Dynamic Access Privilege Adjustment for Separated Employees
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer security systems fail to effectively manage user access to organizational resources during changes in employment status, leading to potential security risks as users may engage in high-risk activities before their departure, such as data exposure or malicious actions.
Innovation Solution
A computer security system dynamically modifies user access privileges based on anticipated changes in employment status, allowing low-risk operations before the effective date of the change and restricting high-risk activities, and further revoking access upon the change becoming effective, using data records and keyword/taxonomy analysis to determine sensitive data and filter communications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a user is allowed to perform all operations during normal employment, then productivity and ease of operation are maintained, but security risk increases when employment status changes
Solution Approach 1:
The system dynamically adjusts user access privileges based on employment status changes. When a user's employment status changes (e.g., termination, resignation), the system automatically modifies their access rights in real-time, transitioning from static access control to dynamic adaptation. This resolves the contradiction by making security flexible without permanently restricting operational ease during normal employment.
Solution Approach 2:
The system changes the parameter of access privilege levels based on employment status events. By detecting employment status changes and automatically adjusting access parameters (from full access to restricted access), the system maintains high productivity during normal operations while ensuring security when employment status changes occur.
2Reliability
If access privileges are restricted before employment status change, then security risk is reduced, but productivity and ease of operation deteriorate
Solution Approach 1:
The system performs preliminary actions by detecting employment status changes and automatically adjusting access privileges before the user can engage in high-risk activities. By proactively monitoring employment status events and pre-restricting access accordingly, the system prevents security incidents without requiring manual intervention or affecting normal operations until the status change occurs.
Solution Approach 2:
The system implements feedback mechanisms by continuously monitoring employment status changes and automatically responding by adjusting access privileges. This closed-loop feedback ensures security is maintained without unnecessarily restricting productivity, as restrictions are applied only when employment status changes are detected through the feedback channel.
3Reliability
If manual monitoring of user activities is implemented, then security risk is reduced, but device complexity and loss of time increase
Solution Approach 1:
The system performs self-service by automatically detecting employment status changes and adjusting user access privileges without requiring manual security administration. The system monitors its own security-relevant events (employment status changes) and autonomously responds by modifying access controls, eliminating the need for complex manual monitoring processes.
Solution Approach 2:
The system introduces an intermediary mechanism that automatically translates employment status changes into access privilege adjustments. This intermediary layer (the automated access control system) mediates between HR systems and security systems, reducing the complexity of manual monitoring while maintaining high security standards through automated event-driven responses.
Data Source
AI summary
In an example method, a system obtains a data record indicating an anticipated change in an employment status of a user at an organization, including a data field indicating an effective time of the anticipated change. At a first time prior to the effective time, the system modifies an access privilege of the user with respect to computer resources of the organization, including (i) allowing the user to perform first operations using the computer resources between the first time and a second time subsequent to the first time, and (ii) preventing the user from performing second operations using the computer resources starting at the first time. At the second time, the system further modifies the access privilege of the user, including preventing the user from performing the operations using the computer resources starting at the second time.


