IP Library Granted Patent US 12,592,985
Granted Patent B2
US 12,592,985 · App. 18/656,259 · Granted Mar 31, 2026

System and method for tagging in identity management artificial intelligence systems and uses for same, including context based governance

Inventors: Norman Anderson, III (Austin, TX); Jeffrey Foreman (Round Rock, TX); Amar Rama (Austin, TX)
Assignee: SAILPOINT TECHNOLOGIES, INC.
H04L67/306G06F16/2264G06F16/2443
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,592,985
App. No.
18/656,259
Granted
Mar 31, 2026
Kind
B2
Abstract

First level fields may include second-level fields or nested-level fields, as will be described at a later point. When a category to search within to find data is specified in a search, the deepest category searched in is the first-level field. In some cases, only a single field is needed for a search. This is the first-level field. If more than one field to is needed to find desired data, the category that is typed last and that appears closest to the search terms in the query, is the first-level field. A first-level field contains actual data, as opposed to containing additional fields to search in.

Claims (37)

1 . An identity management system, comprising:

a processor;

a non-transitory, computer-readable storage medium, including computer instructions for:

maintaining a search index for identity management artifacts utilized in identity management of a distributed enterprise computing environment and determined based on identity management data obtained from one or more source systems in the distributed enterprise computing environment, the search index comprising a document for each of the identity management artifacts;

assigning, by a tagging service, a tag with a set of the identity management artifacts based on one or more defined tagging policies, wherein the one or more defined tagging policies are stored in a data store and each policy comprises a policy definition including a search criteria and one or more associated tags, the set of the identity management artifacts determined by identity management artifacts that meet a particular search criteria;

for each of the identity management artifacts in the set, determining the corresponding document;

storing the tag in each of the corresponding documents; and

indexing the tag in the search index, thereby allowing the set of identity management artifacts to be searched using the tag and the search index.

2 . The identity management system of claim 1 , wherein determining the set of identity management artifacts comprises searching the set of identity management artifacts based on the specified criteria.

3 . The identity management system of claim 1 , wherein the tag is assigned before at least one of the set of the identity management artifacts was determined from the identity management data.

4 . The identity management system of claim 1 , wherein the tag is indexed in association with the at least one of the set of the identity management artifacts at the same time the corresponding document for the at least one of the of the set of the identity management artifacts is determined or created in the search index.

5 . The identity management system of claim 1 , wherein determining the set of the identity management artifacts is based on an association of each of the set of the identity management artifacts with a particular identity management artifact.

6 . The identity management system of claim 5 , wherein the set of the identity management artifacts are identities and the particular identity management artifact is an entitlement.

7 . The identity management system of claim 5 , wherein the tag is obtained from the particular identity management artifact.

8 . A method, comprising:

maintaining a search index for identity management artifacts utilized in identity management of a distributed enterprise computing environment and determined based on identity management data obtained from one or more source systems in the distributed enterprise computing environment, the search index comprising a document for each of the identity management artifacts;

assigning, by a tagging service, a tag with a set of the identity management artifacts based on one or more defined tagging policies, wherein the one or more defined tagging policies are stored in a data store and each policy comprises a policy definition including a search criteria and one or more associated tags, the set of the identity management artifacts determined by identity management artifacts that meet a particular search criteria;

for each of the identity management artifacts in the set, determining the corresponding document;

storing the tag in each of the corresponding documents; and

indexing the tag in the search index, thereby allowing the set of identity management artifacts to be searched using the tag and the search index.

9 . The method of claim 8 , wherein determining the set of identity management artifacts comprises searching the set of identity management artifacts based on the specified criteria.

10 . The method of claim 8 , wherein the tag is assigned before at least one of the set of the identity management artifacts was determined from the identity management data.

11 . The method of claim 8 , wherein the tag is indexed in association with the at least one of the set of the identity management artifacts at the same time the corresponding document for the at least one of the of the set of the identity management artifacts is determined or created in the search index.

12 . The method of claim 8 , wherein determining the set of the identity management artifacts is based on an association of each of the set of the identity management artifacts with a particular identity management artifact.

13 . The method of claim 12 , wherein the set of the identity management artifacts are identities and the particular identity management artifact is an entitlement.

14 . The method of claim 12 , wherein the tag is obtained from the particular identity management artifact.

15 . A non-transitory computer readable medium, comprising instructions that are executable by one or more processors for:

maintaining a search index for identity management artifacts utilized in identity management of a distributed enterprise computing environment and determined based on identity management data obtained from one or more source systems in the distributed enterprise computing environment, the search index comprising a document for each of the identity management artifacts;

assigning, by a tagging service, a tag with a set of the identity management artifacts based on one or more defined tagging policies, wherein the one or more defined tagging policies are stored in a data store and each policy comprises a policy definition including a search criteria and one or more associated tags, the set of the identity management artifacts determined by identity management artifacts that meet a particular search criteria;

for each of the identity management artifacts in the set, determining the corresponding document;

storing the tag in each of the corresponding documents; and

indexing the tag in the search index, thereby allowing the set of identity management artifacts to be searched using the tag and the search index.

16 . The non-transitory computer readable medium of claim 15 , wherein determining the set of identity management artifacts comprises searching the set of identity management artifacts based on the specified criteria.

17 . The non-transitory computer readable medium of claim 15 , wherein the tag was associated before at least one of the set of the identity management artifacts was determined from the identity management data.

18 . The non-transitory computer readable medium of claim 15 , wherein the tag is indexed in association with the at least one of the set of the identity management artifacts at the same time the document for the at least one of the of the set of the identity management artifacts is determined or created in the search index.

19 . The non-transitory computer readable medium of claim 15 , wherein the set of the identity management artifacts is based on an association of each of the set of the identity management artifacts with a particular identity management artifact.

20 . The non-transitory computer readable medium of claim 19 , wherein the set of the identity management artifacts are identities and the particular identity k management artifact is an entitlement.

Assignments (2)
PATENT SECURITY AGREEMENT Recorded Jun 25, 2025
From: SAILPOINT TECHNOLOGIES, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071724/0511 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 3, 2024
From: ANDERSON, NORMAN, III; FOREMAN, JEFFREY; RAMA, AMAR
To: SAILPOINT TECHNOLOGIES, INC.
Reel/Frame 067599/0210 →
Continuity (4)
Continuation 17848057 · Jun 23, 2022
Continuation 16749577 · Jan 22, 2020
Continuation 16440690 · Jun 13, 2019
Related Publication 20240291896A1 · Aug 29, 2024
References Cited (20)
US 4525780A · Bratt · 1985 [cited by examiner]
US 5173939A · Abadi · 1992 [cited by examiner]
US 5315657A · Abadi · 1994 [cited by examiner]
US 5335346A · Fabbio · 1994 [cited by examiner]
US 5347578A · Duxbury · 1994 [cited by examiner]
US 5701458A · Bsaibes · 1997 [cited by examiner]
US 5825877A · Dan · 1998 [cited by examiner]
US 5956715A · Glasser · 1999 [cited by examiner]
US 6157052A · Kuge · 2000 [cited by examiner]
US 6202066B1 · Barkley · 2001 [cited by examiner]
US 6237036B1 · Ueno · 2001 [cited by examiner]
US 6772350B1 · Belani · 2004 [cited by examiner]
US 6816906B1 · Icken · 2004 [cited by examiner]
US 7016945B2 · Bellaton · 2006 [cited by examiner]
US 7380271B2 · Moran · 2008 [cited by examiner]
US 10623520B1 · Anderson, III · 2020 [cited by examiner]
US 20010056494A1 · Trabelsi · 2001 [cited by examiner]
US 20020026592A1 · Gavrila · 2002 [cited by examiner]
US 20040216039A1 · Lane · 2004 [cited by examiner]
US 20070208744A1 · Krishnaprasad · 2007 [cited by examiner]