Systems and methods for delegating access to a protected resource
Abstract
A method for managing access privileges is disclosed. The method includes: obtaining employee hierarchy data associated with an organization; identifying a change in access privileges associated with at least one employee for a protected resource, the identifying including: determining first permissions data indicating current access privileges associated with one or more employees for the protected resource based on the employee hierarchy data; comparing the first permissions data with stored second permissions data that indicates previously granted access privileges associated with the one or more employees for the protected resource; and identifying a difference in access privileges associated with at least one employee based on the comparing, determining that the change in access privileges associated with the at least one employee requires approval from an authorized permissions management entity; and configuring an account at the protected resource that is associated with the authorized permissions management entity to present options for approving the change in access privileges associated with the at least one employee.
Claims
exact text as granted — not AI-modified1 . A computing system, comprising:
a processor; and a memory coupled to the processor, the memory storing instructions that, when executed by the processor, configure the processor to:
obtain employee hierarchy data associated with an organization;
identify a change in access privileges associated with at least one employee for a protected resource, the identifying including:
determining first permissions data indicating current access privileges associated with one or more employees for the protected resource based on the employee hierarchy data;
comparing the first permissions data with stored second permissions data that indicates previously granted access privileges associated with the one or more employees for the protected resource; and
identifying a difference in access privileges associated with at least one employee based on the comparing,
determine that the change in access privileges associated with the at least one employee requires approval from an authorized permissions management entity; and
configure an account at the protected resource that is associated with the authorized permissions management entity to present options for approving the change in access privileges associated with the at least one employee.
2 . The computing system of claim 1 , wherein the instructions, when executed, further configure the processor to:
receive, from the authorized permissions management entity, an indication of approval for the change in access privileges associated with the at least one employee; and in response to receiving the indication of approval, update a user permissions database associated with the protected resource to indicate the change in access privileges associated with the at least one employee.
3 . The computing system of claim 1 , wherein the instructions, when executed, further configure the processor to transmit, to a client server having access to a human resources database of the organization, a request for the employee hierarchy data.
4 . The computing system of claim 1 , wherein at least one of the first or second permissions data comprises a mapping of employee identifiers to access privileges for the protected resource.
5 . The computing system of claim 1 , wherein the instructions, when executed, further configure the processor to:
receive, from a first user device, a request to access the protected resource; and determine that a user associated with the first user device has access privileges for the protected resource.
6 . The computing system of claim 5 , wherein determining that the user associated with the first user device has the access privileges comprises querying a user permissions database using a first employee identifier associated with the user.
7 . The computing system of claim 1 , wherein the instructions, when executed, further configure the processor to transmit, to the authorized permissions management entity, a request to approve the change in access privileges associated with the at least one employee.
8 . The computing system of claim 7 , wherein the request comprises a message indicating the change in access privileges associated with the at least one employee for the protected resource.
9 . The computing system of claim 1 , wherein the first permissions data comprises a mapping of employee identifiers to access privileges for the protected resource.
10 . The computing system of claim 1 , wherein the access privileges for the protected resource comprise at least one of permissions for accessing or authorizing one or more actions in connection with the protected resource.
11 . A method for managing access privileges for a protected resource, the method comprising:
obtaining employee hierarchy data associated with an organization; identifying a change in access privileges associated with at least one employee for a protected resource, the identifying including:
determining first permissions data indicating current access privileges associated with one or more employees for the protected resource based on the employee hierarchy data;
comparing the first permissions data with stored second permissions data that indicates previously granted access privileges associated with the one or more employees for the protected resource; and
identifying a difference in access privileges associated with at least one employee based on the comparing,
determining that the change in access privileges associated with the at least one employee requires approval from an authorized permissions management entity; and configuring an account at the protected resource that is associated with the authorized permissions management entity to present options for approving the change in access privileges associated with the at least one employee.
12 . The method of claim 11 , further comprising:
receiving, from the authorized permissions management entity, an indication of approval for the change in access privileges associated with the at least one employee; and in response to receiving the indication of approval, updating a user permissions database associated with the protected resource to indicate the change in access privileges associated with the at least one employee.
13 . The method of claim 11 , further comprising transmitting, to a client server having access to a human resources database of the organization, a request for the employee hierarchy data.
14 . The method of claim 11 , wherein at least one of the first or second permissions data comprises a mapping of employee identifiers to access privileges for the protected resource.
15 . The method of claim 11 , further comprising:
receiving, from a first user device, a request to access the protected resource; and determining that a user associated with the first user device has access privileges for the protected resource.
16 . The method of claim 15 , wherein determining that the user associated with the first user device has the access privileges comprises querying a user permissions database using a first employee identifier associated with the user.
17 . The method of claim 11 , further comprising transmitting, to the authorized permissions management entity, a request to approve the change in access privileges associated with the at least one employee.
18 . The method of claim 17 , wherein the request comprises a message indicating the change in access privileges associated with the at least one employee for the protected resource.
19 . The method of claim 11 , wherein the first permissions data comprises a mapping of employee identifiers to access privileges for the protected resource.
20 . The method of claim 11 , wherein the access privileges for the protected resource comprise at least one of permissions for accessing or authorizing one or more actions in connection with the protected resource.Join the waitlist — get patent alerts
Track US2022272097A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.