Application Access Permissions for User-Specific Data Governance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multi-site computing environments, manually configuring data access permissions for a large number of users and applications is time-consuming and prone to human error, and existing methods often result in applications accessing unnecessary data or violating data location and governance policies.
Innovation Solution
Implementations automatically generate and store data access permissions for applications that are specifically adapted for each user, limiting access to only authorized folders and preventing unauthorized data access, while considering remote data copying and governance policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If administrators manually configure data access permissions for each user and application, then data security control is achieved, but the process becomes time-consuming and prone to human error
Solution Approach 1:
The system automatically generates and configures data access permissions for applications based on user permissions and application requirements, eliminating the need for manual administrator configuration. The system self-services by determining permissions through automated processes that consider user data access rights, application data needs, and governance policies.
Solution Approach 2:
The system performs preliminary determination of data access permissions by analyzing user permissions and application requirements before actual data access occurs. This advance configuration ensures that proper permissions are established prior to application execution, preventing security issues rather than addressing them reactively.
2Reliability
If administrators manually configure data access permissions for each user and application, then data security control is achieved, but human error increases
Solution Approach 1:
The system replaces the mechanical manual configuration process with an automated computational system. Instead of administrators manually setting permissions, the system uses automated determination processes that analyze user permissions, application requirements, and governance policies to generate accurate permission configurations without human intervention.
Solution Approach 2:
The system incorporates feedback mechanisms by continuously analyzing user permissions and application requirements to determine appropriate data access permissions. The automated determination process uses feedback from policy evaluations and permission assessments to ensure accurate and compliant permission configurations are generated.
3Adaptability or versatility
If applications are given broad data access permissions, then application functionality is improved, but data governance policies may be violated
Solution Approach 1:
The system applies local quality by determining data access permissions specifically for each application based on its individual requirements and the user's permissions. Instead of applying blanket permissions or restrictions, the system tailors permissions locally to each application-context combination, ensuring that each application receives only the specific data access rights it needs to function properly while maintaining compliance.
Solution Approach 2:
The system dynamically adjusts permission parameters by evaluating user permissions, application requirements, and governance policies to determine appropriate data access levels. The automated determination process changes permission parameters based on the specific context, allowing applications to receive adequate functionality while maintaining compliance with data governance policies through adaptive parameter adjustment.
Data Source
AI summary
In some examples, one or more processors are able to communicate with a plurality of user devices associated with a plurality of users, and the one or more processors may provide a plurality of applications executable in association with the plurality of users. For each application of the plurality of applications, the one or more processors may determine data access permissions for the application. Additionally, the one or more processors may determine data access permissions for individual users of a plurality of users. Based on the data access permissions for the plurality of users and the data access permissions for the plurality of applications, the one or more processors may generate a data structure including data access permissions for each of the applications. The generated data access permissions for each of the applications may be customized for, or otherwise specific to, individual users of the plurality of users.


