Existing policy determinations for an identity set
A plurality of identities may be added to a new policy identity pool associated with new policy generation. Each identity of the plurality of identities may have respective selected permissions associated with permission usage by the identity. A new policy may be generated, based on a set of new policy constraints, that corresponds to a largest group of identities within the new policy identity pool for which the set of new policy constraints is satisfied. The set of new policy constraints may include a first constraint that the new policy includes the respective selected permissions for each identity within the largest group of identities and a second constraint that the new policy does not exceed one or more maximum additional permission thresholds. One or more indications may be provided, to a user, to attach the new policy to each identity within the largest group of identities.
1 . A computing system comprising:
one or more processors; and
one or more memories having stored therein instructions that, upon execution by the one or more processors, cause the one or more processors to perform operations comprising:
adding a plurality of user sets to a user set pool associated with new policy generation, wherein each user set of the plurality of user sets has respective permissions associated with permission usage by the user set, wherein the respective permissions include one or more permissions that have been used by the user set within a prior time window;
generating, based on a set of new policy constraints, a new policy that corresponds to a largest group of user sets within the user set pool for which the set of new policy constraints is satisfied, wherein the set of new policy constraints includes a first constraint that the new policy includes the respective permissions for each user set within the largest group of user sets and a second constraint that the new policy does not exceed one or more additional permission thresholds;
providing, to a user, one or more indications to attach the new policy to each user set within the largest group of user sets;
removing the largest group of user sets from the user set pool; and
repeating the generating, the providing, and the removing until the user set pool is empty.
2 . The computing system of claim 1 , wherein the operations further comprise:
determining, individually for each user set of the plurality of user sets, that there is no group of one or more existing policies that satisfies a set of existing policy constraints for the user set.
3 . The computing system of claim 2 , wherein each user set of the plurality of user sets is added to the user set pool based on there being no group of one or more existing policies that satisfies the set of existing policy constraints for the user set.
4 . The computing system of claim 1 , wherein the set of new policy constraints further includes a third constraint that the new policy does not exceed a permission quantity threshold.
5 . A computer-implemented method comprising:
adding a plurality of user sets to a user set pool associated with new policy generation, wherein each user set of the plurality of user sets has respective permissions associated with permission usage by the user set, wherein the respective permissions include one or more permissions that have been used by the user set within a prior time window;
generating, based on a set of new policy constraints, a new policy that corresponds to a largest group of user sets within the user set pool for which the set of new policy constraints is satisfied, wherein the set of new policy constraints includes a first constraint that the new policy includes the respective permissions for each user set within the largest group of user sets and a second constraint that the new policy does not exceed one or more additional permission thresholds; and
providing, to a user, one or more indications to attach the new policy to each user set within the largest group of user sets.
6 . The computer-implemented method of claim 5 , wherein the one or more additional permission thresholds comprise a plurality of additional permission thresholds, and wherein each user set of the user set pool has a respective additional permission threshold of the plurality of additional permission thresholds.
7 . The computer-implemented method of claim 5 , further comprising:
determining, individually for each user set of the plurality of user sets, that there is no group of one or more existing policies that satisfies a set of existing policy constraints for the user set.
8 . The computer-implemented method of claim 7 , wherein each user set of the plurality of user sets is added to the user set pool based on there being no group of one or more existing policies that satisfies the set of existing policy constraints for the user set.
9 . The computer-implemented method of claim 5 , further comprising:
removing the largest group of user sets from the user set pool; and
repeating the generating, the providing, and the removing until the user set pool is empty.
10 . The computer-implemented method of claim 5 , wherein the set of new policy constraints further includes a third constraint that the new policy does not exceed a permission quantity threshold.
11 . The computer-implemented method of claim 5 , wherein the user set pool is a user set cluster of a plurality of user set clusters formed based on a permission-based clustering of a parent user set pool.
12 . The computer-implemented method of claim 5 , further comprising:
determining, for each user set of the plurality of user sets, the respective permissions.
13 . The computer-implemented method of claim 5 , wherein the respective permissions further include permissions that are estimated to have greater than a threshold probability of being used, by the user set, in a future time period.
14 . One or more non-transitory computer-readable storage media having stored thereon computing instructions that, upon execution by one or more computing devices, cause the one or more computing devices to perform operations comprising:
adding a plurality of user sets to a user set pool associated with new policy generation, wherein each user set of the plurality of user sets has respective permissions associated with permission usage by the user set, wherein the respective permissions include one or more permissions that have been used by the user set within a prior time window;
generating, based on a set of new policy constraints, a new policy that corresponds to a largest group of user sets within the user set pool for which the set of new policy constraints is satisfied, wherein the set of new policy constraints includes a first constraint that the new policy includes the respective permissions for each user set within the largest group of user sets and a second constraint that the new policy does not exceed one or more additional permission thresholds; and
providing, to a user, one or more indications to attach the new policy to each user set within the largest group of user sets.
15 . The one or more non-transitory computer-readable storage media of claim 14 , wherein the one or more additional permission thresholds comprise a plurality of additional permission thresholds, and wherein each user set of the user set pool has a respective additional permission threshold of the plurality of additional permission thresholds.
16 . The one or more non-transitory computer-readable storage media of claim 14 , wherein the operations further comprise:
determining, individually for each user set of the plurality of user sets, that there is no group of one or more existing policies that satisfies a set of existing policy constraints for the user set.
17 . The one or more non-transitory computer-readable storage media of claim 16 , wherein each user set of the plurality of user sets is added to the user set pool based on there being no group of one or more existing policies that satisfies the set of existing policy constraints for the user set.
18 . The one or more non-transitory computer-readable storage media of claim 14 , wherein the operations further comprise:
removing the largest group of user sets from the user set pool; and
repeating the generating, the providing, and the removing until the user set pool is empty.
19 . The one or more non-transitory computer-readable storage media of claim 14 , wherein the set of new policy constraints further includes a third constraint that the new policy does not exceed a permission quantity threshold.
20 . The one or more non-transitory computer-readable storage media of claim 14 , wherein the respective permissions further include permissions that are estimated to have greater than a threshold probability of being used, by the user set, in a future time period.