IP Library Granted Patent US 12,143,917
Granted Patent B2
US 12,143,917 · App. 18/239,308 · Granted Nov 12, 2024

Role-based access control system

Inventors: Carmen Raffa (San Francisco, CA); Aish Raj Dahal (San Francisco, CA); Jose Medina (San Francisco, CA); Robin McConnell Balaga (San Francisco, CA); Jennifer Enrique (San Francisco, CA)
Assignee: Salesforce, Inc.
H04W48/04H04L12/1822H04L65/403H04M3/566H04W4/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,143,917
App. No.
18/239,308
Filed
Aug 29, 2023
Granted
Nov 12, 2024
Kind
B2
Examiner
HO, DUC CHI
Art Unit
2465
USPC
455/518
Abstract

A computer-readable media, system, and method for providing role-based access management to channels within a group-based communication system. Role-based access management allows for a plurality of roles to be established and for users to be associated with these roles. Roles may be associated with sets of permissions allowing users assigned to the respective role to perform various actions within the group-based communication system. The group-based communication system may include preset, system roles with predetermined permissions and custom, user-defined roles may be created by administrators within the group-based communication system.

Claims (50)

1. A method for role-based access management within a group-based communication system, the method comprising:

determining that a first role is assigned to a first user, the first role associated with a first set of permissions,

wherein the first role is assigned to the first user within an external application distinct from the group-based communication system;

allowing the first user to access a first set of data shared within the group-based communication system based on the first set of permissions associated with the first role;

determining that a second role is assigned to the first user, the second role associated with a second set of permissions,

wherein the second role is distinct from the first role and the second set of permissions is distinct from the first set of permissions; and

allowing the first user to perform at least one action within the group-based communication system based on the second set of permissions associated with the second role.

2. The method of claim 1 , wherein the second role is assigned to the first user from within the group-based communication system.

3. The method of claim 1 , wherein the first role is a default role and the first set of permissions are default permissions.

4. The method of claim 3 , further comprising:

adding one or more permissions to the first set of permissions associated with the first role to thereby limit access to one or more notifications to a subset of users assigned to the first role.

5. The method of claim 1 , further comprising:

responsive to determining that a second user does not have access to a resource associated with the group-based communication system, generating a notification comprising an indication that the second user does not have access to the resource.

6. The method of claim 1 , wherein the at least one action comprises creating a group-based communication channel within the group-based communication system.

7. The method of claim 6 , wherein the first user is an administrator user and the first role comprises an administrator role.

8. One or more non-transitory computer-readable media that store computer-readable instructions that, when executed by at least one processor, perform a method for role-based access management within a group-based communication system, the method comprising:

determining that a first role is assigned to a first user, the first role associated with a first set of permissions,

wherein the first role is assigned to the first user within an external application distinct from the group-based communication system;

allowing the first user to access a first set of data shared within the group-based communication system based on the first set of permissions associated with the first role; and

determining that a second role is assigned to the first user, the second role associated with a second set of permissions,

wherein the second role is distinct from the first role and the second set of permissions is distinct from the first set of permissions.

9. The one or more non-transitory computer-readable media of claim 8 , wherein the method further comprises:

allowing the first user to perform at least one action within the group-based communication system based on the second set of permissions associated with the second role.

10. The one or more non-transitory computer-readable media of claim 9 , wherein the first user is an administrator user and the first role comprises an administrator role.

11. The one or more non-transitory computer-readable media of claim 10 , wherein the at least one action comprises creating a group-based communication channel within the group-based communication system.

12. The one or more non-transitory computer-readable media of claim 8 , wherein the method further comprises:

responsive to determining that a second user does not have access to a resource associated with the group-based communication system, generating a notification comprising an indication that the second user does not have access to the resource.

13. The one or more non-transitory computer-readable media of claim 8 , wherein the method further comprises:

determining that a second user does not have access to a resource associated with the group-based communication system based on role information.

14. The one or more non-transitory computer-readable media of claim 13 , wherein the method further comprises:

responsive to determining that the second user does not have access to the resource, generating a notification comprising an indication that the second user does not have access to the resource.

15. A system comprising:

at least one processor; and

one or more non-transitory computer-readable media that store computer-readable instructions that, when executed by the at least one processor, perform a method for role-based access management within a group-based communication system, the method comprising:

determining that a first role is assigned to a first user, the first role associated with a first set of permissions;

allowing the first user to access a first set of data shared within the group-based communication system based on the first set of permissions associated with the first role;

determining that a second role is assigned to the first user, the second role associated with a second set of permissions,

wherein the second role is distinct from the first role and the second set of permissions is distinct from the first set of permissions; and

allowing the first user to perform at least one action within the group-based communication system based on the second set of permissions associated with the second role.

16. The system of claim 15 , wherein the first role is assigned to the first user within an external application distinct from the group-based communication system, and wherein the first role comprises a security role and the first set of permissions comprises a permission to edit one or more security settings.

17. The system of claim 16 , wherein the security role is a predefined default security role associated from the external application.

18. The system of claim 17 , wherein the method further comprises:

receiving a request to adjust the permission to edit the one or more security settings of the security role; and

updating the permission to edit the one or more security settings based on the request.

19. The system of claim 15 , wherein the method further comprises:

responsive to determining that a second user does not have access to a resource associated with the group-based communication system, generating a notification comprising an indication that the second user does not have access to the resource.

20. The system of claim 15 , wherein the method further comprises:

receiving, from the first user, a request to access a resource;

responsive to receiving the request to access the resource, determining that the first user does not have access to the resource based on at least one of the first set of permissions and the second set of permissions; and

responsive to determining that the first user does not have access to the resource, generating a permission error notification for the first user.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2023
From: RAFFA, CARMEN; DAHL, AISH; MEDINA, JOSE; BALAGA, ROBIN MCCONNELL; ENRIQUE, JENNIFER
To: SLACK TECHNOLOGIES, INC.
Reel/Frame 064735/0585 →
MERGER Recorded Aug 29, 2023
From: SLACK TECHNOLOGIES, INC.
To: SLACK TECHNOLOGIES, LLC
Reel/Frame 064735/0689 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2023
From: SLACK TECHNOLOGIES, LLC
To: SALESFORCE, INC.
Reel/Frame 064746/0801 →
Continuity (3)
Continuation 17733269 · Apr 29, 2022
Continuation 17038338 · Sep 30, 2020
Related Publication 20230403630A1 · Dec 14, 2023
Cited By (6)
US 12,592,934 US 12,634,213 US 12,634,350 US 12,699,639 US 12,712,727 US 12,726,365