Metadata-Driven Entitlement Selection in Identity Governance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Identity and Access Management (IAM) systems face challenges in efficiently managing and maintaining accurate lists of user entitlements for periodic review campaigns, leading to time-consuming and error-prone processes, which can result in audit failures due to the complexity of determining which entitlements need to be reviewed and how often.
Innovation Solution
An identity governance system is augmented to automate the generation of campaign datasets by extending data models to support user-defined metadata, allowing for the efficient selection of relevant entitlements from various data sources, reducing the need for manual maintenance of large lists of entitlements and enabling automated campaign dataset creation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all possible entitlements are included in certification campaigns to guarantee coverage, then compliance coverage is improved, but the complexity and time required for review increases significantly
Solution Approach 1:
The patent segments entitlements into different categories based on regulatory requirements and business criticality. By dividing the large set of all entitlements into meaningful segments (e.g., critical vs. non-critical, regulated vs. unregulated), the system enables selective inclusion in certification campaigns, reducing complexity while maintaining necessary compliance coverage.
Solution Approach 2:
The patent introduces metadata parameters to entitlements that capture regulatory classification, business criticality, and other attributes. By changing the parameter structure to include these metadata fields, the system enables automated filtering and selection of entitlements based on campaign requirements, transforming the manual review process into an automated parameter-based selection process.
2Measurement precision
If manual maintenance of entitlement lists is performed, then accuracy of campaign content is improved, but time consumption and error rate increase
Solution Approach 1:
The patent implements self-service functionality where the system automatically maintains entitlement metadata and generates campaign datasets without requiring manual intervention. The system serves itself by automatically updating entitlement information, applying regulatory changes, and regenerating campaign content, thereby eliminating manual maintenance while maintaining high accuracy through automated processes.
Solution Approach 2:
The patent incorporates feedback mechanisms where the system continuously monitors changes in entitlements, regulatory requirements, and business conditions. This feedback loop enables the system to automatically adjust campaign content in response to real-time changes, maintaining accuracy without requiring manual review and reduction of maintenance time.
3Quantity of substance
If entitlement lists are expanded to include more applications and data sources, then coverage completeness is improved, but difficulty of determining review scope increases
Solution Approach 1:
The patent introduces metadata as an intermediary layer between entitlements and certification campaigns. This metadata intermediary captures essential information about entitlements (regulatory classification, business criticality, data sources) and enables automated determination of review scope. The metadata acts as a mediator that translates complex entitlement data into actionable campaign selection criteria, reducing the difficulty of determining review scope while expanding coverage.
Solution Approach 2:
The patent creates a universal metadata framework that can be applied across multiple applications, data sources, and regulatory requirements. This universal framework enables a single set of metadata definitions to serve multiple purposes: classifying entitlements, determining campaign scope, identifying regulatory requirements, and generating campaign content. The multi-functionality of this universal approach simplifies the determination of review scope while expanding coverage completeness.
Data Source
AI summary
An identity governance system that automates launching of identity campaigns (e.g., attestation, certification, etc.) is augmented to provide for the more efficient generation of datasets that are to be evaluated in a particular campaign review. To this end, at least one data model supported in the system is extended to support user- or system-defined metadata that, once populated with data, enable the system to generate campaign datasets from various data sources in an automated, efficient manner. Metadata includes, for example, application properties, entitlement properties, and the like. In lieu of maintaining a list of entitlements manually, an administrator defines metadata that should be associated with various datasets, e.g., for each application, entitlement, organization unit, etc. When time to generate a campaign dataset, the system examines the underlying data sources (that are extended via the metadata) to enable automated generation of a campaign dataset that includes the relevant metadata information.


