IP Library › Patent Application 19042452
Patent Application
App. No. 19/042,452

CONTROLLING JUST IN TIME ACCESS TO A CLUSTER

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/042,452
Abstract

Examples include a system and computer-implemented method to receive a notification from an application programming interface (API) of creation of a just in time (JIT) grant, the JIT grant defining a request for a user to be authorized to access a cluster according to a JIT policy; determine if access to the cluster by the user is authorized according to the JIT policy; grant access to the user to the cluster when access is authorized according to the JIT policy; and send a notification to the API that access by the user to the cluster is granted.

Claims (31)

1 . A web services system, comprising:

a processing device; and

a memory device, the processing device configurable to cause:

processing a request from a user of the web services system for just in time (JIT) access to a web services resource received via an interface, the request specifying a role of the user, a justification for the user to access the web services resource, and duration for the user to access the web services resource;

determining that access to the web services resource by the user is authorized according to a policy defining scope of access to web services resources based, at least in part, on the role of the user;

granting, to the user, JIT access to the web services resource for the duration responsive to determining that access is authorized according to the policy, wherein granting, to the user, JIT access to the web services resource includes creating a role binding for the user; and revoking access by the user to the web services resource in response to the duration is elapsing, wherein revoking access includes deleting the role binding.

2 . The web services system of claim 1 , wherein the JIT access comprises temporary elevated access to web services resources of the web services system granted for a business reason.

3 . The web services system of claim 1 , wherein the role binding specifies permissions given to users of the web services system based on an identity and access management role associated with the users.

4 . The web services system of claim 3 , wherein deleting the role binding comprises de-associating the identity and access management role from the user.

5 . The web services system of claim 1 , wherein eligibility of the user to access the web services resource is determined at least in part by membership of the user in one or more groups.

6 . The web services system of claim 1 , wherein the duration is selectable via a user interface displayed on a computing device associated with the user.

7 . The web services system of claim 6 , wherein a maximum duration that is selectable by the user is indicated in the user interface.

8 . A computer-implemented method, comprising:

receiving a request from a user of the web services system for just in time (JIT) access to a web services resource received via an interface, the request specifying a role of the user, a justification for the user to access the web services resource, and duration for the user to access the web services resource;

determining that access to the web services resource by the user is authorized according to a policy defining scope of access to web services resources based, at least in part, on the role of the user;

granting, to the user, JIT access to the web services resource for the duration responsive to determining that access is authorized according to the policy, wherein granting, to the user, JIT access to the web services resource includes creating a role binding for the user; and revoking access by the user to the web services resource in response to the duration is elapsing, wherein revoking access includes deleting the role binding.

9 . The method of claim 8 , wherein the JIT access comprises temporary elevated access to web services resources of the web services system granted for a business reason.

10 . The method of claim 8 , wherein the role binding specifies permissions given to users of the web services system based on an identity and access management role associated with the users.

11 . The method of claim 10 , wherein deleting the role binding comprises de-associating the identity and access management role from the user.

12 . The method of claim 8 , wherein eligibility of the user to access the web services resource is determined at least in part by membership of the user in one or more groups.

13 . The method of claim 8 , wherein the duration is selectable via a user interface displayed on a computing device associated with the user.

14 . The method of claim 13 , wherein a maximum duration that is selectable by the user is indicated in the user interface.

15 . At least one tangible non-transitory machine-readable medium comprising a plurality of instructions that in response to being executed by a processor in a computing system, are configurable to cause:

processing a request from a user of the web services system for just in time (JIT) access to a web services resource received via an interface, the request specifying a role of the user, a justification for the user to access the web services resource, and duration for the user to access the web services resource;

determining that access to the web services resource by the user is authorized according to a policy defining scope of access to web services resources based, at least in part, on the role of the user;

granting, to the user, JIT access to the web services resource for the duration responsive to determining that access is authorized according to the policy, wherein granting, to the user, JIT access to the web services resource includes creating a role binding for the user; and revoking access by the user to the web services resource in response to the duration is elapsing, wherein revoking access includes deleting the role binding.

16 . The at least one tangible non-transitory machine-readable medium of claim 15 , wherein the JIT access comprises temporary elevated access to web services resources of the web services system granted for a business reason.

17 . The at least one tangible non-transitory machine-readable medium of claim 15 , wherein the role binding specifies permissions given to users of the web services system based on an identity and access management role associated with the users.

18 . The at least one tangible non-transitory machine-readable medium of claim 17 , wherein deleting the role binding comprises de-associating the identity and access management role from the user.

19 . The at least one tangible non-transitory machine-readable medium of claim 15 , wherein eligibility of the user to access the web services resource is determined at least in part by membership of the user in one or more groups.

20 . The at least one tangible non-transitory machine-readable medium of claim 15 , wherein the duration is selectable via a user interface displayed on a computing device associated with the user.

Assignments (2)
CHANGE OF NAME Recorded Aug 4, 2026
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 076118/0548 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2025
From: MCQUAID, STEPHEN
To: SALESFORCE.COM, INC.
Reel/Frame 070302/0428 →