Input Table Permission Inheritance for Multi-Role Data Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern businesses face challenges in accessing and sharing data visualizations due to complex database query statements and the need for multiple credentials, which can be computationally expensive and complicated by identity provider implementations.
Innovation Solution
A data visualizer system that creates input tables accessible by multiple account roles, using a service account to generate data visualizations for users without direct access to underlying data, and inherits permissions from a destination location on a cloud-based data warehouse.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a service account is used to generate data visualizations for users without direct access to underlying data, then security is improved, but device complexity increases
Solution Approach 1:
The patent introduces a service account as an intermediary between users and the underlying data. The service account holds the necessary credentials and permissions to access the data warehouse, while regular users only need access to the data visualization interface. This mediator approach allows users to consume visualizations without having direct access to the complex database infrastructure, thereby improving security while managing system complexity through abstraction.
2Ease of operation
If input tables inherit permissions from destination location, then ease of operation is improved, but manufacturing precision worsens
Solution Approach 1:
The patent applies preliminary action by pre-configuring permission inheritance rules at the destination location level before users create input tables. When a user creates an input table at a specific destination location, the system automatically inherits the pre-established permissions for that location. This eliminates the need for users to manually configure complex permission settings while maintaining consistent and accurate permission inheritance, thus improving ease of operation without sacrificing precision.
3Reliability
If multiple credentials are required for accessing data warehouse and visualization systems, then reliability is improved, but ease of operation worsens
Solution Approach 1:
The patent extracts the credential management function from individual user accounts and consolidates it into a dedicated service account. The service account holds the complex credentials required for accessing both the data warehouse and visualization systems. Users interact with the system through simplified interfaces that automatically handle authentication behind the scenes, eliminating the need for users to manage multiple credentials while maintaining secure access through the service account.
4Manufacturing precision
If complex database query statements are used to access data, then manufacturing precision is improved, but ease of operation worsens
Solution Approach 1:
The patent uses copying by creating simplified abstractions of complex database queries through the data visualization interface. Instead of requiring users to construct complex SQL statements, the system copies the intent of data retrieval operations into user-friendly visual elements. The underlying complex query logic is replicated and executed automatically by the system based on user selections in the visualization interface, maintaining accurate data access while dramatically improving ease of operation.
Data Source
AI summary
Creating input tables accessible by multiple account roles including receiving, from a client computing system by a data visualizer, a request to create an input table at a destination location on a cloud-based data warehouse, wherein the request is associated with a first account role; determining, by the data visualizer, that the first account role has access to the destination location based on a set of permissions associated with the destination location; and creating, on the cloud-based data warehouse by the data visualizer, the input table that inherits the set of permissions from the destination location on the cloud-based data warehouse.


