Reusable Access Policies for Faster Resource Request Approval

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional identity governance and administration (IGA) tools are inefficient and time-consuming for managing access requests to resources, leading to unnecessary duplication of roles and difficulty in determining relevant access privileges.

Innovation Solution

Implementing access policies that define relationships between resources and request-and-approval flows, enabling administrators to create policies that can be reused across multiple resources, and displaying a resource catalog to users for efficient access request management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If conventional IGA tools are used to manage access requests, then access control can be implemented, but the process becomes inefficient and time-consuming

Engineering Contradiction:
Improveaccess request processing efficiencyVSAvoidtime to manage access requests
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically generating access policy drafts based on resource metadata and historical access patterns before administrator review. This pre-processing reduces the time required for manual policy creation and approval workflows.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service capabilities where users can independently request access to resources through automated workflows, and the system automatically evaluates and approves routine requests based on predefined policies, reducing administrative overhead and processing time.

Inventive Principle:
Principle #25Self-service

2Reliability

If detailed access policies are created for each resource, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system creates universal access policies that can be applied across multiple resources simultaneously. A single policy definition can govern access to entire resource categories or families, reducing the number of individual policies needed while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system merges related access policies into consolidated policy groups and combines multiple security criteria into unified policy rules. This consolidation reduces the overall number of discrete policies administrators must manage while preserving granular security controls.

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If access policies are reused across multiple resources, then processing overhead is reduced, but determining relevant access privileges becomes more difficult

Engineering Contradiction:
Improvepolicy processing efficiencyVSAvoidaccess privilege visibility
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The system provides feedback mechanisms that automatically track and report which policies are applied to which resources and users. Administrators receive real-time visibility into policy enforcement across the system, making it easy to audit and understand access privileges even when policies are reused extensively.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system introduces an intermediary policy management layer that sits between the reusable policy definitions and their applications to specific resources. This layer maintains mapping relationships and provides a unified view of access privileges, making it easier to trace which policies grant which access rights across multiple resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250337750A1Platform access request management
Publication Date: 2025.10.30 OKTA INC
  • US20250337750A1 patent drawing
  • US20250337750A1 patent drawing
  • US20250337750A1 patent drawing

AI summary

An administrator of an organization may create access policies within an access request management system which define relationships between resources and request-and-approval flows. For example, the administrator may create an access policy, and the access policy may be applied across multiple resources of the organization. The access policy may indicate rules that indicate characteristics of a request-and-approval flow for granting access to the corresponding resources. For example, the rules may indicate a duration to grant access to the users, a group of users that are eligible to request the resource, approving users that provide approval to the requesting user, and information to collect from the requesting users, among other examples.