Granular Permission Control for Group-Based Communication Objects

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing collaborative communication systems lack the ability to provide users with granular control over permissions for group-based communication objects, leading to potential security breaches and misuse of third-party applications.

Innovation Solution

The system introduces a method for selectively granting permissions to group-based communication objects by generating an app user account, creating a permissions interface, and managing a permissions table and app token, allowing users to customize permissions for third-party applications on a per-object and per-action basis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If third-party applications are granted broad access to group-based communication objects, then application functionality and versatility are improved, but system security and user privacy deteriorate

Engineering Contradiction:
Improveapplication functionalityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments permission access by creating a permissions table that divides access rights into individual rows for each group-based communication object (channels, messages, files, users). This allows third-party applications to access only specific objects rather than having blanket access to all objects, thereby maintaining functionality while reducing security risks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by allowing different permission levels for different group-based communication objects. The permissions table stores specific permission data for each object type and instance, enabling the system to grant appropriate access rights locally to each object rather than applying a uniform permission policy system-wide.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If users are provided with granular permission control for each group-based communication object, then user control and security are improved, but system complexity increases

Engineering Contradiction:
Improveuser controlVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling users to directly manage permissions for third-party applications through an intuitive interface. Users can select which group-based communication objects they want to share with specific applications and define the scope of access, making the system easier to operate despite the underlying complexity of granular permission management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by pre-defining permission templates and structures in the permissions table. The system prepares the framework for granular permission control in advance, with predefined object types and permission categories, so that users only need to make simple selections rather than configuring complex permission settings from scratch.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If a permissions interface is implemented for user authorization, then permission management capability is improved, but interface complexity and development effort increase

Engineering Contradiction:
Improvepermission management capabilityVSAvoidinterface complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements universality by designing a permissions interface that handles multiple object types (channels, messages, files, users) and multiple permission scopes through a unified structure. The permissions table and interface use consistent data models and interaction patterns across different object types, reducing interface complexity while maintaining comprehensive permission management capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12238114B2Method, apparatus, and computer program product for selectively granting permissions to group-based objects in a group-based communication system
Publication Date: 2025.02.25 SALESFORCE INC
  • US12238114B2 patent drawing
  • US12238114B2 patent drawing
  • US12238114B2 patent drawing

AI summary

Embodiments of the present disclosure provide methods, systems, apparatuses, and computer program products that provide for an improved, more efficient, and more stable system of networked computing devices. The embodiments disclose an apparatus and system that enable client devices to selectively grant to third party applications permissions to access group-based communication objects of a group-based communication system. The apparatus and system further enable client devices to selectively grant to third party applications permissions to take specific actions with regards to the group-based communication objects within the system. To accomplish the improvements, the disclosed systems, apparatuses, and computing devices maintain a record of the permissions granted to third party applications in a permissions table stored in a computer storage device. The permissions table may be modified to expand the permissions granted to the third party application without requiring a new authentication process that issues a new authenticating token. Further, third party applications are installed at a group level and not at a user level within the system, which increases system stability and efficiency.