Reusable Access Policies for Faster Resource Request Approval
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional identity governance and administration (IGA) tools are inefficient and time-consuming for managing access requests to resources, leading to unnecessary duplication of roles and difficulty in determining relevant access privileges.
Innovation Solution
Implementing access policies that define relationships between resources and request-and-approval flows, enabling administrators to create policies that can be reused across multiple resources, and displaying a resource catalog to users for efficient access request management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If conventional IGA tools are used to manage access requests, then access control can be implemented, but the process becomes inefficient and time-consuming
Solution Approach 1:
The system performs preliminary actions by automatically generating access policy drafts based on resource metadata and historical access patterns before administrator review. This pre-processing reduces the time required for manual policy creation and approval workflows.
Solution Approach 2:
The system enables self-service capabilities where users can independently request access to resources through automated workflows, and the system automatically evaluates and approves routine requests based on predefined policies, reducing administrative overhead and processing time.
2Reliability
If detailed access policies are created for each resource, then security is improved, but system complexity increases
Solution Approach 1:
The system creates universal access policies that can be applied across multiple resources simultaneously. A single policy definition can govern access to entire resource categories or families, reducing the number of individual policies needed while maintaining comprehensive security coverage.
Solution Approach 2:
The system merges related access policies into consolidated policy groups and combines multiple security criteria into unified policy rules. This consolidation reduces the overall number of discrete policies administrators must manage while preserving granular security controls.
3Productivity
If access policies are reused across multiple resources, then processing overhead is reduced, but determining relevant access privileges becomes more difficult
Solution Approach 1:
The system provides feedback mechanisms that automatically track and report which policies are applied to which resources and users. Administrators receive real-time visibility into policy enforcement across the system, making it easy to audit and understand access privileges even when policies are reused extensively.
Solution Approach 2:
The system introduces an intermediary policy management layer that sits between the reusable policy definitions and their applications to specific resources. This layer maintains mapping relationships and provides a unified view of access privileges, making it easier to trace which policies grant which access rights across multiple resources.
Data Source
AI summary
An administrator of an organization may create access policies within an access request management system which define relationships between resources and request-and-approval flows. For example, the administrator may create an access policy, and the access policy may be applied across multiple resources of the organization. The access policy may indicate rules that indicate characteristics of a request-and-approval flow for granting access to the corresponding resources. For example, the rules may indicate a duration to grant access to the users, a group of users that are eligible to request the resource, approving users that provide approval to the requesting user, and information to collect from the requesting users, among other examples.


