KamoCRM

The org graph in KBService and every note read through the one widened predicate — shared notes reach their audience read-only; create and update refuse a shared scope (USE_RELEASE) and the reserved categories (RESERVED_CATEGORY) (KamoCollab CP05 Task 15)

FeatureKBService
Shipped
October 11, 2026 at 9:18 AM UTC
Author
Kamo
Commit
4237f30

- orggraph/OrgGraphBeanConfig + OrgGraphEventListener: the loader, the 60 s cache, and a core subscription to security.orggraph.changed.* that evicts the org (svc_kb's permission is CP02 Task 6A's). - **************** team member and active, team ids, department path, levels up to the effective level; no node = own notes and the org master only. - NotesService: getNote, getAllNotes, searchNotes, getAllCategories, getVersionHistory, restoreVersion and getLinkedNotes read through the NoteRepository visible finders with the resolver's audience; restore and update stay owner-only (or the org master with its right); supervisee reads are the supervisee's own notes (findByMemberId / findByIdAndMemberId). NoteDTO carries knowledgeScope, scopeRef, sensitivity, confidential, confidentialSetByMemberId, owner, and audienceMemberIds for the owner of a NAMED note; editable = own note, or the org master with the right. - NoteVisibleQueryTest: the repository builds on this service's Hibernate and VISIBLE runs as one keyed UNION (ruling CP05-T15-1).

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing