IP Library Granted Patent US 12711262
Granted Patent B1
US 12711262 · App. 19/311,934 · Granted Aug 18, 2026

Management of computational enterprise environment with platform for generating and utilizing sandboxes

Inventors: Fnu Sachin Gopal (San Francisco, CA); Nikunj Aggarwal (Secaucas, NJ); Nitin Aggarwal (San Francisco, CA); Kyle Boston (San Francisco, CA); Varshini Kumar (New York, NY); Munira Godman Rahemtulla (Seattle, WA); Jingru Guo (San Francisco, CA); Murray Leo Spork (San Francisco, CA); Amit Parikh (Foster City, CA); Rupank Bansal (San Francisco, CA); Chi Zhang (Palo Alto, CA)
Assignee: People Center, Inc.
G06F21/6218G06F21/53
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12711262
App. No.
19/311,934
Granted
Aug 18, 2026
Kind
B1
Abstract

Systems, devices, computer-implemented methods, and tangible non-transitory computer readable media for developing and executing sandboxes with instances that perform complex, multi-step workflows for large-scale workforce management systems. For example, a computing device may control communications and operations associated with the sandboxes to avoid interference from the sandboxes with one another. The computing device can manage login-as content associated with corresponding sandbox instances being generated therewith. The sandboxes can be managed utilizing different states controlled by state machines for various types of operations associated with the sandboxes.

Claims (79)

1 . A computing system, comprising:

one or more processors;

a data store storing one or more logical databases with user data;

one or more non-transitory computer-readable media that collectively perform one or more operations, comprising:

establishing a sandbox of a workforce management platform and a logical database for a sandbox instance of the sandbox;

managing objects in the logical database of the sandbox using metadata associated with a corresponding cluster, the logical database isolating the sandbox from one or more other sandboxes;

managing permissioned access to the objects, based on relative assignments of users in an organization;

generating and executing the sandbox instance of the sandbox using the managed objects and the managed permissioned access; and

performing an action using the sandbox instance based on a command and a user profile of a user of the organization, the command being associated with the user and provided based on customer input from a customer.

2 . The computing system of claim 1 , wherein the one or more operations comprise:

dynamically managing the objects and the permissioned access with a sandbox orchestrator using a plurality of sandbox modes in a preview environment by:

dynamically performing the managing of the objects in the sandbox instance with the sandbox orchestrator in a test mode; and

dynamically performing the managing of the permissioned access to the objects with the sandbox orchestrator in the test mode.

3 . The computing system of claim 1 , wherein the one or more operations comprise:

receiving, from a customer device and via customer input to the customer device, a request comprising an identifier utilized to select the sandbox instance and a login-as value utilized to select the user profile, and

wherein performing the action comprises denying the command based on the customer being logged in as the user and a permission of the user not satisfying a requirement to perform the command.

4 . The computing system of claim 1 , wherein the one or more operations comprise:

receiving, from an administrator device, a request to set a permission associated with a folder of the user; and

updating the sandbox instance by setting the permission associated with the folder and sharing the permission to each of a plurality of files in the folder,

wherein the command comprises a request to access a file in the folder, and a permission associated with the file is set in response to the sharing of the permission associated with the folder, and

wherein performing the action comprises granting the request based on a permission assigned to the user satisfying the permission associated with the file.

5 . The computing system of claim 1 , wherein the one or more operations comprise:

receiving, from a customer device and via customer input to the customer device, a first request comprising a first identifier utilized to select the sandbox instance as a first sandbox instance with a first cluster; and

receiving, from the customer device and via customer input to the customer device, a second request comprising a second identifier utilized to select a second sandbox instance associated with a second cluster physically isolated from the first cluster,

wherein the first sandbox instance and the second sandbox instance are logically isolated from one another,

wherein the first sandbox instance and the second sandbox instance are both associated with a base preview cluster, and

wherein the base preview cluster comprises collection and configuration data associated with a plurality of clusters but does not comprise customer data.

6 . The computing system of claim 1 , wherein the logical database comprises a plurality of collections of data from a plurality of different sources associated with a plurality of different databases in the workforce management platform.

7 . The computing system of claim 1 , wherein the one or more operations comprise:

receiving, from a customer device, a request associated with testing a third-party application and the workforce management platform using the sandbox instance; and

performing another action using the third-party application and the workforce management platform with the sandbox instance, and

wherein data in the logical database being modified by the performing of the other action is isolated from other data in other logical databases associated with other sandboxes in the workforce management platform.

8 . The computing system of claim 1 , wherein the one or more operations comprise:

blocking communications to third-party systems by auditing traffic using a network proxy and one or more domain allowlists, the network proxy being coupled between the computing system and the third-party systems.

9 . The computing system of claim 1 wherein the one or more operations comprise:

storing, in a preview instance model, a unique identifier of the sandbox instance; and

storing, in the preview instance model, a status of the sandbox instance.

10 . The computing system of claim 1 , wherein the one or more operations comprise:

managing a sandbox orchestrator by:

provisioning the sandbox instance as a new instance using the sandbox orchestrator in a provisioning state;

identifying using the sandbox orchestrator in a provisioning failed state that the provisioning of the sandbox instance as the new instance failed; and

retrying the provisioning of the sandbox instance as the new instance using the sandbox orchestrator to proceed to a provisioned empty state.

11 . The computing system of claim 1 , wherein the one or more operations comprise:

managing a sandbox orchestrator by:

based on the sandbox orchestrator being a provisioned empty state, resetting the sandbox instance using the sandbox orchestrator in a resetting state;

identifying using the sandbox orchestrator in a reset failed state that the resetting of the sandbox instance failed;

retrying the resetting of the sandbox instance using the sandbox orchestrator to proceed to a restoring state;

restoring the sandbox instance using the sandbox orchestrator in the restoring state;

identifying using the sandbox orchestrator in a restore failed state that the restoring of the sandbox instance failed; and

retrying the resetting and the restoring of the sandbox instance using the sandbox orchestrator to proceed to a ready state.

12 . A computer-implemented method, comprising:

establishing a sandbox of a workforce management platform and a logical database for a sandbox instance of the sandbox;

managing objects in the logical database of the sandbox using metadata associated with a corresponding cluster, the logical database isolating the sandbox from one or more other sandboxes;

managing permissioned access to the objects, based on relative assignments of users in an organization;

generating and executing the sandbox instance of the sandbox using the managed objects and the managed permissioned access; and

performing an action using the sandbox instance based on a command and a user profile of a user of the organization, the command being associated with the user and provided based on customer input from a customer.

13 . The computer-implemented method of claim 12 , further comprising:

blocking outbound network traffic associated with the sandbox instance by default, by using a network proxy to selectively permit traffic using the sandbox instance according to a pre-approved list of domains.

14 . The computer-implemented method of claim 12 , wherein the command comprises a login-as command received from the customer, the customer comprising an administrator of the workforce management platform,

further comprising:

identifying whether to grant within the sandbox a login to the administrator as another employee of the organization, wherein the login enables the administrator to directly view how system changes associated with permissions will appear to the other employee during operation of the workforce management platform.

15 . The computer-implemented method of claim 12 , further comprising:

automatically rerouting one or more notifications from among notifications generated by workflows within the sandbox, the notifications comprising at least one of emails or messaging service messages, the one or more notifications being automatically rerouted to a testing channel accessible by an administrator of the workforce management platform.

16 . The computer-implemented method of claim 12 , further comprising:

registering one or more aliases from among a plurality of aliases associated with the workforce management platform, the one or more aliases not being previously registered at startup along with remaining aliases of the plurality of aliases, the one or more aliases being dynamically registered for the sandbox instance on-demand based on a request for the sandbox instance being received.

17 . One or more non-transitory computer readable media configured to generate multiple sandbox instances per individual customer, the one or more non-transitory computer readable media storing instructions that are executable by one or more processors to perform one or more operations comprising:

establishing a sandbox of a workforce management platform and a logical database for a sandbox instance of the sandbox;

managing objects in the logical database of the sandbox using metadata associated with a corresponding cluster, the logical database isolating the sandbox from one or more other sandboxes;

managing permissioned access to the objects, based on relative assignments of users in an organization;

generating and executing the sandbox instance of the sandbox using the managed objects and the managed permissioned access; and

performing an action using the sandbox instance based on a command and a user profile of a user of the organization, the command being associated with the user and provided based on customer input from a customer.

18 . The one or more non-transitory computer readable media of claim 17 , wherein the one or more operations comprise:

dynamically managing the objects and the permissioned access with a sandbox orchestrator using a plurality of sandbox modes in a preview environment by:

dynamically performing the managing of the objects in the sandbox instance with the sandbox orchestrator in a test mode; and

dynamically performing the managing of the permissioned access to the objects with the sandbox orchestrator in the test mode.

19 . The one or more non-transitory computer readable media of claim 17 , wherein data associated with the organization is captured from multiple different sources and collections and flattened into a single logical database, and

wherein the single logical database is used to provide isolation between the sandbox instance and remaining sandbox instances associated with the sandbox or other sandboxes.

20 . The one or more non-transitory computer readable media of claim 17 , wherein the action comprises a multistep workflow from among a plurality of multistep workflows, and

wherein the plurality of multistep workflows comprising a hiring and onboarding flow, and offboarding flow, and an open enrollment configurations flow.