RPA Workflow Governance Using Policy-Based Access Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Robotic process automation (RPA) systems lack effective access control and governance mechanisms, leading to potential violations of laws and regulations such as GDPR and HIPAA, and can overwhelm legacy systems with their speed, causing compliance and security risks.

Innovation Solution

Implementing a computer program that analyzes RPA workflow activities against access control and governance policy rules, preventing the generation or publication of RPA robots until compliance is ensured, and enforcing policies at both design time and runtime through a code analyzer and conductor application.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If RPA robots operate at high speed to improve productivity, then productivity increases, but legacy systems may be overwhelmed causing system instability

Engineering Contradiction:
ImproveRPA robot execution speedVSAvoidlegacy system stability
Core Design Contradiction:
ProductivityVSStability of the object's composition

Solution Approach 1:

The patent applies preliminary action by analyzing and validating RPA workflows against governance policies during the design phase before deployment. The code analyzer examines workflow definitions, activity configurations, and data access patterns in advance to identify potential risks to legacy systems. This pre-validation ensures that when RPA robots execute at high speed, they do so within approved parameters that protect legacy system stability, thus resolving the contradiction between productivity and system stability.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If access control policies are enforced strictly to improve security and compliance, then compliance with laws and regulations improves, but system complexity increases due to additional governance mechanisms

Engineering Contradiction:
Improvecompliance with laws and regulationsVSAvoidgovernance mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the RPA workflow to automatically analyze and validate itself against governance policies through the code analyzer. The system performs self-examination of workflow definitions, activity configurations, and data access patterns without requiring manual compliance checks. This automated self-validation approach improves compliance reliability while minimizing the addition of complex manual governance mechanisms, as the system governs itself through embedded policy enforcement.

Inventive Principle:
Principle #25Self-service

3Manufacturing precision

If code analysis and policy validation are performed thoroughly to ensure compliance, then compliance accuracy improves, but development time increases

Engineering Contradiction:
Improvecompliance verification accuracyVSAvoidworkflow development time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by performing code analysis and policy validation during the workflow design phase rather than after deployment. The code analyzer examines workflow definitions and activity configurations upfront, providing immediate feedback on compliance issues. This early detection approach ensures high compliance verification accuracy while reducing overall development time, as compliance problems are identified and resolved during design rather than requiring lengthy post-deployment testing and correction cycles.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20230350373A1Robot access control and governance for robotic process automation
Publication Date: 2023.11.02 UIPATH INC
  • US20230350373A1 patent drawing
  • US20230350373A1 patent drawing
  • US20230350373A1 patent drawing

AI summary

Robot access control and governance for robotic process automation (RPA) is disclosed. A code analyzer of an RPA designer application, such as a workflow analyzer, may read access control and governance policy rules for an RPA designer application and analyze activities of an RPA workflow of the RPA designer application against the access control and governance policy rules. When one or more analyzed activities of the RPA workflow violate the access control and governance policy rules, the code analyzer prevents generation of an RPA robot or publication of the RPA workflow until the RPA workflow satisfies the access control and governance policy rules. When the analyzed activities of the RPA workflow comply with all required access control and governance policy rules, the RPA designer application may generate an RPA robot implementing the RPA workflow or publish the RPA workflow.