Techniques for access certification reviewer selection

US12587538B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12587538-B2
Application numberUS-202217811020-A
CountryUS
Kind codeB2
Filing dateJul 6, 2022
Priority dateJul 6, 2022
Publication dateMar 24, 2026
Grant dateMar 24, 2026

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Methods, systems, and devices for discounting extensibility latency are described. A software platform may identify a first time period of a campaign to certify access to one or more resources for a plurality of users. The software platform may determine, for each user of the multiple of users, one or more criteria associated with the campaign that are satisfied by respective information associated with each user. The software platform may select, for each user of the multiple users, a reviewer to certify access to the one or more resources for a respective user based on the one or more criteria.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method for access management, comprising: identifying a first time period of a campaign to certify access to one or more resources for a plurality of users; determining, for a first user of the plurality of users that is associated with a first set of user information indicating a first set of user profile attributes, that one or more user profile attributes of the first set of user profile attributes of the first user satisfies a first criteria of a plurality of criteria associated with the campaign and a second criteria of the plurality of criteria associated with the campaign, the second criteria being different than the first criteria; determining, for a second user of the plurality of users that is associated with a second set of user information indicating a second set of user profile attributes, that the one or more user profile attributes of the second set of user profile attributes of the second user satisfies a third criteria of the plurality of criteria associated with the campaign, the third criteria being different than both the first criteria and the second criteria, wherein the third criteria is indicative of a lack of satisfaction of the first criteria and the second criteria; selecting, for the first user of the plurality of users, a first reviewer from a plurality of reviewers to certify access to the one or more resources for the first user based at least in part on the first criteria and the second criteria being satisfied by the one or more user profile attributes indicated via the first set of user information for the first user, wherein selection of the first reviewer is based at least in part on the first reviewer being associated with both the first criteria and the second criteria that are satisfied by the one or more user profile attributes associated with the first user; and selecting, for the second user of the plurality of users, a second reviewer from the plurality of reviewers to certify access to the one or more resources for the second user based at least in part on the third criteria being satisfied by the one or more user profile attributes indicated via the second set of user information for the second user, the second reviewer being different than the first reviewer, wherein the selection of the second reviewer is based at least in part on the second reviewer being associated with the third criteria that is satisfied by the one or more user profile attributes associated with the second user. 2 . The method of claim 1 , wherein determining that the first criteria and the second criteria are satisfied and that the third criteria is satisfied comprises: comparing, for the first user, at least a portion of the first set of user profile attributes indicated via the first set of user information associated with the first user of the plurality of users to the first criteria and the second criteria of the plurality of criteria; and comparing, for the second user, at least a portion of the second set of user profile attributes indicated via the second set of user information associated with the second user of the plurality of users to the first criteria, the second criteria, and the third criteria of the plurality of criteria. 3 . The method of claim 1 , wherein each criterion of the plurality of criteria comprises a conditional expression. 4 . The method of claim 3 , wherein the conditional expression comprises business logic. 5 . The method of claim 1 , further comprising: determining that a default criterion of the plurality of criteria associated with the campaign is satisfied by at least one user profile attribute of a third set of user profile attributes indicated via a third set of user information associated with a third user of the plurality of users; and selecting, for the third user, a default reviewer from the plurality of reviewers to certify access to the one or more resources for the third user based at least in part on the default criterion, wherein selection of the default reviewer is based at least in part on the default reviewer being associated with the default criterion that is satisfied by the at least one user profile attribute of the third set of user profile attributes indicated via the third set of user information associated with the third user. 6 . The method of claim 5 , wherein determining that the default criterion is satisfied by the third set of user information associated with the third user comprises: determining that a respective selected reviewer comprises the third user, wherein selecting the default reviewer is based at least in part on the determination, and wherein the default reviewer is different from the first user, the second user, or both. 7 . The method of claim 1 , further comprising: transmitting, to a respective selected reviewer, a message indicating the respective selected reviewer to certify access to the one or more resources for a respective user that is associated with a respective one or more criteria of the plurality of criteria that is satisfied by the one or more user profile attributes associated with the respective user. 8 . The method of claim 1 , wherein certifying access to the one or more resources comprises approving access to at least one resource of the one or more resources, revoking access to at least one resource of the one or more resources, reassigning a respective user to another reviewer, or a combination thereof. 9 . The method of claim 1 , wherein a respective set of user profile attributes indicated via a respective set of user information associated with a respective user of the plurality of users comprises a username of the respective user, a status of the respective user, a title of the respective user, a location associated with the respective user, an organization associated with the respective user, a department associated with the respective user, a cost center associated with the respective user, a manager of the respective user, or any combination thereof. 10 . The method of claim 1 , wherein a respective set of user information associated with a respective user of the plurality of users is stored in a directory service. 11 . The method of claim 1 , wherein the first user of the plurality of users has access to at least one resource of the one or more resources during the first time period, the second user of the plurality of users has access to at least one resource of the one or more resources during the first time period, or a combination thereof. 12 . An apparatus for access management, comprising: a processor; memory coupled with the processor; and instructions stored in the memory and executable by the processor to cause the apparatus to: identify a first time period of a campaign to certify access to one or more resources for a plurality of users; determine, for a first user of the plurality of users that is associated with a first set of user information indicating a first set of user profile attributes, that one or more user profile attributes of the first set of user profile attributes of the first user satisfies a first criteria of a plurality of criteria associated with the campaign and a second criteria of the plurality of criteria associated with the campaign, the second criteria being different than the first criteria; determine, for a second user of the plurality of users that is associated with a second set of user information indicating a second set of user profile attributes, that the one or more user profile attributes of the second set of user profile attributes of the second user satisfies a third criteria of the plurality of criteria associated with the campaign, the third criteria bei

Assignees

Inventors

Classifications

  • H04L63/104Primary

    Grouping of entities · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12587538B2 cover?
Methods, systems, and devices for discounting extensibility latency are described. A software platform may identify a first time period of a campaign to certify access to one or more resources for a plurality of users. The software platform may determine, for each user of the multiple of users, one or more criteria associated with the campaign that are satisfied by respective information associ…
Who is the assignee on this patent?
Okta Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/104. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Mar 24 2026 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 4 related publications on this page (citations in our corpus or others sharing the same primary CPC).