Global Access Control Mesh for Proximity-Based Onboarding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing enterprise onboarding processes for new employees are inefficient and costly, particularly in granting and revoking access to various resources and spaces, and do not adequately support remote and mobile workers, leading to a stressful experience that affects employee confidence and productivity.
Innovation Solution
A Global Control Access Platform (GCAP) that implements a dynamic access control system based on proximity, automatically granting and revoking access permissions to resources and spaces based on an individual's role within a team, using a mesh configuration that associates teams with access permissions, and dynamically updates these permissions based on team activities and learning mechanisms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual access control processes are used for each resource and location, then access permissions can be individually managed, but the time and effort required for onboarding new employees increases significantly
Solution Approach 1:
The patent merges multiple individual access control processes into a single unified automated system. Instead of manually managing access to each resource separately, the system combines all access control operations into one integrated workflow that automatically provisions access across multiple resources when a new employee joins, thereby reducing onboarding time while maintaining individualized access management.
Solution Approach 2:
The system performs preliminary actions by pre-configuring access permissions and resource associations before new employees arrive. Access policies, resource mappings, and permission sets are established in advance, so that when a new employee is onboarded, access is automatically granted immediately without requiring manual configuration during the onboarding process.
2Adaptability or versatility
If multiple different processes are used per item or location requiring access, then specific access requirements can be met, but the complexity of managing access control increases
Solution Approach 1:
The patent implements a universal access control system that can handle multiple different resource types and access scenarios through a single multi-functional platform. The system provides adaptable permission configurations for various resources (workspaces, applications, files, devices) while maintaining a unified management interface, thereby reducing system complexity while preserving the ability to meet specific access requirements for each item or location.
3Reliability
If access is granted manually to each resource, then security control can be maintained, but the cost and effort of access management increases
Solution Approach 1:
The system enables self-service access management by automatically provisioning and revoking access permissions based on predefined policies and resource associations. When a new employee joins or an existing employee's role changes, the system automatically grants or revokes access to appropriate resources without requiring manual security review for each individual resource, thereby maintaining security control while significantly improving access management efficiency and reducing operational costs.
4Reliability
If access permissions are manually revoked when employees leave or transfer, then security is maintained, but the burden on multiple users who issued access increases
Solution Approach 1:
The system automatically revokes access permissions when employees leave, transfer, or have their roles changed, eliminating the manual burden on multiple users who previously had to individually revoke access. The centralized system tracks all access grants and automatically reverses them according to policy, maintaining security control while making the revocation process effortless and eliminating operational burden on individual users.
Data Source
AI summary
A method for providing controlled access to resources in an enterprise begins by defining a “mesh” that associates a workplace team to a set of one or more workplace resources. The team has a role that, with respect to the resources, has a set of access permissions. An individual that is not then associated with the workplace team, e.g., in the given role, is assigned a physical or virtual token that represents the individual in the workplace environment. In response to detecting that the token is in physical or logical proximity to a member of the workplace team, the permissions are then automatically extended to the token. The resources are then accessible using the token. When the individual possessing the token is no longer in proximity, the access permissions are automatically revoked. The scope of the mesh configuration may be dynamically updated based on tracking activities of the workplace team.


