Computing system providing saas application access with different capabilities based upon user personas
Abstract
A computing device may include a memory and a processor configured to cooperate with the memory to log a client computing device(s) into a user account having an enterprise persona and a private persona associated therewith. While the at least one client computing device is logged into the user account, the processor may further determine whether the enterprise or private persona is active based upon a context associated with the client computing device(s). When the enterprise persona is active, the processor may provide the at client computing device(s) with access to a SaaS application with a first set of capabilities enabled, and when the private persona is active with access to the SaaS application with a second set of capabilities enabled that is different than the first set. The first set may allow downloading of data from the SaaS application, and the second set may not allow downloading of data.
Claims
exact text as granted — not AI-modified1 . A computing device comprising:
a memory and a processor configured to cooperated with the memory to
log at least one client computing device into a user account, the user account having an enterprise persona and a private persona associated therewith; and
while the at least one client computing device is logged into the user account,
determine whether the enterprise persona or the private persona is active based upon a context associated with the at least one client computing device,
when the enterprise persona is active, provide the at least one client computing device with access to a Software as a Service (SaaS) application with a first set of capabilities enabled, and
when the private persona is active, provide the at least one client computing device with access to the SaaS application with a second set of capabilities enabled that is different than the first set of capabilities;
wherein the first set of capabilities allows downloading of data from the SaaS application, and the second set of capabilities does not allow downloading of data from the SaaS application.
2 . The computing device of claim 1 wherein the processor determines whether the enterprise persona or the private persona is active based upon a location of the client computing device.
3 . The computing device of claim 1 wherein the processor determines whether the enterprise persona or the private persona is active based upon a type of data to be accessed by the at least one client computing device.
4 . The computing device of claim 1 wherein the processor determines whether the enterprise persona or the private persona is active based upon a time of day.
5 . The computing device of claim 1 wherein the first and second sets of capabilities are also associated with different respective data loss prevention (DLP) access levels.
6 . The computing device of claim 1 wherein the processor is further configured to migrate between the first and second instances of the SaaS application while the at least one client computing device remains authenticated based upon a change in the context.
7 . The computing device of claim 1 wherein the first set of capabilities further includes data recording, and the second set of capabilities does not include data recording.
8 . A method for using a server comprising:
logging at least one client computing device into a user account, the user account having an enterprise persona and a private persona associated therewith; and while the at least one client computing device is logged into the user account,
determining whether the enterprise persona or the private persona is active based upon a context associated with the at least one client computing device,
when the enterprise persona is active, providing the at least one client computing device with access to a Software as a Service (SaaS) application with a first set of capabilities enabled, and
when the private persona is active, providing the at least one client computing device with access to the SaaS application with a second set of capabilities enabled that is different than the first set of capabilities;
wherein the first set of capabilities allows downloading of data from the SaaS application, and the second set of capabilities does not allow downloading of data from the SaaS application.
9 . The method of claim 8 wherein determining whether the enterprise persona or the private persona is active comprises determining whether the enterprise persona or the private persona is active based upon a location of the client computing device.
10 . The method of claim 8 wherein determining whether the enterprise persona or the private persona is active comprises determining whether the enterprise persona or the private persona is active based upon a type of data to be accessed by the at least one client computing device.
11 . The method of claim 8 wherein determining whether the enterprise persona or the private persona is active comprises determining whether the enterprise persona or the private persona is active based upon a time of day.
12 . The method of claim 8 wherein the first and second sets of capabilities are also associated with different respective data loss prevention (DLP) access levels.
13 . The method of claim 8 further comprising migrating between the first and second instances of the SaaS application while the at least one client computing device remains authenticated based upon a change in the context.
14 . The method of claim 8 wherein the first set of capabilities further includes data recording, and the second set of capabilities does not include data recording.
15 . A non-transitory computer-readable medium having computer-executable instructions for causing a server to perform steps comprising:
logging at least one client computing device into a user account, the user account having an enterprise persona and a private persona associated therewith; and while the at least one client computing device is logged into the user account,
determining whether the enterprise persona or the private persona is active based upon a context associated with the at least one client computing device,
when the enterprise persona is active, providing the at least one client computing device with access to a Software as a Service (SaaS) application with a first set of capabilities enabled, and
when the private persona is active, providing the at least one client computing device with access to the SaaS application with a second set of capabilities enabled that is different than the first set of capabilities;
wherein the first set of capabilities allows downloading of data from the SaaS application, and the second set of capabilities does not allow downloading of data from the SaaS application.
16 . The non-transitory computer-readable medium of claim 15 wherein determining whether the enterprise persona or the private persona is active comprises determining whether the enterprise persona or the private persona is active based upon a location of the client computing device.
17 . The non-transitory computer-readable medium of claim 15 wherein determining whether the enterprise persona or the private persona is active comprises determining whether the enterprise persona or the private persona is active based upon a type of data to be accessed by the at least one client computing device.
18 . The non-transitory computer-readable medium of claim 15 wherein determining whether the enterprise persona or the private persona is active comprises determining whether the enterprise persona or the private persona is active based upon a time of day.
19 . The non-transitory computer-readable medium of claim 15 wherein the first and second sets of capabilities are also associated with different respective data loss prevention (DLP) access levels.
20 . The non-transitory computer-readable medium of claim 15 further having computer-executable instructions for causing the server to perform a step of migrating between the first and second instances of the SaaS application while the at least one client computing device remains authenticated based upon a change in the context.Join the waitlist — get patent alerts
Track US2022239647A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.