IP Library Granted Patent US 8,447,779
Granted Patent B2
US 8,447,779 · App. 13/370,247 · Granted May 21, 2013

On-demand database service system, method and computer program product for conditionally allowing an application of an entity access to data of another entity

Inventors: Lexi Viripaeff (Novato, CA); Vinod Mehra (Fremont, CA); Alex Warshavsky (San Francisco, CA); Nate Horne (Walnut Creek, CA); Peter J. Dapkus (Oakland, CA)
Assignee: salesforce.com, inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,447,779
App. No.
13/370,247
Granted
May 21, 2013
Kind
B2
Abstract

In accordance with embodiments, there are provided mechanisms and methods for conditionally allowing an application of an entity access to data of another entity in an on-demand database service. These mechanisms and methods for conditionally allowing an application of an entity access to data of another entity in an on-demand database service can enable embodiments to limit such access to the data, as desired. Furthermore, embodiments of such mechanisms and methods may provide additional security when sharing data among different subscribers to an on-demand database service.

Claims (45)

1. A method, comprising:

receiving a request from an application created by a first entity, wherein the application includes business logic and the request includes a request to access data of a second entity stored in a database of an on-demand database service; determining, utilizing a hardware processor, whether the application is authorized to access the data of the second entity stored in the database of the on-demand database service using a plurality of data access limitations associated with the application and indicated in a profile, wherein the data access limitations are presented to the second entity for acceptance by the second entity;

conditionally allowing the access to the data of the second entity stored in the database of the on-demand database service, based on the determination and the acceptance; and

in response to an update associated with the application, requesting that the second entity accept the update associated with the application, and conditionally allowing the access to the data of the second entity stored in the database of the on-demand database service utilizing the application, based on the acceptance of the update associated with the application;

wherein the application is authenticated, and the application is conditionally installed based on the authentication;

wherein the data access limitations grant the application created by the first entity access to the data of the second entity;

wherein the first entity and the second entity are different tenants of the on-demand database service, such that the on-demand database service processes requests for each of the first entity and the second entity and stores information for each of the first entity and the second entity, and wherein the profile indicating the data access limitations granting the application created by the first entity access to the data of the second entity provides sharing with the first entity the data of the second entity that is stored in the database of the on-demand database service;

wherein a package includes the application and the data access limitations, and the package is installed by the second entity.

2. The method of claim 1 , wherein the first entity and the second entity include different organizations.

3. The method of claim 1 , wherein the first entity and the second entity include different divisions of a single organization.

4. The method of claim 1 , wherein the data access limitations are determined by the second entity.

5. The method of claim 1 , wherein the data access limitations include a plurality of data access levels.

6. The method of claim 1 , wherein the data access limitations include limitations on at least one type of the data of the second entity stored in the database of the on-demand database service that can be accessed.

7. The method of claim 1 , wherein the data access limitations include limitations on at least one action that may be performed on the data of the second entity stored in the database of the on-demand database service.

8. The method of claim 1 , and further comprising receiving the update associated with the application.

9. The method of claim 8 , and further comprising presenting the update to the second entity for acceptance by the second entity, and conditionally allowing the access to the data of the second entity stored in the database of the on-demand database service utilizing the update, based on the acceptance.

10. The method of claim 1 , wherein the application is served by the on-demand database service.

11. A non-transitory machine-readable medium carrying one or more sequences of instructions which, when executed by one or more processors, cause the one or more processors to carry out the steps of:

receiving a request from an application created by a first entity, wherein the application includes business logic and the request includes a request to access data of a second entity stored in a database of an on-demand database service;

determining whether the application is authorized to access the data of the second entity stored in the database of the on-demand database service using a plurality of data access limitations associated with the application and indicated in a profile, wherein the data access limitations are presented to the second entity for acceptance by the second entity;

conditionally allowing the access to the data of the second entity stored in the database of the on-demand database service, based on the determination and the acceptance; and

in response to an update associated with the application, requesting that the second entity accept the update associated with the application, and conditionally allowing the access to the data of the second entity stored in the database of the on-demand database service utilizing the application, based on the acceptance of the update associated with the application;

wherein the application is authenticated, and the application is conditionally installed based on the authentication;

wherein the data access limitations grant the application created by the first entity access to the data of the second entity;

wherein the first entity and the second entity are different tenants of the on-demand database service, such that the on-demand database service processes requests for each of the first entity and the second entity and stores information for each of the first entity and the second entity, and wherein the profile indicating the data access limitations granting the application created by the first entity access to the data of the second entity provides sharing with the first entity the data of the second entity that is stored in the database of the on-demand database service;

wherein a package includes the application and the data access limitations, and the package is installed by the second entity.

12. An apparatus, comprising:

a processor; and

one or more stored sequences of instructions which, when executed by the processor, cause the processor to carry out the steps of:

receiving a request from an application created by a first entity, wherein the application includes business logic and the request includes a request to access data of a second entity stored in a database of an on-demand database service;

determining whether the application is authorized to access the data of the second entity stored in the database of the on-demand database service using a plurality of data access limitations associated with the application and indicated in a profile, wherein the data access limitations are presented to the second entity for acceptance by the second entity;

conditionally allowing the access to the data of the second entity stored in the database of the on-demand database service, based on the determination and the acceptance; and

in response to an update associated with the application, requesting that the second entity accept the update associated with the application, and conditionally allowing the access to the data of the second entity stored in the database of the on-demand database service utilizing the application, based on the acceptance of the update associated with the application;

wherein the application is authenticated, and the application is conditionally installed based on the authentication;

wherein the data access limitations grant the application created by the first entity access to the data of the second entity;

wherein the first entity and the second entity are different tenants of the on-demand database service, such that the on-demand database service processes requests for each of the first entity and the second entity and stores information for each of the first entity and the second entity, and wherein the profile indicating the data access limitations granting the application created by the first entity access to the data of the second entity provides sharing with the first entity the data of the second entity that is stored in the database of the on-demand database service; wherein a package includes the application and the data access limitations, and the package is installed by the second entity.

13. A method for transmitting code for use in a multi-tenant database system on a transmission medium, the method comprising:

transmitting code for receiving a request from an application created by a first entity, wherein the application includes business logic and the request includes a request to access data of a second entity stored in a database of an on-demand database service;

transmitting code for determining, utilizing a hardware processor, whether the application is authorized to access the data of the second entity stored in the database of the on-demand database service using a plurality of data access limitations associated with the application and indicated in a profile, wherein the data access limitations are presented to the second entity for acceptance by the second entity;

transmitting code for conditionally allowing the access to the data of the second entity stored in the database of the on-demand database service, based on the determination and the acceptance;

transmitting code for, in response to an update associated with the application, requesting that the second entity accept the update associated with the application, and conditionally allowing the access to the data of the second entity stored in the database of the on-demand database service utilizing the application, based on the acceptance of the update associated with the application; and

wherein the application is authenticated, and the application is conditionally installed based on the authentication;

wherein the data access limitations grant the application created by the first entity access to the data of the second entity;

wherein the first entity and the second entity are different tenants of the on-demand database service, such that the on-demand database service processes requests for each of the first entity and the second entity and stores information for each of the first entity and the second entity, and wherein the profile indicating the data access limitations granting the application created by the first entity access to the data of the second entity provides sharing with the first entity the data of the second entity that is stored in the database of the on-demand database service;

wherein a package includes the application and the data access limitations, and the package is installed by the second entity.

Continuity (3)
Continuation 12176026 · Jul 18, 2008
Provisional Application 60950836 · Jul 19, 2007
Related Publication 20120143916A1 · Jun 7, 2012