IP Library Granted Patent US 12,634,293
Granted Patent B2
US 12,634,293 · App. 19/236,071 · Granted May 19, 2026

Automated least privilege using risk and usage

Inventors: Gaurav Rastogi (San Francisco, CA); Murali Basavaiah (Los Altos, CA); Kevin Alejandro Roundy (El Segundo, CA); Kamalakannan Congevaram Muralidharan (Milpitas, CA)
Assignee: Andromeda Security
H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,634,293
App. No.
19/236,071
Granted
May 19, 2026
Kind
B2
Abstract

A set of one or more permissions associated with an identity is determined. One or more risk metrics and corresponding usage associated with the one or more permissions associated with the identity are determined. Access associated with at least one permission from the set of one or more permissions associated with the identity is modified based on the one or more determined risk metrics and corresponding usage associated with the one or more permissions associated with the identity.

Claims (32)

1 . A system, comprising:

a processor configured to:

determine a set of one or more permissions associated with an identity;

for each permission of the set of one or more permissions, determine one or more risk metrics that are calculated independently of historical usage, and determine corresponding usage of the one or more permissions associated with the identity; and

modify access associated with at least one permission from the set of one or more permissions associated with the identity based on the one or more determined risk metrics and corresponding usage of the one or more permissions associated with the identity, including maintaining a first permission from the set of one or more permissions as standing access when the risk metrics associated with the permission are below a risk threshold, and converting a second permission from the set of one or more permissions from standing access to just-in-time access when the risk metrics associated with the second permission exceed the risk threshold and the corresponding usage indicates a need for the second permission; and

a memory coupled to the processor and configured to provide the processor with instructions.

2 . The system of claim 1 , wherein the set of one or more permissions associated with the identity is an initial set of permissions.

3 . The system of claim 1 , wherein the set of one or more permissions associated with the identity is a previously determined least privilege set of permissions.

4 . The system of claim 1 , wherein the set of one or more permissions associated with the identity is determined according to a schedule, in response to a user command, or in response to an event.

5 . The system of claim 1 , wherein the set of one or more permissions associated with the identity includes one or more low privilege permissions after access associated with the at least one permission from the set of one or more permissions is modified.

6 . The system of claim 1 , wherein the one or more risk metrics that are calculated independently of historical usage are based in part on an account risk and an identity risk.

7 . The system of claim 6 , wherein the account risk is based on one or more of a permission risk, a policy risk, data sensitivity, and customer criticality.

8 . The system of claim 7 , wherein the permission risk is based in part on an access level associated with a permission.

9 . The system of claim 8 , wherein to determine the access level associated with the permission, the processor is configured to:

provide to a large language model a description of the permission and an instruction to determine the access level associated with the permission based on the permission;

receive a response from the large language model; and

assign the access level associated with the permission to the permission based on the response.

10 . The system of claim 6 , wherein the identity risk is based on a posture risk metric, a behavior risk metric, and/or a privilege risk metric.

11 . The system of claim 1 , wherein the corresponding usage associated with the one or more permissions is based on cloud event log history, identity provider activity, and/or actions performed by the identity within an application after authentication.

12 . The system of claim 1 , wherein the processor is configured to determine an excessive privilege score based on the one or more risk metrics and the corresponding usage associated with the one or more permissions associated with the identity.

13 . The system of claim 12 , wherein the processor is configured to compare a risk score that is based on the excessive privilege score, the one or more risk metrics associated with the permission, and a corresponding usage associated with the permission to a risk threshold.

14 . The system of claim 13 , wherein the processor is configured to remove a permission from the set of one or more permissions in response to determining that the risk is not less than a risk threshold and a second risk threshold.

15 . A method, comprising:

determining a set of one or more permissions associated with an identity;

for each permission of the set of one or more permissions, determining one or more risk metrics that are calculated independently of historical usage, and determining corresponding usage of the one or more permissions associated with the identity; and

modifying access associated with at least one permission from the set of one or more permissions associated with the identity based on the one or more determined risk metrics and corresponding usage of the one or more permissions associated with the identity, including maintaining a first permission from the set of one or more permissions as standing access when the risk metrics associated with the permission are below a risk threshold, and converting a second permission from the set of one or more permissions from standing access to just-in-time access when the risk metrics associated with the second permission exceed the risk threshold and the corresponding usage indicates a need for the second permission.

16 . The method of claim 15 , wherein the set of one or more permissions associated with the identity includes one or more low privilege permissions after access associated with the at least one permission from the set of one or more permissions is modified.

17 . The method of claim 15 , wherein the one or more risk metrics are based in part on an account risk and an identity risk.

18 . A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:

determining a set of one or more permissions associated with an identity;

for each permission of the set of one or more permissions, determining one or more risk metrics that are calculated independently of historical usage, and determining corresponding usage of the one or more permissions associated with the identity; and

modifying access associated with at least one permission from the set of one or more permissions associated with the identity based on the one or more determined risk metrics and corresponding usage of the one or more permissions associated with the identity, including maintaining a first permission from the set of one or more permissions as standing access when the risk metrics associated with the permission are below a risk threshold, and converting a second permission from the set of one or more permissions from standing access to just-in-time access when the risk metrics associated with the second permission exceed the risk threshold and the corresponding usage indicates a need for the second permission.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 26, 2025
From: RASTOGI, GAURAV; BASAVAIAH, MURALI; ROUNDY, KEVIN ALEJANDRO; CONGEVARAM MURALIDHARAN, KAMALAKANNAN
To: ANDROMEDA SECURITY
Reel/Frame 072119/0832 →
Continuity (2)
Provisional Application 63659752 · Jun 13, 2024
Related Publication 20250385921A1 · Dec 18, 2025
References Cited (37)
US 9137263B2 · Chari · 2015 [cited by applicant]
US 9648036B2 · Seiver · 2017 [cited by applicant]
US 10198597B2 · Ekambaram · 2019 [cited by applicant]
US 10230734B2 · Seigel · 2019 [cited by applicant]
US 11640470B1 · Amar · 2023 [cited by examiner]
US 12028346B1 · Cannard · 2024 [cited by applicant]
US 12058142B2 · Kumar · 2024 [cited by applicant]
US 12177254B2 · Alaeddini · 2024 [cited by applicant]
US 12437094B2 · Warshavsky · 2025 [cited by applicant]
US 12455987B2 · Pu · 2025 [cited by applicant]
US 20130298243A1 · Kumar · 2013 [cited by applicant]
US 20140196104A1 · Chari · 2014 [cited by applicant]
US 20160323288A1 · Peterson · 2016 [cited by applicant]
US 20180033006A1 · Goldman · 2018 [cited by applicant]
US 20190207953A1 · Klawe · 2019 [cited by applicant]
US 20200259852A1 · Wolff · 2020 [cited by applicant]
US 20210126912A1 · Maclean · 2021 [cited by applicant]
US 20210150023A1 · Juncker · 2021 [cited by applicant]
US 20210234856A1 · Rehnelt · 2021 [cited by applicant]
US 20210281610A1 · Applegate-Swanson · 2021 [cited by examiner]
US 20220060507A1 · Crabtree · 2022 [cited by applicant]
US 20220166762A1 · Srour · 2022 [cited by applicant]
US 20230109755A1 · Qadri · 2023 [cited by applicant]
US 20240179184A1 · Dayan · 2024 [cited by applicant]
US 20240193519A1 · Holovacs · 2024 [cited by applicant]
US 20240223567A1 · Istomin · 2024 [cited by applicant]
US 20250126145A1 · Sapir · 2025 [cited by examiner]
US 20250202899A1 · Chen · 2025 [cited by applicant]
US 20250202910A1 · Kondapi · 2025 [cited by applicant]
US 20250335558A1 · Alhomsi · 2025 [cited by applicant]
CN 110519241 · 2019 [cited by applicant]
CN 112543176 · 2021 [cited by applicant]
CN 120200863 · 2025 [cited by applicant]
EP 3571619 · 2021 [cited by applicant]
WO 2001011452 · 2001 [cited by applicant]
WO 2016067117 · 2016 [cited by applicant]
Dos Santos et al., A Dynamic Risk-based Access Control Architecture for Cloud Computing, IEEE Xplore, 2014, 9 Pages. [cited by applicant]