IP Library › Granted Patent US 12,355,776
Granted Patent B2
US 12,355,776 · App. 18/656,336 · Granted Jul 8, 2025

Computing system permission administration engine

Inventors: Freeman Parks (San Francisco, CA); Ryan D. Woebkenberg (San Francisco, CA)
Assignee: Salesforce, Inc.
H04L63/104G06F18/24G06N7/01G06N20/00H04L63/101H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,355,776
App. No.
18/656,336
Filed
May 6, 2024
Granted
Jul 8, 2025
Kind
B2
Examiner
SONG, HEE K
Art Unit
2497
USPC
726/4
Abstract

A plurality of permissions associated with the on-demand computing services environment may be identified. Each of the permissions may identify a respective one or more actions permitted to be performed within the on-demand computing services environment. Each of the permissions may be granted to a respective one or more user accounts within the on-demand computing services environment. A degree of overlap between a first group of the user accounts granted a first one of the permissions and a second group of the user accounts granted a second one of the permissions may be determined. When the degree of overlap exceeds a designated threshold, a designated permission set that includes the first permission and the second permission may be created.

Claims (48)

1. A method implemented across multi-cloud environments, the method comprising:

granting, via an authorization system to one or more user accounts associated with a first one of the environments, one or more permissions of a plurality of permissions associated with the multi-cloud environments, each of the plurality of permissions corresponding to a respective one or more of a plurality of actions permitted to be performed on resources;

continuously monitoring use of the one or more permissions by the one or more user accounts;

detecting, based on the continuous monitoring and a machine learning procedure, one or more atypical permission usages by the one or more user accounts;

in response to detecting the atypical permission usages, creating a notification associated with the detected atypical permission usages; and providing, to an entity associated with the first environment, the notification in association with permissions management tools configurable to modify or revoke the one or more permissions for the one or more user accounts based on the alert.

2. The method of claim 1 , wherein the user accounts comprise identities and the authorization system comprises a system that grants access to the identities.

3. The method of claim 1 , further comprising:

generating, based on detecting the atypical permission usage, a forensic report detailing the atypical permission usage.

4. The method of claim 1 , further comprising:

based on prior activity log information, classifying, and determining typical behavior for the one or more user accounts.

5. The method of claim 4 , further comprising:

providing, to the entity, a selection configurable to allow the entity to choose from pre-configured alerts to be sent to the entity in response to atypical or suspicious activity in the first environment.

6. The method of claim 5 , further comprising:

notifying, based on preconfigured alerts selected by the entity, that an account has performed an unusual number of tasks.

7. The method of claim 6 , further comprising:

automatically populating new permissions associated with a new role, based on historical activity of users selected by the entity.

8. A permissions management system implemented using a server system comprising one or more hardware processors, the permissions management system configurable to cause:

granting, via an authorization system to one or more user accounts associated with a first environment of a multi-cloud environment, one or more permissions of a plurality of permissions associated with the multi-cloud environments, each of the plurality of permissions corresponding to a respective one or more of a plurality of actions permitted to be performed on resources;

continuously monitoring use of the one or more permissions by the one or more user accounts;

detecting, based on the continuous monitoring and a machine learning procedure, one or more atypical permission usages by the one or more user accounts;

in response to detecting the atypical permission usages, creating a notification associated with the detected atypical permission usages; and

providing, to an entity associated with the first environment, the notification in association with permissions management tools configurable to modify or revoke the one or more permissions for the one or more user accounts based on the alert.

9. The permissions management system of claim 8 , wherein the user accounts comprise identities and the authorization system comprises a system that grants access to the identities.

10. The permissions management system of claim 8 , the permissions management system further configurable to cause:

generating, based on detecting the atypical permission usage, a forensic report detailing the atypical permission usage.

11. The permissions management system of claim 8 , the permissions management system further configurable to cause:

based on prior activity log information, classifying, and determining typical behavior for the one or more user accounts.

12. The permissions management system of claim 11 , the permissions management system further configurable to cause:

providing, to the entity, a selection configurable to allow the entity to choose from pre-configured alerts to be sent to the entity in response to atypical or suspicious activity in the first environment.

13. The permissions management system of claim 12 , the permissions management system further configurable to cause:

notifying, based on preconfigured alerts selected by the entity, that an account has performed an unusual number of tasks.

14. The permissions management system of claim 13 , the permissions management system further configurable to cause:

automatically populating new permissions associated with a new role, based on historical activity of users selected by the entity.

15. A computer program product comprising non-transitory computer-readable program code capable of being executed by one or more processors when retrieved from a non-transitory computer-readable medium, the program code comprising instructions configurable to cause the one or more processors to perform a method comprising:

granting, via an authorization system to one or more user accounts associated with a first environment of a multi-cloud environment, one or more permissions of a plurality of permissions associated with the multi-cloud environments, each of the plurality of permissions corresponding to a respective one or more of a plurality of actions permitted to be performed on resources;

continuously monitoring use of the one or more permissions by the one or more user accounts;

detecting, based on the continuous monitoring and a machine learning procedure, one or more atypical permission usages by the one or more user accounts;

in response to detecting the atypical permission usages, creating a notification associated with the detected atypical permission usages; and

providing, to an entity associated with the first environment, the notification in association with permissions management tools configurable to modify or revoke the one or more permissions for the one or more user accounts based on the alert.

16. The computer program product of claim 15 , wherein the user accounts comprise identities and the authorization system comprises a system that grants access to the identities.

17. The computer program product of claim 15 , the method further comprising:

generating, based on detecting the atypical permission usage, a forensic report detailing the atypical permission usage.

18. The computer program product of claim 15 , the method further comprising:

based on prior activity log information, classifying, and determining typical behavior for the one or more user accounts.

19. The computer program product of claim 18 , the method further comprising:

providing, to the entity, a selection configurable to allow the entity to choose from pre-configured alerts to be sent to the entity in response to atypical or suspicious activity in the first environment.

20. The computer program product of claim 18 , the method further comprising:

notifying, based on preconfigured alerts selected by the entity, that an account has performed an unusual number of tasks.

Assignments (2)
CHANGE OF NAME Recorded Aug 4, 2026
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 076118/0548 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 17, 2024
From: PARKS, FREEMAN; WOEBKENBERG, RYAN D.
To: SALESFORCE.COM, INC.
Reel/Frame 067743/0234 →
Continuity (3)
Continuation 17812977 · Jul 15, 2022
Continuation 16681932 · Nov 13, 2019
Related Publication 20240348620A1 · Oct 17, 2024
References Cited (12)
US 7437718B2 · Fournet et al. · 2008 [cited by applicant]
US 11121981B1 · Ping · 2021 [cited by examiner]
US 11425130B2 · Parks et al. · 2022 [cited by applicant]
US 20190068612A1 · Eads et al. · 2019 [cited by applicant]
US 20190188288A1 · Holm et al. · 2019 [cited by applicant]
US 20190190917A1 · Joe · 2019 [cited by examiner]
US 20210144144A1 · Parks et al. · 2021 [cited by applicant]
US 20220385666A1 · Parks et al. · 2022 [cited by applicant]
U.S. Appl. No. 17/812,977, USPTO e-Office Action: CTNF—Non-Final Rejection, Sep. 21, 2023, 9 pages. [cited by applicant]
U.S. Appl. No. 17/812,977, USPTO e-Office Action: NOA—Corrected Notice Of Allowance And Fees Due (Ptol-85), Mar. 19, 2024, 7 pages. [cited by applicant]
U.S. Appl. No. 17/812,977, USPTO e-Office Action: NOA—Notice Of Allowance And Fees Due (Ptol-85), Feb. 7, 2024, 7 pages. [cited by applicant]
U.S. Appl. No. 16/681,932, Notice of Allowance mailed Apr. 18, 2022, 9 pgs. [cited by applicant]