SaaS Application Identity Linking for Enterprise Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Software-as-a-Service (SaaS) models face challenges in identifying decision makers for enterprise licensing, managing SaaS applications within enterprises, enforcing enterprise IT policies, and ensuring data privacy and compliance, particularly in scenarios where users adopt SaaS applications without explicit IT department knowledge or control.
Innovation Solution
A programming model that enables SaaS applications to support organic adoption using app-local or social identities, integrates with enterprise identities for single sign-on authentication, and allows seamless transition to enterprise management without code changes, providing features like identity linking, data ownership, and compliance with enterprise policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users adopt SaaS applications without explicit IT department knowledge or control, then ease of operation is improved, but IT department control deteriorates
Solution Approach 1:
The system performs preliminary actions by automatically discovering applications users have adopted before IT management is involved. The discovery mechanism proactively identifies SaaS applications through various signals (login patterns, data flows, user feedback) and prepares management options before IT intervention is required, thus maintaining ease of user adoption while enabling subsequent IT control.
Solution Approach 2:
The system implements feedback loops where user adoption behaviors generate signals that are fed back to the discovery mechanism. This continuous feedback enables the system to automatically detect and report on applications users are using, allowing IT to maintain control through informed decision-making without restricting user access.
2Reliability
If enterprise policies are enforced after software purchase and management, then reliability is improved, but ease of operation deteriorates
Solution Approach 1:
The programming model incorporates preliminary action by designing the software architecture to be policy-ready from the outset. The model includes pre-configured hooks and interfaces that allow enterprise policies to be applied without requiring code modifications later, thus maintaining ease of operation while ensuring reliable policy enforcement.
Solution Approach 2:
The system uses parameter changes to enforce enterprise policies by modifying configuration parameters rather than code structure. The programming model allows policies to be implemented through parameter adjustments in the software configuration, enabling reliable policy enforcement without requiring code changes that would compromise ease of operation.
3Ease of operation
If SaaS applications use app-local or social identities for organic adoption, then ease of operation is improved, but adaptability deteriorates
Solution Approach 1:
The programming model implements universality by designing an identity system that can function with multiple identity types (app-local, social, and enterprise identities) through a unified interface. This multi-functional identity framework allows the software to adapt to different enterprise requirements while maintaining ease of operation with various authentication methods.
Solution Approach 2:
The system applies dynamics by making the identity mechanism flexible and adaptable. The programming model allows the identity system to dynamically switch between or combine different identity types based on enterprise needs, transforming from a static single-identity approach to a dynamic multi-identity framework that enhances both ease of operation and adaptability.
4Ease of repair
If seamless transition to enterprise management is enabled without code changes, then ease of repair is improved, but manufacturing precision deteriorates
Solution Approach 1:
The programming model uses parameter changes to enable seamless transition to enterprise management. By implementing policies through configurable parameters rather than code changes, the system achieves ease of deployment and modification while maintaining precise policy implementation through structured parameter validation and enforcement mechanisms.
Solution Approach 2:
The system introduces an intermediary layer (the programming model interface) that mediates between the software code and enterprise policies. This intermediary allows policy changes to be implemented without modifying the underlying code, providing ease of deployment while ensuring precise policy implementation through the structured interface that translates policies into executable configurations.
Data Source
AI summary
A system includes a processor and machine readable instructions stored on a tangible machine readable medium and executable by the processor, for a computer program, configured to allow one or more accounts of an enterprise to access the computer program before the enterprise purchases and manages the computer program and to allow the computer program to implement, after the enterprise purchases and manages the computer program, one or more policies of the enterprise regarding use of the computer program without modifying the computer program.


