User and Asset Grouping for Non-Hierarchical Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional SaaS data models are inadequate for computer environments that do not follow a single hierarchy, preventing the replication of SaaS behavior and efficient organization of assets such as user roles, permissions, and licensing.

Innovation Solution

A system that manages access to assets in a computer environment based on user and asset grouping, utilizing an environment state component, asset group component, and user group component to facilitate interaction and define access characteristics, enabling users to interact with assets through user interfaces.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a conventional SaaS container-or folder-based data model is used to organize assets in a single hierarchy, then access control and functionality organization are simplified, but the system cannot replicate conventional SaaS behavior in environments with multiple hierarchies or no hierarchy

Engineering Contradiction:
Improveability to replicate SaaS behavior in non-hierarchical environmentsVSAvoidcomplexity of access management system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The access control system is segmented into separate components: an environment state component that tracks hierarchical relationships, an asset group component that manages asset access rules, and a user group component that manages user access rules. This segmentation allows each component to handle specific aspects of access control independently, enabling the system to replicate SaaS behavior in non-hierarchical environments without overwhelming complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An intermediary access control mechanism is introduced between users and assets. The environment state component acts as a mediator that determines whether an asset has a hierarchy, and the asset group and user group components work together to apply appropriate access rules. This intermediary layer enables flexible access control that adapts to different environmental structures

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If assets are allowed to belong to multiple hierarchies simultaneously, then flexibility and adaptability are improved, but access control and organization become more difficult to manage

Engineering Contradiction:
Improveflexibility of asset organizationVSAvoidease of access management
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The access control system is designed to be dynamic rather than static. The environment state component continuously tracks the hierarchical status of assets, and the asset group and user group components dynamically apply appropriate access rules based on the current environmental state. This dynamic approach allows the system to handle multiple hierarchies flexibly while maintaining ease of operation through automated access determination

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes parameters based on environmental conditions. When an asset has a hierarchy, the system applies one set of access control parameters; when an asset does not have a hierarchy, the system applies different parameters. The environment state component monitors these conditions and triggers appropriate parameter changes in the access control logic, making management simpler despite the flexibility of multi-hierarchy support

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250330472A1Systems and methods to manage access to assets of a computer environment based on user and asset grouping
Publication Date: 2025.10.23 ASANA INC
  • US20250330472A1 patent drawing
  • US20250330472A1 patent drawing
  • US20250330472A1 patent drawing

AI summary

Systems and methods to manage access to assets of a computer environment based on user and asset grouping are described herein. Exemplary implementations may perform one or more of: manage asset groups associated with one or more assets of a computer environment; manage user groups associated with individual asset groups; assign users to user groups to cause access characteristics of associated assets to be granted to users; enable and/or disable individual access characteristics based on assigned ones of the user groups; and/or other operations.