ERP Module Usage Tracking for Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The complexity of managing and securing enterprise resource planning (ERP) systems in large organizations is exacerbated by the decentralized structure, where local administrators may be unaware of other systems and users, leading to potential security vulnerabilities and inefficient data management due to unused modules and unauthorized access.
Innovation Solution
A data collection system identifies and records module usage across ERP systems, generating reports to manage and restrict access, and an access control system prevents unauthorized access by setting attributes and limiting user views to authorized components, integrating data with organizational charts for intuitive management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If decentralized ERP systems are implemented to allow local administrators to manage their own systems, then ease of operation and local autonomy are improved, but system complexity and security management difficulty increase
Solution Approach 1:
The patent implements a central administrator as an intermediary who maintains a comprehensive database of all ERP systems, modules, and users across the organization. This central administrator mediates between local administrators' autonomy and organizational-wide security requirements, resolving the contradiction by providing centralized oversight without eliminating local management capabilities.
Solution Approach 2:
The patent creates a universal access control system that operates across all decentralized ERP systems. The central administrator uses a single comprehensive interface to manage security policies, user access, and module availability across multiple systems, making the management process universal rather than system-specific.
2Ease of operation
If local administrators manage only their local system users, then ease of operation is improved, but security vulnerability detection capability deteriorates
Solution Approach 1:
The central administrator acts as an intermediary who aggregates security information from all local systems and performs comprehensive security assessments. This intermediary role enables organization-wide security monitoring while preserving local administrators' operational simplicity in managing their own users.
Solution Approach 2:
The patent implements a feedback mechanism where the central administrator receives information about all users and systems, performs security assessments, and communicates findings back to relevant local administrators. This feedback loop improves security vulnerability detection while maintaining local management autonomy.
3Adaptability or versatility
If all ERP modules are installed and active in each system, then adaptability and functionality are improved, but data management complexity and unauthorized access risks increase
Solution Approach 1:
The patent applies local quality by allowing each ERP system to have different module configurations based on local needs. The central administrator database tracks which modules are active in each system, enabling tailored functionality while simplifying data management through centralized awareness of the actual module distribution across the organization.
Data Source
AI summary
Systems and methods for managing multiple systems in an enterprise resource planning system are provided. In an embodiment, data identifying modules and entities using modules or systems may be collected from each system in enterprise resource planning system. The collected data may then be organized to show a usage landscape of entire enterprise resource planning system. In an embodiment, the collected data may also be merged with other organizational data, such as organizational chart data, to present the usage landscape in an intuitive manner using the organizational structure data from the organizational chart. The collected data may also be used to identify potential data inconsistencies across different systems or may be used to limit connectivity to only authorized systems or modules. In some embodiments, attributes such as attributes identifying modules and entities may be inputted into a system which then distributes the attributes to other systems.


