Multitenant Access Delegation for External User Groups

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Multitenant content management systems face challenges in efficiently managing access to shared content, particularly when tenants need to share files with external users whose identities may change frequently, leading to access control issues.

Innovation Solution

The system allows tenants to delegate administrative privileges to external users, enabling them to manage access to shared content by adding or removing users from user groups, thus maintaining accurate access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual external users are added as collaborators on folders or files, then access control for shared content is achieved, but management complexity increases when user identities change frequently

Engineering Contradiction:
Improveaccess control accuracyVSAvoiduser management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary mechanism by allowing tenants to delegate administrative privileges to external users. This delegation system acts as a mediator between the tenant's access control requirements and the dynamic nature of external user identities, enabling automated group management without requiring the tenant to directly manage each external user's access permissions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements self-service by enabling external users to autonomously manage their own access to shared content through delegated administrative privileges. External users can add or remove themselves from user groups without requiring direct intervention from the tenant, allowing the system to adapt automatically to changes in external user identities.

Inventive Principle:
Principle #25Self-service

2Reliability

If tenants manually manage external user access, then security control is maintained, but responsiveness to user identity changes decreases

Engineering Contradiction:
Improveaccess control securityVSAvoidaccess management efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent enables external users to autonomously manage their own access to shared content through delegated administrative privileges. This self-service mechanism allows external users to add or remove themselves from user groups without requiring direct intervention from the tenant, maintaining security while improving responsiveness to user identity changes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements a feedback mechanism where the system automatically detects when external users should be added or removed from user groups based on delegated administrative privileges. This feedback loop enables the system to automatically update access permissions in response to user identity changes, maintaining both security and efficiency.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If external users are granted administrative privileges, then dynamic group management is enabled, but system security risks increase

Engineering Contradiction:
Improvegroup management flexibilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by granting administrative privileges selectively to specific external users based on their relationship with the tenant, rather than universally to all external users. This targeted delegation allows flexible group management while maintaining security by limiting administrative capabilities to trusted external users only.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12235994B2System and method for external users in groups of a multitenant system
Publication Date: 2025.02.25 OPEN TEXT SA ULC
  • US12235994B2 patent drawing
  • US12235994B2 patent drawing
  • US12235994B2 patent drawing

AI summary

Content management systems are implemented according to a multitenant architecture by which software and its supporting architecture serves multiple customers of a service. Each tenant may be given a share of the application's data, configuration, user management, and other aspects of the application. Each tenant's data is isolated and typically remains invisible to other tenants so that tenants do not share or see each other's data. Embodiments described herein provide mechanisms by which a tenant can delegate administrator rights to an external user such that the external user can grant other users access to the tenant's content while the tenant controls the level of access that is provided to the external users.