IP Library › Granted Patent US 12,010,120
Granted Patent B2
US 12,010,120 · App. 17/812,977 · Granted Jun 11, 2024

Computing system permission administration engine

Inventors: Freeman Parks (San Francisco, CA); Ryan D. Woebkenberg (Carmel, IN)
Assignee: Salesforce, Inc.
H04L63/104G06F18/24G06N7/01G06N20/00H04L63/101H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,010,120
App. No.
17/812,977
Filed
Jul 15, 2022
Granted
Jun 11, 2024
Kind
B2
Examiner
SONG, HEE K
Art Unit
2497
USPC
726/4
Abstract

A plurality of permissions associated with the on-demand computing services environment may be identified. Each of the permissions may identify a respective one or more actions permitted to be performed within the on-demand computing services environment. Each of the permissions may be granted to a respective one or more user accounts within the on-demand computing services environment. A degree of overlap between a first group of the user accounts granted a first one of the permissions and a second group of the user accounts granted a second one of the permissions may be determined. When the degree of overlap exceeds a designated threshold, a designated permission set that includes the first permission and the second permission may be created.

Claims (41)

1. A method implemented in an on-demand computing services environment, the method comprising:

granting, to one or more user accounts, a first permission set including one or more permissions of a plurality of permissions associated with the on-demand computing services environment, each of the plurality of permissions corresponding to a respective one or more of a plurality of actions permitted to be performed by the on-demand computing services environment, wherein a machine learning classification procedure is used to generate the first permission set from the plurality of permissions associated with the on-demand computing services environment;

monitoring use of the one or more permissions by the one or more user accounts;

determining, based on the monitoring, one or more atypical permission set usages by the one or more user accounts;

in response to the determining, identifying a designated permission set based, at least in part, on the determined atypical permission set usages; and

recommending that the first permission set be updated to the designated permission set for the one or more user accounts.

2. The method of claim 1 , wherein determining one or more atypical permission set usages comprises:

determining at least one permission of the first set of permissions that is underutilized in comparison with a threshold.

3. The method of claim 2 , wherein the designated permission set does not include the at least one underutilized permission.

4. The method of claim 1 , wherein the designated atypical permission set does not include at least one permission used by other user accounts.

5. The method of claim 1 , wherein the designated permission set includes at least one permission used by other user accounts.

6. The method of claim 1 , wherein the designated permission set includes at least one permission of the first set of permissions.

7. The method of claim 1 , wherein determining one or more atypical permission set usages by the one or more user accounts comprises:

determining whether a level of utilization of an action associated with the first set of permissions falls below a threshold.

8. A non-transitory computer-readable medium comprising computer-readable program code capable of being executed by one or more processors when, the program code comprising computer-readable instructions configurable to cause:

granting, to one or more user accounts, a first permission set including one or more permissions of a plurality of permissions associated with the on-demand computing services environment, each of the plurality of permissions corresponding to a respective one or more of a plurality of actions permitted to be performed by the on-demand computing services environment, wherein a machine learning classification procedure is used to generate the first permission set from the plurality of permissions associated with the on-demand computing services environment;

monitoring use of the one or more permissions by the one or more user accounts;

determining, based on the monitoring, one or more atypical permission set usages by the one or more user accounts;

in response to the determining, identifying a designated permission set based, at least in part, on the determined atypical permission set usages; and

recommending that the first permission set be updated to the designated permission set for the one or more user accounts.

9. The non-transitory computer-readable medium of claim 8 , wherein determining one or more atypical permission set usages comprises:

determining at least one permission of the first set of permissions that is underutilized in comparison with a threshold.

10. The non-transitory computer-readable medium of claim 9 , wherein the designated permission set does not include the at least one underutilized permission.

11. The non-transitory computer-readable medium computer program product of claim 8 , wherein the designated permission set does not include at least one permission used by other user accounts.

12. The non-transitory computer-readable medium of claim 8 , wherein the designated permission set includes at least one permission used by other user accounts.

13. The non-transitory computer-readable medium of claim 8 , wherein the designated permission set includes at least one permission of the first set of permissions.

14. The non-transitory computer-readable medium of claim 8 , wherein determining one or more atypical permission set usages by the one or more user accounts comprises:

determining whether a level of utilization of an action associated with the first set of permissions falls below a threshold.

15. A system comprising: a database system implemented using a server system, the database system configurable to cause:

granting, to one or more user accounts, a first permission set including one or more permissions of a plurality of permissions associated with the on-demand computing services environment, each of the plurality of permissions corresponding to a respective one or more of a plurality of actions permitted to be performed by the on-demand computing services environment wherein a machine learning classification procedure is used to generate the first permission set from the plurality of permissions associated with the on-demand computing services environment;

monitoring use of the one or more permissions by the one or more user accounts;

determining, based on the monitoring, one or more atypical permission set usages by the one or more user accounts;

in response to the determining, identifying a designated permission set based, at least in part, on the determined atypical permission set usages; and

recommending that the first permission set be updated to the designated permission set for the one or more user accounts.

16. The system of claim 15 , wherein determining one or more atypical permission set usages comprises:

determining at least one permission of the first set of permissions that is underutilized in comparison with a threshold.

17. The system of claim 16 , wherein the designated permission set does not include the at least one underutilized permission.

18. The system of claim 15 , wherein the designated permission set does not include at least one permission used by other user accounts.

19. The system of claim 15 , wherein the designated permission set includes at least one permission used by other user accounts.

20. The system of claim 15 , wherein determining one or more atypical permission set usages by the one or more user accounts comprises:

determining whether a level of utilization of an action associated with the first set of permissions falls below a threshold.

Assignments (2)
CHANGE OF NAME Recorded Aug 4, 2026
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 076118/0548 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 28, 2022
From: PARKS, FREEMAN; WOEBKENBERG, RYAN D.
To: SALESFORCE.COM, INC.
Reel/Frame 061245/0388 →
Continuity (2)
Continuation 16681932 · Nov 13, 2019
Related Publication 20220385666A1 · Dec 1, 2022
Cited By (1)
US 12,598,188