Enterprise Entitlement Normalization via Automated Agents

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies fail to provide an effective solution for enterprise-wide visibility and compliance management across diverse application and data assets, leading to challenges in security risk and regulatory compliance due to the lack of collaboration between security and business teams in access governance.

Innovation Solution

A compliance manager system that automates the collection, normalization, and reporting of user entitlements and roles across enterprise applications, providing a unified framework for IT security and compliance teams, enabling accountability and transparent access rights decisions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If manual data collection methods are used across diverse enterprise applications, then data can be gathered from various sources, but the process becomes time-consuming and labor-intensive

Engineering Contradiction:
Improveability to collect data from diverse applicationsVSAvoidtime for data collection
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system enables self-service data collection through automated agents that deploy to enterprise applications and autonomously extract entitlement data without requiring manual intervention from compliance teams. The agents automatically connect to applications, retrieve access rights information, and transmit it to the central platform.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical data collection processes with automated electronic agents and software-based data extraction mechanisms. These agents use programmatic interfaces to gather entitlement data, replacing the need for manual querying and data entry across multiple applications.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If data is collected from multiple enterprise applications with different formats, then comprehensive coverage is achieved, but data normalization becomes complex

Engineering Contradiction:
Improvecoverage across enterprise applicationsVSAvoiddata normalization complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system transforms diverse entitlement data from different applications into a unified standardized format by changing the parameters and structure of the collected data. The normalization engine applies transformation rules that convert various data formats into a common schema, enabling consistent analysis across all enterprise applications.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces a central compliance manager platform that acts as an intermediary between diverse enterprise applications and the compliance analysis system. This intermediary normalizes and standardizes data from multiple sources before presenting it for compliance review, simplifying the complexity of handling diverse formats.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If enterprise-wide visibility into entitlements is implemented, then compliance monitoring is improved, but system complexity increases

Engineering Contradiction:
Improvecompliance monitoringVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the complex task of enterprise-wide compliance monitoring into manageable components: deployment agents that collect data from individual applications, a central platform that normalizes and aggregates data, and compliance teams that review standardized reports. This segmentation reduces overall system complexity while maintaining comprehensive visibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The compliance manager platform provides universal functionality that works across all enterprise applications through standardized agents and a common data model. This multi-functional approach allows the same system to monitor entitlements across diverse applications without requiring application-specific complex configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Productivity

If automated compliance monitoring is deployed, then continuous visibility is achieved, but implementation complexity increases

Engineering Contradiction:
Improvecompliance monitoring efficiencyVSAvoidimplementation complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-deploying standardized agents to enterprise applications and pre-configuring data collection parameters. This preliminary setup enables automated continuous monitoring without requiring complex real-time configuration or intervention during operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by deploying identical standardized agent templates across multiple enterprise applications. Instead of implementing custom monitoring solutions for each application, the same agent template is copied and adapted to work with different applications, reducing implementation complexity while maintaining automated continuous monitoring.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9286595B2System and method for collecting and normalizing entitlement data within an enterprise
Publication Date: 2016.03.15 EMC IP HLDG CO LLC
  • US9286595B2 patent drawing
  • US9286595B2 patent drawing
  • US9286595B2 patent drawing

AI summary

A compliance manager system automates monitoring, reporting, certification and remediation of user entitlements and roles, making it possible for organizations to easily establish a sustainable access governance model. The system enables organizations to gain enterprise-wide visibility into all user entitlements and roles and, in particular, to monitor who has access to what application, how they got access, and who approved such access. In one embodiment, a discovery and aggregation mechanism acquires identity, entitlement and role information together with associated metadata from enterprise infrastructure and applications. This information is normalized producing a unified view that is complete and correlated across users, entitlements, roles and resources.