Method and system for identifying and managing access to data across multiple data platforms
The system automates access and authorization of sensitive data across multiple SAAS platforms by discovering, classifying, and normalizing permissions, addressing unintended access and enhancing security through uniform access control.
Patent Information
- Application Number
- JP2025527029
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-12-08
- Filing Date
- 2023-10-24
- Publication Date
- 2025-12-16
AI Technical Summary
Enterprises face security and data breaches due to unintended access of regulated and sensitive data across multiple Software as a Service (SAAS) platforms, where a user with access on one platform can access the same data on another platform without proper permission control.
A system and method for automating access and authorization of sensitive data across multiple SAAS platforms by discovering, classifying, and normalizing permission models, ensuring consistent access permissions across all platforms, using a central server to identify, tag, and propose authorization rules based on predetermined criteria.
Provides visibility and control over sensitive data access, preventing unintended access and enhancing security by ensuring uniform access permissions across all enterprise SAAS platforms, thereby reducing data breaches.
Smart Images

Figure 2025540626000001_ABST
Abstract
Description
[Technical Field]
[0001] The subject matter of this disclosure is directed to managing data, and in particular, managing the permissions of users of a network to access various data. [Background technology]
[0002] Enterprises typically run multiple platforms. For example, an enterprise may run multiple Software as a Service (SAAS) platforms, on which regulated and sensitive data is stored. Across the various platforms, a user who does not have access to regulated and sensitive data on one of the enterprise's SAAS platforms may be able to access the same regulated and sensitive data on another, different SAAS platform. Such unintended access can pose security and data breaches. Summary of the Invention
[0003] The subject matter of the present disclosure provides visibility and control of regulated and sensitive data (hereinafter referred to as "sensitive data," "sensitive data assets," "privileged data," or "privileged data assets," which are used interchangeably herein) to a user and / or multiple users who have permission to access the data, such as the same data stored on different SAAS platforms by an enterprise.
[0004] As used herein, reference will be made to the following terms used consistently or interchangeably, including variations thereof:
[0005] "Computer" includes machines, computers and computing or computer systems (e.g., physically separate locations or devices), servers, computers and computing devices, processors, processing systems, computing cores (e.g., shared devices), and similar systems, workstations, modules, and combinations thereof. Such "computers" come in a variety of types, including personal computers (e.g., laptops, desktops, tablet computers), or any type of computing device, including mobile devices that can be easily moved from one place to another (e.g., smartphones, personal digital assistants (PDAs), mobile or cellular phones, watches digitally linked to a network such as the Internet, or digital watches, bracelets or wristbands, or other wearable technology (also known as wearables), such as Bluetooth headsets or other network-connected headsets.
[0006] A "server" is typically a remote computer or computer system, or computer program thereof, or one hosted by a cloud-based service (e.g., Amazon Web Services (AWS)), in accordance with the above definition of "computer," accessible via a communications medium such as a communications network or other computer network, including the Internet. A "server" provides services to or performs functions for other computer programs (and their users) in the same or other computers. A server may also include a virtual machine or software-based emulation of a computer.
[0007] The terms "n" and "nth" refer to the last component in a series or sequence of components, eg, a server, database, computer, platform, element, whether the series is definite or indefinite.
[0008] Unless otherwise defined herein, all technical and / or scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the disclosed subject matter pertains. Although methods and materials similar or equivalent to those described herein can be used in the practice or testing of embodiments of the disclosed subject matter, exemplary methods and / or materials are described below. To the extent of conflict, the patent specification, including definitions, will control. Furthermore, the materials, methods, and examples are illustrative only and not intended to be limiting. [Brief explanation of the drawings]
[0009] The present disclosure will be more fully understood from the following detailed description of the embodiments thereof, taken in conjunction with the drawings, in which like reference numerals and / or letters indicate corresponding or similar elements, and in which: [Figure 1A] FIG. 1 illustrates an exemplary environment for a system in which embodiments of the disclosed subject matter may be implemented. [Figure 1B] FIG. 1 is a diagram of an example portion of a data table in a database associated with a Software as a Service (SAAS) platform. [Figure 2] 1B is a diagram of the architecture of the main server of FIG. 1A and its system, according to an embodiment of the disclosed subject matter. [Figure 3] FIG. 1 is a diagram of a database showing data classifications. [Figure 4] FIG. 1 is a flow diagram of an exemplary process according to an embodiment of the disclosed subject matter. [Figure 5A] FIG. 5 is a diagram of a platform used to explain the process of FIG. 4 in accordance with an embodiment of the disclosed subject matter. [Figure 5B] FIG. 5 is a diagram of a platform used to explain the process of FIG. 4 in accordance with an embodiment of the disclosed subject matter. [Figure 5C] FIG. 5 is a diagram of a platform used to explain the process of FIG. 4 in accordance with an embodiment of the disclosed subject matter. [Figure 5D]FIG. 5 is a diagram of a platform used to explain the process of FIG. 4 in accordance with an embodiment of the disclosed subject matter. [Figure 5E] FIG. 5 is a diagram of a platform used to explain the process of FIG. 4 in accordance with an embodiment of the disclosed subject matter. [Figure 5F] FIG. 5 is a diagram of a platform used to explain the process of FIG. 4 in accordance with an embodiment of the disclosed subject matter. DETAILED DESCRIPTION OF THE INVENTION
[0010] Before describing at least one embodiment of the disclosed subject matter in detail, it is to be understood that the disclosed subject matter is not necessarily limited in its application to the details of construction and arrangement of components and / or methods set forth in the following description and / or drawings. The disclosed subject matter is capable of other embodiments or of being practiced or carried out in various ways.
[0011] As will be appreciated by those skilled in the art, aspects of the presently disclosed subject matter can be embodied as a system, a method, or a computer program product. Accordingly, aspects of the presently disclosed subject matter can take the form of an entirely hardware embodiment, an entirely software embodiment (including firmware, resident software, microcode, etc.), or an embodiment combining software and hardware aspects, all of which are referred to generally herein as a "circuit," "module," or "system." Furthermore, aspects of the presently disclosed subject matter can take the form of a computer program product embodied in one or more non-transitory computer-readable (storage) medium(s) having computer-readable program code embodied therein.
[0012] Throughout this specification, numerous textual and graphical references are made to trademarks and domain names. These trademarks and domain names are the property of their respective owners and are referenced herein for illustrative purposes only.
[0013] <Summary> The present disclosure provides systems and methods for automating access and authorization of sensitive or privileged data by various users or entities (the terms "user(s)" and "entity / entities" are used interchangeably herein), such as those associated with an enterprise. For example, an enterprise may use multiple Software as a Service (SAAS) platforms, such that the same user has the same access permissions to the same data across all of the enterprise's SAAS platforms.
[0014] An example process provides users (or entities) with the same access to the same data across all platforms in an enterprise, including, for example, discovering the data assets to which the user has access and / or permissions, classifying the data assets, controlling access to the data assets, and proposing an appropriate access permission model for the data assets.
[0015] Data asset discovery may include, for example, identifying various types of data assets located within each of the enterprise's SaaS environments or platforms to which the user has access.
[0016] Classification of data assets involves organizing data assets according to, for example, various standards, regulations, and classification policies, and is typically performed automatically by a computer.
[0017] Controlling access to data assets includes, for example, normalizing permission models across different platforms, such as SAAS platforms, and providing insight into which users can access which data assets on each platform, such as SAAS platforms and CrossSAAS platforms.
[0018] Suggestions include, for example, selecting the appropriate permission model for a particular data asset for a particular user and applying it to all enterprise platforms that the user has access to.
[0019] The disclosed methods and systems operate across multiple platforms, such as SAAS platforms, with millions of data assets within the multiple platforms being operated. These operations include, for example, data asset search, identification, isolation, and comparison operations. These operations include, for example, "big data" analytics, which involves analyzing, systematically extracting, or otherwise processing information from data sets that are too large or complex to be processed by traditional data processing application software and / or software tools, such as dedicated computers (e.g., special-purpose computers) including processors, computer hardware, and / or software, to capture, curate, manage, and process data in real time, on the order of seconds, within acceptable elapsed times, such as short periods of time.
[0020] <System Description> Reference is now made to Figure 1A, which illustrates an exemplary operating environment including a network 100 to which a main server (MS) 102, also known as a central server, is linked. While the main server 102 is shown, the main server 102 and / or portions thereof may also be hosted by a service in the cloud, such as Amazon® Web Services (AWS). Accordingly, the description provided herein for the main server 102 also applies to cloud-based services.
[0021] Main server 102 also defines system 102' (FIG. 2), either alone or together with other computers including servers, components, and applications associated with main server 102, e.g., client applications, as described in more detail below. System 102' links to platforms (platform 1-platform n) 106a-106n (shown in one or more servers represented by server 107), e.g., SAAS platforms such as Salesforce®, Workday®, ServiceNow®, etc., which may be run by enterprise 110, for example.
[0022] The main server 102, for example, is typically part of an enterprise 110 and is linked to the platforms 106a-106n either directly or via a network 100, e.g., a local area network (LAN), also known as an enterprise network. Alternatively, the main server 102 may be linked to the platforms 106a-106n via a communications network, such as a wide area network (WAN), including public networks such as the Internet.
[0023] Network 100 may be a single network such as the Internet or a LAN, including a corporate network, but is typically a combination of networks (e.g., including a corporate network) and / or multiple networks, including, for example, combinations of the foregoing networks as well as cellular or Bluetooth or other networks. As used herein, "linked" includes both direct or indirect wired or wireless links that place computers, including servers, components, etc., in electronic and / or data communication with each other.
[0024] 1B, data assets 120 (120a, 120b, 120c for illustrative purposes) are identified from data tables (or portions thereof) from a platform, e.g., Platform 1 106a. For example, each data asset 120 (e.g., 120a, 120b, 120c) is an atomic unit of data and includes an identification, such as a data asset name, a definition, one or more descriptive terms or content of the data held as the data asset, and a type of data asset.
[0025] Users or entities A, B, C, D, E, and P, Q, R, represented by computers 115a-115e and 115p-115r, are linked to network 100 and therefore have access to platforms 106a-106n with different permissions to different data assets within the various platforms 106a-106n.
[0026] Continuing to refer to FIG. 1B, looking at data asset “Patrick Macombs” 120a, it has an identification or field of “Account Name (ACCT.NAME)” and is a data asset of type “Name,” and the actual words “Patrick” and “Macombs” are the representational terms or content of the data asset.
[0027] Referring to FIG. 2, the architecture of the system 102′ is shown. The system 102′ is formed from components including, for example, processors, storage media, databases, modules, and models, to provide numerous additional server functions and operations and to execute the processes of the system 102′ of the present disclosure. Components relevant to the disclosure are shown and described below. The main server (MS) 102 can be associated with additional storage, memory, caches, and databases, both internal and external. For illustrative purposes, the main server (HS) 102 can have a Uniform Resource Locator (URL) of, for example, www.example.ms.com.
[0028] Central processing unit (CPU) 202 may comprise, for example, one or more processors in direct or indirect communication, including electronic and / or data communication, with storage / memory 204. CPU 202 also communicates with database 211 and storage medium 212, as well as data asset isolator or isolation module 221, tagger or tagging module 222, searcher / normalizer or search and normalization module 223, and authorization model 231.
[0029] A "module," as used herein, includes, for example, a component for storing instructions (e.g., machine-readable instructions) for performing a process, and includes or is associated with a processor in CPU 202 for executing the instructions. All components 202, 204, 211, 212, 221, 222, 223, and 231 are directly or indirectly linked to each other for communicating directly or indirectly with each other.
[0030] The central processing unit (CPU) 202 comprises one or more processors, including a microprocessor, to perform the functions and operations of the main server 102 and / or system 102 as described herein. Typically, the processor-based CPU 202 comprises a general-purpose computer that is programmed with software to perform the functions described herein. The software may be downloaded to the computer in electronic form, for example, over a network, or alternatively or additionally, may be provided and / or stored on a non-transitory tangible medium, such as magnetic, optical, or electronic memory. The processor may be a conventional processor, such as those used in servers, computers, and other computing devices, including hardware processors. For example, the processor may include an AMD (Advanced Micro Devices®) x86 processor and an Intel®, Xenon®, and Pentium® processor, as well as any combination thereof.
[0031] Storage / memory 204 is any conventional storage medium. Storage / memory 204 stores machine-executable instructions executed by CPU 202 to perform the disclosed processes. Storage / memory 204 also includes machine-executable instructions related to the operation of components including database 211 and storage medium 212, separation module 221, tagging module 222, search and normalization module 223, and permission model 231. Storage / memory 204 also stores rules and policies for system 102′ and main server 102, for example. While shown as a single component for exemplary purposes, the processor of CPU 202 and storage / memory 204 may be multiple components and may be external to main server 102 and / or system 102′ and linked to main server 102 and / or system 102′ via communications network 100.
[0032] Database 211 provides a classification into groups, each of which includes designated fields and indicators of various criteria related to the fields and data assets therein, such as whether the field is sensitive and / or privileged. For example, as shown in FIG. 3, a sampling of individual fields and groups with their sensitive / privileged or non-sensitive designations is shown. In FIG. 3, for the group "Financial," the CC# (Credit Card Number), CC (Credit Card) Issuer, and IBAN are sensitive, and access to them is privileged. Similarly, for example, in the "Personal Identification Information (PII)" group, the ACCT.NAME and Mobile Telephone Number fields are sensitive, and access to them is privileged.
[0033] Returning to FIG. 2, storage medium 212 provides storage of tagged and untagged data assets from a variety of platforms, as described in more detail below.
[0034] The data asset isolation or data asset isolation module 221 functions to identify and isolate data assets within the various platforms 106a-106n.
[0035] The tagging module 222 operates by tagging the identified and separated data assets obtained from each of the analyzed platforms 106 a-106 n for various criteria, such as whether they are sensitive or privileged. This module 222 operates in conjunction with the database 211 to determine which data assets should be tagged based on the data assets meeting one or more criteria, such as whether they are sensitive / privileged, and whether access to these fields / data assets should be provided to a limited number of users (entities) within the enterprise 110.
[0036] The search / normalization module 223 retrieves tagged data assets from one of the platforms, e.g., Platform 1 106a (the “source of truth” platform), and, based on the representational terms and / or content of the data assets, examines data assets in other or subsequent platforms, e.g., Platform 2 through Platform n 106b through 106n, to identify data assets that correspond to, match, are equivalent to, are nearly equivalent to, or are identical (e.g., equivalence, approximate equivalence, or identicalness programmed into the system 102′ and / or determined by a system administrator) to the tagged data assets that contain the representational terms and / or their content.
[0037] The permission model 231 analyzes the privileges for each data asset and the privileged users for each data asset on one platform, e.g., Platform 1 106a, and proposes rules to users of other platforms, e.g., Platform 2 through Platform n 106b through 106n, who are found to have access to the corresponding privileged data asset in the other platforms 106b through 106n.
[0038] Attention is now directed to Figure 4, which shows a flow diagram detailing a computer-implemented process according to an embodiment of the disclosed subject matter. Reference is also made to elements shown in Figures 1A, 1B, 2, and 3. Figures 5A-5F are diagrams illustrating various processes and / or sub-processes of the flow diagram of Figure 4. The processes and sub-processes of Figure 4 are computer processes executed by system 102'. The aforementioned processes and sub-processes may be executed, for example, automatically and, for example, in real time.
[0039] At start block 402, system 102' is active and running at least two platforms, such as SAAS platforms, such as Platform 1 and Platform 2 of Figures 5A-5D.
[0040] The process continues at block 404, where one platform shown in Figure 5A, e.g., Platform 1, is considered the base or first platform, i.e., the "source of truth." At block 406, the data asset isolation module 221 is used to identify and isolate data assets (example data assets are shown by element numbers 520a, 520b, and 520c) within Platform 1, as shown in Figure 5B.
[0041] In block 408, using the tagging module 222, a database 211 of group classifications, such as the database 211 shown in FIG. 3, is searched to determine whether a data asset meets one or more criteria for being tagged. For example, a data asset is tagged for meeting criteria (e.g., predetermined criteria) of "privileged" according to the group and classification in the database 211. As shown in FIG. 5C, PII data assets in the fields "Account Name (ACCT.NAME)" and "MOBILE TEL. No." are deemed and tagged as privileged according to the database 211. The tags are indicated by a star (*). Similarly, the FINANCIAL fields "CC#" and "CC ISSUER" are privileged, and data assets from these fields are also tagged, and the tags are indicated by a star (*).
[0042] Proceeding to block 410, in a second or subsequent platform (different from the "source of truth" platform), i.e., Platform 2, data assets within Platform 2 are identified and segregated, for example, by module 221. These identified data assets from Platform 2 are analyzed in block 412 against tagged and untagged data assets of Platform 1 for correspondence, as shown in FIG. 5D.
[0043] Proceeding to block 414, based on the representation terms or content of the data assets in the first platform, Platform 1, data assets in Platform 2 whose representation terms and content match or correspond to the tagged (privileged) data assets from Platform 1 are tagged as, for example, privileged. This is the case, for example, as shown in FIG. 5E, where a data asset from Platform 1 having content 816-999-1515 in the field "MOBILE TEL. NO." is found in Platform 2 as a data asset in the field "DESCRIPTION," indicated by arrow 530a. Similarly, Platform 1's data assets of BOA and BNP from the field "CC ISSUER" are found in Platform 2, as indicated by arrows 530b-1 and 530b-2 to the field "BANK REFERENCE," and a field containing the term "NAME" is identified in Platform 2, as indicated by arrow 530c.
[0044] Proceeding to block 416, for a particular data asset from Platform 1 and Platform 2, entities (e.g., users) with privileges (e.g., access) to the data asset (e.g., tagged data asset) are identified. As shown in FIG. 5F, the data asset "816-999-1515" from Platform 1 is accessible by entities (users) A, B, C, and D. The same data asset on Platform 2 is accessible by entities (users) P, Q, and R. For example, entities A, B, C, D, P, Q, and R all have permissions, such as access to the tagged data asset "MOBLLE TEL. NO. 816-999-1515," which is Patrick Macombs's mobile phone number, an Account on Platform 1, and a Customer on Platform 2.
[0045] The process then proceeds to block 418, where authorization rules are proposed to entities (users) with privileges to the tagged data asset in the subsequent platform. The authorization rules may be, for example, rules for access to data in a particular data field (access rules). For example, the proposed rules for authorization to an entity / entity (user) to the tagged data asset in the subsequent platform (e.g., Platform 2) are typically rules that correspond to, and typically match, the rules for authorization to the entity (user) of the corresponding tagged data asset in the first or "source of truth" platform, e.g., Platform 1.
[0046] Optionally, the proposed rules may be implemented and / or adopted by the enterprise across all or part of its platform, for example, a SAAS platform.
[0047] The process proceeds to block 420 where it ends. This process may be repeated for as long as desired.
[0048] The disclosed subject matter relates to a method, including a computerized method, for providing access to data across multiple platforms, the method comprising: identifying, in a first platform, one or more data assets; tagging each data asset identified from the first platform that meets predetermined criteria; identifying one or more data assets in one or more subsequent platforms; For data assets in one or more subsequent platforms that correspond to tagged data assets of the first platform, tagging corresponding data assets of the one or more subsequent platforms; For each tagged data asset of the first platform and corresponding tagged data assets from one or more subsequent platforms, identifying entities that have permissions to the tagged data asset; For the tagged data asset in the one or more subsequent platforms, providing to an entity having authorization for the tagged data asset in the one or more subsequent platforms one or more rule proposals regarding authorization for the tagged data asset; Includes.
[0049] Optionally, in the method, providing a proposal of one or more rules regarding permission to an entity having permission to the tagged data asset in the one or more subsequent platforms includes proposing rules corresponding to the rules regarding permission to the tagged data asset to an entity having permission to the tagged data asset in the first platform.
[0050] The authorization includes access to the tagged data asset in the method.
[0051] Optionally, in the method, the plurality of platforms includes a Software as a Service (SAAS) platform.
[0052] Optionally, in the method, the data assets in the one or more subsequent platforms that correspond to the tagged data assets of the first platform include data assets that match the expression terms or content of the tagged data assets of the first platform.
[0053] Optionally, in the method, the corresponding data assets of the one or more subsequent platforms include the matching data assets in the first platform.
[0054] The disclosed subject matter relates to a system for providing access to data across multiple platforms, the system comprising: a non-transitory storage medium for storing the computer components; a computer processor for executing the computer components; the computer component includes: an identification module that identifies one or more data assets within one or more data platforms; a tagging module that tags 1) each identified data asset from the first data platform that meets predetermined criteria, and 2) data assets in one or more subsequent data platforms that correspond to the tagged data asset of the first data platform; a search module for searching for data assets in the subsequent data platform that correspond to the tagged data assets in the first data platform; an identification module for identifying entities having permissions to 1) tagged data assets in a first data platform and 2) corresponding tagged data assets in one or more subsequent data platforms; a permission model for providing suggested rules regarding entity permissions for tagged data assets within one or more subsequent data platforms; Includes.
[0055] Optionally, in the system, the permission model for providing the proposed rules corresponding to the rules regarding the entity's permissions for the corresponding tagged data asset includes permissions for the tagged data asset in the first data platform.
[0056] Optionally, in the system, the rules regarding permissions include rules regarding access to tagged data assets.
[0057] Optionally, in the system, the data platform includes a Software as a Service (SAAS) platform.
[0058] Optionally, in the system, the corresponding data assets of one or more subsequent data platforms include the matching data assets in the first platform.
[0059] Implementation of the disclosed embodiment methods and / or systems may include performing or completing selected tasks manually, automatically, or a combination thereof. Further, depending on the actual equipment and implementation of the disclosed embodiment methods and / or systems, some selected tasks may be performed by hardware, software, firmware, or a combination thereof, using an operating system or cloud-based platform.
[0060] For example, hardware for performing selected tasks according to the disclosed embodiments can be implemented as a chip or circuit. As software, selected tasks according to the disclosed embodiments can be implemented as a plurality of software instructions executed by a computer using any suitable operating system. In the disclosed exemplary embodiments, one or more tasks according to exemplary embodiments of the methods and / or systems described herein are performed by a data processor, such as a computing platform, for executing a plurality of instructions. Optionally, the data processor includes volatile memory for storing instructions and / or data and / or non-volatile storage for storing instructions and / or data, e.g., a non-transitory storage medium such as a magnetic hard disk and / or removable media. Optionally, a network connection is also provided. Optionally, a display and / or a user input device, such as a keyboard or mouse, is also provided.
[0061] For example, any combination of one or more non-transitory computer-readable (storage) media can be utilized in accordance with the above examples of the present disclosure. The non-transitory computer-readable (storage) medium may be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium may be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the above. More specific examples (non-exhaustive list) of computer-readable storage media include: an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the context of this specification, a computer-readable storage medium may be any tangible medium that can contain or store a program used by or in connection with an instruction execution system, apparatus, or device.
[0062] A computer-readable signal medium may include a propagated data signal in which computer-readable program code is embodied, for example, in baseband or as part of a carrier wave. Such a propagated signal may take various forms, including, but not limited to, electromagnetic, optical, or any suitable combination thereof. A computer-readable signal medium may be any computer-readable medium that is not a computer-readable storage medium and that can communicate, propagate, or transport an instruction execution system, apparatus, or program for use by or in connection with an apparatus.
[0063] As can be understood with reference to the above paragraphs and the referenced drawings, various examples of computer-implemented methods are provided herein, some of which may be performed by the various example devices and systems described herein, and some of which may be performed according to instructions stored on non-transitory computer-readable storage media described herein. It should be noted that some of the example computer-implemented methods described herein may be performed by other devices or systems and may be performed according to instructions stored on computer-readable storage media other than those described herein, as will be apparent to those skilled in the art with reference to the examples described herein. References to systems and computer-readable storage media in the following computer-implemented methods are provided for illustrative purposes and are not intended to limit any of such systems and such non-transitory computer-readable storage media with respect to the above computer-implemented method examples. Similarly, references to systems and computer-readable storage media in the following computer-implemented methods are provided for illustrative purposes and are not intended to limit any of such computer-implemented methods disclosed herein.
[0064] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various examples of the present disclosure. In this regard, each block in the flowcharts or block diagrams may represent a module, segment, or portion of code, which comprises one or more executable instructions for implementing a particular logical function. It should also be noted that in some alternative implementations, the functions noted in the blocks may occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order. Block diagrams and / or flowchart diagrams, and combinations of blocks in block diagrams and / or flowchart diagrams, may be implemented by special-purpose hardware-based systems that perform particular functions or operations, or by a combination of special-purpose hardware and computer instructions. The description of various examples of the present disclosure has been presented for illustrative purposes and is not intended to be exhaustive or limited to the disclosed examples. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments.
[0065] As used herein, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise.
[0066] It will be understood that certain features of the disclosure that are, for clarity, described in the context of separate embodiments, may also be provided in combination in a single embodiment. Conversely, various features of the disclosure that are, for brevity, described in the context of a single embodiment, may also be provided separately or in any suitable subcombination or in any other described embodiment of the disclosure, as appropriate. Certain features described in the context of various embodiments are not considered essential features of those embodiments, unless the embodiments cannot function without those elements.
[0067] The processes described above, including portions thereof, can be implemented by software, hardware, and combinations thereof. These processes, or portions thereof, can be implemented by computers, computer-based devices, workstations, cloud-based platforms, processors, microprocessors, other electronic search tools, and their associated memories and other non-transitory storage devices. The processes, or portions thereof, can also be embodied in programmable non-transitory storage media, such as compact discs (CDs) or other machine-readable, magnetic, optical, or other disks, or other computer-usable storage media, including magnetic, optical, or semiconductor storage, or other electronic signal sources.
[0068] The processes (methods) and systems herein, including their components, have been described with illustrative reference to specific hardware and software. The processes (methods) are described illustratively, whereby certain steps and their order can be omitted and / or modified by one of ordinary skill in the art to practice these examples without undue experimentation. The processes (methods) and systems are described in a manner sufficient to enable one of ordinary skill in the art to readily adapt other hardware and software required to practice any of the examples without undue experimentation and without the use of conventional techniques.
[0069] The descriptions of the disclosed examples in this application are provided by way of example and are not intended to limit the scope of the disclosure. The described embodiments include different features, not all of which are required in all of the disclosed examples. Some embodiments utilize only some of the features or possible combinations of features. Variations of the disclosed examples described, and examples of the disclosed examples including different combinations of features described in the described embodiments, will be apparent to those skilled in the art. The scope of the disclosure is limited only by the claims.
[0070] Accordingly, it will be understood that the above-described examples do not limit the disclosed subject matter to that particularly shown and described herein. Rather, the scope of the present disclosure includes both combinations and subcombinations of the various features described herein, as well as variations and modifications thereof not disclosed in the prior art that would become apparent to one skilled in the art upon reading the foregoing description. Documents incorporated by reference into this patent application are considered an integral part of this application, except that to the extent that terms are defined in those incorporated documents in a manner that is inconsistent with definitions expressly or impliedly made herein, only the definitions herein shall be considered.
Claims
1. 1. A method for providing access to data across multiple platforms, comprising: identifying, at a first platform, one or more data assets; tagging each data asset identified from said first platform that meets predetermined criteria; identifying the one or more data assets in one or more subsequent platforms; For data assets in the one or more subsequent platforms that correspond to tagged data assets of the first platform, tagging corresponding data assets of the one or more subsequent platforms; for each tagged data asset of the first platform and a corresponding tagged data asset from the one or more subsequent platforms, identifying entities that have permissions to the tagged data asset; For a tagged data asset on the one or more subsequent platforms, providing to an entity having authorization for the tagged data asset on the one or more subsequent platforms one or more suggested rules regarding authorization for the tagged data asset; A method comprising:
2. 2. The method of claim 1, wherein providing one or more rule proposals regarding permissions to entities having permissions to the tagged data asset in the one or more subsequent platforms includes proposing rules corresponding to rules regarding permissions to the tagged data asset to entities having permissions to the tagged data asset in the first platform.
3. The method of claim 2 , wherein the permission includes access to a tagged data asset.
4. The method of claim 1 , wherein the plurality of platforms includes a Software as a Service (SAAS) platform.
5. 5. The method of claim 1, wherein the data assets in the one or more subsequent platforms that correspond to the tagged data assets of the first platform include data assets that have matching expression terms or content with the tagged data assets of the first platform.
6. The method of any of claims 1 to 4, wherein the corresponding data assets of the one or more subsequent platforms include matching data assets in the first platform.
7. 1. A system for providing access to data across multiple platforms, comprising: a non-transitory storage medium for storing the computer components; a computer processor for executing the computer components; the computer component comprising: an identification module that identifies one or more data assets within one or more platforms; a tagging module that tags 1) each identified data asset from a first platform that meets predetermined criteria, and 2) data assets in one or more subsequent platforms that correspond to the tagged data asset of the first platform; a search module for searching for data assets in the subsequent platform that correspond to tagged data assets in the first platform; an identification module for identifying entities having permissions to 1) a tagged data asset in the first platform and 2) a corresponding tagged data asset in the one or more subsequent platforms; a permission model for providing suggested rules regarding entity permissions for tagged data assets within the one or more subsequent platforms; Including, the system.
8. The system of claim 7 , wherein a permission model for providing suggested rules corresponding to rules regarding entity permissions for corresponding tagged data assets includes permissions for tagged data assets in the first platform.
9. The system of claim 8 , wherein the authorization rules include rules regarding access to tagged data assets.
10. The system of claim 8 , wherein the plurality of platforms includes a Software as a Service (SAAS) platform.
11. The system of any of claims 7 to 10, wherein the corresponding data assets of the one or more subsequent platforms include matching data assets in the first platform.