IP Library › Granted Patent US 12,639,457
Granted Patent B2
US 12,639,457 · App. 18/593,681 · Granted May 26, 2026

Visibility for particularized data security

Inventors: Matthew David Hilliard (Washington, DC); Kevin Gajewski (Chatham, NJ); Andrew Donald Brian Radcliffe (Arlington, VA); Max Henry Harper (Arlington, VA); Stephanie L. Colen (Alexandria, VA)
Assignee: Appian Corporation
G06F21/62G06F21/6227
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,639,457
App. No.
18/593,681
Granted
May 26, 2026
Kind
B2
Abstract

Methods, systems, apparatuses, and non-transitory computer-readable media are provided for particularized data security in a data storage environment. Operations may include identifying data security rules for a type of record, a record of the type including a plurality of data items; receiving a request by a first user to access a particular record of the type of record; determining, based on the data security rules and the request, that the first user is permitted to access the particular record; identifying visibility configurations, for the type of record, indicating different sets of data items, selected from the plurality of data items, for different types of users; determining, based on the visibility configurations and a user type of the first user, a first set of data items; and based on the request, causing a display, via a first user interface, of the first set of data items.

Claims (65)

1 . A system for particularized data security in a data storage environment, the system comprising:

at least one non-transitory storage medium configured to store program code; and

at least one hardware processor configured to execute the program code to perform operations comprising:

identifying one or more data security rules for a type of record, wherein the one or more data security rules relate to one or more data sources, and wherein a record of the type includes a plurality of data items;

receiving a request by a first user to access a particular record of the type of record;

determining, based on the one or more data security rules and the request by the first user, that the first user is permitted to access the particular record;

identifying visibility configurations for the type of record, wherein the visibility configurations indicate different sets of one or more data items, selected from the plurality of data items, for different types of users;

determining, based on the visibility configurations and a user type of the first user, a first set of one or more data items of the plurality of data items;

based on the request by the first user, causing a display, via a first user interface, of the first set of one or more data items;

receiving, from a second user, an indication to share security permissions associated with the second user for the particular record with the first user; and

based on the indication, causing a display, via the first user interface, of a second set of one or more data items of the plurality of data items, wherein the second set is different from the first set.

2 . The system of claim 1 , wherein the operations further comprise:

receiving a request by the second user to access the particular record;

determining, based on the one or more data security rules and the request by the second user, that the second user is permitted to access the particular record;

determining, based on the visibility configurations and a user type of the second user, the second set of one or more data items of the plurality of data items; and

based on the request by the second user, causing a display, via a second user interface, of the second set of one or more data items.

3 . The system of claim 1 , wherein the plurality of data items include an information item or an actionable item.

4 . The system of claim 3 , wherein the actionable item is configured to trigger one or more processes executable by the at least one hardware processor.

5 . The system of claim 1 , wherein the plurality of data items include a plurality of tabs in a user interface.

6 . The system of claim 1 , wherein the first user interface includes a web browser.

7 . The system of claim 1 , wherein the operations further comprise:

identifying, in the visibility configurations, one or more rules for the user type of the first user, wherein the one or more rules indicate a default set of data items, of the plurality of data items, to be displayed for the user type of the first user.

8 . The system of claim 7 , wherein the operations further comprise:

updating the one or more rules for the user type of the first user by changing the default set of data items to be displayed for the user type of the first user.

9 . The system of claim 1 , wherein the operations further comprise:

generating a plurality of records based on input data; and

permitting or denying access to the plurality of records, based on the one or more data security rules.

10 . The system of claim 9 , wherein the operations further comprise:

identifying, based on the one or more data security rules, a first set of records of the plurality of records, wherein the first user is permitted to access the first set of records; and

identifying, based on the one or more data security rules, a second set of records of the plurality of records, wherein the second user is permitted to access the second set of records, and wherein the second set of records is different from the first set of records.

11 . The system of claim 10 , wherein the operations further comprise:

generating, based on the first set of records, a first report of aggregated information, wherein the first user is permitted to access the first report; and

generating, based on the second set of records, a second report of aggregated information, wherein the second user is permitted to access the second report, and wherein the second report is different from the first report.

12 . A non-transitory computer-readable medium including instructions that, when executed by at least one processor, cause the at least one processor to perform operations for particularized data security in a data storage environment, the operations comprising:

identifying one or more data security rules for a type of record, wherein the one or more data security rules relate to one or more data sources, and wherein a record of the type includes a plurality of data items;

receiving a request by a first user to access a particular record of the type of record;

determining, based on the one or more data security rules and the request by the first user, that the first user is permitted to access the particular record;

identifying visibility configurations for the type of record, wherein the visibility configurations indicate different sets of one or more data items, selected from the plurality of data items, for different types of users;

determining, based on the visibility configurations and a user type of the first user, a first set of one or more data items of the plurality of data items;

based on the request by the first user, causing a display, via a first user interface, of the first set of one or more data items;

receiving, from a second user, an indication to share security permissions associated with the second user for the particular record with the first user; and

based on the indication, causing a display, via the first user interface, of a second set of one or more data items of the plurality of data items, wherein the second set is different from the first set.

13 . The non-transitory computer-readable medium of claim 12 , wherein the operations further comprise:

receiving a request by the second user to access the particular record;

determining, based on the one or more data security rules and the request by the second user, that the second user is permitted to access the particular record;

determining, based on the visibility configurations and a user type of the second user, the second set of one or more data items of the plurality of data items; and

based on the request by the second user, causing a display, via a second user interface, of the second set of one or more data items.

14 . The non-transitory computer-readable medium of claim 12 , wherein the plurality of data items include an information item or an actionable item.

15 . The non-transitory computer-readable medium of claim 14 , wherein the actionable item is configured to trigger one or more processes executable by the at least one hardware processor.

16 . A method for particularized data security in a data storage environment, the method comprising:

identifying, by a computing device, one or more data security rules for a type of record, wherein the one or more data security rules relate to one or more data sources, and wherein a record of the type includes a plurality of data items;

receiving a request by a first user to access a particular record of the type of record;

determining, based on the one or more data security rules and the request by the first user, that the first user is permitted to access the particular record;

identifying visibility configurations for the type of record, wherein the visibility configurations indicate different sets of one or more data items, selected from the plurality of data items, for different types of users;

determining, based on the visibility configurations and a user type of the first user, a first set of one or more data items of the plurality of data items;

based on the request by the first user, causing a display, via a first user interface, of the first set of one or more data items;

receiving, from a second user, an indication to share security permissions associated with the second user for the particular record with the first user; and

based on the indication, causing a display, via the first user interface, of a second set of one or more data items of the plurality of data items, wherein the second set is different from the first set.

17 . The method of claim 16 , further comprising:

receiving a request by the second user to access the particular record;

determining, based on the one or more data security rules and the request by the second user, that the second user is permitted to access the particular record;

determining, based on the visibility configurations and a user type of the second user, the second set of one or more data items of the plurality of data items; and

based on the request by the second user, causing a display, via a second user interface, of the second set of one or more data items.

18 . The method of claim 16 , wherein the plurality of data items include an information item or an actionable item.

19 . The method of claim 18 , wherein the actionable item is configured to trigger one or more processes executable by the at least one hardware processor.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 12, 2024
From: HILLIARD, MATTHEW DAVID; GAJEWSKI, KEVIN; RADCLIFFE, ANDREW DONALD BRIAN; HARPER, MAX HENRY; COLEN, STEPHANIE L.
To: APPIAN CORPORATION
Reel/Frame 066727/0872 →
Continuity (2)
Provisional Application 63488427 · Mar 3, 2023
Related Publication 20240296244A1 · Sep 5, 2024
References Cited (10)
US 9275094B2 · Lee · 2016 [cited by examiner]
US 11232230B1 · Mudgil · 2022 [cited by examiner]
US 20070288614A1 · May · 2007 [cited by examiner]
US 20090132419A1 · Grammer · 2009 [cited by examiner]
US 20110208739A1 · Weissman · 2011 [cited by examiner]
US 20110295839A1 · Collins · 2011 [cited by examiner]
US 20120131064A1 · Browning · 2012 [cited by examiner]
US 20160210470A1 · Rozenberg · 2016 [cited by examiner]
US 20210005302A1 · McFarlane · 2021 [cited by examiner]
US 20220335148A1 · Gandhi · 2022 [cited by examiner]