Agent-User
Knowledge Base / Graph / Tiered Permissions

Enterprise knowledge hub, isolated by enterprise / department / business line / role

Agent-User supports multi-source knowledge ingestion, knowledge graph construction, and multi-tier permission governance, so employees can access authorized content by permission policy, and every answer carries traceable sources.

Enterprise knowledge base· 4 tiers
+ New
Enterprise1,284 docs
Product R&D428 docs
Sales Center316 docs
East Region
South Region
Overseas
Support184 docs
Finance92 docs
Personal drafts12 docs
Sales CenterEast RegionSouth RegionCustomer files
Inverted permission pyramid · 5 tiers
544 rules · 1,502 cases
Strict at the top · broad at the bottom · lower tiers stay governed
Central rules carry the most weight · personal workspaces stay flexible
L1 · EnterpriseEnterprise
Group-wide rules
1
cases
  • Data export policy / zero trust
  • Signed audit trail + tamper evidence
  • Tenant isolation + end-to-end encryption
  • SM2/SM3/SM4 enforcement
  • Classified protection + ISO 27001
  • Legal / finance / HR guardrails
  • Model allowlist / denylist
  • HITL approval for major actions
rules
248
cases
1

Knowledge sources

Supports four source types: documents, databases, APIs, third-party systems.

Local files / shared drives

PDF / Word / Excel / PPT / Markdown / images / scans; incremental fingerprint indexing.

Enterprise wiki / knowledge bases

Connects Confluence / Notion / SharePoint / Yuque / Feishu Docs / DingTalk Docs.

Business databases

Connects MySQL / PostgreSQL / Oracle / SQL Server / DM / KingbaseES; read-only + row-level security.

Business system APIs

Connects ERP / CRM / ticketing / OA / in-house systems; OAuth 2.0 / short-lived token auth.

Multi-tier permission matrix

Knowledge is isolated by enterprise / department / business line / role — each tier has its own visibility scope, edit rights, and approval flow.

TierVisibilityEdit rightsApproval flow
Enterprise knowledge
Group-wide common knowledge (policies / processes / training / product manuals)Knowledge admins / HQ-designated staffHQ knowledge governance committee + version change audit
Department knowledge
Department-internal business knowledge (rules / SOPs / project docs)Department lead / department knowledge specialistDepartment lead approval + HQ authorization for cross-department visibility
Business line knowledge
Business-line specific knowledge (product docs / industry research / customer cases)Business-line lead / product managerBusiness-line lead approval + secondary authorization for cross-line access
Role knowledge
Personal / role-specific knowledge (notes / role handbooks / project workspace)Owner / direct managerDefault private; sharing requires explicit authorization + time-bound settings

Knowledge graph

Auto-build entity-relationship graphs from unstructured documents, with visual editing and querying.

Entity recognition

Auto-extract organizations, products, people, projects, contracts, and customers from documents; supports custom entity types and synonyms.

Relation extraction

Auto-identify relations between entities (affiliation, supply, partnership, reference, etc.); supports incremental building and manual correction.

Visual editor

Graph browser supports filter, focus, and path query; can be integrated as a Skill into the digital workforce workflow.

Hybrid retrieval

Keyword + vector + knowledge graph triple fusion, with runtime context policy redaction.

Keyword + vector hybrid

Dual channels of keyword exact match and vector semantic match, dynamically weighted by query type.

Knowledge graph path query

Complex relation questions go through graph path query (e.g. "all partners of department A"), results are explainable.

Citation locator v2

Every answer carries source locator (page / paragraph / section), parser type, and confidence score.

Runtime redaction

Runtime model context policy ensures users access authorized fragments by policy; raw paths and data keys are not exposed by default.

Security model

Three layers of protection for knowledge assets.

Encrypted index

Runtime-only wrapped data-key lifecycle; index material and cache default to AES-256-GCM encryption.

Citation & confidence

Every citation carries confidence score, source locator v2 metadata; retrieval quality gate ensures minimum citation quality.

Context policy

Runtime model context policy decides which fragments can be sent to external models; sensitive fragments are auto-truncated or redacted.

Apply for knowledge integration plan

We provide end-to-end service from knowledge organizing, permission modeling, graph construction to retrieval tuning.