IP Library Granted Patent US 12701121
Granted Patent B2
US 12701121 · App. 18/155,197 · Granted Aug 4, 2026

Entitlement engine for certifying user permissions

Inventor: Sidharth Garg (Atlanta, GA)
Assignee: TRUIST BANK
H04L63/104H04L63/102H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12701121
App. No.
18/155,197
Granted
Aug 4, 2026
Kind
B2
Abstract

A system and method for providing an entitlement engine and certifying user permissions is described herein. The system presenting a graphical user interface displaying an entitlement engine to a primary user to select permissions for a list of secondary users for application features and transmitting the selected permissions to a server computer for storing on a user profile and generating an entitlement logic code based on the user's profile. The entitlement logic code is utilized to generate a graphical user interface displaying the user dashboard for the secondary user upon receiving a request from the secondary user and validating the secondary user based on authentication data.

Claims (72)

1 . A system for certifying user permissions, the system comprising:

an entitlement engine configured to generate an entitlement logic code within a distributed computing environment;

a user computing device comprising at least one processor, a memory, and a communication device, wherein the user computing device is configured to communicate with the entitlement engine; and

a server computer system comprising at least one processor, a memory, and a communication device, wherein the server computer system is configured to communicate with the entitlement engine;

wherein the user computing device is configured to:

initiate presentation of a graphical user interface enabling display of an entitlement engine, the entitlement engine comprising a list of secondary users and a list of application features;

receive user input, from a user input device, selecting one or more permissions corresponding to at least one of the list of secondary users and at least one of the list of application features; and

initiate transmission of the selected one or more permissions across a communication channel between the user computing device and the server computer system; and

wherein the server computer system is configured to:

receive the transmission of the one or more permissions from the user computing device, and over the communication channel;

analyze the received transmission to identify information to be stored, including identifying the one or more permissions corresponding to the at least one of the list of secondary users and the at least one of the list of application features;

associate the one or more permissions with a user profile of the at least one of the list of secondary users, wherein the user profile comprises: job title, user type, tenure, and location;

generate an entitlement logic code, based on the user profile, wherein the entitlement logic code comprises executable code indicating the one or more permissions associated with the user profile and the entitlement logic code is configured to update based on changes to the user profile, and when the entitlement logic code is executed, a digital account environment of the at least one of the list of secondary users comprises the one or more permissions associated with the user profile; and

store the entitlement logic code in the user profile.

2 . The system according to claim 1 , wherein the user computing device is further configured to:

receive second user input from a secondary user, the second input comprising a request for access to an application and user authentication data;

initiate a transmission of the user authentication data between the user computing device and the server computer system across the communication channel; and

wherein the server computer system is further configured to:

receive the transmission of the user authentication data from the user computing device, and over the communication channel;

validate the secondary user, based on the user authentication data;

retrieve the user profile associated with the secondary user;

retrieve the stored entitlement logic code from the user profile; and

initiate a transmission of the stored entitlement logic code between the server computer system and the user computing device across the communication channel.

3 . The system according to claim 2 , wherein the user computing device is further configured to:

receive the transmission of the stored entitlement logic code from the server computer system, and over the communication channel; and

initiate presentation of a second graphical user interface display of a dashboard of the secondary user, the dashboard of the secondary user comprising services and data based on the stored entitlement logic code.

4 . The system according to claim 1 , wherein the user type comprises custom-access or full-access.

5 . The system according to claim 1 , wherein the user type comprises administrator or standard.

6 . The system according to claim 1 , wherein the one or more permissions comprise one or more of: viewing an application feature from the list of application features, using the application feature from the list of application features, and making changes to the application feature from the list of application features.

7 . A system for certifying user permissions comprising, the system comprising:

an entitlement engine configured to generate an entitlement logic code within a distributed computing environment;

a user computing device comprising at least one processor, a memory, and a communication device, wherein the user computing device is configured to communicate with the entitlement engine; and

a server computer system comprising at least one processor, a memory, and a communication device, wherein the server computer system is configured to communicate with the entitlement engine;

wherein the user computing device is configured to:

receive user input from a secondary user, the input comprising a request for access to an application and user authentication data;

initiate a transmission of the user authentication data between the user computing device and the server computer system across the communication channel; and

wherein the server computer system is further configured to:

receive the transmission of the user authentication data from the user computing device, and over the communication channel;

validate the secondary user, based on the user authentication data;

retrieve a user profile associated with the secondary user, wherein the user profile comprises: job title, user type, tenure, and location;

generate an entitlement logic code based on the user profile, wherein the entitlement logic code comprises executable code indicating the one or more permissions associated with the user profile, and the entitlement logic code is configured to update based on changes to the user's profile, and when the entitlement logic code is executed, a digital account environment of the at least one of the list of secondary users comprises the one or more permissions associated with the user profile; and

initiate a transmission of the entitlement logic code between the server computer system and the user computing device across the communication channel.

8 . The system according to claim 7 , wherein the user computing device is further configured to:

receive the transmission of the entitlement logic code from the server computer system, and over the communication channel; and

initiate presentation of a second graphical user interface display of a dashboard of the secondary user, the dashboard of the secondary user comprising services and data based on the entitlement logic code.

9 . The system according to claim 7 , wherein the user type comprises custom-access or full-access.

10 . The system according to claim 7 , wherein the user type comprises administrator or standard.

11 . The system according to claim 7 , wherein the one or more permissions comprise one or more of: viewing an application feature from the list of application features, using the application feature from the list of application features, and making changes to the application feature from the list of application features.

12 . A method for certifying user permissions comprising, the method being executed by a server computer system interoperating with a user computing devices, the method comprising:

initiating, on the user computing device, presentation of a graphical user interface enabling display of an entitlement engine, the entitlement engine comprising a list of secondary users and a list of application features and configured to generate an entitlement logic code within a distributed computing environment, wherein the server computer system is configured to communicate with the entitlement engine and the user computing device is configured to communicate with the entitlement engine;

receive user input, from a user input device, selecting one or more permissions corresponding to at least one of the list of secondary users and at least one of the list of application features;

initiating transmission of the selected one or more permissions across a communication channel between the user computing device and the server computer system;

receiving, on the server computer system, transmission from the user computing device and over the communication channel, of the transmitted one or more permissions;

analyzing, the received transmission to identify information to be stored, including identifying the one or more permissions corresponding to the at least one of the list of secondary users and the at least one of the list of application features;

associating the one or more permissions with a user profile of the at least one of the list of secondary users, wherein the user profile comprises: job title, user type, tenure, and location;

generating an entitlement logic code, based on the user profile, wherein the entitlement logic code comprises executable code indicating the one or more permissions associated with the user profile, and the entitlement logic code is configured to update based on changes to the user's profile;

storing the entitlement logic code in the user profile; and

executing the entitlement logic code, wherein executing the entitlement logic code results in a digital account environment of the at least one of the list of secondary users comprising the one or more permissions associated with the user profile.

13 . The method according to claim 12 , further comprising:

receiving, with the user computing device, second user input from a secondary user, the second input comprising a request for access to an application and user authentication data;

initiating a transmission of the user authentication data between the user computing device and the server computer system across the communication channel; and

receiving, on the server computer system, the transmission of the user authentication data from the user computing device, and over the communication channel;

validating the secondary user, based on the user authentication data;

retrieving the user profile associated with the secondary user;

retrieving the stored entitlement logic code from the user profile;

initiating a transmission of the stored entitlement logic code between the server computer system and the user computing device across the communication channel.

14 . The method according to claim 13 , further comprising:

receiving, on the user computing device, the transmission of the stored entitlement logic code from the computer, and over the communication channel; and

initiating presentation of a second graphical user interface display of a dashboard of the secondary user, the dashboard of the secondary user comprising services and data based on the stored entitlement logic code.

15 . The method according to claim 12 , wherein the user type comprises custom-access or full-access.

16 . The method according to claim 12 , wherein the user type comprises administrator or standard.

17 . The method according to claim 12 , wherein the one or more permissions comprise one or more of: viewing an application feature from the list of application features, using the application feature from the list of application features, and making changes to the application feature from the list of application features.