Automated Actions Permissions Ownership System for Enterprise ERP
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In large enterprises, effectively managing actions and permissions across multiple ERP systems to ensure data security, integrity, and availability is challenging due to the complexity of defining and assigning appropriate roles, as role owners may not have the necessary expertise or access to application owners' insights.
Innovation Solution
An automated Actions and Permissions Ownership (APO) system that involves application owners in the role creation and modification process by looking up and requesting approval from corresponding application owners for changes to actions and permissions, ensuring that only authorized personnel have access to sensitive data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If role owners independently define and manage actions and permissions in ERP systems, then role management autonomy is improved, but data security and access control reliability deteriorate due to lack of application owner expertise
Solution Approach 1:
The patent introduces an automated APO system as an intermediary that mediates between role owners and application owners. The system automatically looks up application owners, sends approval requests, and coordinates changes to actions and permissions, ensuring both role management autonomy and data security are maintained through structured collaboration.
Solution Approach 2:
The system implements a feedback mechanism where application owners receive automatic notifications and approval requests when their applications' actions or permissions are modified. This feedback loop ensures application owners can review and approve changes, maintaining security while allowing role management flexibility.
2Reliability
If application owners are involved in every role creation and modification process, then data security is improved, but management efficiency and productivity deteriorate due to increased approval steps
Solution Approach 1:
The system enables self-service capabilities where application owners can pre-approve actions and permissions for their applications in advance. This allows role owners to make changes without real-time approval for routine modifications, improving efficiency while maintaining security through pre-established authorization frameworks.
Solution Approach 2:
The system performs preliminary actions by automatically looking up application owners and preparing approval requests before changes are implemented. This advance preparation streamlines the approval process and reduces delays in role management while ensuring security requirements are met.
3Device complexity
If manual processes are used for managing actions and permissions across multiple ERP systems, then system complexity is reduced, but time consumption and operational overhead increase
Solution Approach 1:
The patent creates a universal APO system that can manage actions and permissions across multiple different ERP systems through a single automated platform. This multi-functional system handles lookup, notification, approval, and modification processes universally, reducing time consumption without requiring separate manual processes for each ERP system.
Solution Approach 2:
The system replaces manual mechanical processes (manual lookup, manual notification, manual approval tracking) with automated electronic processes. The automated APO circuit performs these functions electronically, dramatically reducing time consumption while maintaining process simplicity through automation rather than increased mechanical complexity.
Data Source
AI summary
A method of actions and permissions ownership (APO) for managing applications of an enterprise is provided. The method includes: receiving a request from an owner of a role to modify an action or permission of the role or to add the action or permission to the role. The action or permission controls access to a corresponding one of the applications. In response to receiving such a request, the method includes looking up an owner of the corresponding application in a non-transitory electronic APO database, requesting an approval from the corresponding application owner to modify or add the action or permission, receiving the approval to modify or add the action or permission, and, in response to receiving the approval, updating a non-transitory electronic role database to modify the action or permission of the role or to add the action or permission to the role.

