DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This Office Action is responsive to Applicant's amendment filed on 9 September 2026. Applicant’s amendment on 9 September amended Claims 1, 2, 4-7, 10, 11, 13, 14, 16-20, and 22-24. Currently Claims 1-11, 13-20 and 22-24 are pending and have been examined. Claim 12 and 25 were previously canceled, claim 21 was never presented. The Examiner notes that the 101 Alice rejection is maintained, but the prior art rejection was previously withdrawn for claims 1-11, 13-20 and 22-24.
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 9 September 2026 has been entered.
Examiner’s Note
The Examiner notes that the prior art rejection has been withdrawn based on the amendment and the arguments currently presented.
Response to Arguments
Applicant's arguments filed 13 April 2026 have been fully considered but they are not persuasive.
The Applicant argues on pages 20-21 that independent claims 1, 20, and 24 are directed to patent eligible subject matter under the two-part Alice/Mayo test, asserting that a claim is only directed to a judicial exception if it both recites a judicial exception under Prong One and fails to integrate that exception into a practical application under Prong Two.
The Examiner respectfully disagrees.
With respect to the argument the Examiner notes that while Applicant correctly recites the legal framework of the two-step Alice/Mayo eligibility analysis as set forth in MPEP 2106.04, a correct statement of the applicable legal standard does not, standing alone, establish that the claims satisfy it. The Examiner has applied precisely this framework throughout prosecution and maintains that the claims fail at both prongs of the Step 2A analysis. Specifically, the claims recite an abstract idea at Step 2A, Prong One in the form of collecting, correlating, and organizing IT incident information to identify, select, order, and execute remediation tasks a concept that, under its broadest reasonable interpretation, covers performance of those foundational steps mentally or with pen and paper but for the recitation of generic computer components and the claims further fail to integrate that abstract idea into a practical application at Step 2A, Prong Two for the reasons set forth in the prior Office Action and as further addressed in response to Applicant's remaining arguments. Applicant's recitation of the correct legal standard, without more, provides no basis for withdrawing the rejection, and accordingly the rejection is maintained.
The Applicant argues on pages 21-23 that The Applicant argues that the amended claim's addition of graph construction, telemetry-integration, and rollback limitations, combined with the Office's prior acknowledgment that certain limitations cannot practically be performed in the human mind, removes the factual premise of the Examiner's Prong One finding, because constructing two graph data structures, traversing dependency edges to govern telemetry collection and integration, and traversing the skill relationship graph to select a fallback skill by comparative match score are not processes a human analyst can carry out mentally or with pen and paper.
The Examiner respectfully disagrees.
With respect to the argument the Examiner notes that as an initial matter, the Examiner acknowledges, consistent with the August 4, 2025 Memorandum and MPEP 2106.04(a)(2)(III), that specific limitations including generating an ordering using a machine learning model, automatically invoking automation tools to change operational states, traversing the topology graph's dependency edges to govern telemetry integration, and selecting a fallback skill by comparative match score from the skill relationship graph data structure are operations the human mind is not equipped to perform as a practical matter, and the Examiner does not apply the mental process grouping to those specific limitations. However, Applicant's argument that these additions are collectively dispositive of Prong One for the claim as a whole misapplies the applicable standard. MPEP 2106.04(a) and the August 4, 2025 Memorandum require evaluation of the claim in its entirety, and a claim recites a judicial exception when, considered as a whole, it sets forth or describes an abstract idea even if some individual limitations within the claim cannot be mentally performed. The Memorandum instructs examiners not to expand the mental process grouping to improperly capture AI-specific limitations that cannot be mentally performed; it does not instruct examiners to disregard other limitations in the same claim that independently satisfy an enumerated grouping.
The amended claim continues to recite, as foundational operational steps, receiving an IT incident notification, retrieving data structures, executing correlation operations that correlate the topology graph with the knowledge graph to identify IT remediation tasks, generating an IT remediation task skill set by identifying skills associated with those tasks, classifying those skills, and generating an IT incident remediation task workflow. These limitations, evaluated under their broadest reasonable interpretation, describe the collection, correlation, and organization of information about an IT incident to identify and order remediation tasks a concept that a skilled IT analyst could perform mentally, or with the aid of notes, when reviewing incident data, consulting known remediation knowledge, and deciding on a course of action. Spec. par. [0028]–[0029] confirms this framing, describing the underlying problem as SRE teams needing to identify tasks, determine ordering, determine required skills, and orchestrate performance precisely the process these limitations automate. The fact that the claim now adds graph data structure labels to the retrieved data and specifies that the topology graph's edges are consumed downstream does not transform the foundational collect-correlate-organize steps into operations the human mind cannot perform; a human analyst reviewing a network topology diagram and using its dependency relationships to identify affected resources and sequence remediation steps is performing exactly the mental process these limitations describe, irrespective of whether the data is labeled a "graph data structure" with "nodes" and "edges."
Furthermore, Applicant's assertion that the Examiner has failed to identify specific claim limitations reciting the exception, and has instead restated the claim at a level of generality untethered from the claim language, is not accurate. The prior Office Action and Advisory Action specifically identified the following limitations as reciting the abstract idea: receiving an IT incident notification; retrieving the IT topology graph data structure; generating the knowledge graph data structure; executing the first correlation operation correlating the topology graph with the knowledge graph to identify IT remediation tasks; generating the IT remediation task skill set; classifying skills; executing the second correlation operation; and generating the IT incident remediation task workflow. Each of these identified limitations describes a step in the process of collecting, correlating, and organizing IT incident information to reach an operational decision the identified abstract idea and each can, under its broadest reasonable interpretation, be performed mentally by a human analyst but for the recitation of generic computer components. The characterization of these limitations collectively as directed to collecting, correlating, and organizing information to identify and order remediation tasks is not a restatement at a level of generality untethered from the claim language; it is a faithful characterization of what those specific, identified limitations recite when read individually and as an ordered combination.
Accordingly, because the claim as a whole recites a judicial exception through these identified limitations independent of the separately-analyzed, non-mentally-performable limitations which are properly reserved for Prong Two the Prong One finding is maintained and the rejection is maintained.
The Applicant argues on pages 23-24 that the amended claim's specific recitations two monitoring agents executing at topologically defined locations collecting run-time and configuration information, integration of that data in accordance with topology graph edges to determine whether an operational state change was successful, resetting the IT resource to its prior state, and selecting a fallback skill from the skill relationship graph by comparative match score are machine-generated operations and physical machine acts with no mental equivalent that remove the claim from the mental process grouping.
The Examiner respectfully disagrees.
With respect to argument the Examiner notes that while the Examiner acknowledges, consistent with the August 4, 2025 Memorandum and MPEP 2106.04(a)(2)(III), that the specific limitations Applicant identifies collecting run-time and configuration information from software agents resident on two topologically related IT resources, integrating that monitoring data in accordance with topology graph edges, resetting a live IT resource to a temporally defined prior state, and selecting a fallback skill by comparative match score from the skill relationship graph data structure are operations the human mind is not equipped to perform as a practical matter, and the Examiner does not apply the mental process grouping to these specific limitations. These limitations are properly treated as additional elements to be evaluated at Step 2A, Prong Two, and that evaluation is addressed in response to Applicant's remaining arguments.
However, the fact that these specific limitations cannot be mentally performed does not, as Applicant contends, remove the claim as a whole from the mental process grouping or resolve Prong One in Applicant's favor. As established in the prior Office Action and Advisory Action, and as further explained in response to Argument 1 above, the claim as a whole continues to recite, as foundational operational steps independent of the identified machine-act limitations, the receipt of an IT incident notification, retrieval of the IT topology graph data structure and knowledge graph data structure, execution of correlation operations to identify IT remediation tasks, generation of an IT remediation task skill set, classification of skills, and generation of an IT incident remediation task workflow. These foundational steps, evaluated under their broadest reasonable interpretation, describe the collection, correlation, and organization of IT incident information to reach an operational decision a process that a skilled IT analyst could perform mentally when reviewing incident data and known remediation knowledge to decide on a course of action, as confirmed by the specification's own framing of the underlying problem at paragraph [0029]. The presence within the same claim of additional limitations that cannot be mentally performed does not immunize these foundational limitations from the mental process grouping; the August 4, 2025 Memorandum instructs examiners not to expand the mental process grouping to improperly capture AI-specific limitations, but it does not instruct examiners to disregard separately-analyzed limitations in the same claim that independently recite a mental process. Each limitation must be evaluated on its own terms at Prong One, with non-mentally-performable limitations reserved for Prong Two as additional elements, which is precisely the analytical path the Examiner has followed throughout prosecution. Accordingly, the Prong One finding is maintained and the rejection is maintained.
The Applicant argues on page 24 that SRI International, Inc. v. Cisco Systems, Inc., 930 F.3d 1295 (Fed. Cir. 2019), which the Office Action itself cited as a benchmark for eligibility, compels a finding of eligibility here because the features of amended claim 1 map directly onto each of the four elements the Federal Circuit found dispositive in holding the SRI claim eligible at Alice step one as directed to a specific technique for solving a technological problem in computer networks.
The Examiner respectfully disagrees.
With respect to the argument the Examiner notes that while the Examiner acknowledges that SRI is an instructive and relevant benchmark one the Office Action cited precisely because it illustrates the level of technical specificity required to integrate an abstract idea into a practical application a surface-level structural mapping of amended claim 1's elements onto SRI's dispositive features does not establish eligibility unless the amended claim achieves the same species and degree of technical specificity that grounded the Federal Circuit's holding. The SRI court's eligibility finding did not turn on the mere presence of deployed monitors, data collection, report generation, and integration in an ordered sequence; it turned on the particular technical character of how each of those functions was carried out specifically, a plurality of network monitors deployed at distinct locations across an enterprise network, each directly examining enumerated specific categories of network traffic data at the packet level (e.g., network packet type, header, or routing information as construed by the court), generating detection reports of suspicious activity, which were then automatically received and integrated by one or more hierarchical monitors. The specificity of the data categories examined, the distributed deployment architecture, and the hierarchical integration mechanism were themselves the claimed technical solution to the technical problem of network intrusion detection, not merely a framework within which a generic detection function was performed.
The assertion that amended claim 1's features "map directly" onto each of these dispositive elements is addressed specifically in response to Arguments 5 through 7 below, where the Examiner evaluates each proposed mapping in detail. As a threshold matter, however, the Examiner notes that a mapping argument of this nature is only as strong as the precision of the mapping itself, and where, as here, the amended claim recites monitoring agents, data categories, integration, and rollback at a level of functional generality that differs materially from the technical specificity the Federal Circuit credited in SRI, the mapping does not hold. The specific distinctions are fully addressed in the responses to Arguments 5 through 7, and those responses are incorporated here. Accordingly, SRI does not compel a finding of eligibility, and the rejection is maintained.
The Applicant argues on pages 24-25 that the amended claim addresses the Advisory Action's objections regarding monitoring agent specificity by: (1) fixing the deployment locations of two monitoring agents to topologically defined positions in the IT infrastructure governed by the dependency edges of the IT topology graph data structure, paralleling SRI's plurality of monitors deployed at distinct network locations; and (2) enumerating the categories of data each agent collects run-time information and configuration information paralleling SRI's enumerated categories of network traffic data obtained by direct packet-level examination, thereby distinguishing both from derived statistics or aggregated measures.
The Examiner respectfully disagrees.
With respect to the argument the Examiner notes that while the Examiner acknowledges that the amendments add specificity relative to the prior claim version by identifying two monitoring agents, tying their deployment locations to the topology graph's dependency edges, and enumerating two categories of collected data, this recitation does not achieve the species or degree of technical particularity that was dispositive in SRI for either of the two proposed parallels.
Regarding the first proposed parallel deployment locations the SRI court's finding did not rest merely on the fact that monitors were deployed at distinct, structurally defined locations in a network. The dispositive feature was that a plurality of monitors was deployed at distinct locations, each performing local detection by directly examining specific categories of packet-level data at those locations, and feeding detection reports upward into a specified hierarchical monitor architecture. The structural significance of the deployment locations in SRI was inseparable from the technical function each monitor performed at its location direct packet-level examination and the hierarchical architecture through which their outputs were integrated. By contrast, amended claim 1 recites a first monitoring agent executing on the primary IT resource and a second monitoring agent executing on a topologically dependent IT resource, with those locations fixed by the dependency edges of the topology graph. While tying deployment locations to topology graph edges is a more specific recitation than a generic reference to monitoring agents at large, it defines a relational constraint which resources the agents reside on without specifying the technical protocol by which the agents communicate, any hierarchical architectural relationship among them comparable to SRI's specified multi-tier monitor hierarchy, or the technical mechanism by which their collected data is transmitted and processed. Two agents at topologically related locations is a structural arrangement, but it is not the same species of specified distributed-plus-hierarchical monitoring architecture that the SRI court found dispositive.
Regarding the second proposed parallel enumerated data categories the SRI court's construction of network traffic data as data obtained by direct examination of network packets was significant not merely because the data was directly obtained rather than derived, but because the enumerated packet-level categories packet type, header, routing information specified with technical particularity what each monitor directly examined at the network level, providing the technical grounding for the court's finding that the claim recited a specific detection technique rather than a generic monitoring function. The data categories enumerated in amended claim 1 run-time information and configuration information are functional classifications that describe broad classes of operational data without specifying the particular technical parameters, signals, thresholds, or operational characteristics that the monitoring agents examine to determine whether an operational state change was successful. That these categories are obtained directly from agents resident on the IT resources, rather than from derived statistics, establishes the directness of the data source but does not supply the missing technical specificity as to what within those broad categories is examined and how the agents technically arrive at an abnormal-condition or failure determination. In SRI, it was the combination of what data was examined and how the monitoring architecture was structured that constituted the specific technique; amended claim 1 specifies broad data classes and a two-agent relational arrangement, neither of which individually nor in combination reaches that level of technical specificity. Accordingly, the Advisory Action's objections are not fully addressed by the amendments, and the rejection is maintained.
The Applicant argues that the amended claim's recitation that the second automation tool integrates monitoring data from two agents "in accordance with the edges of the at least one IT topology graph data structure" constitutes the same species of hierarchical report integration the Federal Circuit credited in SRI, and that the claim goes further than SRI because the integrated determination operates as a conditional trigger that automatically invokes rollback and workflow regeneration without human review, thereby changing what the machine does next rather than merely surfacing a result for human consumption.
The Examiner respectfully disagrees.
With respect to the argument the Examiner acknowledges that the amendment adds the specification that monitoring data integration is performed in accordance with the topology graph's dependency edges, which provides a defined structural basis for the integration step that was absent from prior claim versions, and that the claim's conditional trigger for rollback and regeneration represents a more complete automation loop than was previously recited. These additions have been carefully considered. However, neither the topology-edge-governed integration nor the conditional trigger establishes the species of hierarchical report integration that was dispositive in SRI, and the claim's extension beyond SRI's output does not supply the missing technical specificity.
Regarding the proposed parallel to SRI's hierarchical report integration, the Federal Circuit's eligibility finding in SRI rested on a specified multi-tier monitor architecture in which individual network monitors, each performing local packet-level detection at distinct network locations, generated detection reports that were automatically received and integrated by one or more hierarchical monitors positioned above them in the architecture. The hierarchical integration in SRI was technically significant because it described a particular architectural arrangement distributed lower-level monitors feeding upward into higher-level integrating monitors that itself constituted the claimed technical solution to the network intrusion detection problem. The integration was not merely performed according to a defined structural relationship; the specific multi-tier architecture was the structural relationship, and the integration mechanism was inseparable from it. By contrast, amended claim 1 recites that a single, generically-described second automation tool correlated with a monitor skill receives monitoring data from two agents and integrates that data in accordance with the topology graph's dependency edges. Specifying that integration is performed in accordance with topology edges defines the relational basis on which the integration operates which resources' data is weighted or ordered according to their dependency relationships but does not specify the technical mechanism by which that integration is carried out, what the integration operation produces at a technical implementation level, or any multi-tier hierarchical architectural relationship among multiple monitoring components comparable to SRI's specified monitor hierarchy. A single automation tool integrating data from two agents according to a topological relationship is a two-level functional arrangement, not a specified hierarchical monitor architecture of the kind the SRI court found dispositive.
Regarding Applicant's argument that the claim goes further than SRI because the integrated determination triggers further automated machine action rather than being surfaced for human review, the Examiner does not dispute that closing the remediation loop within automated machine components such that the monitoring determination directly triggers rollback and workflow regeneration without human intervention represents a more complete automation of the remediation process than was previously claimed. However, the degree of automation of a process's output does not determine whether the underlying process is recited with sufficient technical specificity to integrate an abstract idea into a practical application. As established in MPEP 2106.05(f), mere automation of a process using generic computer components, even complete end-to-end automation with no human in the loop, does not integrate a judicial exception into a practical application where the automation is accomplished through generically-described components performing their generic functions. The conditional trigger recited in amended claim 1 responsive to determining that the operational state was not changed successfully, automatically invoking the third automation tool to roll back the change describes a generic if-then automation pattern applied to the IT remediation context, in which a generically-described automation tool is invoked upon detection of a failure condition. Neither the condition evaluated nor the corrective action invoked is specified at a technical implementation level; the claim specifies the logical structure of the decision (if failure, then rollback) and the functional outcome (reset to prior state) without specifying the technical mechanism by which the second automation tool arrives at its failure determination or by which the third automation tool technically accomplishes the reset. That the result of this generic conditional logic changes what the machine does next, rather than what a human does next, is a difference in the degree and direction of automation, not a difference in the technical character of the underlying operations that would establish integration into a practical application. Accordingly, the rejection is maintained.
The Applicant argues on page 26 that the amended claim recites a specific technique for solving a technological problem in IT infrastructure the ordered action-monitor-rollback-regenerate sequence and that as amended, this technique is now recited with the specific operational particulars the Advisory Action identified as missing, including where telemetry is collected, what it consists of, how it is integrated, what condition triggers correction, what the correction does, and how the substitute task is chosen.
The Examiner respectfully disagrees.
With respect to the argument the Examiner acknowledges that the amendments have added meaningful operational detail to the claim, and that the action-monitor-rollback-regenerate sequence is now recited with considerably more specificity than in prior versions. The Examiner has credited this increased specificity throughout prosecution and does not minimize it here. However, the "specific technique" the Federal Circuit found dispositive in SRI was not defined by specifying the roles, triggers, outcomes, and decision criteria of an ordered sequence of generically-described components; it was defined by the particular technical mechanism by which each component carried out its assigned function specifically, what packet-level data the monitors directly examined, and how the specified multi-tier hierarchical architecture technically accomplished the integration of detection reports across the network. In SRI, the specificity of the claimed technique resided in how the detection and integration were technically implemented, not merely in what the sequence was designed to accomplish or what conditions governed its execution.
Evaluating each of the operational particulars Applicant identifies against this standard, the Examiner finds that each specifies the decision logic, relational structure, or functional outcome of the claimed sequence at a level that does not reach the technical implementation specificity that was dispositive in SRI. Where telemetry is collected agents executing on the primary IT resource and on a topologically dependent second IT resource in accordance with the topology edges specifies the relational locations of the agents but not the technical protocol by which they operate, communicate, or report. What the telemetry consists of run-time information and configuration information enumerates broad functional data classes without specifying the particular technical parameters, signals, or operational characteristics within those classes that the agents examine to detect an abnormal condition or failure, in contrast to SRI's enumerated packet-level data categories that specified with technical particularity what each monitor directly examined at the network level. How the telemetry is integrated in accordance with the edges of the IT topology graph data structure specifies the structural relationship that governs the integration but not the technical mechanism by which a single automation tool carries out that integration at an implementation level, in contrast to SRI's specified multi-tier hierarchical monitor architecture in which the integration mechanism was itself a defined architectural arrangement of components. What condition triggers correction monitoring data specifying an abnormal condition or failure of either resource occurring after the invoking of the first automation tool specifies the logical predicate of the conditional trigger but not the technical means by which the second automation tool determines that an abnormal condition or failure has occurred from within the broad classes of run-time and configuration information it receives. What the correction does resets the IT resource to the previous state existing prior to the invoking of the first automation tool specifies the functional outcome of the rollback operation but not the technical mechanism by which the third automation tool accomplishes that reset at an implementation level, such as what specific operations are executed on the computing device, storage device, or network resource to restore its prior state. How the substitute task is chosen a fallback skill selected from the skill relationship graph by a match score less than the action skill's score and greater than a minimum threshold, having an associated rollback skill specifies the decision criterion for fallback selection with useful particularity, and the Examiner credits this as the most technically specific of the operational particulars Applicant identifies. However, this specificity is specificity of decision logic the scoring and selection criterion rather than specificity of a technical mechanism that itself constitutes a claimed improvement to how the IT infrastructure, automation tools, or monitoring agents technically function.
Taken together, the operational particulars Applicant identifies define the what, where, and when of the claimed sequence with meaningful precision, but they do not define the how at a technical implementation level that is, the specific technical mechanism by which each component carries out its assigned function which is the species of specificity that was dispositive in SRI. The distinction between specificity of decision logic and specificity of technical implementation mechanism is not a formalistic one; it reflects the substantive difference between a claim that recites a particular way of organizing and executing an information-processing workflow which, however specifically described, remains an application of generic components to perform the abstract process of collecting, correlating, and acting on IT incident data and a claim that recites a specific technical mechanism that itself constitutes an improvement to how the underlying technology functions, as in SRI. Accordingly, the amended claim does not recite a specific technique of the kind and degree found dispositive in SRI, and the rejection is maintained.
The Applicant argues on page 27 that amended claim 1 satisfies the DDR Holdings/SRI "override" rationale for eligibility because it overrides the conventional sequence in which a failed remediation action leaves the affected IT resource in a failed state pending human escalation, by instead automatically resetting the IT resource to its prior state, regenerating the workflow with a fallback task selected from the skill relationship graph data structure, and re-executing the regenerated workflow without human intervention.
The Examiner respectfully disagrees.
With respect to the argument the Examiner notes that the DDR Holdings/SRI override rationale requires that the claimed technical solution depart from how the underlying technology itself conventionally operates at a technical level, not merely that it replaces a human actor in an otherwise conventional corrective process with an automated one. This distinction is critical and dispositive here.
In DDR Holdings, the eligible claims technically modified how a web server responded to a hyperlink click rather than the server conventionally directing the browser to the third party's website, the claimed system generated a hybrid web page that retained the host site's look and feel while displaying third-party content, thereby technically altering the behavior of the web server itself in response to a conventional browser-server interaction. The override was rooted in a specific technical modification to the conventional operation of web server and browser technology, disclosed with sufficient implementation detail. In SRI, similarly, the override was rooted in a specific network-monitor architecture that technically changed how intrusion detection was carried out across an enterprise network the distributed deployment of monitors performing local packet-level detection feeding into a hierarchical integration architecture represented a departure from how network monitoring conventionally operated at a technical level, not merely a replacement of a human network administrator with an automated tool.
By contrast, the "conventional sequence" Applicant identifies a failed remediation action leaving an IT resource in a failed state pending human escalation and intervention is not a technical limitation of how computing resources, automation tools, monitoring agents, or network infrastructure conventionally operate at a technical level. It is a description of a conventional human organizational workflow, as the specification itself confirms. Paragraph [0029] frames the underlying problem expressly in terms of SRE teams being overwhelmed, blinded by unforeseen problems, and struggling to quickly identify resolution actions a characterization of a human operational and organizational challenge, not a technical constraint of the computing or network infrastructure itself. The conventional sequence Applicant describes is therefore the conventional human process of IT incident management, not the conventional technical behavior of the computing systems involved.
Replacing the human escalation and intervention step with automated tools that detect failure, invoke a rollback tool, regenerate the workflow, and re-execute it is the automation of a conventional human organizational process using generic automation tools performing their generic cataloged functions. This is precisely the scenario addressed in MPEP 2106.05(f), which distinguishes between claims that recite a technological solution to a technological problem of the kind found in DDR Holdings and SRI and claims that merely automate a manual or organizational process using generic computer components, however completely that automation eliminates human involvement. The fact that the claimed sequence executes entirely within automated machine components without human intervention does not transform the automation of a human organizational process into a technical override of how the underlying computing technology conventionally operates; it is a difference in who performs the conventional corrective steps, not a difference in the technical character of those steps or the technical behavior of the systems on which they are performed.
Furthermore, the specification's own description of the rollback and fallback mechanisms at paragraphs [0040]–[0041], [0058], and [0095], cited by Applicant as disclosing the override, confirms this characterization. These paragraphs describe the rollback and fallback mechanisms in terms of what skill or action is substituted for example, uninstalling Java as the rollback for installing Java and what decision logic governs the substitution, without disclosing any technical modification to how the affected computing device, storage device, network resource, or automation tools themselves function at a technical level. The specification discloses a decision-making and task-substitution framework, not a technical departure from how the underlying technology conventionally operates, and the amended claim tracks that functional level of disclosure. Accordingly, the amended claim does not satisfy the DDR Holdings/SRI override rationale, and the rejection is maintained.
The Applicant argues on page 27 that amended claim 1 is distinguishable from Electric Power Group because the subject of the claim is not an external system managed by computers but rather the IT infrastructure itself changing, verifying, reversing, and restoring the operational state of applications, computing devices, storage devices, or network resources and that the specification identifies the resulting benefit as improved IT infrastructure operation and availability.
The Examiner respectfully disagrees.
With respect to the argument the Examiner notes the distinction SRI drew from Electric Power Group was not simply whether the claimed system's subject matter is a computer network or IT infrastructure as opposed to an external physical system such as a power grid. The operative distinction was whether the claim recites a specific technical means of improving the operation of the system being addressed, as opposed to merely applying generic computer functions collecting, analyzing, correlating, and acting on information to manage or monitor that system, regardless of what that system is. Subject matter proximity to computer technology does not, standing alone, establish eligibility; the claim must reflect a specific technical mechanism by which an improvement to that technology is achieved.
This is clearly illustrated by examining what the Electric Power Group court actually found ineligible. The claims in Electric Power Group recited gathering data from various sources related to a power grid, analyzing that data, and displaying results generic data-processing functions applied to power-grid monitoring and management. The court found those claims ineligible not because the subject matter was a power grid rather than a computer network, but because the claimed means of gathering, analyzing, and acting on information were generic, without any specific technical mechanism that itself constituted an improvement to how the sensors, computers, or network components involved actually operated. SRI was eligible not merely because its subject matter was a computer network, but because the claim specified a particular technical detection technique enumerated packet-level data categories, distributed monitors, and a hierarchical integration architecture that changed how the network's own intrusion detection function was technically carried out, with the specific technical mechanism being itself the claimed improvement.
Applying this framework to amended claim 1, the claim recites receiving an IT incident notification, retrieving data structures, executing correlation operations, generating a skill set, classifying skills, generating a workflow, and invoking generically-described catalog-selected automation tools to perform state-change, monitoring, and rollback functions which are generic data-processing and tool-invocation functions applied to the field of IT infrastructure remediation. This is closely analogous to Electric Power Group's generic collect-analyze-act functions applied to power-grid management, not to SRI's specific technical detection and integration architecture. That the resources being acted upon are computing devices, storage devices, and network resources rather than power-grid components does not supply the missing technical specificity; Electric Power Group's claims likewise acted directly upon the power grid monitoring its state and directing corrective action and that direct operational relationship to the underlying system was insufficient for eligibility precisely because the claimed means of action were generic.
Amended claim 1 does not specify any technical modification to how the automation tools, monitoring agents, computing devices, storage devices, or network resources themselves technically operate or interoperate. It specifies only that generically-described, catalog-selected automation tools are invoked to perform generic state-change, monitoring, and rollback functions, selected according to a skill-classification and scoring scheme. The automation tools are described in the specification at paragraph [0046] as pre-existing catalog entries performing whatever generic functions they were already cataloged as providing; the claim does not recite any modification to those tools or to the IT resources on which they operate that would constitute a technical improvement to how those components function. As to the specification's identification of improved IT infrastructure operation and availability as the resulting benefit, the Examiner notes, consistent with the December 5, 2025 Desjardins memorandum and MPEP 2106.04(d)(1), that a stated benefit of improved system operation does not establish eligibility unless the specification describes the specific technical mechanism by which that improvement is achieved with sufficient detail that a person of ordinary skill in the art would recognize it as a genuine technical improvement rather than a conclusory assertion, and the claim itself reflects that disclosed mechanism. Here, the specification frames the identified benefit at paragraph [0067] as flowing from the ability to leverage the skills and capabilities of both automated tools and SRE teams an organizational task-allocation and efficiency benefit rather than from a disclosed technical modification to the functioning of the IT resources, automation tools, or monitoring agents themselves. A benefit characterized in organizational and operational efficiency terms, achieved through the application of generic tools to perform their generic functions according to a skill-classification framework, does not constitute the type of technical improvement to computer functionality that distinguished SRI from Electric Power Group. Accordingly, the subject-matter proximity of amended claim 1 to the IT infrastructure does not establish the SRI-type improvement to computer or network functionality, and the rejection is maintained.
The Applicant argues on pages 27-28 that because the Office Action acknowledged that the operative claim steps cannot practically be performed in the human mind, no other enumerated grouping applies, the claim recites no mathematical formula or method of organizing human activity, every actor is a machine, and the workflow executes without human intervention, the analysis must end favorably at Prong One.
The Examiner respectfully disagrees.
With respect to the argument the Examiner notes hat as explained in response to Arguments 2 and 3 above, the Office Action's acknowledgment that specific limitations cannot practically be performed in the human mind was expressly limited to those identified limitations and does not extend to the claim as a whole. The claim continues to recite, as core operational steps, the receipt of an IT incident notification, retrieval of data structures, execution of correlation operations, generation of a skill set, classification of skills, and generation of a workflow limitations that, under their broadest reasonable interpretation, describe collecting, correlating, and organizing information to reach an operational decision, a process a skilled IT analyst could perform mentally when evaluating incident data to decide on a remediation course of action. That the claim also recites certain limitations that cannot be mentally performed does not remove these remaining limitations from the mental process grouping; the August 4, 2025 Memorandum instructs examiners not to expand the mental process grouping to improperly capture AI-specific limitations, but it does not instruct examiners to disregard other limitations in the same claim that independently recite a mental process. Additionally, Applicant's argument that the "without human intervention" language and the machine-only actors remove the claim from the mental process grouping conflates the question of who executes the steps with the question of whether the steps describe a concept that can be performed mentally. A claim can automate end-to-end a process that a human could perform mentally here, an IT analyst reviewing incident data, topology, and remediation knowledge to decide on and order a course of action without thereby removing the claim from the mental process grouping as to those specific steps, because the grouping asks whether the limitation under its broadest reasonable interpretation covers mental performance, not whether the claim as drafted requires human execution. Furthermore, Applicant's citation to the specification's characterization of the invention as directed to computer logic rather than human actions is the type of attorney characterization that MPEP 2106.04(a) instructs examiners to evaluate against the claim language itself rather than accept at face value. Accordingly, because the claim as a whole recites a judicial exception through its data-collection, correlation, and workflow-organization limitations, the analysis does not end favorably at Prong One, and the rejection is maintained.
The Applicant argues on page 28 that the prior Office Action's sole substantive Prong Two objection directed to the generality of the machine learning and NLP limitations is moot as to the independent claims because those limitations have been removed from the independent claims, and that the closed-loop execution architecture now recited in the independent claims independently satisfies Prong Two, with SRI confirming that eligibility turns on the specificity of the claimed arrangement of machine components rather than on the level of algorithmic or computational detail recited.
The Examiner respectfully disagrees on both points.
With respect to arguments the Examiner notes that regarding Applicant's characterization of the prior Prong Two objection as the Office's "sole substantive" objection directed exclusively to the generality of the machine learning and NLP limitations, this characterization does not accurately reflect the scope of the prior Office Action's Prong Two analysis. While the Office Action did identify the generality of the machine learning and NLP limitations as a basis for the Prong Two finding, the analysis did not rest solely on those limitations. The Office Action evaluated the claim as a whole at Prong Two, including the correlation operations, skill classification, workflow generation, and the action-monitor-rollback architecture, and found that the overall combination of elements described generic machine learning, NLP, and monitoring functions at a level of generality that did not reflect a specific technical improvement to computer technology sufficient to integrate the abstract idea into a practical application. The removal of the explicit NLP limitation from the independent claims reduces the scope of one component of the prior Prong Two analysis but does not render that analysis moot, because the remaining limitations correlation operations, skill classification, ML-based task selection and ordering, workflow generation, and the action-monitor-rollback-regenerate sequence continue to be recited at a functional level that does not reflect a specific technical improvement to how the underlying IT resources, automation tools, or monitoring agents technically function, for the reasons set forth throughout prosecution and further addressed below.
Regarding Applicant's argument that the closed-loop execution architecture independently satisfies Prong Two, and that SRI confirms eligibility turns on the specificity of the claimed arrangement of machine components rather than on computational or algorithmic detail, the Examiner has addressed this argument extensively in the responses to Arguments 4 through 9 above, which are incorporated here in their entirety. As a consolidated response to this argument specifically, the Examiner makes the following observations.
First, while the Examiner agrees that SRI's eligibility did not require recitation of a specific algorithm or computational mechanism for the monitors' internal analysis, this does not mean SRI imposed no specificity requirement as to the arrangement of machine components and data. To the contrary, as explained in the responses to Arguments 5 and 6, SRI's claim specified with technical particularity the enumerated categories of packet-level data each monitor directly examined, the distributed deployment of a plurality of monitors at distinct network locations, and the hierarchical multi-tier architecture by which detection reports were integrated details that together constituted the specific technical mechanism of the claimed intrusion detection technique. The SRI framework therefore requires specificity of component arrangement and data at a technical implementation level, not merely specificity of the roles components play, the data classes they process, and the logical conditions governing their invocation.
Second, the list of specifics Applicant identifies in the amended claim data sources, data categories, consuming component, integration manner, condition evaluated, machine act upon failure, and further machine act triggered defines the decision logic, relational structure, and functional outcomes of the closed-loop architecture with meaningful precision, and the Examiner has consistently credited this increased specificity throughout prosecution. However, as explained in the responses to Arguments 5 through 7, each of these specifics describes what the sequence does and under what conditions at a functional level, rather than how each component technically carries out its assigned function at an implementation level. The source of the monitoring data is identified relationally by topology graph edges but without specifying the technical protocol by which the agents operate or report. The categories of data run-time information and configuration information are broad functional classes without specifying the particular technical parameters examined to detect an abnormal condition. The manner of integration in accordance with topology graph edges specifies the relational basis of integration without specifying the technical mechanism of integration. The machine act upon failure invoking a third automation tool to reset to prior state specifies the functional outcome without specifying what technical operations accomplish that reset. These are functional descriptions of a decision-making and execution framework, not specifications of a technical mechanism that itself constitutes an improvement to how the underlying technology operates, which is what the improvement consideration under MPEP 2106.05(a) and the precedential Desjardins decision require.
Third, and importantly, the Desjardins decision, designated precedential on November 4, 2025 and incorporated into the MPEP by the December 5, 2025 memorandum, reinforces that the improvement consideration requires that the specification describe how the claimed system itself operates in a technically improved manner not merely what decision logic it implements or what organizational efficiency it achieves and that the claim reflect that disclosed technical improvement. In Desjardins, the claims were found eligible at Prong Two because the specification disclosed a specific improvement to how the machine learning model itself operated training to learn new tasks while protecting knowledge about previous tasks to overcome catastrophic forgetting, with enumerated technical benefits including reduced storage capacity and reduced system complexity and the claims reflected that specific operational improvement through limitations directed to adjusting model parameters to optimize performance on a new task while protecting performance on prior tasks. Here, by contrast, the specification discloses the decision logic of the claimed system in useful detail but does not disclose a specific improvement to how the automation tools, monitoring agents, IT resources, or machine learning model themselves technically operate, and the claims reflect that functional level of disclosure by reciting roles, conditions, and outcomes rather than specific technical mechanisms of improvement.
Accordingly, the removal of the NLP limitation from the independent claims does not moot the Prong Two analysis, the closed-loop architecture does not independently satisfy Prong Two under the SRI framework for the reasons consistently maintained throughout prosecution, and the rejection is maintained.
The Applicant argues on pages 30-31 that the amended claim recites a specific, ordered, self-correcting feedback loop constituting a particular sequence of machine operations producing a concrete technical result, that the specification satisfies both requirements of MPEP 2106.04(d)(1) by identifying the prior-art deficiency, the curing mechanisms, and the resulting technical benefit, and that the amended claims now incorporate the specific skill relationship graph, comparative match-score criterion, and run-time and configuration information limitations that the Advisory Action identified as residing in the specification but absent from prior claim versions.
The Examiner respectfully disagrees.
With respect to the argument the Examiner acknowledges that the amendments have incorporated into the independent claims several specific mechanisms that were previously identified only in the specification the skill relationship graph data structure recording the classified action and rollback skill relationships, the comparative match-score criterion for fallback skill selection, and the run-time and configuration information collected from two topologically related IT resources. These additions have been carefully considered and represent a meaningful advance in claim specificity relative to prior versions. However, the Examiner finds that the claim still does not satisfy the two requirements of MPEP 2106.04(d)(1) as clarified by the December 5, 2025 Desjardins memorandum. As to the first requirement, while the specification at paragraph [0029] identifies a stated shortcoming of prior AIOps tools, the paragraphs cited as disclosing the curing mechanism paragraphs [0040]–[0041] (defining rollback and fallback skills by functional example), [0058] and [0095] (describing that alternative sequences may be generated dynamically), and [0062]–[0064] and [0094]–[0095] (describing ML-based scoring of alternative skill sequences) describe what the invention does at a functional level without disclosing the specific technical mechanism by which a monitoring agent determines that an IT resource has experienced an abnormal condition or failure, by which a rollback automation tool technically resets the IT resource to its prior state at an implementation level, or by which the skill relationship graph is traversed and the match-score comparison is technically executed. The Desjardins decision, which is now precedential and incorporated into the MPEP per the December 5, 2025 memorandum, requires that the specification describe the improvement to how the machine learning model or technical system itself operates not merely the decision logic it implements in a manner apparent to a person of ordinary skill in the art. The specification here discloses the decision logic in useful detail but does not disclose a technical improvement to how the underlying IT resources, automation tools, or monitoring agents themselves function, comparable to the improvement to the machine learning model's own operation in Desjardins (addressing catastrophic forgetting, reducing storage, reducing system complexity). As to the second requirement, while the amended claims now recite the skill relationship graph and the match-score criterion, these limitations define the structure and criterion of the decision logic rather than the specific technical means by which the claimed improvement to IT infrastructure operation is achieved, and accordingly the claim does not adequately reflect a specific technical improvement to computer or network functionality as opposed to a specific improvement to the information-processing decision logic used to manage IT operations. Accordingly, the rejection is maintained.
The Applicant argues on pages 32-33 that three related points: (1) the monitoring data is not insignificant extra-solution activity under MPEP 2106.05(g) because it serves as the decision-determinative input to the conditional branch governing rollback and regeneration; (2) the three automation tools are not interchangeable generic computer components under MPEP 2106.05(f) because they are non-interchangeable, structurally and temporally constrained in defined roles recorded in the skill relationship graph data structure, with the third tool invoked only upon failure to reverse the specific change made by the first; and (3) the claim effects a transformation of a particular article under MPEP 2106.05(c) because the amended claim now specifies the transformation at both ends of the operational loop the first automation tool changes the operational state and the third resets it to a temporally defined prior state with the intervening determination made from run-time and configuration information collected from the affected resource and a topologically dependent resource.
The Examiner respectfully disagrees.
With respect to the argument the examiner notes that regarding Applicant's first point under MPEP 2106.05(g), the Examiner agrees that the monitoring data is not insignificant extra-solution activity in the sense of being merely incidental to the claimed abstract idea. The monitoring data serves a decision-determinative function as the input to the conditional branch governing whether rollback and regeneration occur, and the Examiner does not characterize it as incidental data gathering appended to an otherwise complete abstract idea. This characterization is consistent with the prior Office Action's Prong Two analysis, which did not rest primarily on an insignificant-extra-solution-activity theory with respect to the monitoring and rollback limitations specifically. However, the observation that monitoring data is not incidental that it plays a functional role in the claimed conditional logic goes to whether the limitation constitutes extra-solution activity at all, not to whether the limitation, once recognized as integral to the claimed decision logic, is recited with sufficient technical specificity to integrate the abstract idea into a practical application. As established throughout prosecution and in the responses to Arguments 5 through 12 above, the monitoring data limitation specifies that run-time and configuration information is received from two agents at topologically defined locations, which identifies the data source and broad data classes but does not specify the particular technical parameters examined or the technical means by which the agents arrive at an abnormal-condition or failure determination. The functional significance of the monitoring data within the claimed decision logic does not supply the missing technical specificity as to how that determination is technically made, and it is the absence of that technical specificity not the characterization of the monitoring data as extra-solution activity that underlies the Prong Two finding. Accordingly, while the Examiner agrees the monitoring data is not insignificant extra-solution activity, this agreement does not advance the eligibility analysis in Applicant's favor.
Regarding Applicant's second point under MPEP 2106.05(f), the Examiner has consistently acknowledged throughout prosecution, and reaffirms here, that the three automation tools occupy non-interchangeable, structurally and temporally defined roles in the claimed sequence this was expressly credited in the prior Office Action at page 8 as adding specificity relative to a bare abstract idea, and that credit is not withdrawn. The Examiner further acknowledges that the amendment's addition of the skill relationship graph data structure as the source from which skill classifications and rollback relationships are recorded and retrieved adds a defined structural basis for the role assignments that was absent from prior claim versions. However, MPEP 2106.05(f)'s inquiry is not whether the claimed computer components occupy distinct, non-interchangeable roles it is whether those components are invoked to perform their generic, pre-existing functions as catalog-selected tools, as opposed to being modified or specially configured to provide a new technical capability that constitutes an improvement to how the underlying technology operates. As established throughout prosecution, the three automation tools are pre-existing, catalog-selected tools drawn from the automation tools catalog data structure, as disclosed at specification paragraph [0046]; they perform whatever generic action, monitoring, or rollback functions they were already cataloged as providing. The skill relationship graph data structure and the match-score criterion define the logic by which these generic tools are selected and sequenced, but they do not modify or specially configure the tools themselves. Defining a structured, non-interchangeable pattern of invocation for pre-existing generic tools according to a skill-classification and scoring framework is a particular pattern of use of those generic tools, not a technical modification to the tools themselves that would take the claim beyond a mere "apply it" instruction under MPEP 2106.05(f). The structural and temporal constraints Applicant identifies are constraints on the decision logic governing tool invocation, not constraints that reflect a technical improvement to how the tools, monitoring agents, or IT resources themselves function, which is the distinction MPEP 2106.05(f) requires.
Regarding Applicant's third point under MPEP 2106.05(c), the Examiner acknowledges that the amendment now specifies the transformation at both ends of the operational loop with greater precision than prior claim versions the first automation tool executes operations that change an operational state of a named class of IT resource, and the third automation tool executes operations that reset that IT resource to the state it occupied prior to the first tool's invocation, with the intervening determination made from run-time and configuration information from two topologically related resources. The Examiner further acknowledges that tying the reversion to a particular, temporally defined prior state of a particular machine adds specificity over the prior claim's generic reference to rolling back a change. These additions represent a genuine improvement in claim precision and have been carefully considered. However, the transformation consideration under MPEP 2106.05(c), as derived from the Bilski and Diehr line of authority, requires that the transformation be tied to a specific, technically-described process rather than an abstractly-claimed change of state effected by invoking an unspecified catalog-selected automation tool. While the amended claim specifies the temporal reference point of the prior state the state existing prior to the invoking of the first automation tool and identifies the class of article transformed an application, computing device, storage device, or network resource it does not specify what physical or technical operations the first automation tool executes to change the operational state or what physical or technical operations the third automation tool executes to reset it to the prior state at an implementation level. The claim recites that these tools "execute operations" that achieve these functional outcomes, without specifying the nature of those operations at a technical level for example, what specific hardware reconfiguration, memory modification, storage-level operation, network configuration change, or other technically-described implementation step is performed. The transformation consideration requires more than identifying that a named class of article undergoes a state change and reversion effected by generic catalog-selected tools; it requires that the transformation be tied to a specific technical process, which is absent here for the same reasons identified throughout prosecution.
Considering all three of Applicant's points together, and consistent with the precedential Desjardins decision and MPEP 2106.04(d)(1) and 2106.05(a), the additional elements of the amended claim while adding meaningful specificity to the decision logic, structural constraints, and operational scope of the claimed system relative to prior versions do not individually or in combination reflect a specific technical improvement to the functioning of the automation tools, monitoring agents, or IT resources themselves at an implementation level. The claim recites a sophisticated and specifically-described decision-making and execution framework applied to IT incident remediation using generic catalog-selected automation tools performing their pre-existing generic functions, which does not integrate the judicial exception into a practical application under Step 2A, Prong Two. Because the Prong Two finding is maintained, the Step 2B analysis is reached, and for the same reasons that the additional elements do not integrate the abstract idea into a practical application at Prong Two, they do not amount to significantly more than the abstract idea at Step 2B. Accordingly, the rejection is maintained.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-11, 13-20 and 22-24 are rejected under 35 U.S.C. 101 because the claimed
Claims 1–11, 13–20, and 22–24 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. The claims recite the abstract idea of collecting, correlating, and organizing information technology incident information to identify, select, order, and execute remediation tasks a mental process that, under its broadest reasonable interpretation, covers performance of the foundational claim steps in the human mind but for the recitation of generic computer components. This judicial exception is not integrated into a practical application because the additional elements beyond the abstract idea, considered individually and in combination, do not reflect a specific technical improvement to the functioning of a computer or to another technology or technical field; rather, they amount to the application of generically-described machine learning, correlation, and automation tool invocation functions to perform the abstract idea using generic computer components. The claims do not include additional elements sufficient to amount to significantly more than the judicial exception because the additional elements constitute no more than mere instructions to apply the abstract idea using generic computer components and generic catalog-selected automation tools performing their pre-existing generic functions.
STEP 1
Regarding Step 1 of the Subject Matter Eligibility Test for Products and Processes, claims 1–11, 13–19, and 22 are directed to a method (process); claim 20 is directed to a non-transitory computer-readable medium (manufacture); and claim 24 is directed to an apparatus (machine). Therefore, the claims fall within the statutory categories of invention.
STEP 2A, PRONG ONE
Identification of the Abstract Idea
The independent claims 1, 20, and 24 recite the following specific limitations that constitute the identified abstract idea:
Receiving an information technology (IT) incident notification specifying an IT incident;
Retrieving at least one IT topology graph data structure associated with at least one IT resource corresponding to the IT incident, the data structure comprising nodes representing IT resources and edges representing dependencies between them;
Generating at least one knowledge graph data structure comprising nodes corresponding to IT incidents and IT remediation tasks and edges representing relationships between them;
Executing at least one first correlation operation that correlates the IT topology graph data structure with the knowledge graph data structure to identify one or more IT remediation tasks associated with the IT resource;
Selecting, using a machine learning model, one or more IT remediation tasks for handling the IT incident;
Generating, using the machine learning model and based on results of the first correlation operation, an ordering of the one or more IT remediation tasks;
Generating an IT remediation task skill set by identifying one or more skills in a plurality of predetermined skills that are associated with the IT remediation tasks;
Classifying the skills as one of an action skill type, a monitor skill type, a fallback skill type, or a rollback skill type, and recording those skills in a skill relationship graph data structure; and
Executing at least one second correlation operation that correlates an automation tools catalog data structure with the IT remediation task skill set.
Abstract Idea Grouping Analysis – Mental Process
These limitations, under their broadest reasonable interpretation, collectively describe the abstract idea of collecting, correlating, and organizing information about an IT incident to identify and order remediation tasks a concept that a skilled IT analyst could perform mentally, or with the aid of pen and paper, when reviewing incident data, consulting known remediation knowledge, and deciding on a course of action. Specifically:
The step of receiving an IT incident notification is the mental act of becoming aware of an IT problem, an observation that can be performed by a human IT analyst reviewing an alert or ticket.
The step of retrieving an IT topology graph data structure encompasses the mental act of consulting a known network diagram or topology map to identify the IT resources associated with an incident, including understanding the dependency relationships among those resources a process a skilled SRE performs routinely when reviewing network documentation.
The step of generating a knowledge graph data structure comprising nodes for IT incidents and remediation tasks and edges for their relationships encompasses the mental act of organizing known information about IT incidents and remediation procedures into a structured representation the kind of conceptual mapping a skilled IT analyst performs mentally or in notes when reviewing remediation documentation.
The step of executing a first correlation operation that correlates the topology graph with the knowledge graph to identify IT remediation tasks encompasses the mental act of cross-referencing the topology information with known remediation knowledge to identify which remediation steps apply to which affected IT resources a process an IT analyst performs mentally when reviewing incident data against known knowledge bases and runbooks.
The steps of generating an IT remediation task skill set and classifying skills as action, monitor, fallback, or rollback types and recording them in a skill relationship graph data structure encompass the mental acts of identifying what skills are required to perform each remediation task and categorizing those skills by type judgments and organizational decisions a human IT manager makes mentally when planning remediation workflows.
The step of executing a second correlation operation that correlates the automation tools catalog with the skill set encompasses the mental act of matching available tools or personnel to the required skills a matching process a human IT manager performs when assigning resources to remediation tasks.
The specification itself confirms that these foundational steps correspond to a process conventionally performed by human personnel. As stated at paragraph [0029], "SRE teams need to be ahead of application and IT infrastructure outages and resolve incidents before they impact users," and "SRE teams struggle to quickly identify resolution actions for IT incidents as they have to sift through multiple data sources, such as metrics, topology, events, logs, tickets, alerts, and chat conversations" to identify and order remediation actions. The specification further explains at paragraph [0028] that "determining what tasks are needed for addressing an IT incident, what order the tasks need to be performed in, what skills are required to perform the tasks, what human/computing tool resources provide the required skills, and then orchestrating the performance of these tasks" is the underlying problem the invention addresses a characterization that confirms these steps describe a process of human mental activity and decision-making that the claimed invention automates.
The mere recitation of a processor, a memory, computer-readable medium, or generic computing components does not remove these foundational limitations from the mental process grouping. See MPEP 2106.04(a)(2), subsection III.
Important Note Regarding AI-Specific Limitations
Consistent with the August 4, 2025 Memorandum (Reminders on Evaluating Subject Matter Eligibility of Claims Under 35 U.S.C. 101) and MPEP 2106.04(a)(2)(III), the Examiner acknowledges that certain specific limitations recited in the independent claims including generating an ordering of IT remediation tasks using a machine learning model based on correlation results, automatically invoking a first automation tool to execute operations that change an operational state of an IT resource, automatically invoking a second automation tool to integrate monitoring data from agents in accordance with topology graph edges to determine whether an operational state was changed successfully, automatically invoking a third automation tool to reset an IT resource to a prior state, and dynamically regenerating the IT incident remediation task workflow using a fallback skill selected from the skill relationship graph data structure by comparative match score are operations that the human mind is not equipped to perform as a practical matter. Consistent with the August 4, 2025 Memorandum's instruction that examiners not expand the mental process grouping to encompass claim limitations that cannot practically be performed in the human mind, the Examiner does not apply the mental process grouping to these specific limitations. These limitations are properly treated as additional elements and are evaluated at Step 2A, Prong Two below.
The presence of these non-mentally-performable limitations, however, does not remove the claim as a whole from Step 2A, Prong One. As explained above, the claim contains a mixture of limitations: the foundational data-collection, correlation, skill-generation, skill-classification, and workflow-organization steps that can be performed mentally by a skilled IT analyst, and the separately-identified AI-specific and machine-act limitations that cannot. The claim as a whole recites a judicial exception through the former set of limitations, with the latter properly reserved for Prong Two analysis. See August 4, 2025 Memorandum; MPEP 2106.04(a).
Accordingly, independent claims 1, 20, and 24 recite an abstract idea in the form of a mental process, and the analysis proceeds to Step 2A, Prong Two.
STEP 2A, Prong Two
The independent claims 1, 20, and 24 recite the following additional elements beyond the identified abstract idea:
Generating an IT incident remediation task workflow that assigns, for at least one IT remediation task, a first automation tool correlated with an action skill, a second automation tool correlated with a monitor skill, and a third automation tool correlated with at least one rollback or fallback skill;
Automatically executing, without human intervention, the generated IT incident remediation task workflow by: (i) automatically invoking the first automation tool to execute operations that change an operational state of at least one of an application, computing device, storage device, or network resource; (ii) automatically invoking the second automation tool to determine, based on monitoring data received from a first monitoring agent executing on the IT resource and a second monitoring agent executing on a second IT resource dependent on the IT resource in accordance with the topology graph edges, wherein the monitoring data comprises run-time information and configuration information, and wherein the second automation tool integrates the monitoring data in accordance with the topology graph edges to determine whether the operational state was changed successfully; (iii) responsive to determining the operational state was not changed successfully, automatically invoking the third automation tool to roll back the change by resetting the IT resource to its previous state existing prior to invoking the first automation tool;
Dynamically regenerating, without human intervention, the IT incident remediation task workflow to replace the IT remediation task with a fallback IT remediation task correlated with a fallback skill selected from the skill relationship graph data structure as a skill having a match score generated by the machine learning model that is less than the action skill's match score and greater than a minimum threshold score, and having an associated skill of the rollback skill type, and automatically executing the regenerated workflow to restore the IT resource to a stable operational state;
The IT topology graph data structure comprising nodes representing IT resources and edges representing dependencies between them;
The skill relationship graph data structure associating a first skill classified as action type with a second skill classified as rollback type;
One or more processors and/or a non-transitory computer-readable medium storing instructions; and
A memory configured to store a plurality of incident-solution pairs (claim 24).
Analysis of Additional Elements
Improvement to Technology or Technical Field (MPEP 2106.05(a) and MPEP 2106.04(d)(1)):
The Examiner has carefully evaluated whether the specification and claims satisfy the two requirements of MPEP 2106.04(d)(1), as clarified by the precedential Ex Parte Desjardins decision (Appeal No. 2024-000567, PTAB September 26, 2025, designated precedential November 4, 2025) and the December 5, 2025 USPTO Memorandum incorporating Desjardins into the MPEP.
Regarding the first requirement that the specification provide sufficient detail that a person of ordinary skill in the art (POSITA) would recognize the claimed invention as providing an improvement in the functioning of a computer or to another technology or technical field the Examiner acknowledges that the specification at paragraph [0029] identifies a stated shortcoming of prior AIOps tools: their lack of capability to perform exploratory orchestration of mixed-methodology IT incident remediation workflows and their inability to identify skill gaps and coordinate human and automated tool performance of remediation tasks. The specification further discloses at paragraphs [0040]–[0041] rollback and fallback skills defined by functional example (e.g., "Uninstall Java" as the rollback for "Install Java"); at paragraphs [0062]–[0064] and [0094]–[0095] ML-based scoring of alternative skill sequences using probability scores (e.g., Skill A - Skill B (score=0.98) - Skill C vs. alternative Skill A - Skill D (score=0.95) - Skill C); at paragraphs [0058] and [0095] dynamic generation of alternative sequences upon task failure; and at paragraphs [0050]–[0051], [0074], [0087], and [0089] the skill relationship graph data structure recording skill classifications and rollback relationships.
However, the Desjardins decision requires that the specification describe the improvement to how the claimed system itself operates at a technical level not merely the decision logic it implements or the organizational outcome it achieves with sufficient particularity that the improvement would be apparent to a POSITA rather than being merely a conclusory assertion. In Desjardins, the specification disclosed a specific technical improvement to how the machine learning model itself operated, namely training to learn new tasks while protecting knowledge about previous tasks to overcome the specific, enumerated technical problem of catastrophic forgetting, with disclosed technical benefits including reduced storage capacity and reduced system complexity rooted in how the model's own parameters were adjusted during training.
By contrast, the specification paragraphs cited above disclose the decision logic and task-substitution framework of the claimed system at a functional level what skill or action is substituted under what scoring conditions without disclosing the specific technical mechanism by which: (a) the monitoring agents determine that an IT resource has experienced an abnormal condition or failure from within the broad classes of run-time and configuration information they receive; (b) the third automation tool technically resets the IT resource to its prior state at an implementation level; or (c) the dynamic regeneration operation is technically accomplished beyond re-invoking the same scoring and correlation process used to generate the primary workflow. The specification describes at paragraph [0067] that the resulting benefit is improved "IT infrastructure operation and availability of IT resources," but frames this benefit as flowing from the ability to "leverage the skills and capabilities of both automated tools and SREs/SRE teams" an organizational task-allocation and efficiency benefit rather than from a disclosed technical modification to the functioning of the IT resources, automation tools, or monitoring agents themselves. A conclusory statement of beneficial outcome does not satisfy the first requirement of MPEP 2106.04(d)(1). See also Intellectual Ventures I LLC v. Symantec Corp.
Regarding the second requirement that the claim itself reflect the disclosed improvement the Examiner acknowledges that the amended independent claims now incorporate several specific mechanisms previously identified in the specification but absent from prior claim versions: the skill relationship graph data structure recording classified action and rollback skill relationships; the comparative match-score criterion for fallback skill selection; the specification of two monitoring agents at topologically defined locations collecting run-time and configuration information; and the integration of monitoring data in accordance with topology graph edges. These additions represent a meaningful and good-faith improvement in claim specificity relative to prior versions, and the Examiner has carefully considered them. However, where, as here, the specification's disclosures do not themselves establish a specific technical improvement to how the underlying technology operates at a technical implementation level for the reasons stated under the first requirement above, incorporating those disclosures into the claim language does not satisfy the second requirement, because there is no disclosed technical improvement at that level for the claim to reflect. The amended claim recites the skill relationship graph and the match-score criterion as components of the decision-making framework rather than as technical mechanisms that themselves constitute improvements to how the IT resources, automation tools, or monitoring agents technically function.
The Examiner notes that the Desjardins memorandum instructs that "Examiners and panels should not evaluate claims at such a high level of generality that potentially meaningful technical limitations are dismissed without adequate explanation." Consistent with this instruction, the Examiner has evaluated the specific additional elements identified above, not dismissed them categorically, and finds that their recitation at a functional level describing the roles, conditions, outcomes, and decision criteria of the claimed sequence without specifying the technical implementation mechanism does not, under the applicable standard, establish integration into a practical application through the improvement consideration. This finding is fully explained above and is not a dismissal at a high level of generality. See Ex Parte Desjardins; Enfish, LLC v. Microsoft Corp.; McRO, Inc. v. Bandai Namco Games Am. Inc.
Mere Instructions to Apply the Exception (MPEP 2106.05(f)):
The additional elements amount to instructions to apply the abstract idea using generic computer components and generic catalog-selected automation tools. The three automation tools recited in the independent claims are pre-existing, catalog-selected tools drawn from the automation tools catalog data structure, as disclosed at specification paragraph [0046], which perform whatever generic action, monitoring, or rollback functions they were already cataloged as providing. The skill relationship graph data structure and the match-score criterion define the logic by which these generic tools are selected and sequenced, but do not modify or specially configure the tools themselves. Defining a structured, conditional, non-interchangeable pattern of invocation for pre-existing generic tools according to a skill-classification and scoring framework is a particular pattern of use of those generic tools a "specific way of applying" the abstract idea using those tools not a technical modification to the tools or the IT resources on which they operate that would reflect a specific technical improvement to computer functionality. See Alice Corp. Pty. Ltd. v. CLS Bank Int'l; MPEP 2106.05(f).
The Examiner acknowledges that the three automation tools occupy non-interchangeable, structurally and temporally defined roles the first performs an action, the second monitors success, and the third performs a rollback and that this role-based architecture is more specific than an undifferentiated reference to "a computer." This increased specificity has been credited throughout prosecution. However, specificity of role-based invocation logic does not equate to a technical modification to the tools or resources themselves, and a structured application of generic tools performing their generic functions to execute the abstract idea does not take the claim beyond a "apply it" instruction under MPEP 2106.05(f).
Particular Machine (MPEP 2106.05(b)):
The claims recite processors, memories, and non-transitory computer-readable media as generic computing components. These components are recited at a high level of generality and do not impose meaningful limits on the claim scope beyond performing the abstract idea on a computer. The automation tools are similarly recited generically as catalog-selected tools without specification of particular technical configurations. Accordingly, the particular machine consideration does not establish integration into a practical application.
Transformation (MPEP 2106.05(c)):
The Examiner acknowledges that the amended independent claims recite a transformation at both ends of the operational loop: the first automation tool executes operations that change an operational state of an application, computing device, storage device, or network resource, and the third automation tool executes operations that reset the IT resource to the state it occupied prior to the first tool's invocation, with the intervening determination made from run-time and configuration information. This is more specific than prior claim versions and ties the reversion to a particular, temporally defined prior state of a particular class of machine. However, the transformation consideration requires that the transformation be tied to a specific, technically-described process, not merely an abstractly-claimed change of state effected by invoking a generic catalog-selected automation tool. The amended claim specifies that these tools "execute operations" that achieve these functional outcomes without specifying the nature of those operations at a technical implementation level e.g., what specific hardware reconfiguration, memory modification, storage-level operation, or network configuration change is performed. This level of recitation is insufficient to establish transformation as an independent basis for integration into a practical application. See Bilski v. Kappos; Diamond v. Diehr.
Insignificant Extra-Solution Activity (MPEP 2106.05(g)):
The Examiner does not characterize the monitoring data limitation as insignificant extra-solution activity. The monitoring data serves a decision-determinative function as the input to the conditional branch governing whether rollback and regeneration occur, and is not incidental to the abstract idea. Accordingly, this consideration does not weigh against eligibility. However, this finding does not establish integration into a practical application because, as explained above, the monitoring data limitation specifies the data source and broad data classes without specifying the particular technical parameters examined or the technical means by which the agents determine success or failure, and it is the absence of that technical specificity not the characterization of the monitoring data as extra-solution activity that underlies the Prong Two finding.
Considering the additional elements individually and in combination, the claim as a whole does not integrate the identified judicial exception into a practical application. The additional elements, while adding meaningful specificity to the decision logic, structural constraints, and operational scope of the claimed system relative to prior versions, do not reflect a specific technical improvement to the functioning of the automation tools, monitoring agents, or IT resources themselves at a technical implementation level, and do not otherwise impose meaningful limits on practicing the abstract idea beyond applying it using generic computer components and catalog-selected automation tools performing their generic functions. Accordingly, the claims are directed to a judicial exception.
STEP 2B
As discussed with respect to Step 2A, Prong Two, the additional elements in the claims amount to no more than mere instructions to apply the abstract idea using generic computer components and catalog-selected automation tools performing their pre-existing generic functions. The same analysis applies at Step 2B: instructions to apply a judicial exception using generic computer components and generic tools cannot provide an inventive concept. See MPEP 2106.05(f); Alice Corp.
The additional elements, when considered individually and in combination, do not amount to significantly more than the abstract idea. Specifically, the processors, memories, and non-transitory computer-readable media are generic computing components that the courts have found to be well-understood, routine, and conventional in the computer arts. See Alice Corp., (citing Mayo Collaborative Servs. v. Prometheus Labs., Inc.; see also Benson. The catalog-selected automation tools are pre-existing tools performing their generic cataloged functions, as disclosed in the specification at paragraph [0046]. The skill relationship graph data structure, the match-score criterion, and the topology-edge-governed integration, while adding specificity to the decision logic, constitute the abstract idea itself organizing and applying information to make operational decisions implemented using generic computing components, rather than an inventive application that amounts to significantly more.
Accordingly, the claims do not include additional elements sufficient to amount to significantly more than the judicial exception.
Dependent claim analysis
The dependent claims recite additional limitations that further narrow the abstract idea but do not provide additional elements that integrate the judicial exception into a practical application or amount to significantly more:
Claims 2, 11, 14, 17, 22: These claims add a third correlation operation correlating at least one site reliability engineer (SRE) with at least one corresponding skill in the IT remediation task skill set, and generating the workflow based on the results of that third correlation. These limitations further extend the abstract idea of correlating available resources (human or automated) to required skills the same foundational concept of matching skills to tasks performed by human IT managers and do not add any element that reflects a specific technical improvement to computer functionality or otherwise integrates the exception into a practical application. Assigning SREs or SRE teams to perform remediation tasks based on skill matching is a human organizational activity that, when automated, constitutes the application of the abstract idea using generic computer components.
Claims 3, 23: These claims add the identification of one or more skill gaps a skill in the IT remediation task skill set for which there is no automation tool that provides the skill. Identifying the absence of a matching resource for a required skill is the mental act of recognizing a gap between what is needed and what is available, a judgment a human IT manager performs routinely. This limitation further defines the abstract idea's decision logic but does not integrate it into a practical application.
Claims 4, 5, 6: These claims further define the skill gap resolution process, including determining whether a fallback IT remediation task is available, whether an automation tool can perform it, and if not, performing a lookup in an SRE data structure to assign an SRE or SRE team. These limitations further narrow the abstract idea's decision tree for resolving skill gaps using human and automated resources but do not add elements that constitute a specific technical improvement. The lookup operation in an SRE data structure is a generic data retrieval step, and the fallback task substitution is a further instantiation of the abstract task-management concept.
Claim 7: This claim specifies that retrieving the IT topology graph data structure includes identifying the IT resource by evaluating dependencies between IT resources based on the topology graph. This further defines the data retrieval step but remains within the abstract idea of consulting organizational dependency information to identify affected resources a step a human analyst performs when reviewing a network topology diagram.
Claims 8, 9: These claims specify that the knowledge graph data structure comprises at least one natural language document, and that generating the ordering of IT remediation tasks comprises executing natural language processing configured with an IT remediation task vocabulary on the knowledge graph data structure, and identifying an ordered sequence based on that NLP. Claim 9 further specifies sentence similarity processing between the IT remediation task vocabulary and portions of knowledge articles. These limitations add NLP as a tool for performing the abstract idea of extracting remediation task information from knowledge documentation a further application of the abstract information-processing concept using a generic NLP technique as a tool. The NLP and sentence similarity operations do not reflect a specific technical improvement to computer functionality and constitute additional instructions to apply the abstract idea using a generic AI technique.
Claim 10: This claim specifies that executing the second correlation operation comprises performing NLP of automation tool descriptions and a sentence similarity analysis of those descriptions with the skills in the IT remediation task skill set. This limitation is similarly directed to the use of NLP as a tool to perform the abstract matching operation and does not add an element that integrates the exception into a practical application.
Claims 13: This claim specifies that identifying the skills associated with the IT remediation tasks comprises identifying a subset of nodes in the knowledge graph data structure corresponding to the IT incident and identifying the skills based on characteristics of those nodes. This further specifies the data structure traversal by which skill identification is performed within the abstract data-organization framework and does not add a technical improvement.
Claims 14, 15, 16: These claims specify that generating the IT incident remediation task workflow comprises selecting, for each IT remediation task, at least one automation tool or SRE based on a trained ML computer model that scores the automation tools and SREs based on correlation results, skill classifications, degree of skill matching, and whether rollback or fallback skills are present. Claim 16 adds performing an exploratory orchestration operation by identifying fallback tasks and generating alternative workflows. These limitations further specify the ML-based scoring and selection logic of the abstract idea, without adding a technical improvement to how the ML model or the underlying IT infrastructure operates. The scoring and selection criteria are the decision logic of the abstract task-management concept, not a disclosed technical improvement to computer functionality of the kind identified in Desjardins.
Claims 17, 18: These claims specify that generating the workflow comprises executing a trained ML computer tool on input features including IT remediation task skill set characteristics, automation tool characteristics, SRE characteristics, and skill correspondences to score each automation tool and SRE for performing each IT remediation task, and selecting, for each task, at least one automation tool, SRE, or SRE team based on the scores. These limitations further define the ML-based scoring input features and selection outcome, remaining within the abstract idea's decision-logic framework without adding a specific technical improvement.
Claim 19: This claim specifies that automatically executing the workflow further comprises, for each automated task, automatically invoking the automation tool and awaiting a completion response, and, for each SRE-assigned task, automatically transmitting an electronic communication to the SRE's computing device and awaiting a responsive communication indicating completion. These limitations add the orchestration and communication steps for mixed-methodology execution, but these steps invoking tools and sending notifications are generic computer functions (invoking software tools, transmitting electronic communications) applied to the IT-remediation domain, and do not reflect a specific technical improvement to computer functionality. Transmitting electronic communications to notify human personnel is well-understood, routine, and conventional activity in the computer arts.
The dependent claims, individually and in combination with the independent claims, do not remedy the deficiencies identified above and do not integrate the judicial exception into a practical application or provide an inventive concept under Step 2B.
For the foregoing reasons, claims 1–11, 13–20, and 22–24 are rejected under 35 U.S.C. 101 as directed to non-statutory subject matter. The claims are directed to the abstract idea of collecting, correlating, and organizing information technology incident information to identify, select, order, and execute remediation tasks a mental process and the additional elements of the claims, considered individually and in combination, do not integrate that judicial exception into a practical application or amount to significantly more than the exception itself.
The Examiner notes that this rejection is made because it is more likely than not (greater than 50%) that the claims are ineligible under 35 U.S.C. 101, consistent with the standard set forth in MPEP 2106 and the August 4, 2025 Memorandum. This rejection is not based on uncertainty; it is based on the Examiner's considered determination, following careful evaluation of the claims as a whole including all additional elements individually and in combination, and without dismissing any limitation at a high level of generality that the claims as drafted do not reflect a specific technical improvement to the functioning of a computer or to another technology or technical field that would integrate the identified judicial exception into a practical application. See Ex Parte Desjardins (precedential); Enfish, LLC v. Microsoft Corp.; SRI Int'l, Inc. v. Cisco Systems, Inc; Electric Power Group, LLC v. Alstom S.A.; Alice Corp. Pty. Ltd. v. CLS Bank Int'l.
The burden now shifts to the Applicant to demonstrate that the claims are directed to patent-eligible subject matter. See MPEP 2106.07.
Conclusion
The prior art made of record and not relied upon considered pertinent to Applicant’s disclosure.
Zimmerman
Any inquiry concerning this communication or earlier communications from the examiner should be directed to STEPHEN S SWARTZ whose telephone number is (571)270-7789. The examiner can normally be reached Mon-Fri 9:00 - 6:00.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Boswell Beth can be reached at 571 272-6737. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/S.S.S/Examiner, Art Unit 3625
/JOSEPH M WAESCO/Primary Examiner, Art Unit 3625