Automated Access Revocation System for Enterprise Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Companies face delays in revoking access to applications for former employees or contractors, leading to potential security risks due to lingering access permissions.
Innovation Solution
An automated access revocation system that receives revocation settings from various business divisions, compiles them into standardized settings, and automatically determines whether access should be revoked, applying these settings to items associated with user access to applications, thereby removing access permissions as needed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual notification processes are used to inform business groups about employee termination, then human communication can be maintained, but significant delays occur in revoking access
Solution Approach 1:
The system enables automatic self-service access revocation by having the HR system directly trigger and execute the access revocation process without requiring manual intervention from business groups. The HR system automatically receives termination notifications, processes them according to predefined rules, and executes revocation across multiple applications, eliminating the time loss associated with manual notification processes.
2Object-affected harmful factors
If manual access revocation processes are used, then human control is maintained, but former employees can still access applications creating security risks
Solution Approach 1:
The system implements automated feedback loops where termination notifications automatically trigger revocation processes across multiple applications. The HR system receives termination data, processes it according to predefined security rules, and executes revocation actions, creating a closed-loop feedback mechanism that eliminates delays and ensures former employees lose access promptly, thereby reducing unauthorized access risks.
Solution Approach 2:
The system performs preliminary actions by pre-configuring revocation rules and policies before employee termination occurs. These predefined rules automatically guide the revocation process, ensuring that access is revoked according to established security protocols without requiring real-time human decision-making, thus reducing complexity while maintaining security.
3Productivity
If centralized automated revocation systems are implemented, then access revocation speed improves, but system complexity increases
Solution Approach 1:
The HR system is designed with multi-functionality, serving both as the notification system and the automated revocation execution system. By integrating multiple functions into a single centralized system, the solution achieves fast access revocation speed while managing complexity through consolidation rather than proliferation of separate systems.
Solution Approach 2:
The system manages complexity by dynamically adjusting processing parameters based on the termination notification received. It processes revocation requests according to predefined rules and priorities, changing its operational parameters adaptively to handle different scenarios efficiently, thereby achieving high productivity without proportional increases in system complexity.
Data Source
AI summary
Systems and apparatuses for revoking access to one or more applications for one or more individuals or users are provided. In some examples, revocation settings may be received from different business divisions or enterprises or business groups within an entity and may be compiled to form a standardized set of revocation settings that may be applied across the entity. Accordingly, upon receiving an item that may be associated with access and may include one or more applications to which access may be revoked and/or one or more users from which access may be revoked, the system may apply the standardized revocation settings to determine whether access should be revoked. If it is determined that access should be revoked, the system may revoke access to the one or more applications for the one or more users.


