IP Library Granted Patent US 11,675,927
Granted Patent B2
US 11,675,927 · App. 17/097,642 · Granted Jun 13, 2023

System and method for external users in groups of a multitenant system

Inventors: Kyle Anthony Aziz (Kitchener, CA); Scott Grasley (Kitchener, CA); Feng Guo (Waterloo, CA)
Assignee: OPEN TEXT SA ULC
G06F21/6245H04L63/101H04L63/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,675,927
App. No.
17/097,642
Granted
Jun 13, 2023
Kind
B2
Abstract

Content management systems are implemented according to a multitenant architecture by which software and its supporting architecture serves multiple customers of a service. Each tenant may be given a share of the application's data, configuration, user management, and other aspects of the application. Each tenant's data is isolated and typically remains invisible to other tenants so that tenants do not share or see each other's data. Embodiments described herein provide mechanisms by which a tenant can delegate administrator rights to an external user such that the external user can grant other users access to the tenant's content while the tenant controls the level of access that is provided to the external users.

Claims (65)

1. A computer program product comprising a non-transitory, computer-readable medium storing a set of computer-executable instructions, the set of computer-executable instructions comprising instructions translatable by a content management application on a computing platform for:

receiving a user group definition from a first tenant, the user group definition including an indication of an external user external to the first tenant as a group administrator;

creating a first user group for the first tenant based on the user group definition from the first tenant, the creating including:

creating a user group object; and

updating a data structure with the user group object that indicates the external user as the group administrator;

associating the first user group with the first tenant, thereby delegating the external user with group administrative privileges with respect to the first user group associated with the first tenant; and

based on the indication of the external user as the group administrator, providing a user interface with the group administrative privileges delegated to the external user to allow the external user to add a user to or remove a user from the first user group associated with the first tenant.

2. The computer program product of claim 1 , wherein the set of computer-executable instructions further comprise instructions for preventing the external user as the group administrator from removing the first user group.

3. The computer program product of claim 1 , wherein the user group definition includes an indication of a set of group members.

4. The computer program product of claim 3 , wherein the set of computer-executable instructions further comprise instructions for:

based on a determination that the indication of the set of group members specifies an unregistered user, automatically send a message to the unregistered user to invite the unregistered user to register with a multitenant service.

5. The computer program product of claim 3 , wherein the set of computer-executable instructions further comprise instructions for:

providing an interface with controls to allow a member of the first tenant to define the first user group; and

limiting the member of the first tenant to selecting the group administrator and the set of group members from a set of registered users of a multitenant service.

6. The computer program product of claim 1 , wherein the external user is a member of a second tenant.

7. The computer program product of claim 1 , wherein the set of computer-executable instructions further comprise instructions for:

receiving a share definition, the share definition including an indication of a data resource of the first tenant to be shared with the first user group and specifying a level of access to the data resource for the first user group; and

based on the share definition, setting permissions for the first user group on the data resource.

8. The computer program product of claim 7 , wherein the set of computer-executable instructions further comprise instructions for:

receiving a request to access the data resource from a requesting user; and

based on a determination that the requesting user is a member of the first user group, providing the requesting user access to the data resource according to the level of access specified for the first user group to the data resource.

9. A multi-tenant system comprising:

a processor;

a non-transitory computer-readable medium storing a set of computer-executable instructions, the set of computer-executable instructions comprising instructions translatable by the processor for:

receiving a user group definition from a first tenant, the user group definition including an indication of an external user external to the first tenant as a group administrator;

creating a first user group for the first tenant based on the user group definition from the first tenant, the creating including:

creating a user group object; and

updating a data structure with the user group object that indicates the external user as the group administrator;

associating the first user group with the first tenant, thereby delegating the external user with group administrative privileges with respect to the first user group associated with the first tenant; and

based on the indication of the external user as the group administrator, providing a user interface with the group administrative privileges delegated to the external user to allow the external user to add a user to or remove a user from the first user group associated with the first tenant.

10. The multi-tenant system of claim 9 , wherein the set of computer-executable instructions further comprise instructions for preventing the external user as the group administrator from removing the first user group.

11. The multi-tenant system of claim 9 , wherein the user group definition includes an indication of a set of group members.

12. The multi-tenant system of claim 11 , wherein the set of computer-executable instructions further comprise instructions for:

based on a determination that the indication of the set of group members specifies an unregistered user, automatically send a message to the unregistered user to invite the unregistered user to register with a multitenant service.

13. The multi-tenant system of claim 11 , wherein the set of computer-executable instructions further comprise instructions for:

providing an interface with controls to allow a member of the first tenant to define the first user group; and

limiting the member of the first tenant to selecting the group administrator and the set of group members from a set of registered users of a multitenant service.

14. The multi-tenant system of claim 9 , wherein the external user is a member of a second tenant.

15. The multi-tenant system of claim 9 , wherein the set of computer-executable instructions further comprise instructions for:

receiving a share definition, the share definition including an indication of a data resource of the first tenant to be shared with the first user group and specifying a level of access to the data resource for the first user group; and

based on the share definition, setting permissions for the first user group on the data resource.

16. The multi-tenant system of claim 15 , wherein the set of computer-executable instructions further comprise instructions for:

receiving a request to access the data resource from a requesting user; and

based on a determination that the requesting user is a member of the first user group, providing the requesting user access to the data resource according to the level of access specified for the first user group to the data resource.

17. A method for group administration in a multi-tenant environment, the method comprising:

receiving, by a content management application on a computing platform, a user group definition from a first tenant, the user group definition including an indication of an external user external to the first tenant as a group administrator;

creating, by the content management application on the computing platform, a first user group for the first tenant based on the user group definition from the first tenant, the creating including:

creating a user group object; and

updating a data structure with the user group object that indicates the external user as the group administrator;

associating, by the content management application on the computing platform, the first user group with the first tenant, thereby delegating the external user with group administrative privileges with respect to the first user group associated with the first tenant; and

based on the indication of the external user as the group administrator, providing, by the content management application on the computing platform, a user interface with the group administrative privileges delegated to the external user to allow the external user to add a user to or remove a user from the first user group associated with the first tenant.

18. The method of claim 17 , further comprising preventing the external user as the group administrator from removing the first user group.

19. The method of claim 17 , wherein the user group definition includes an indication of a set of group members.

20. The method of claim 19 , further comprising:

based on a determination that the indication of the set of group members specifies an unregistered user, automatically send a message to the unregistered user to invite the unregistered user to register with a multitenant service.

21. The method of claim 19 , further comprising:

providing an interface with controls to allow a member of the first tenant to define the first user group; and

limiting the member of the first tenant to selecting the group administrator and the set of group members from a set of registered users of a multitenant service.

22. The method of claim 17 , wherein the external user is a member of a second tenant.

23. The method of claim 17 , further comprising:

receiving a share definition, the share definition including an indication of a data resource of the first tenant to be shared with the first user group and specifying a level of access to the data resource for the first user group; and

based on the share definition, setting permissions for the first user group on the data resource.

24. The method of claim 23 , further comprising:

receiving a request to access the data resource from a requesting user; and

based on a determination that the requesting user is a member of the first user group, providing the requesting user access to the data resource according to the level of access specified for the first user group to the data resource.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 3, 2021
From: AZIZ, KYLE ANTHONY; GRASLEY, SCOTT; GUO, FENG
To: OPEN TEXT SA ULC
Reel/Frame 056118/0248 →
Continuity (2)
Provisional Application 62934841 · Nov 13, 2019
Related Publication 20210141930A1 · May 13, 2021