effective conclusiongated HR view
ROLE_DEPARTMENT_HEAD本部门员工/岗位/测评状态/组织 request 入口跨部门敏感数据department scope preview
ROLE_EMPLOYEE自己的基础画像与任务状态干部 validation、他人数据、敏感推荐动作self_scope
ROLE_REVIEWER授权 review 范围脱敏信息完整 conclusion 与 answer_payloadreview_scope_limited

字段边界

字段策略适用范围
answer_payloadhiddenall manager/boss/reviewer
assessment_resultssummarymanager/boss; HRBP gated
algorithm outputmaskedmanager/boss
employee profilesummary_visiblemanager/department head
cadre validationHR gated onlymanager/boss hidden or aggregate
recommended_actions_previewmasked/hiddenno people action
risk_flagsmasked/aggregateaudit_required
talent_tagssummaryno formal conclusion
salary / compensationhiddendenied
business-effective conclusionhiddennot generated

权限规则基线

count
action_permission_rules141
data_scope_rules6
field_permission_rules195
page_permission_rules120