IP Library Granted Patent US 11,227,055
Granted Patent B1
US 11,227,055 · App. 17/389,497 · Granted Jan 18, 2022

System and method for automated access request recommendations

Inventors: Mohamed M. Badawy (Round Rock, TX); Rajat Kabra (Austin, TX); Quoc Co Tran (Houston, TX); Jostine Fei Ho (Austin, TX)
Assignee: SAILPOINT TECHNOLOGIES, INC.
G06F21/604G06F16/9024G06F21/6218G06N20/00G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,227,055
App. No.
17/389,497
Granted
Jan 18, 2022
Kind
B1
Abstract

Systems and methods for embodiments of graph based and machine learning artificial intelligence systems for generating access item recommendations in an identity management system are disclosed. Embodiments of the identity management systems disclosed herein may utilize a graph based approach, a machine learning based approach, and hybrid combinations thereof for generating access item recommendations.

Claims (41)

1. A method, comprising:

determining a set of peer identities to a target identity in an identity management system based on attributes of identities of the identity management system;

identifying access items of the identity management system associated with the set of peer identities;

for each of the identified access items, determining a concurrency with other of the identified access items

identifying a first set of access items of the identified access items, the first set of access items having a high concurrency with other of the identified access items;

generating a generalized access recommendation for the target identity that the target identity obtain access to the first set of access items;

identifying a second set of access items of the identified access items, the second set of access items having a insufficient concurrency with other of the identified access items; and

analyzing the identified access items, the set of peer identities, and the target identity to generate personalized access recommendations for the target identity, each of the personalized access recommendations recommending that the target identity obtain access to a respective access item, wherein the first and second sets of access items are excluded from the generated personalized access recommendations.

2. The method of claim 1 , wherein the identified access items, the set of peer identities, and the target identity are analyzed using a graph database query.

3. The method of claim 1 , wherein the attributes of the identities include groups, job titles, and departments.

4. The method of claim 1 , wherein the determined concurrency relates to the probability of two more identities or groups of identities having access to the same access item or group of access items.

5. The method of claim 1 , further comprising, responsive to a generated generalized or personalized access recommendation, receiving an access request from the target identity for access to a respective access item.

6. The method of claim 5 , further comprising, responsive to receiving the access request from the target identity, initiating an approval process for access to the respective access item by the target identity.

7. A non-transitory computer readable medium, comprising instruction for:

determining a set of peer identities to a target identity in an identity management system based on attributes of identities of the identity management system;

identifying access items of the identity management system associated with the set of peer identities;

for each of the identified access items, determining a concurrency with other of the identified access items

identifying a first set of access items of the identified access items, the first set of access items have a high concurrency with other of the identified access items;

generating a generalized access recommendation for the target identity that the target identity obtain access to the first set of access items;

identifying a second set of access items of the identified access items, the second set of access items having insufficient concurrency with other of the identified access items; and

analyzing the identified access items, the set of peer identities, and the target identity to generate personalized access recommendations for the target identity, each of the personalized access recommendations recommending that the target identity obtain access to a respective access item, wherein the first and second sets of access items are excluded from the generated personalized access recommendations.

8. The non-transitory computer readable medium of claim 7 , wherein the identified access items, the set of peer identities, and the target identity are analyzed using a graph database query.

9. The non-transitory computer readable medium of claim 7 , wherein the attributes of the identities include groups, job titles, and departments.

10. The non-transitory computer readable medium of claim 7 , wherein the determined concurrency relates to the probability of two more identities or groups of identities having access to the same access item or group of access items.

11. The non-transitory computer readable medium of claim 7 , further comprising, responsive to a generated generalized or personalized access recommendation, receiving an access request from the target identity for access to a respective access item.

12. The non-transitory computer readable medium of claim 11 , further comprising, responsive to receiving the access request from the target identity, initiating an approval process for access to the respective access item by the target identity.

13. A system, comprising:

a processor; and

a non-transitory computer readable medium comprising instructions for:

determining a set of peer identities to a target identity in an identity management system based on attributes of identities of the identity management system;

identifying access items of the identity management system associated with the set of peer identities;

for each of the identified access items, determining a concurrency with other of the identified access items

identifying a first set of access items of the identified access items, the first set of access items having a high concurrency with other of the identified access items;

generating a generalized access recommendation for the target identity that the target identity obtain access to the first set of access items;

identifying a second set of access items of the identified access items, the second set of access items having insufficient concurrency with other of the identified access items; and

analyzing the identified access items, the set of peer identities, and the target identity to generate personalized access recommendations for the target identity, each of the personalized access recommendations recommending that the target identity obtain access to a respective access item, wherein the first and second sets of access items are excluded from the generated personalized access recommendations.

14. The system of claim 13 , wherein the identified access items, the set of peer identities, and the target identity are analyzed using a graph database query.

15. The system of claim 13 , wherein the attributes of the identities include groups, job titles, and departments.

16. The system of claim 13 , wherein the determined concurrency relates to the probability of two more identities or groups of identities having access to the same access item or group of access items.

17. The system of claim 13 , further comprising, responsive to a generated generalized or personalized access recommendation, receiving an access request from the target identity for access to a respective access item.

18. The system of claim 11 , further comprising, responsive to receiving the access request from the target identity, initiating an approval process for access to the respective access item by the target identity.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Jun 27, 2025
From: GOLUB CAPITAL MARKETS LLC
To: SAILPOINT TECHNOLOGIES, INC.; SAILPOINT TECHNOLOGIES HOLDINGS, INC.
Reel/Frame 071776/0411 →
PATENT SECURITY AGREEMENT Recorded Jun 25, 2025
From: SAILPOINT TECHNOLOGIES, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071724/0511 →
SECURITY INTEREST Recorded Aug 17, 2022
From: SAILPOINT TECHNOLOGIES, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 061202/0540 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 26, 2021
From: BADAWY, MOHAMED M.; KABRA, RAJAT; TRAN, QUOC CO; HO, JOSTINE FEI
To: SAILPOINT TECHNOLOGIES, INC.
Reel/Frame 057304/0205 →
Cited By (2)
US 12,632,524 US 12,694,336