- Homepage
- /
- Tencent WeDa
- /
- administrator
Tencent WeDa Administrator Configuration Guide
Governance manual for enterprise IT administrators under Tencent WeDa + WeCom: organizational structure, role permissions, release process, security compliance, audit logs, operation and maintenance monitoring and disaster recovery and backup all in one place.
6 Great administrator ability map
Organization and members
Synchronize WeCom address book, department level, job label, external member grouping; automatically receive rights after resignation.
Roles and permissions
Preset three types of roles: administrator/developer/user; supports custom role templates and fine-grained resource authorization.
Application release governance
Release approval, environment isolation, version snapshot, grayscale volume scaling, one-click rollback, and blacklist interception.
Security Compliance
Data desensitization, watermarking, anti-downloading, IP whitelist, Class A guarantee/financial compliance, key KMS hosting.
System integration
WeCom / SSO / AD / Feishu / DingTalk / ERP / CRM / HR unified identity and data docking.
Operation, Maintenance and Disaster Recovery
Cloud monitoring alarms, log CLS, automatic backup, cross-availability zone disaster recovery, and disaster drills.
Typical role permission matrix
| Capabilities/Resources | super administrator | application manager | Developer | user | visitor |
|---|---|---|---|---|---|
| Organization/Member Management | ✓ | ✗ | ✗ | ✗ | ✗ |
| Role authorization/permission template | ✓ | part | ✗ | ✗ | ✗ |
| Application creation/publishing | ✓ | ✓ | ✓ | ✗ | ✗ |
| Data source/connector configuration | ✓ | within range | ✓ | ✗ | ✗ |
| Data reading and writing (business) | ✓ | ✓ | ✓ | Authorization scope | ✗ |
| Audit log view | ✓ | This application | ✗ | ✗ | ✗ |
| View sensitive fields | ✓ | by strategy | ✗ | ✗ | ✗ |
Recommendation: Business users have no auditing/no sensitive field viewing by default; developers can only access the development/testing environment.
SSO & Ecological Integration
🆔 Identity source
- WeCom (recommended primary identity)
- WeChat applet
- DingTalk/Feishu (Connector)
- AD/LDAP (API Gateway Bridging)
🔐 Authentication protocol
- OAuth 2.0 / OIDC
- SAML 2.0
- CAS (enterprise-owned IdP)
- JWT token bridging
🔌Business system
- ERP:用友 / 金蝶 / SAP
- CRM: Tencent Qidian/Salesforce
- HR: Beisen/Moka
- BI:腾讯云 BI / Power BI
Audit, Compliance and Data Security
📝 Audit log dimensions
- Login / Logout / Authorization changes
- Data addition, deletion, modification (CRUD)
- Export/Print/Share
- Process approval track
- Sensitive field access
🔒 Data Security Policy
- Field-level desensitization (mobile phone/ID card/bank card)
- Watermark + anti-screenshot (H5 / applet)
- IP whitelist + device fingerprint
- Export approval + secondary verification
- File virus scanning (Cloud API)
🏛️ Compliance Alignment
- Class 3/4 scenario requirements
- "Personal Information Protection Law" PIPL
- Financial industry regulatory requirements
- Industry data classification and grading
🔑 Key management
- Tencent Cloud KMS Hosting
- SSM parameter warehouse (environment variables)
- Connector keys rotate regularly
- Disable hard coding into code blocks
Operation, maintenance, monitoring and disaster recovery
📊 Monitoring
Cloud monitoring: application visits, error rate, P95 delay, SCF trigger times; receive enterprise micro alarms.
🧾 Log
Front-end/cloud function log → CLS; create keyword alarms (such as timeout, 500).
💾 Backup
Database is fully backed up on a daily basis + real-time CDC increment; object storage is replicated across regions; configuration is exported to Git.
🌐 High availability
Multi-availability zone deployment; API gateway current limiting and fusing; key applications blue and green releases.
🧪 Walkthrough
Quarterly disaster recovery switching drills; core link stress testing before release.
📞On duty
P0 failure will be responded to within 15 minutes, and the SOP will clarify the upgrade path and review mechanism.
Admin resources
WeDa official documentation · Management manual
Administrator backend, permissions, publishing and environment management
Tencent Cloud CAM Access Management
Universal capabilities to unify identities, policies and roles
Tencent Cloud CLS Log Service
Collection and analysis of audit/operation and maintenance logs
Tencent Cloud KMS Key Management
Enterprise-grade key escrow and data encryption
WeCom Administrator Help
Address Book/Application Management/Permission Policy
National Class Insurance Compliance Inquiry
Level protection policies, requirements, and filing portals