IP Library › Patent Application 19235493
Patent Application
App. No. 19/235,493

COMPUTING SYSTEM PERMISSION ADMINISTRATION ENGINE

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/235,493
Filed
Jun 11, 2025
Art Unit
OPAP
USPC
726/4
Abstract

A plurality of permissions associated with the on-demand computing services environment may be identified. Each of the permissions may identify a respective one or more actions permitted to be performed within the on-demand computing services environment. Each of the permissions may be granted to a respective one or more user accounts within the on-demand computing services environment. A degree of overlap between a first group of the user accounts granted a first one of the permissions and a second group of the user accounts granted a second one of the permissions may be determined. When the degree of overlap exceeds a designated threshold, a designated permission set that includes the first permission and the second permission may be created.

Claims (35)

1 . A method implemented across a computing services environment, the method comprising:

granting, via an identity and access management system, to one or more user identities associated with a first organization in the computing services environment, one or more permissions of a plurality of permissions associated with the first organization, each of the plurality of permissions corresponding to a respective one or more of a plurality of actions permitted to be performed on resources;

continuously monitoring use of the one or more permissions by the one or more user identities;

detecting, based on the continuous monitoring and a machine learning model, one or more atypical permission usages by the one or more user identities;

in response to detecting the atypical permission usages, creating a notification associated with the detected atypical permission usages; and

providing, to an entity associated with the first environment, the notification in association with a permissions management dashboard configurable to present data describing the one or more atypical permission usages by the one or more user identities.

2 . The method of claim 1 , wherein the atypical permission usage comprises a lack of use of the permissions by the one or more user identities.

3 . The method of claim 2 , wherein the permissions management dashboard is configurable to present data describing unused access keys for users of the identity and access management system, unused passwords for users of the identity and access management system, and unused services associated with the identity and access management system.

4 . The method of claim 1 , wherein the notification includes enriched metadata associated with threat detection.

5 . The method of claim 1 , wherein the identity and access management system is configurable to allow an authorized administrator to manage permissions controlling resource access by users and authentication and authorization for the first organization.

6 . The method of claim 1 , wherein the machine learning model is used to identify unusual activity within the first organization.

7 . The method of claim 1 , wherein the notification is provided to an administrator associated with the first organization, the identity and access management being configurable to allow the authorized administrator to remove permissions that are no longer needed using the permissions management dashboard.

8 . An identity and access management system implemented in a computing services environment using at least a server computing device, the access governance system configurable to cause:

granting to one or more user identities associated with a first organization in the computing services environment, one or more permissions of a plurality of permissions associated with the first organization, each of the plurality of permissions corresponding to a respective one or more of a plurality of actions permitted to be performed on resources;

continuously monitoring use of the one or more permissions by the one or more user identities;

detecting, based on the continuous monitoring and a machine learning model, one or more atypical permission usages by the one or more user identities;

in response to detecting the atypical permission usages, creating a notification associated with the detected atypical permission usages; and

providing, to an entity associated with the first environment, the notification in association with a permissions management dashboard configurable to present data describing the one or more atypical permission usages by the one or more user identities.

9 . The identity and access management system of claim 8 , wherein the atypical permission usage comprises a lack of use of the permissions by the one or more user identities.

10 . The identity and access management system of claim 9 , wherein the permissions management dashboard is configurable to present data describing unused access keys for users of the identity and access management system, unused passwords for users of the identity and access management system, and unused services associated with the identity and access management system.

11 . The identity and access management system of claim 8 , wherein the notification includes enriched metadata associated with threat detection.

12 . The identity and access management system of claim 8 , wherein the identity and access management system is configurable to allow an authorized administrator to manage permissions controlling resource access by users and authentication and authorization for the first organization.

13 . The identity and access management system of claim 8 , wherein the machine learning model is used to identify unusual activity within the first organization.

14 . The identity and access management system of claim 8 , wherein the notification is provided to an administrator associated with the first organization, the identity and access management being configurable to allow the authorized administrator to remove permissions that are no longer needed using the permissions management dashboard.

15 . A computer program product comprising computer-readable program code capable of being executed by one or more processors when retrieved from a non-transitory computer-readable medium, the program code comprising computer-readable instructions configurable to cause:

granting, via an identity and access management system implemented in a computing services environment, to one or more user identities associated with a first organization in the computing services environment, one or more permissions of a plurality of permissions associated with the first organization, each of the plurality of permissions corresponding to a respective one or more of a plurality of actions permitted to be performed on resources;

continuously monitoring use of the one or more permissions by the one or more user identities;

detecting, based on the continuous monitoring and a machine learning model, one or more atypical permission usages by the one or more user identities;

in response to detecting the atypical permission usages, creating a notification associated with the detected atypical permission usages; and

providing, to an entity associated with the first environment, the notification in association with a permissions management dashboard configurable to present data describing the one or more atypical permission usages by the one or more user identities.

16 . The computer program product system of claim 15 , wherein the atypical permission usage comprises a lack of use of the permissions by the one or more user identities.

17 . The computer program product of claim 16 , wherein the permissions management dashboard is configurable to present data describing unused access keys for users of the identity and access management system, unused passwords for users of the identity and access management system, and unused services associated with the identity and access management system.

18 . The computer program product of claim 15 , wherein the notification includes enriched metadata associated with threat detection.

19 . The computer program product of claim 15 , wherein the identity and access management system is configurable to allow an authorized administrator to manage permissions controlling resource access by users and authentication and authorization for the first organization.

20 . The computer program product of claim 15 , wherein the machine learning model is used to identify unusual activity within the first organization.

Assignments (2)
CHANGE OF NAME Recorded Aug 4, 2026
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 076118/0548 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2025
From: PARKS, FREEMAN; WOEBKENBERG, RYAN D.
To: SALESFORCE.COM, INC.
Reel/Frame 071567/0655 →