Automated Access Control for Role-Change Resource Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manual processes for adjusting access to resources following a role change in an organization are resource-intensive, lead to delays, introduce human errors, and can overload computer systems, especially during peak hours.

Innovation Solution

An automated process using application programming interfaces (APIs) to transmit commands to various computer systems for adjusting access, including identity management, workflow software, equipment provisioning, and building access, while scheduling executions to avoid peak times and reducing network interactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual processes are used to adjust access to resources following a role change, then administrators can directly control and verify each access adjustment, but the process becomes resource-intensive, time-consuming, and prone to human errors

Engineering Contradiction:
Improveaccuracy of access adjustmentVSAvoidtime for access adjustment
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system automatically detects role changes and self-adjusts access permissions without requiring administrator intervention. The access control system monitors role changes in real-time and automatically updates access rights across multiple resources, enabling the system to serve itself rather than requiring manual administrative action.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-configures access adjustment rules and policies in advance. When a role change is detected, the system automatically applies the pre-defined access adjustments based on these预先配置的规则, eliminating the need for administrators to manually determine and implement each access change.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual processes are used to adjust access to resources following a role change, then administrators can verify each change, but the process introduces human errors and becomes resource-intensive

Engineering Contradiction:
Improveaccuracy of access adjustmentVSAvoidcomputational resources consumed
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system automatically detects role changes and self-adjusts access permissions without requiring administrator intervention. The access control system monitors role changes in real-time and automatically updates access rights across multiple resources, enabling the system to serve itself rather than requiring manual administrative action.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces manual administrative actions with automated computational processes. Instead of administrators manually reviewing and adjusting each access permission, the system uses automated algorithms to detect role changes and apply appropriate access adjustments, substituting mechanical human operations with efficient computational automation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If manual access adjustment processes are used, then administrators can control access changes, but the processes can overload computer systems during peak hours

Engineering Contradiction:
Improvecontrol over access changesVSAvoidsystem performance
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The system automatically detects role changes and self-adjusts access permissions without requiring administrator intervention. The access control system monitors role changes in real-time and automatically updates access rights across multiple resources, enabling the system to serve itself rather than requiring manual administrative action.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-configures access adjustment rules and policies in advance. When a role change is detected, the system automatically applies the pre-defined access adjustments based on these预先配置的规则, eliminating the need for administrators to manually determine and implement each access change.

Inventive Principle:
Principle #10Preliminary action

4Productivity

If automated processes are used to adjust access following a role change, then resource consumption is reduced and human errors are prevented, but system complexity increases

Engineering Contradiction:
Improveefficiency of access adjustmentVSAvoidcomplexity of access control system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system uses a universal automated access adjustment mechanism that handles multiple types of resources and role changes through a single integrated process. Rather than requiring separate manual procedures for different resources, the universal system automatically manages access across all resources based on role changes, reducing overall system complexity despite the automation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces an intermediary automated access control module that sits between role change events and resource access permissions. This intermediary automatically processes role changes and applies appropriate access adjustments, simplifying the overall system architecture by centralizing the control logic rather than requiring complex point-to-point manual configurations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12572671B2Access control system for automatically adjusting access to resources in response to detecting a role change
Publication Date: 2026.03.10 TRUIST BANK
  • US12572671B2 patent drawing
  • US12572671B2 patent drawing
  • US12572671B2 patent drawing

AI summary

A computer can detect a role change associated with an individual of a group of individuals. In response to detecting the role change, execute an automated process for adjusting access of the individual to one or more resources. The automated process can involve automatically interacting with computer systems. The automated process can involve automatically transmitting a first command to an identity management system. The automated process can involve automatically transmitting a second command to a workflow software server. The automated process can involve automatically transmitting a third command to an information asset management server. The automated process can involve automatically transmitting a fourth command to an equipment provisioning server.