Najpierw nazwij klasę dokumentu i autorytet
Ten sam format może służyć różnym celom. Dla każdej istotnej klasy wskaż właściciela i ustal dostęp, wersje, OCR, storage, retention, recovery oraz acceptance.
Krótka odpowiedź
Użyj natywnych załączników dla ograniczonych plików pomocniczych; eskaluj, gdy dokument ma własny cykl życia
Open Mercato dostarcza rozbudowaną bibliotekę załączników, linki do rekordów, metadane, local lub S3 storage, preview, resizing obrazów, ekstrakcję i wybrane OCR. Zbuduj domenę dokumentu, gdy to dokument ma identity, wersje, approval lub retention; dla wysokich wymagań pozostaw autorytet specjalistycznemu DMS, archiwum, korespondencji lub trust service.
- Sprawdzono
- 2026-07-14
- Bieżący kod
- 01911d00e28f44cf484d0b1d04860dcfef5370bf (v0.6.5-1202-g01911d00e)
- Najnowszy tag i pakiet
- v0.6.5 · 0.6.5
Ta metoda redakcyjna wspiera planowanie dokumentów. Porady prawne, akceptację records, certyfikację bezpieczeństwa, walidację podpisu, zapewnienia archiwum i dowody wdrożenia muszą przedstawić właściwi specjaliści oraz właściciele.
Legenda dowodów i terminologia
Oddziel zachowanie wydane, tę rewizję develop, kontrole projektu, możliwości providera, brak dowodu, drift narracji i rekomendacje.
- 1. released
- 2. reviewed current develop
- 3. implementation-dependent
- 4. external or provider control
- 5. not established
- 6. documentation drift
- 7. editorial recommendation
Zdefiniuj autorytet, identity, cykl życia, kopie, dowody i wykluczone znaczenia. Jeden binary może wspierać kilka znaczeń biznesowych, a jeden dokument może mieć wiele wersji lub renditions.
- 1. file or binary object
- 2. attachment
- 3. business document
- 4. record
- 5. DMS
- 6. ECM
- 7. DAM
- 8. electronic archive
- 9. correspondence system
- 10. e-signature or trust service
Czteropoziomowa drabina dokumentów
1. Record attachment
- Dopasowanie
- A supporting file follows an existing business record lifecycle.
- Eskalacja
- Escalate if the file gains independent identity, approval, version or retention.
- Stop
- Stop without owner-record authorization, storage and recovery evidence.
- Właściciel i ryzyko
- Przypisz odpowiedzialnego właściciela i jawnie zachowaj niezamknięte luki.
2. Shared attachment library
- Dopasowanie
- Files can be browsed, tagged, assigned, previewed and reused.
- Eskalacja
- Escalate when classification, review, acknowledgement or versions matter.
- Stop
- Stop if generic library grants replace need-to-know control.
- Właściciel i ryzyko
- Przypisz odpowiedzialnego właściciela i jawnie zachowaj niezamknięte luki.
3. Document domain in Open Mercato
- Dopasowanie
- A project module owns document identity, states, versions, commands, permissions, events and retention decisions.
- Eskalacja
- Escalate when trust, archive, collaboration or regulated controls exceed the project domain.
- Stop
- Stop without funded module, operations, migration and acceptance owners.
- Właściciel i ryzyko
- Przypisz odpowiedzialnego właściciela i jawnie zachowaj niezamknięte luki.
4. Specialist external authority
- Dopasowanie
- DMS, ECM, archive, correspondence, signature, DAM or records platform remains authoritative.
- Eskalacja
- Integrate references, bounded copies, events and reconciliation.
- Stop
- Stop without canonical identity, outage, conflict, hold/delete and exit contracts.
- Właściciel i ryzyko
- Przypisz odpowiedzialnego właściciela i jawnie zachowaj niezamknięte luki.
Macierz stanu możliwości
Klasyfikuj jako native, configured, project module, provider lub external albo not established. Zapisz dokładne źródło, właściciela, ograniczenie, dowód odbioru i eskalację.
- 1. upload
- 2. record link
- 3. shared library
- 4. metadata
- 5. tags
- 6. assignments
- 7. custom attributes
- 8. image preview
- 9. original download
- 10. image resizing
- 11. OCR and extraction
- 12. filename search
- 13. full-text search
- 14. document versions
- 15. approval workflow
- 16. signature creation or validation
- 17. retention schedule
- 18. legal hold
- 19. immutability or WORM
- 20. malware scan or CDR
- 21. backup
- 22. restore
- 23. export or portability
- 24. read-access evidence
- 25. external exchange
- 26. recycle bin or recoverable delete
Bieżący rekord załącznika i brakujące kontrole dokumentu
Bieżące właściwości
- entityId
- recordId
- organizationId
- tenantId
- partitionCode
- fileName
- mimeType
- fileSize
- storageDriver
- storagePath
- storageMetadata
- url
- content
- createdAt
Niepotwierdzone w sprawdzonym rekordzie
- stable document number
- document class
- version family
- current version
- draft, approved or superseded state
- check-in or check-out
- approval evidence
- signature validation
- retention schedule
- disposition event
- legal hold
- immutable rendition
- checksum
- OCR status and confidence
- page coordinates
- malware-scan status
- classification label
- access-history ledger
entityId i recordId łączą attachment przez identyfikatory. Tags i assignments są w JSON metadata, a attachment custom fields rozszerzają metadata. Assignments mają type, id, opcjonalny label i href. Brakuje dowodów na foreign keys, constraints i sprawdzanie permission rekordu targetu.
Kontrakt kontroli dokumentu i odpowiedzialności
- business owner
- information owner
- application owner
- security and privacy owner
- records or legal owner where applicable
- infrastructure operator
- implementation team
- storage provider
- OCR or model provider
- external DMS or signature provider
- acceptance owner
Rozpocznij discovery od celu i autorytetu. Format pliku i folder ustal później. Twórz osobną decyzję dla każdej istotnie odmiennej klasy dokumentu.
Przypisz źródło, właściciela, regułę, dowód, zachowanie awarii i trigger przeglądu.
- 1. purpose
- 2. business owner
- 3. information owner
- 4. system of record
- 5. document class
- 6. owning entity and record
- 7. stable document id and numbering
- 8. original versus working copy
- 9. authoritative rendition
- 10. file formats and size
- 11. naming
- 12. metadata and tags
- 13. assignments and relations
- 14. custom attributes
- 15. version, replace and supersede rule
- 16. state and approval
- 17. signature, seal and timestamp need
- 18. tenant and organization scope
- 19. read roles
- 20. write roles
- 21. delete roles
- 22. public roles
- 23. sensitivity and classification
- 24. storage partition and driver
- 25. provider and region
- 26. encryption and keys
- 27. malware and quarantine
- 28. OCR formats and model
- 29. OCR status, quality and review
- 30. search, index and freshness
- 31. preview, download and share
- 32. external integrations
- 33. event, audit and access evidence
- 34. retention trigger and disposition
- 35. legal hold
- 36. backup, restore, RPO and RTO
- 37. export and portability
- 38. orphan reconciliation
- 39. acceptance owner
- 40. evidence date
Wyłącznie przykład strukturalny
Założenie: abstrakcyjny plik pomocniczy podąża za istniejącym rekordem. Właściciel nadal zatwierdza private lub public, format, storage, dostęp do owner record, delete, backup, restore i dowód jakości. Filename, identifier, klient, reguła prawna i domyślna konfiguracja produktu pozostają do ustalenia.
Cykl życia, wersje i okna awarii
Zapisz, czy etap należy do core, project module, providera czy external authority oraz jaki ma dowód końcowy.
- 1
capture or upload
- 2
technical validation
- 3
classification
- 4
link to owner
- 5
text extraction
- 6
human or automated review
- 7
use and share
- 8
revision
- 9
supersession
- 10
retention
- 11
legal hold
- 12
disposition
- 13
export or exit
- 14
reconciliation
- 15
evidence closure
Nowy upload tworzy nowy attachment row. Edycja metadata nie potwierdza replacement contentu, version family, nowego dokumentu, controlled rendition ani supersession. Zdefiniuj je oddzielnie.
Obiekt może zostać zapisany przed commit attachment row i custom attributes, więc failure persystencji może pozostawić orphan object. Delete usuwa row przed best-effort driver deletion; błędy local lub S3 mogą pozostawić orphan object. Wymagaj detection, alerting, retry, cleanup, dowodu i reconciliation dla originals, thumbnails, OCR, indexes, backups i external copies.
Zmiana drivera partycji kieruje tylko przyszłe uploady. Istniejące rows zachowują driver. Testuj mixed-driver read, download, delete, OCR, backup, restore i exit. Traktuj zmianę jako konfigurację; migracja wymaga przeniesienia istniejących rows.
Macierz OCR i ekstrakcji formatów
1. plain text
- Ścieżka
- direct text extraction
- Czas
- synchronous during upload
- Provider
- none
- Wynik
- content field
- Odbiór
- no first-class status
2. CSV, Markdown and log
- Ścieżka
- direct text-like extraction
- Czas
- synchronous during upload
- Provider
- none
- Wynik
- content field
- Odbiór
- format-specific accuracy test
3. PDF with text layer
- Ścieżka
- pdfjs-dist text extraction
- Czas
- direct or PDF processing
- Provider
- none for text layer
- Wynik
- content field
- Odbiór
- layout and table acceptance
4. scanned PDF
- Ścieżka
- page rendering then LLM OCR
- Czas
- asynchronous setImmediate path
- Provider
- configured OpenAI service
- Wynik
- content field
- Odbiór
- pending, failure and review must be modeled
5. image
- Ścieżka
- LLM OCR when enabled and key exists
- Czas
- asynchronous setImmediate path
- Provider
- configured OpenAI service
- Wynik
- content field
- Odbiór
- quality and provider controls required
6. DOCX
- Ścieżka
- mammoth text extraction
- Czas
- synchronous during upload
- Provider
- none
- Wynik
- content field
- Odbiór
- structure fidelity acceptance
7. legacy DOC
- Ścieżka
- not established
- Czas
- no extraction
- Provider
- none
- Wynik
- null content
- Odbiór
- unsupported must be visible
8. XLS or XLSX
- Ścieżka
- not established
- Czas
- no extraction
- Provider
- none
- Wynik
- null content
- Odbiór
- unsupported must be visible
9. PPT or PPTX
- Ścieżka
- not established
- Czas
- no extraction
- Provider
- none
- Wynik
- null content
- Odbiór
- unsupported must be visible
10. MSG
- Ścieżka
- not established
- Czas
- no extraction
- Provider
- none
- Wynik
- null content
- Odbiór
- unsupported must be visible
11. archive
- Ścieżka
- not established
- Czas
- no extraction
- Provider
- none
- Wynik
- null content
- Odbiór
- bomb and policy decision
12. audio or video
- Ścieżka
- not established
- Czas
- no extraction
- Provider
- none
- Wynik
- null content
- Odbiór
- specialist provider decision
13. password-protected or corrupt
- Ścieżka
- not established or failure
- Czas
- path dependent
- Provider
- possibly none
- Wynik
- empty or null
- Odbiór
- must differ from no text
14. unknown binary
- Ścieżka
- not established
- Czas
- no extraction
- Provider
- none
- Wynik
- null content
- Odbiór
- deny or governed storage decision
Ścieżka LLM dla obrazu i scanned PDF może wysłać kwalifikujący się content do skonfigurowanego OpenAI. Po persistence uruchamia ją in-process setImmediate. Brakuje durable queue, a failures są logowane bez first-class pending, failed, retry, confidence, coordinates ani reviewed. Jawnie zaprojektuj klasyfikację, minimalizację, warunki dostawcy, region, retention i training assumptions, sekrety, koszt, rate, outage, deletion i incident review.
Dla consequential use zbuduj jawny status i human review. Oceń reprezentatywną próbę względem ground truth według klasy, języka, jakości skanu, layoutu i tabel; przeglądaj false positives i negatives, wyjątki oraz drift po zmianie modelu lub źródła. Nie sugerujemy progu accuracy.
Search, preview i retrieval
Sprawdzone wyszukiwanie w bibliotece dopasowuje fragment nazwy pliku (fileName). Dla pozostałych ścieżek poniżej sprawdź zakres, aktualność, usuwanie danych, odmowę dostępu i nieaktualne wyniki we wdrożeniu.
- 1. filename
- 2. tag
- 3. partition
- 4. assignment label or id
- 5. custom attribute
- 6. extracted content
- 7. global search or query index
- 8. attachment API
- 9. deleted item
- 10. denied role or scope
- 11. stale OCR or stale index
Preview extracted content, generic query-index side effects i manager-ready full-text search to różne rzeczy. Bezpieczne obrazy mogą renderować inline i być resized; inne originals są wymuszane do download z nagłówkami nosniff i sandbox. Preview nie waliduje treści ani podpisów. Nie tworzy również obrazu archiwalnego.
Kontrole wejścia pliku
Oznacz bieżącą kontrolę produktu, decyzję projektu lub proxy, kontrolę providera, ryzyko, test i właściciela. Bieżące trasy sprawdzają content length, a potem parsują multipart formData w pamięci.
- 1. allowed business formats
- 2. extension
- 3. MIME and signature
- 4. safe name
- 5. file-size limit
- 6. tenant quota
- 7. total request limit
- 8. rate and concurrency
- 9. active content
- 10. executable segments
- 11. image dimensions and pixel bombs
- 12. archive bombs
- 13. parser isolation
- 14. malware and quarantine
- 15. content disarm and reconstruction
- 16. authentication
- 17. authorization
- 18. storage location
- 19. logging
- 20. incident response
Bieżący kod sanitizes names, odrzuca executable segments i aktywny HTML, XML lub SVG-like content, ustala MIME z signatures, extension i client hints, stosuje limity pliku i quota po parsing, ogranicza inline types, waliduje obrazy i containment local paths. W sprawdzonych ścieżkach nie potwierdzono first-party malware scanner ani CDR result. Sprawdź ponownie i jawnie zaprojektuj malware, quarantine, archive bomb, body, rate i incident controls.
Powierzchnie autoryzacji i publikacji
Oddziel feature grant, scope tenantu i organizacji, visibility partycji, permission owner record oraz posiadanie id lub URL. attachments.view lub attachments.manage i same-organization nie dowodzą need-to-know dla rekordu biznesowego. Fully global rows w public partitions mogą być anonymous. Public to decyzja publikacyjna. Wygoda przechowywania jej nie uzasadnia.
Testuj actor allow i deny, wrong tenant i organization, owner-record denial, guessed id, stale URL, visibility mismatch, context superadmin i partial-null scope. Dodaj domain authorization hook, gdy jest wymagany.
- 1. library page and list
- 2. per-record list
- 3. metadata detail
- 4. upload
- 5. metadata edit
- 6. transfer
- 7. delete
- 8. original download
- 9. image preview and resize
- 10. OCR content
- 11. assignment enrichment
- 12. filename search
- 13. API key
- 14. direct S3
- 15. signed URL
- 16. superadmin
- 17. public anonymous
- 18. owning business record
- 19. partial-null or global scope
Klasyfikuj dane przed public use; testuj caching i CDN, indexing, referrer i log leakage, revocation i stale copies. Nie twórz global public records dla wygody. Signed URLs delegują time-limited operations od 60 sekund do siedmiu dni w sprawdzonym kodzie; forwarding, provider logs, clocks i limity revocation pozostają ryzykiem.
Metadane, storage i external authority
Free-text tags wymagają normalization, language, rename i retirement. Assignments mogą się zestarzeć przez deleted targets, label drift, href risk, transfer lub multiple owners. Attachment custom fields rozszerzają metadata. Nie zapewniają workflow ani referential integrity.
Zapisz location, owner, access, encryption, retention, deletion, restore, reconciliation i evidence niezależnie.
- 1. attachment metadata database
- 2. original object
- 3. thumbnail and image cache
- 4. temporary OCR files
- 5. extracted content
- 6. query index and search projection
- 7. logs and events
- 8. provider credentials
- 9. backups and replicas
- 10. exports and external copies
Local storage wymaga durable mount, ownership root/path, permissions, monitoringu capacity i inode, backup i restore, worker access, rolling deployment i orphan reconciliation. S3 attachment partitions i standalone storage_s3 API to oddzielne kontrakty: direct routes nie tworzą attachment rows, links, OCR, retention ani domain ACL. Defaults drivera nie obejmują provider versioning, encryption, Object Lock, legal hold, lifecycle, replication, access logs ani KMS.
Dla external authority zakontraktuj stable external id, canonical metadata, deep link, working copy, signed URL, events, opcjonalny designed checksum lub version token, authority delete i hold, reconciliation, outage, conflict i exit. Application row delete, provider object delete, delete markers lub versions, backup expiry i legal disposition to różne zdarzenia.
Granice DMS, records, signature, DAM i AI
Zapisz native evidence i eskalację do modułu, providera lub specjalisty. Brak w attachment row nie prowadzi do konkluzji prawnej.
- 1. document identity
- 2. classification and folders
- 3. version family
- 4. co-authoring or check-in
- 5. workflow and approval
- 6. templates
- 7. correspondence and capture
- 8. e-signature validation
- 9. records schedule
- 10. legal hold
- 11. immutable archive
- 12. access evidence
- 13. federation
- 14. bulk import and export
Przechowywanie PDF z widocznym podpisem nie zapewnia tworzenia ani walidacji signature, qualified signature, seal, timestamp ani trust service. Retention, hold i disposition wymagają polityki, authority, controls i evidence. Sam bucket S3 lub audit log nie zapewnia systemu records. Public product media i resize nie zapewniają pełnego DAM z renditions, rights, approvals i channels. OCR provider i AI-chat attachment delivery to oddzielne external data flows.
Trzy syntetyczne scenariusze i jeden antywzorzec
Wczytaj rekord strukturalny, aby sprawdzić evidence state, tier, contract, responsibilities, stop i acceptance bez danych dokumentu.
Wyłącznie hipotetyczny
Synthetic supporting business-record file
Wyłącznie hipotetyczny
Synthetic policy or certificate library
Wyłącznie hipotetyczny
Synthetic high-control signed record
Stop: przypadkowy confidential shared drive
Nie używaj generic attachment library jako confidential shared drive z szerokim dostępem, bez information owner, controlled classification, retention authority i recovery evidence.
Narzędzie lokalne
Rejestr decyzji kontroli dokumentów
Zaczyna pusty i pozostaje lokalnie w tej przeglądarce. Kompletny rekord zawiera wyłącznie ustalenia planistyczne. Nie rejestruje akceptacji DMS, records, signature, security ani legal.
Nie wpisuj danych rzeczywistych: Używaj tylko notatek strukturalnych. Nie wpisuj realnych nazw firm, filenames, osób, klientów, contents, podpisów, ids, credentials, tenant data, reguł retention ani konfiguracji produkcyjnej. Shared devices, browser backups, extensions i screenshots mogą ujawnić lokalne wpisy.
Prywatność: Strona nie wysyła treści arkusza i nie zapisuje jej w adresie URL ani w plikach cookie.
Pakiet odbioru menedżera
Podaj setup, actor, klasę, file state, scope, oczekiwany row i object, stan widoczny, evidence, wynik zabroniony, failure injection, cleanup, reconciliation, owner i kryterium pass.
- 1. authorized upload
- 2. record link
- 3. metadata row and object
- 4. safe preview or forced download
- 5. filename search
- 6. tag and partition filters
- 7. metadata edit
- 8. transfer
- 9. delete reconciliation
- 10. text extraction
- 11. PDF text layer
- 12. scanned PDF OCR
- 13. image OCR
- 14. DOCX extraction
- 15. unsupported format
- 16. no key
- 17. empty result
- 18. provider failure
- 19. restart before OCR callback
- 20. deleted during processing
- 21. wrong tenant
- 22. wrong organization
- 23. owning-record denial
- 24. missing feature
- 25. guessed id
- 26. public and private mismatch
- 27. fully global public row
- 28. stale signed URL
- 29. direct S3 separation
- 30. create-side orphan
- 31. delete-side orphan
- 32. mixed storage drivers
- 33. thumbnail failure
- 34. stale search index
- 35. backup and restore
- 36. rows without objects
- 37. objects without rows
- 38. version distinction
- 39. signature not validated
- 40. retention and hold conflict
- 41. export and exit reconciliation
- 42. accessibility and print
Zatrzymaj lub odłóż
- no accountable information owner.
- no source of truth.
- unclear public or private choice.
- no owning-record authorization.
- unsupported or untested format.
- no malware or quarantine decision.
- no OCR exception path.
- no durable storage.
- no restore evidence.
- no retention or deletion authority.
- no legal-hold design.
- no version rule.
- no signature or trust design.
- no reconciliation.
- unaccepted high-impact gap.
Praktyczne pytania
Kiedy wybrać system zarządzania dokumentami?
Załączniki sprawdzają się jako pliki pomocnicze powiązane z rekordem biznesowym. Własne wersje dokumentu, zatwierdzanie, wstrzymanie usunięcia lub weryfikacja podpisu wymagają odrębnego modelu dokumentów albo systemu specjalistycznego.
Z których plików można odczytać tekst lub wykonać OCR?
Opisane ścieżki obejmują tekst, PDF z warstwą tekstową i DOCX. OCR obrazów oraz skanowanych PDF zależy od skonfigurowanych usług. Przed użyciem wyników sprawdź własne pliki, nieobsługiwane formaty i awarię dostawcy.
Kto powinien mieć prawo pobrać plik?
Ustal uprawnienia do załącznika i rekordu, do którego należy. Sprawdź pobieranie oryginału, podgląd, link publiczny i bezpośredni dostęp do magazynu plików. Samo powiązanie z rekordem nie potwierdza prawa dostępu.
Czy usunięte pliki można odtworzyć?
Odtworzenie zależy od sposobu przechowywania oraz kopii plików i metadanych. Przećwicz odzyskanie pliku razem z powiązaniami. Sam zasobnik S3 lub kopia bazy nie potwierdzają pełnego odtworzenia.