Identity Management System for Temporal Account Entitlements
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current enterprise systems face challenges in effectively managing user identities and access to resources across multiple target systems, leading to inefficiencies in account creation, entitlement provisioning, and access policy enforcement.
Innovation Solution
An Identity Management (IDM) system is implemented to manage accounts and entitlements by receiving requests for account creation and entitlement provisioning, associating activation and deactivation times based on user information or access policies, and synchronizing these changes across target systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If manual account creation and entitlement provisioning is performed across multiple target systems, then flexibility in managing individual accounts is maintained, but time consumption and operational complexity increase significantly
Solution Approach 1:
The patent applies preliminary action by pre-defining entitlement templates with associated metadata and activation rules before they are needed. When an account is created, the system automatically retrieves and applies the appropriate template, pre-configuring entitlements without manual intervention. This resolves the contradiction by preparing entitlement structures in advance, enabling rapid account provisioning while maintaining control over entitlement assignment.
Solution Approach 2:
The system implements self-service by enabling accounts to automatically receive and activate entitlements based on predefined rules and metadata associations. The entitlement management system autonomously matches accounts with appropriate entitlement templates, determines activation timing, and provisions entitlements without requiring manual administrative actions. This automates the provisioning process, significantly reducing time loss while maintaining organizational control through rule-based management.
2Productivity
If entitlements are granted immediately upon account creation, then user productivity is improved, but security and compliance risks increase due to premature access
Solution Approach 1:
The patent applies dynamics by making entitlement activation timing flexible and condition-based rather than fixed. Entitlements can be configured to activate immediately, at a future date, or when specific conditions are met, allowing the system to adapt activation timing to security requirements while maintaining user productivity. This dynamic approach resolves the contradiction by enabling security-conscious delayed activation when needed, while allowing immediate activation when appropriate.
Solution Approach 2:
The system implements parameter changes by allowing the activation time parameter of entitlements to be dynamically adjusted based on account type, organizational policies, and security requirements. The entitlement template metadata includes configurable activation parameters that can be modified without changing the core entitlement structure. This enables the system to change activation timing parameters to balance security needs with productivity requirements for different user scenarios.
3Device complexity
If multiple target systems are managed independently, then system autonomy and simplicity are maintained, but coordination of account lifecycle events becomes complex and error-prone
Solution Approach 1:
The patent applies universality by creating a centralized entitlement management system that can provision and manage entitlements across multiple different target systems through a single interface. The system uses standardized entitlement templates and metadata that can be applied universally across various target systems, whether they are HR systems, IT service management platforms, or application access systems. This universal approach reduces integration complexity while maintaining synchronization reliability across diverse systems.
Solution Approach 2:
The entitlement management system acts as an intermediary between account creation events in target systems and the actual entitlement provisioning process. It receives account information from target systems, processes entitlement assignments according to predefined rules, and then provisions entitlements back to the appropriate systems. This intermediary layer coordinates account lifecycle events across multiple systems, ensuring synchronization and consistency while allowing each target system to maintain its autonomy.
4Adaptability or versatility
If manual tracking of account activation and deactivation times is performed, then policy customization is flexible, but administrative overhead and error rates increase
Solution Approach 1:
The system implements self-service by automatically calculating and setting account activation and deactivation times based on organizational policies and account metadata. When an account is created or modified, the system autonomously determines the appropriate entitlement activation timing and expiration based on predefined rules, eliminating the need for manual tracking. This maintains policy customization flexibility while reducing administrative overhead and errors through automated policy enforcement.
Solution Approach 2:
The entitlement management system implements feedback by continuously monitoring account status, activation times, and policy requirements, then automatically adjusting entitlement provisioning accordingly. The system receives feedback from target systems about account changes and uses this information to automatically update entitlement assignments and timing. This feedback loop maintains policy flexibility while reducing management complexity through automated policy interpretation and enforcement.
Data Source
AI summary
A method and system for managing temporal aspects of accounts and entitlements in target systems in an organization is provided. In an embodiment, an identity management system may receive request to create an account on a target system of the organization. In some embodiments, the identity management system may cause, in co-operation with the target system, the account to be created in the target system, at a first time. In some aspects, the identity management system may associate a second time with the account. In some examples, the second time may correspond to an activation time of the account. In some embodiments, the identity management system may cause in co-operation with the target system, the account to be activated on the target system, at the second time.


