Enterprise knowledge hub, isolated by enterprise / department / business line / role
Agent-User supports multi-source knowledge ingestion, knowledge graph construction, and multi-tier permission governance, so employees can access authorized content by permission policy, and every answer carries traceable sources.
Central rules carry the most weight · personal workspaces stay flexible
- Data export policy / zero trust
- Signed audit trail + tamper evidence
- Tenant isolation + end-to-end encryption
- SM2/SM3/SM4 enforcement
- Classified protection + ISO 27001
- Legal / finance / HR guardrails
- Model allowlist / denylist
- HITL approval for major actions
Knowledge sources
Supports four source types: documents, databases, APIs, third-party systems.
Local files / shared drives
PDF / Word / Excel / PPT / Markdown / images / scans; incremental fingerprint indexing.
Enterprise wiki / knowledge bases
Connects Confluence / Notion / SharePoint / Yuque / Feishu Docs / DingTalk Docs.
Business databases
Connects MySQL / PostgreSQL / Oracle / SQL Server / DM / KingbaseES; read-only + row-level security.
Business system APIs
Connects ERP / CRM / ticketing / OA / in-house systems; OAuth 2.0 / short-lived token auth.
Multi-tier permission matrix
Knowledge is isolated by enterprise / department / business line / role — each tier has its own visibility scope, edit rights, and approval flow.
| Tier | Visibility | Edit rights | Approval flow |
|---|---|---|---|
Enterprise knowledge | Group-wide common knowledge (policies / processes / training / product manuals) | Knowledge admins / HQ-designated staff | HQ knowledge governance committee + version change audit |
Department knowledge | Department-internal business knowledge (rules / SOPs / project docs) | Department lead / department knowledge specialist | Department lead approval + HQ authorization for cross-department visibility |
Business line knowledge | Business-line specific knowledge (product docs / industry research / customer cases) | Business-line lead / product manager | Business-line lead approval + secondary authorization for cross-line access |
Role knowledge | Personal / role-specific knowledge (notes / role handbooks / project workspace) | Owner / direct manager | Default private; sharing requires explicit authorization + time-bound settings |
Knowledge graph
Auto-build entity-relationship graphs from unstructured documents, with visual editing and querying.
Entity recognition
Auto-extract organizations, products, people, projects, contracts, and customers from documents; supports custom entity types and synonyms.
Relation extraction
Auto-identify relations between entities (affiliation, supply, partnership, reference, etc.); supports incremental building and manual correction.
Visual editor
Graph browser supports filter, focus, and path query; can be integrated as a Skill into the digital workforce workflow.
Hybrid retrieval
Keyword + vector + knowledge graph triple fusion, with runtime context policy redaction.
Keyword + vector hybrid
Dual channels of keyword exact match and vector semantic match, dynamically weighted by query type.
Knowledge graph path query
Complex relation questions go through graph path query (e.g. "all partners of department A"), results are explainable.
Citation locator v2
Every answer carries source locator (page / paragraph / section), parser type, and confidence score.
Runtime redaction
Runtime model context policy ensures users access authorized fragments by policy; raw paths and data keys are not exposed by default.
Security model
Three layers of protection for knowledge assets.
Encrypted index
Runtime-only wrapped data-key lifecycle; index material and cache default to AES-256-GCM encryption.
Citation & confidence
Every citation carries confidence score, source locator v2 metadata; retrieval quality gate ensures minimum citation quality.
Context policy
Runtime model context policy decides which fragments can be sent to external models; sensitive fragments are auto-truncated or redacted.
Apply for knowledge integration plan
We provide end-to-end service from knowledge organizing, permission modeling, graph construction to retrieval tuning.