IP Library Granted Patent US 11,080,420
Granted Patent B2
US 11,080,420 · App. 16/673,899 · Granted Aug 3, 2021

Representing access permissions to documents

Inventors: Scott Rickard (Bellevue, WA); Anuprit Kale (San Drancisco, CA); Victor Spivak (San Mateo, CA); Yanik Grignon (Cedar Park, TX); Venkatesan Chandrasekaran (Pleasanton, CA)
Assignee: salesforce.com, inc.
G06F21/6227G06F21/604
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,080,420
App. No.
16/673,899
Granted
Aug 3, 2021
Kind
B2
Abstract

A record management system stores records for an organization having a plurality of members and a plurality of groups, and manages accessibility of the records for the organization according to a specified record access policy. The record management system generates an accessibility database that indicates, for each member, records that are explicitly or implicitly accessible by each member such that the records accessible for each member can be quickly determined if needed. A member has explicit access to a record if there is an explicit indication of accessibility between the member and the record. A member has implicit access to a record through membership associations to other members or groups that have access to the record. The record management system also receives search queries from members and returns records that are relevant and accessible to the members based on the accessibility database.

Claims (77)

1. A computer implemented method for processing search queries, the method comprising:

receiving, by a computer system, a first search query from a first client device associated with a first member;

receiving, by the computer system, a second search query from a second client device associated with a second member;

determining, by the computer system, that the first member has access to less than a threshold number of records from a plurality of records;

responsive to determining that the first member has access to less than the threshold number of records from the plurality of records:

determining, by the computer system, records accessible by the first member from the plurality of records;

identifying, by the computer system, records relevant to the first search query from the determined records accessible by the first member; and

transmitting, by the computer system to the first client device, first search results that include the identified records relevant to the first search query;

determining, by the computer system, that the second member has access to more than the threshold number of records from the plurality of records; and

responsive to determining that the second member has access to more than the threshold number of records from the plurality of records:

identifying, by the computer system from the plurality of records, records relevant to the second search query;

determining, by the computer system, records accessible by the second member from the identified records relevant to the second search query; and

transmitting, by the computer system to the second client device, second search results that include the determined records accessible by the second member.

2. The method of claim 1 , further comprising:

identifying, by the computer system, one or more first databases including first information indicating records explicitly accessible by each member from a plurality of members including the first member and the second member, and records explicitly accessible by each group from a plurality of groups;

identifying, by the computer system, one or more second databases including second information indicating membership associations between the plurality of members and the plurality of groups; and

generating a third database by combining at least a portion of the first information and the second information, the third database indicating for at least the first member and the second member, records explicitly and implicitly accessible by the first member, and records explicitly and implicitly accessible by the second member.

3. The method of claim 2 , wherein determining that the first member has access to less than the threshold number of records and determining that the second member has access to more than the threshold number of records is based on the third database.

4. The method of claim 2 , wherein determining the records accessible by the first member and determining the records accessible by the second member is based on the third database.

5. The method of claim 2 , wherein the third database is generated by combining the portion of the first information and the second information through matrix multiplication.

6. The method of claim 1 , wherein determining the records accessible by the first member and determining the records accessible by the second member is based on an accessibility database that indicates records explicitly and implicitly accessible by the first member and records explicitly and implicitly accessible by the second member.

7. The method of claim 1 , further comprising:

identifying, by the computer system, one or more first databases including first information indicating records explicitly accessible by each member from a plurality of members including the first member and the second member, and records explicitly accessible by each group from a plurality of groups;

identifying, by the computer system, one or more second databases including second information indicating membership associations between the plurality of members and the plurality of groups; and

combining a portion of the second information corresponding to membership associations for the first member and the second member with the one or more first databases to determine the records accessible by the first member and to determine the records accessible by the second member.

8. A non-transitory computer readable storage medium storing instructions that when executed by a computer processor, cause the computer processor to perform steps comprising:

receiving, by a computer system, a first search query from a first client device associated with a first member;

receiving, by the computer system, a second search query from a second client device associated with a second member;

determining, by the computer system, that the first member has access to less than a threshold number of records from a plurality of records;

responsive to determining that the first member has access to less than the threshold number of records from the plurality of records:

determining, by the computer system, records accessible by the first member from the plurality of records;

identifying, by the computer system, records relevant to the first search query from the determined records accessible by the first member; and

transmitting, by the computer system to the first client device, first search results that include the identified records relevant to the first search query;

determining, by the computer system, that the second member has access to more than the threshold number of records from the plurality of records; and

responsive to determining that the second member has access to more than the threshold number of records from the plurality of records:

identifying, by the computer system from the plurality of records, records relevant to the second search query;

determining, by the computer system, records accessible by the second member from the identified records relevant to the second search query; and

transmitting, by the computer system to the second client device, second search results that include the determined records accessible by the second member.

9. The non-transitory computer readable storage medium of claim 8 , wherein the stored instructions further cause the computer processor to perform steps comprising:

identifying, by the computer system, one or more first databases including first information indicating records explicitly accessible by each member from a plurality of members including the first member and the second member, and records explicitly accessible by each group from a plurality of groups;

identifying, by the computer system, one or more second databases including second information indicating membership associations between the plurality of members and the plurality of groups; and

generating a third database by combining at least a portion of the first information and the second information, the third database indicating for at least the first member and the second member, records explicitly and implicitly accessible by the first member, and records explicitly and implicitly accessible by the second member.

10. The non-transitory computer readable storage medium of claim 9 , wherein determining that the first member has access to less than the threshold number of records and determining that the second member has access to more than the threshold number of records is based on the third database.

11. The non-transitory computer readable storage medium of claim 9 , wherein determining the records accessible by the first member and determining the records accessible by the second member is based on the third database.

12. The non-transitory computer readable storage medium of claim 9 , wherein the third database is generated by combining the portion of the first information and the second information through matrix multiplication.

13. The non-transitory computer readable storage medium of claim 8 , wherein determining the records accessible by the first member and determining the records accessible by the second member is based on an accessibility database that indicates records explicitly and implicitly accessible by the first member and records explicitly and implicitly accessible by the second member.

14. The non-transitory computer readable storage medium of claim 8 , wherein the stored instructions further cause the computer processor to perform steps comprising:

identifying, by the computer system, one or more first databases including first information indicating records explicitly accessible by each member from a plurality of members including the first member and the second member, and records explicitly accessible by each group from a plurality of groups;

identifying, by the computer system, one or more second databases including second information indicating membership associations between the plurality of members and the plurality of groups; and

combining a portion of the second information corresponding to membership associations for the first member and the second member with the one or more first databases to determine the records accessible by the first member and to determine the records accessible by the second member.

15. A computer system comprising:

a computer processor; and

a non-transitory computer readable storage medium storing instructions that when executed by the computer processor, cause the computer processor to perform steps comprising:

receiving, by a computer system, a first search query from a first client device associated with a first member;

receiving, by the computer system, a second search query from a second client device associated with a second member;

determining, by the computer system, that the first member has access to less than a threshold number of records from a plurality of records;

responsive to determining that the first member has access to less than the threshold number of records from the plurality of records:

determining, by the computer system, records accessible by the first member from the plurality of records;

identifying, by the computer system, records relevant to the first search query from the determined records accessible by the first member; and

transmitting, by the computer system to the first client device, first search results that include the identified records relevant to the first search query;

determining, by the computer system, that the second member has access to more than the threshold number of records from the plurality of records; and

responsive to determining that the second member has access to more than the threshold number of records from the plurality of records:

identifying, by the computer system from the plurality of records, records relevant to the second search query;

determining, by the computer system, records accessible by the second member from the identified records relevant to the second search query; and

transmitting, by the computer system to the second client device, second search results that include the determined records accessible by the second member.

16. The computer system of claim 15 , wherein the stored instructions further cause the computer processor to perform steps comprising:

identifying, by the computer system, one or more first databases including first information indicating records explicitly accessible by each member from a plurality of members including the first member and the second member, and records explicitly accessible by each group from a plurality of groups;

identifying, by the computer system, one or more second databases including second information indicating membership associations between the plurality of members and the plurality of groups; and

generating a third database by combining at least a portion of the first information and the second information, the third database indicating for at least the first member and the second member, records explicitly and implicitly accessible by the first member, and records explicitly and implicitly accessible by the second member.

17. The computer system of claim 16 , wherein determining that the first member has access to less than the threshold number of records and determining that the second member has access to more than the threshold number of records is based on the third database.

18. The computer system of claim 16 , wherein determining the records accessible by the first member and determining the records accessible by the second member is based on the third database.

19. The computer system of claim 16 , wherein the third database is generated by combining the portion of the first information and the second information through matrix multiplication.

20. The computer system of claim 15 , wherein determining the records accessible by the first member and determining the records accessible by the second member is based on an accessibility database that indicates records explicitly and implicitly accessible by the first member and records explicitly and implicitly accessible by the second member.

21. The computer system of claim 15 , wherein the stored instructions further cause the computer processor to perform steps comprising:

identifying, by the computer system, one or more first databases including first information indicating records explicitly accessible by each member from a plurality of members including the first member and the second member, and records explicitly accessible by each group from a plurality of groups;

identifying, by the computer system, one or more second databases including second information indicating membership associations between the plurality of members and the plurality of groups; and

combining a portion of the second information corresponding to membership associations for the first member and the second member with the one or more first databases to determine the records accessible by the first member and to determine the records accessible by the second member.

Assignments (3)
CHANGE OF NAME Recorded Dec 18, 2024
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 069717/0452 →
CORRECTIVE ASSIGNMENT TO CORRECT THE SPELLING OF THE FIFTH ASSIGNOR'S NAME PREVIOUSLY RECORDED ON REEL 052435 FRAME 0138. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 6, 2021
From: RICKARD, SCOTT; KALE, ANUPRIT; SPIVAK, VICTOR; GRIGNON, YANIK; CHANDRASEKARAN, VENKATESAN
To: SALESFORCE.COM, INC.
Reel/Frame 055845/0630 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 17, 2020
From: RICKARD, SCOTT; KALE, ANUPRIT; SPIVAK, VICTOR; GRIGNON, YANIK; CHANDRASEKARAN, VENKAT
To: SALESFORCE.COM, INC.
Reel/Frame 052435/0138 →