Email-Based Recovery Action Mechanism for Hosted Environment Incident Response
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional systems restrict engineers and operators from performing automated recovery actions in hosted environments, leading to increased service disruptions during incidents due to permission limitations.
Innovation Solution
An email-based recovery action mechanism that forwards requests from users without permission to an approval manager for evaluation and approval, allowing disruptive actions on application servers like email and web servers, with options for one-time, limited-time, or permanent permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If engineers and operators are restricted from performing automated recovery actions in hosted environments, then service stability is maintained, but service disruption increases during incidents due to inability to repair active problems
Solution Approach 1:
The patent introduces an approval manager as an intermediary component that receives recovery action requests from engineers, evaluates them against predefined policies, and either approves or denies the actions. This mediator enables automated recovery actions while maintaining control, resolving the contradiction between service stability and incident response efficiency
2Productivity
If engineers are allowed to perform disruptive actions on application servers, then incident response efficiency improves, but service disruption risk increases
Solution Approach 1:
The patent implements dynamic permission management where engineers can perform disruptive actions temporarily when approved for specific incidents, rather than having static permanent permissions. The system dynamically adjusts authorization based on incident context, policy evaluation, and approval status, enabling efficient incident response while controlling service disruption risk through time-bound and context-specific permissions
Data Source
AI summary
Email-based recovery actions may be provided. A request from a user to perform an action may be received. If the user is determined not to have permission to perform the action, a message may be sent to a second user to approve the requested action. If the second user approves the requested action, the requested action may be performed.


