CONTROLLING ACCESS TO DATA IN A CLOUD-BASED SOFTWARE PLATFORM BASED ON USER ROLES
Aspects of the present disclosure relate to systems and methods for managing access to data in a cloud-based software platform. An end-user account associated with an organization account may request access to data in a data store of the organization account. A schema associated with the data may specify collections of user access permissions, each collection being associated with a different user role. The request for access to the data is then granted (or denied) subject to the collection of user access permissions that is associated with the user role of the end-user account.
1 . A method for managing access to data in a cloud-based software platform, the method comprising:
storing data associated with an organization account in a data store of the cloud-based software platform, the data store being associated with the organization account;
receiving a data access request associated with an end-user account, the end-user account being associated with the organization account and having a user role among a plurality of user roles;
retrieving, based on the user role, a collection of user access permissions from a plurality of collections of user access permissions associated with different user roles, the collections of user access permissions being defined by a schema associated with the data; and
granting the data access request subject to the collection of user access permissions.
2 . The method of claim 1 , wherein the data access request is generated based on a request for data to populate a user interface accessed by the end-user account, and
wherein the method further comprises transmitting the data to the user interface subject to the user access permissions.
3 . The method of claim 1 , wherein the data is generated by a cloud-based software application running on the cloud-based software platform and connected to the organization account.
4 . The method of claim 3 , wherein the schema is defined by the cloud-based software application.
5 . The method of claim 1 , wherein the schema is stored in a repository comprising a plurality of schemas available to cloud-based software applications running on the cloud-based software platform.
6 . The method of claim 1 , wherein the granting the data access request subject to the user access permissions comprises filtering the data such that the data that is accessible is in accordance with the collection of user access permissions associated with the user role.
7 . The method of claim 1 , wherein the data comprises:
first data structured in accordance with the schema; and
second data structured in accordance with a second schema, and
wherein the method further comprises:
retrieving, based on the user role, a second collection of user access permissions from a plurality of second collections of user access permissions associated with different user roles, the second collections of user access permissions being defined by the second schema; and
granting the data access request with respect to the second data subject to the second collection of user access permissions, wherein the second data is different from the first data.
8 . A cloud-based software platform comprising:
a processor; and
memory storing instructions that, when executed by the processor, cause the processor to:
store data associated with an organization account in a data store of the cloud-based software platform, the data store being associated with the organization account;
receive a data access request associated with an end-user account, the end-user account being associated with the organization account and having a user role among a plurality of user roles;
retrieve, based on the user role, a collection of user access permissions from a plurality of collections of user access permissions associated with different user roles, the collections of user access permissions being granted by the organization account in accordance with a schema associated with the data; and
grant the data access request subject to the collection of user access permissions.
9 . The cloud-based software platform of claim 8 , wherein the data access request is generated based on a request for data to populate a user interface accessed by the end-user account, and
wherein the memory further stores instructions that, when executed by the processor, cause the processor to transmit the data to the user interface subject to the user access permissions.
10 . The cloud-based software platform of claim 8 , wherein the data is generated by a cloud-based software application running on the cloud-based software platform and connected to the organization account.
11 . The cloud-based software platform of claim 10 , wherein the schema is defined by the cloud-based software application.
12 . The cloud-based software platform of claim 8 , wherein the schema is stored in a repository comprising a plurality of schemas available to cloud-based software applications running on the cloud-based software platform.
13 . The cloud-based software platform of claim 8 , wherein the instructions to grant the data access request subject to the user access permissions comprise instructions that, when executed by the processor, cause the processor to filter the data such that the data that is accessible is in accordance with the collection of user access permissions associated with the user role.
14 . The cloud-based software platform of claim 8 , wherein the data comprises:
first data structured in accordance with the schema; and
second data structured in accordance with a second schema, and
wherein the memory further stores instructions that, when executed by the processor, cause the processor to:
retrieve, based on the user role, a second collection of user access permissions from a plurality of second collections of user access permissions associated with different user roles, the second collections of user access permissions being defined by the second schema; and
grant the data access request with respect to the second data subject to the second collection of user access permissions, wherein the second data is different from the first data.
15 . A non-transitory computer-readable medium storing instructions that, when executed by a processor, cause the processor to:
store data associated with an organization account in a data store of a cloud-based software platform, the data store being associated with the organization account;
receive a data access request associated with an end-user account, the end-user account being associated with the organization account and having a user role among a plurality of user roles;
retrieve, based on the user role, a collection of user access permissions from a plurality of collections of user access permissions associated with different user roles, the collections of user access permissions being granted by the organization account in accordance with a schema associated with the data; and
grant the data access request subject to the collection of user access permissions.
16 . The non-transitory computer-readable medium of claim 15 , wherein the data access request is generated based on a request for data to populate a user interface accessed by the end-user account, and
wherein the instructions further comprise instructions that, when executed by the processor, cause the processor to transmit the data to the user interface subject to the user access permissions.
17 . The non-transitory computer-readable medium of claim 15 , wherein the data is generated by a cloud-based software application running on the cloud-based software platform and connected to the organization account.
18 . The non-transitory computer-readable medium of claim 17 , wherein the schema is defined by the cloud-based software application.
19 . The non-transitory computer-readable medium of claim 15 , wherein the schema is stored in a repository comprising a plurality of schemas available to cloud-based software applications running on the cloud-based software platform.
20 . The non-transitory computer-readable medium of claim 15 , wherein the instructions to grant the data access request subject to the user access permissions comprise instructions that, when executed by the processor, cause the processor to filter the data such that the data that is accessible is in accordance with the collection of user access permissions associated with the user role.