Integrating Enterprise Data Warehouse and BPC Authorizations
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data warehouse authorization systems require centralized IT departments to manage authorizations for multiple lines of business, leading to inefficiencies and delays, as local IT departments must wait for centralized approval for user-specific customizations.
Innovation Solution
Implementing a system that integrates enterprise data warehouse authorizations with environment authorizations and user-based data access profiles, allowing local IT departments to define and configure authorizations independently, while ensuring compliance with centralized frameworks, thus decentralizing the authorization process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized IT departments manage all authorizations, then security and compliance are maintained, but authorization configuration time and local responsiveness deteriorate
Solution Approach 1:
The authorization management system is segmented into centralized and local components. Centralized IT departments define framework authorizations and security policies, while local IT departments can independently configure user-specific authorizations within the framework. This segmentation allows local departments to respond quickly to business needs without requiring centralized approval for each authorization change.
Solution Approach 2:
Centralized IT departments prepare and publish framework authorizations in advance that define the structure and security requirements. Local IT departments then use these pre-defined frameworks to quickly configure user authorizations without needing real-time centralized approval, reducing configuration time while maintaining compliance.
2Reliability
If centralized IT departments approve all authorizations, then security standards are maintained, but local IT department autonomy and productivity deteriorate
Solution Approach 1:
Authorization management is divided into two segments: centralized framework definition and local user-specific configuration. Local IT departments gain autonomy to configure authorizations independently within the security framework, improving their productivity while centralized control maintains security compliance through the predefined framework.
Solution Approach 2:
The system allows local IT departments to customize authorizations according to their specific business needs and user requirements while adhering to the centralized security framework. This local quality approach enables local departments to be more efficient and responsive without compromising overall security standards.
3Speed
If local IT departments configure authorizations independently, then configuration speed improves, but authorization consistency and compliance control worsen
Solution Approach 1:
Centralized IT departments prepare framework authorizations that define the structure, permissions, and security requirements in advance. Local IT departments then use these pre-established frameworks to configure user authorizations quickly and consistently, ensuring that speed does not compromise authorization consistency or compliance.
Solution Approach 2:
The framework authorizations serve multiple functions: they provide the structural template for consistent authorization design, enforce security compliance, and enable local departments to configure user-specific permissions efficiently. This multi-functionality allows the system to achieve both speed and consistency simultaneously.
Data Source
AI summary
The present disclosure describes methods, systems, and computer program products for integrating authorizations. One computer-implemented method includes: reading enterprise data warehouse (EDW) authorizations for a user from an authorization database in response to a query generated by the user for EDW data; responsive to a determination that the user is assigned to an environment, reading environment authorizations from a business planning and consolidation (BPC) system; enhancing the EDW authorizations for the user with the environment authorizations read from the BPC system to create a new authorization set; reading a user-based data access profile (DAP) from the BPC; and intersecting the new authorization set with the DAP to create an overall user authorization set.


