Multi-Tenant Support Access via Mediator User Class
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for providing support access to multi-tenant database systems are inefficient and insecure, requiring credential exchange and screen sharing, which lead to high administrative overhead and security vulnerabilities.
Innovation Solution
The package support access system introduces a support user class with read-only metadata access and user impersonation capabilities, allowing support representatives to diagnose issues without exchanging credentials or using screen sharing, through a licensed management application and graphical user interface for secure and controlled access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If credential exchange and screen sharing are used for support access, then support representatives can diagnose issues, but administrative overhead increases and security vulnerabilities arise
Solution Approach 1:
The patent introduces a support user class as an intermediary mechanism that mediates between support representatives and tenant data. This support user class enables support access without requiring direct credential exchange between support personnel and tenant administrators, thereby reducing administrative overhead while maintaining security through controlled, standardized access procedures
Solution Approach 2:
The patent creates a support user class that copies or replicates the necessary access permissions for support representatives without requiring actual tenant credentials. This allows support personnel to access and diagnose issues in a tenant environment without handling or exchanging sensitive tenant credentials, thus improving security while maintaining diagnostic capabilities
2Productivity
If support representatives access tenant data for troubleshooting, then issues can be diagnosed, but data protection risks increase
Solution Approach 1:
The patent applies local quality by granting different access permissions to different user classes within the same system. The support user class is given specific, limited permissions tailored for troubleshooting purposes, allowing access to necessary diagnostic information while restricting access to sensitive tenant data, thus enabling efficient troubleshooting while maintaining data protection
Solution Approach 2:
The support user class serves as an intermediary layer between support representatives and tenant data, enabling troubleshooting activities while enforcing data protection policies. This intermediary mechanism allows support personnel to perform diagnostic functions without directly accessing or exposing sensitive tenant information, thereby maintaining both productivity and data security
3Loss of time
If screen sharing is used for support access, then real-time diagnosis is possible, but security vulnerabilities and interaction overhead increase
Solution Approach 1:
The support user class creates a copied or replicated access environment for support representatives, allowing them to view and diagnose tenant system issues without requiring real-time screen sharing. This copied access mechanism enables efficient troubleshooting while eliminating the security vulnerabilities and interaction overhead associated with screen sharing protocols
Data Source
AI summary
Embodiments are described for providing access by application vendors to applications deployed in an enterprise network environment. A package access system defines a support user class in a user profile database for an application executed within organization resources maintained in a multi-tenant data store. The support user is granted read only privileges to metadata of the application. An organization administrator can grant the application vendor access to the application as a support user, allowing the vendor to view and analyze the metadata. The organization administrator can further grant access by a specific support representative to the application as a specific user within the organization user for a limited term. The support representative can then log into the organization and access and use the application in order to diagnose any post-installation usage problems with the application.


