Prosecution Insights
Last updated: August 17, 2026
Application No. 18/470,812

COMPLIANT AND AUDITABLE WAY FOR A USER TO PERFORM AN ACTION WITHOUT SUFFICIENT PRIVILEGES

Final Rejection §103
Filed
Sep 20, 2023
Examiner
SCHMIDT, KARI L
Art Unit
2439
Tech Center
2400 — Computer Networks
Assignee
Microsoft Technology Licensing, LLC
OA Round
4 (Final)
74%
Grant Probability
Favorable
5-6
OA Rounds
10m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 74% — above average
74%
Career Allowance Rate
557 granted / 752 resolved
+16.1% vs TC avg
Strong +42% interview lift
Without
With
+42.4%
Interview Lift
resolved cases with interview
Typical timeline
3y 9m
Avg Prosecution
14 currently pending
Career history
774
Total Applications
across all art units

Statute-Specific Performance

§101
17.1%
-22.9% vs TC avg
§103
50.9%
+10.9% vs TC avg
§102
10.9%
-29.1% vs TC avg
§112
13.1%
-26.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 752 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This Office Action is in response to the Amendment filed on 5/15/2026. In instant Amendment, claims 1, 10 and 17 have been amended; claims 21 and 22 have been newly added; claims 1, 10 and 17 are independent claims. Claims 1-22 have been examined and are pending. This Action is made FINAL. Response to Arguments Applicants’ arguments with respect to claims 1-20 have been considered but are moot in view of the new ground(s) of rejection; however, the examiner notes the following: Applicant Argues: To clarify this distinction, Applicant has amended independent claim 1 to recite "the temporal constraint includes a time limit on performing the requested action." As the period of time in Harb only relates to when to notify another user of the access request and does not impact time limit on performing the requested action," as recited of the temporal constraint in amended independent claim 1. Thus, Harb fails to cure the deficiencies of Padmanabhan with respect to at least these aspects of amended independent claim 1. Examiner’s Response: The examiner respectfully notes the rejection below has been updated to account for amended claim 1. Therefore, this argument is moot in view of new grounds of rejection. Applicant Argues: Moreover, as previously explained, Padmanabhan fails to disclose or suggest performing the action "without providing the permission to the first user account," as recited in independent claim 1. The Office Action cites paragraph [0029] of Padmanabhan as disclosing "[t]he administrator may respond to the second email message indicating that the user should be allowed to request the NAS operation. The message processing module 206 may receive the administrator's response (e.g., email message) and may cause the NAS device 210 to perform the NAS operation (e.g., may transmit a message to the NAS device 210 instructing the NAS device 210 to perform the NAS operation). The message processing module 206 may also update the database 225 with data indicating that the user has permission to perform the NAS operation." Thus, in Padmanabhan, the administrator's response is necessarily granting permission for the user to perform the NAS operation. The Office Action fails to show where Padmanabhan discloses or suggests at least "performing, for the second user account on the cloud-computing environment in response to approval of the second request, the action without providing the permission to the first user account," as recited in independent claim 1. Examiner’s Response: The examiner respectfully disagrees. Padmanabhan states in [0029] – “In one embodiment, the message processing module 206 may determine whether a user associated with the sender email address (e.g., the sender of the email message) has permission to request the NAS device 210 to perform the one or more NAS operations. For example, the message processing module 206 may access the database 225 to determine whether the user associated with the sender email address is allowed to request the NAS device 210 to perform the NAS operation. If the user is not allowed to request the NAS device 210 to perform the NAS operation, the message processing module 206 may optionally send a second email message to an administrator of the NAS device 210 indicating that the user has requested the NAS device 210 to perform the NAS operation. The administrator may respond to the second email message indicating that the user should be allowed to request the NAS operation. The message processing module 206 may receive the administrator's response (e.g., email message) and may cause the NAS device 210 to perform the NAS operation (e.g., may transmit a message to the NAS device 210 instructing the NAS device 210 to perform the NAS operation). The message processing module 206 may also update the database 225 with data indicating that the user has permission to perform the NAS operation. If the user is allowed to request the NAS device 210 to perform the NAS operation, the message processing module 206 may cause the NAS device 210 to perform the NAS operation." The examiner respectfully notes that an administrator instructing the NAS device to perform the operation is noted to reasonably read on “"performing, for the second user account on the cloud-computing environment in response to approval of the second request, the action without providing the permission to the first user account.” Therefore, the examiner finds this argument not persuasive. Applicant Argues: For example, with respect to claim 3, in the Response to Arguments, the Office Action asserts that Padmanabhan discloses "messaging and indicating the results of one or more NAS operations." See, Office Action, page 7. Padmanabhan, however, fails to disclose or suggest that the indicated results would specifically indicate "performance of the action by the second user account on behalf of the request from the first user account," as recited in claim 3 (e.g., rather than a generic indication of the result of the NAS operation). Karunakaran is also completely silent regarding at least such aspects. Examiner’s Response: The examiner respectfully disagrees. Padmanabhan states in [0029] – “In one embodiment, the message processing module 206 may determine whether a user associated with the sender email address (e.g., the sender of the email message) has permission to request the NAS device 210 to perform the one or more NAS operations. For example, the message processing module 206 may access the database 225 to determine whether the user associated with the sender email address is allowed to request the NAS device 210 to perform the NAS operation. If the user is not allowed to request the NAS device 210 to perform the NAS operation, the message processing module 206 may optionally send a second email message to an administrator of the NAS device 210 indicating that the user has requested the NAS device 210 to perform the NAS operation. The administrator may respond to the second email message indicating that the user should be allowed to request the NAS operation. The message processing module 206 may receive the administrator's response (e.g., email message) and may cause the NAS device 210 to perform the NAS operation (e.g., may transmit a message to the NAS device 210 instructing the NAS device 210 to perform the NAS operation). The message processing module 206 may also update the database 225 with data indicating that the user has permission to perform the NAS operation. If the user is allowed to request the NAS device 210 to perform the NAS operation, the message processing module 206 may cause the NAS device 210 to perform the NAS operation." The examiner respectfully notes that an administrator instructing the NAS device to perform the operation is based on the permission to request the NAS device from a sender, thus, this is noted to reasonably read on “"performance of the action by the second user account on behalf of the request from the first user account.” Therefore, the examiner finds this argument not persuasive. Applicant Argues: Claims 21 and 22 are newly added herein and are also allowable at least based on their dependency to the above discussed independent claim 1, and because they recite a combination of subject matter that has not been shown as disclosed or suggested by the cited references. Examiner’s Response: The examiner respectfully notes the rejection below has been updated to account for newly added claim(s) 21 and 22. Therefore, this argument is moot in view of new grounds of rejection. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1, 2, 4, 10, 11, 17, and 18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Padmanabhan (US 2015/0372962 A1) in view of Marx et al. (US 2014/0379576 A1). Regarding Claim 1; Padmanabhan teaches a method for controlling, by a cloud security module, permissions for performing actions in a cloud-computing environment ([0009] and [0029]), comprising: receiving, from a first user account of the cloud computing environment, a first request to perform an action on the cloud computing environment ([0009] - For example, a NAS device may include hardware, software, or a combination of such elements, configured such that the NAS device operates as a file server. NAS devices/systems can provide a convenient mechanism for sharing data among multiple computers and/or remotely accessing data stored on the NAS devices/systems. As compared to traditional file servers, benefits of NAS devices/systems may include the ability to access data from various locations (e.g., remote locations), faster data access, easier administration, and/or simpler configuration and [0029] - In one embodiment, the message processing module 206 may determine whether a user associated with the sender email address (e.g., the sender of the email message) has permission to request the NAS device 210 to perform the one or more NAS operations. For example, the message processing module 206 may access the database 225 to determine whether the user associated with the sender email address is allowed to request the NAS device 210 to perform the NAS operation. If the user is not allowed to request the NAS device 210 to perform the NAS operation, the message processing module 206 may optionally send a second email message to an administrator of the NAS device 210 indicating that the user has requested the NAS device 210 to perform the NAS operation. The administrator may respond to the second email message indicating that the user should be allowed to request the NAS operation. The message processing module 206 may receive the administrator's response (e.g., email message) and may cause the NAS device 210 to perform the NAS operation (e.g., may transmit a message to the NAS device 210 instructing the NAS device 210 to perform the NAS operation); determining that the first user account does not have permission to perform the action ([0029] - In one embodiment, the message processing module 206 may determine whether a user associated with the sender email address (e.g., the sender of the email message) has permission to request the NAS device 210 to perform the one or more NAS operations. For example, the message processing module 206 may access the database 225 to determine whether the user associated with the sender email address is allowed to request the NAS device 210 to perform the NAS operation. If the user is not allowed to request the NAS device 210 to perform the NAS operation, the message processing module 206 may optionally send a second email message to an administrator of the NAS device 210 indicating that the user has requested the NAS device 210 to perform the NAS operation. The administrator may respond to the second email message indicating that the user should be allowed to request the NAS operation. The message processing module 206 may receive the administrator's response (e.g., email message) and may cause the NAS device 210 to perform the NAS operation (e.g., may transmit a message to the NAS device 210 instructing the NAS device 210 to perform the NAS operation); identifying a second user account of the cloud computing environment having permission to perform the action ([0009] and [0029] - In one embodiment, the message processing module 206 may determine whether a user associated with the sender email address (e.g., the sender of the email message) has permission to request the NAS device 210 to perform the one or more NAS operations. For example, the message processing module 206 may access the database 225 to determine whether the user associated with the sender email address is allowed to request the NAS device 210 to perform the NAS operation. If the user is not allowed to request the NAS device 210 to perform the NAS operation, the message processing module 206 may optionally send a second email message to an administrator of the NAS device 210 indicating that the user has requested the NAS device 210 to perform the NAS operation. The administrator may respond to the second email message indicating that the user should be allowed to request the NAS operation. The message processing module 206 may receive the administrator's response (e.g., email message) and may cause the NAS device 210 to perform the NAS operation (e.g., may transmit a message to the NAS device 210 instructing the NAS device 210 to perform the NAS operation); transmitting, to the second user account, a second request for approval to perform the action ([0029] - In one embodiment, the message processing module 206 may determine whether a user associated with the sender email address (e.g., the sender of the email message) has permission to request the NAS device 210 to perform the one or more NAS operations. For example, the message processing module 206 may access the database 225 to determine whether the user associated with the sender email address is allowed to request the NAS device 210 to perform the NAS operation. If the user is not allowed to request the NAS device 210 to perform the NAS operation, the message processing module 206 may optionally send a second email message to an administrator of the NAS device 210 indicating that the user has requested the NAS device 210 to perform the NAS operation. The administrator may respond to the second email message indicating that the user should be allowed to request the NAS operation. The message processing module 206 may receive the administrator's response (e.g., email message) and may cause the NAS device 210 to perform the NAS operation (e.g., may transmit a message to the NAS device 210 instructing the NAS device 210 to perform the NAS operation); receiving, from the second user account, a performance response indicating approval of the requested action ([0029] - In one embodiment, the message processing module 206 may determine whether a user associated with the sender email address (e.g., the sender of the email message) has permission to request the NAS device 210 to perform the one or more NAS operations. For example, the message processing module 206 may access the database 225 to determine whether the user associated with the sender email address is allowed to request the NAS device 210 to perform the NAS operation. If the user is not allowed to request the NAS device 210 to perform the NAS operation, the message processing module 206 may optionally send a second email message to an administrator of the NAS device 210 indicating that the user has requested the NAS device 210 to perform the NAS operation. The administrator may respond to the second email message indicating that the user should be allowed to request the NAS operation. The message processing module 206 may receive the administrator's response (e.g., email message) and may cause the NAS device 210 to perform the NAS operation (e.g., may transmit a message to the NAS device 210 instructing the NAS device 210 to perform the NAS operation. The message processing module 206 may also update the database 225 with data indicating that the user has permission to perform the NAS operation). performing, for the second user account on the cloud computing environment, in accordance with... and in response to approval of the second request, the action without providing the permission to the first user account ([0029] - In one embodiment, the message processing module 206 may determine whether a user associated with the sender email address (e.g., the sender of the email message) has permission to request the NAS device 210 to perform the one or more NAS operations. For example, the message processing module 206 may access the database 225 to determine whether the user associated with the sender email address is allowed to request the NAS device 210 to perform the NAS operation. If the user is not allowed to request the NAS device 210 to perform the NAS operation, the message processing module 206 may optionally send a second email message to an administrator of the NAS device 210 indicating that the user has requested the NAS device 210 to perform the NAS operation. The administrator may respond to the second email message indicating that the user should be allowed to request the NAS operation. The message processing module 206 may receive the administrator's response (e.g., email message) and may cause the NAS device 210 to perform the NAS operation (e.g., may transmit a message to the NAS device 210 instructing the NAS device 210 to perform the NAS operation. The message processing module 206 may also update the database 225 with data indicating that the user has permission to perform the NAS operation). As construed the administrator’s response (i.e., email message), which is noted to be the performance response, causes the NAS device to perform the NAS operation. Padmanabhan fails to explicitly disclose determining, from an action store, a temporal constraint associated with the requested action, wherein the temporal constraint includes a time limit on performing the requested action; [...] performing, ... in accordance with the temporal constraint.... However, in an analogous art, Marx teaches determining, from an action store, a temporal constraint associated with the requested action, wherein the temporal constraint includes a time limit on performing the requested action ([0013] - Thus, based on the type of transaction or other transaction information (such as amount of purchase), appropriate delay may be provided pending the primary user's approval and [0022] - On the other hand, if the service provider determines that approval from the primary is required based on the restriction profile of the secondary user, the service provider may forward an approval request to the primary user and delay the transaction for a specified period of time at step 110. As noted above, online merchants may set the specified delay time based on the type of purchases. For example, food vendors, such as a pizza shop, may set a shorter delay time of five minutes. Electronic retailers may set a longer delay time of 24 hours. The length of delay may also be set based on the amount of purchases, e.g., a larger amount may correspond to a longer delay. Thus, adequate delay time may be allotted for the primary user to respond and approve the purchase, based on the type of transactions and [0029] - If approval from the primary user is required, the payment provider service may execute an API DoDelay type function to delay the transaction for a specified period of time, e.g., Step 112. The payment provider service then may send an approval request to the primary user to request approval from the primary user, e.g., Step 110. As noted above, the payment provider service may text, email, or call the primary user. If the payment provider service receives an approval from the primary user within the specified period of time, PayPal may proceed with the transaction). [...] performing, ... in accordance with the temporal constraint... (FIG. 1 and [0013] and [0022] and [0029]). Therefore, it would have been obvious to one of ordinarily skill in the art before the effective filing date of the claimed invention to combine the teachings of Marx to the request/action of Padmanabhan to include determining, from an action store, a temporal constraint associated with the requested action, wherein the temporal constraint includes a time limit on performing the requested action; [...] performing, ... in accordance with the temporal constraint.... One would have been motivated to combine the teachings of Marx to Padmanabhan to do so as it provides / allows a primary user ... to monitor or control ... a secondary user in real time (Marx, [0006]). Regarding Claim 2; Padmanabhan and Marx disclose the method to Claim 1. Padmanabhan teaches wherein the permission permits the action over a plurality of resources, and performing the action comprises performing the action over a resource of the plurality of resources and not over other resources of the plurality of resources ([0023] - The NAS device 210 may perform various operations that may be related to the management of the NAS device 210 and/or accessing data (e.g., reading data, writing data, modifying data, etc.) on the NAS device 210. These operations may be referred to as NAS operations. In one embodiment, a NAS operation may be any operations, function, action, activity, act, etc., that may be performed by the NAS device 210. Examples of NAS operations include, but are not limited to, reading data, writing data, modifying data, moving data, obtaining usage statistics and/or the status of the NAS device 210 (as discussed later below), performing a diagnostic test, etc. and [0028]-[0029] – ...path... and [0039] - The message processing module 311 may allow users (e.g., end users, system administrators, technical support staff, etc.) to access and/or manage the NAS device 310 using email messages.). Regarding Claim 4; Padmanabhan and Marx disclose the method to Claim 1. Padmanabhan further discloses further comprising: transmitting a notification to the first user account indicating performance of the action ([0029] and [0031] and [0032] - In one embodiment, the message processing module 206 may identify one or more NAS operations that the NAS device 210 should perform. The message processing module 206 may generate and/or send an email message to a user (e.g., an administrator) indicating the one or more NAS operations. Based on a response email message from the user, the message).processing module 206 may cause the NAS device to perform the one or more NAS operations. The NAS device 210 may provide the results of the one or more NAS operations to the message processing module 206 (e.g., transmit a message to the message processing module 206) and the message processing module 206 may also send another email message to the user with the results of the one or more NAS operation). Regarding Claim(s) 10 and 11; claim(s) 10 and 11 is/are directed to a/an device associated with the method claimed in claim(s) 1 and 2. Claim(s) 10 and 11 is/are similar in scope to claim(s) 1 and 2, and is/are therefore rejected under similar rationale. As construed a NAS acts as a cloud device, see [0010]. Regarding Claim(s) 17 and 18; claim(s) 17 and 18 is/are directed to a/an computer-readable device associated with the method claimed in claim(s) 1 and 2. Claim(s) 17 and 18 is/are similar in scope to claim(s) 1 and 2, and is/are therefore rejected under similar rationale. Claim(s) 3, 12, and 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Padmanabhan (US 2015/0372962 A1) in view of Marx et al. (US 2014/0379576 A1) and further in view of Karunakaran et al. (US 2018/0288045 A1). Regarding Claim 3; Padmanabhan and Marx disclose the method to Claim 1. Padmanabhan further discloses further comprising: “logging” in... the cloud-computing environment.... performance of the action by the second user account on behalf to the request from the first user account ([0009] and [0029] - In one embodiment, the message processing module 206 may determine whether a user associated with the sender email address (e.g., the sender of the email message) has permission to request the NAS device 210 to perform the one or more NAS operations. For example, the message processing module 206 may access the database 225 to determine whether the user associated with the sender email address is allowed to request the NAS device 210 to perform the NAS operation. If the user is not allowed to request the NAS device 210 to perform the NAS operation, the message processing module 206 may optionally send a second email message to an administrator of the NAS device 210 indicating that the user has requested the NAS device 210 to perform the NAS operation. The administrator may respond to the second email message indicating that the user should be allowed to request the NAS operation. The message processing module 206 may receive the administrator's response (e.g., email message) and may cause the NAS device 210 to perform the NAS operation (e.g., may transmit a message to the NAS device 210 instructing the NAS device 210 to perform the NAS operation and [0031] – ...statistics... and [0032] - In one embodiment, the message processing module 206 may identify one or more NAS operations that the NAS device 210 should perform. The message processing module 206 may generate and/or send an email message to a user (e.g., an administrator) indicating the one or more NAS operations. Based on a response email message from the user, the message).processing module 206 may cause the NAS device to perform the one or more NAS operations. The NAS device 210 may provide the results of the one or more NAS operations to the message processing module 206 (e.g., transmit a message to the message processing module 206) and the message processing module 206 may also send another email message to the user with the results of the one or more NAS operation and [0037]). Padmanabhan and Marx fail to explicitly disclose ...logging, in an audit log of the cloud-computing environment... However, in an analogous art, Karunakaran teaches ...logging, in an audit log of an cloud-computing environment [performance of an action] ([0049] - In the example shown, cloud service provider audit log 400 includes for each access (e.g., login/attempt) or other logged event (e.g., each row) a date/time stamp, a user (e.g., username, display name, etc.) associated with the event, a device type and/or identifier, a user email address, an IP address, an action (e.g., login, used new app to log in, etc.) and an item/name and/or details field that provides further information about the event (e.g., browser or other software used, etc.). Therefore, it would have been obvious to one of ordinarily skill in the art before the effective filing date of the claimed invention to combine the teachings of Karunakaran to the logging of Padmanabhan and Marx to include ...logging, in an audit log of an cloud-computing environment [performance of an action] One would have been motivated to combine the teachings of Karunakaran to Padmanabhan and Marx to do so as it provides / allows capture and provide secure access to a cloud service (Karunakaran, [0049]). Regarding Claim(s) 12; claim(s) 12is/are directed to a/an device associated with the method claimed in claim(s) 3. Claim(s) 12 is/are similar in scope to claim(s) 3, and is/are therefore rejected under similar rationale. As construed a NAS acts as a cloud device, see [0010]. Regarding Claim(s) 19; claim(s) 19 is/are directed to a/an computer-readable device associated with the method claimed in claim(s) 3. Claim(s) 19 is/are similar in scope to claim(s) 3, and is/are therefore rejected under similar rationale Claim(s) 5 and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Padmanabhan (US 2015/0372962 A1) in view of Marx et al. (US 2014/0379576 A1) and further in view of Matsumoto et al. (US 2020/0219179 A1). Regarding Claim 5; Padmanabhan and Marx disclose the method to Claim 1. Padmanabhan and Marx fail to explicitly disclose wherein the permission provides access to a resource for a first predetermined period of time, and wherein performing the action comprises providing access to the resource for a second predetermined period of time that is less than the first predetermined period of time However, in an analogous art, Matsumoto teaches [similar concepts related to resources] wherein the permission provides access to a resource for a first predetermined period of time, and wherein performing the action comprises providing access to the resource for a second predetermined period of time that is less than the first predetermined period of time ([0065] - When the request acquiring unit 432a acquires data regarding a use request, the rental permission unit 432b searches the use plan created by the reservation management unit 431 for vehicle reservable time periods not included in the reserved vehicle use dates and times, and when a retrieved time period is within a first predetermined time period Δta (e.g., 1 hour) and not shorter than a second predetermined time period Δtb (e.g., 30 minutes), the rental permission unit 432b permits use of the vehicle 1 for the second predetermined time period Δtb within said time period. This is based on the reasoning that if a vehicle unreserved time period is 1 hour, for instance, the station manager can be allowed to use the vehicle 1 for a certain period within 1 hour (e.g., for 30 minutes). The station manager is thus able to use the vehicle 1 for short periods within periods when the vehicle 1 is not reserved. So even without owning a car, the station manager has access to one (the vehicle 1) to use for, for example, local shopping or transporting family or friends to or from a local station, and can therefore effectively utilize the vehicle 1, even if only occasionally). Therefore, it would have been obvious to one of ordinarily skill in the art before the effective filing date of the claimed invention to combine the teachings of Matsumoto to the permission of Padmanabhan and Marx to include wherein the permission provides access to a resource for a first predetermined period of time, and wherein performing the action comprises providing access to the resource for a second predetermined period of time that is less than the first predetermined period of time. One would have been motivated to combine the teachings of Matsumoto to Padmanabhan and Marx to do so as it provides / allows utilize a resource effectively (as gleaned from Matsumoto, [0065]). Regarding Claim(s) 20 claim(s) 20 is/are directed to a/an computer-readable device associated with the method claimed in claim(s) 5. Claim(s) 20 is/are similar in scope to claim(s) 5, and is/are therefore rejected under similar rationale. Claim(s) 6-9 and 14-16 is/are rejected under 35 U.S.C. 103 as being unpatentable over Padmanabhan (US 2015/0372962 A1) in view of Marx et al. (US 2014/0379576 A1) and further in view of Delacourt et al. (US 10,552,796 B1). Regarding Claim 6; Padmanabhan and Marx disclose the method to Claim 1. Padmanabhan further discloses [concepts of] performing in response to approval of the ... request, the ...action without providing the permission to the first user account ([0029] - In one embodiment, the message processing module 206 may determine whether a user associated with the sender email address (e.g., the sender of the email message) has permission to request the NAS device 210 to perform the one or more NAS operations. For example, the message processing module 206 may access the database 225 to determine whether the user associated with the sender email address is allowed to request the NAS device 210 to perform the NAS operation. If the user is not allowed to request the NAS device 210 to perform the NAS operation, the message processing module 206 may optionally send a second email message to an administrator of the NAS device 210 indicating that the user has requested the NAS device 210 to perform the NAS operation. The administrator may respond to the second email message indicating that the user should be allowed to request the NAS operation. The message processing module 206 may receive the administrator's response (e.g., email message) and may cause the NAS device 210 to perform the NAS operation (e.g., may transmit a message to the NAS device 210 instructing the NAS device 210 to perform the NAS operation. The message processing module 206 may also update the database 225 with data indicating that the user has permission to perform the NAS operation). As construed “[...] may also update the database 225 with data indicating that the user has permission to perform the NAS operation [...]” as construed is a step that may also not occur as may is expressed as a possibility. Padmanabhan further discloses multiple users (e.g., end users, system administrators, technical support staff/personnel, etc.) to access and/or manage) ([0024); however, Padmanabhan and Marx fail to explicitly disclose wherein the action is a first action, and further comprising: receiving, from the first user account, a third request to perform a second action; determining that the first user account does not have permission to perform the second action; identifying a third user account having permission to perform the second action; identifying, based on a resource associated with the second action, an alternative action to the second action; transmitting, to the third user account, a fourth request for approval to perform the second action or the alternative action to the second action; and performing, in response to approval of the fourth request, the second action or the alternative to the second action [...]. However, in an analogous art, Delacourt teaches wherein the action is a first action, and further comprising: receiving, from the first user account, a third request to perform a second action (col. 3, lines 62-col. 4, lines 9 - As described in more detail herein, in some embodiments, the approval service may employ a notification service that is provided by the service provider system to manage actionable notification messages that include approval requests. In such embodiments, members of various approval groups may retrieve approval requests from specific message inboxes (e.g., one per approval group) and may respond to them by selecting one of several available actions (e.g., by selecting “approve”, “deny”, or “request more information”); determining that the first user account does not have permission to perform the second action (col. 32, lines 9-20 - For example, in a system that employs the actionable notification messages described herein, if an end user attempts to perform on operation that the end user does not have permission to perform (e.g., to access a service or other resource that the end user is not authorized to access), rather than just returning a denial of the request, an actionable notification message may be returned to the end user that presents multiple available actions the end user can take. In this example, those actions may include requesting permission to perform the operation, retrying the operation, or cancelling the request); identifying a third user account having permission to perform the second action (col. 3, lines 39-61 – template... single approval... For example, the IT administrator may associate an approval template with a given approval request (or with multiple requests) and may associate different approval groups (e.g., first level team leaders, IT administrators, legal team members, or second level managers) with each approval level defined in the approval template); identifying, based on a resource associated with the second action, an alternative action to the second action (col. 3, lines 62-col. 4, lines 9 - As described in more detail herein, in some embodiments, the approval service may employ a notification service that is provided by the service provider system to manage actionable notification messages that include approval requests. In such embodiments, members of various approval groups may retrieve approval requests from specific message inboxes (e.g., one per approval group) and may respond to them by selecting one of several available actions (e.g., by selecting “approve”, “deny”, or “request more information”));; transmitting, to the third user account, a fourth request for approval to perform the second action or the alternative action to the second action (col. 3, lines 39-61 – template... single approval... For example, the IT administrator may associate an approval template with a given approval request (or with multiple requests) and may associate different approval groups (e.g., first level team leaders, IT administrators, legal team members, or second level managers) with each approval level defined in the approval template and col. 3, lines 62-col. 4, lines 9 - As described in more detail herein, in some embodiments, the approval service may employ a notification service that is provided by the service provider system to manage actionable notification messages that include approval requests. In such embodiments, members of various approval groups may retrieve approval requests from specific message inboxes (e.g., one per approval group) and may respond to them by selecting one of several available actions (e.g., by selecting “approve”, “deny”, or “request more information”); and performing, in response to approval of the fourth request, the second action or the alternative to the second action [...] (col. 3, lines 39-61 – template... single approval... For example, the IT administrator may associate an approval template with a given approval request (or with multiple requests) and may associate different approval groups (e.g., first level team leaders, IT administrators, legal team members, or second level managers) with each approval level defined in the approval template and col. 3, lines 62-col. 4, lines 9 - As described in more detail herein, in some embodiments, the approval service may employ a notification service that is provided by the service provider system to manage actionable notification messages that include approval requests. In such embodiments, members of various approval groups may retrieve approval requests from specific message inboxes (e.g., one per approval group) and may respond to them by selecting one of several available actions (e.g., by selecting “approve”, “deny”, or “request more information”). Therefore, it would have been obvious to one of ordinarily skill in the art before the effective filing date of the claimed invention to combine the teachings of Delacourt to the permission of Padmanabhan and Marx to include wherein the action is a first action, and further comprising: receiving, from the first user account, a third request to perform a second action; determining that the first user account does not have permission to perform the second action; identifying a third user account having permission to perform the second action; identifying, based on a resource associated with the second action, an alternative action to the second action; transmitting, to the third user account, a fourth request for approval to perform the second action or the alternative action to the second action; and performing, in response to approval of the fourth request, the second action or the alternative to the second action [...]. One would have been motivated to combine the teachings of Delacourt to Padmanabhan and Marx to do so as it provides / allows an uncomplicated approach for provisioning, administering, and managing the physical computing resources (as gleaned from Delacourt, col. 1, lines 5-59). Regarding Claim 7; Padmanabhan and Marx discloses the method to Claim 1. Padmanabhan further discloses [concepts of] performing in response to approval of the ... request, the ...action without providing the permission to the first user account ([0029] - In one embodiment, the message processing module 206 may determine whether a user associated with the sender email address (e.g., the sender of the email message) has permission to request the NAS device 210 to perform the one or more NAS operations. For example, the message processing module 206 may access the database 225 to determine whether the user associated with the sender email address is allowed to request the NAS device 210 to perform the NAS operation. If the user is not allowed to request the NAS device 210 to perform the NAS operation, the message processing module 206 may optionally send a second email message to an administrator of the NAS device 210 indicating that the user has requested the NAS device 210 to perform the NAS operation. The administrator may respond to the second email message indicating that the user should be allowed to request the NAS operation. The message processing module 206 may receive the administrator's response (e.g., email message) and may cause the NAS device 210 to perform the NAS operation (e.g., may transmit a message to the NAS device 210 instructing the NAS device 210 to perform the NAS operation. The message processing module 206 may also update the database 225 with data indicating that the user has permission to perform the NAS operation). As construed “[...] may also update the database 225 with data indicating that the user has permission to perform the NAS operation [...]” as construed is a step that may also not occur as may is expressed as a possibility. Padmanabhan further discloses multiple users (e.g., end users, system administrators, technical support staff/personnel, etc.) to access and/or manage) ([0024]); however, Padmanabhan and Marx fail to explicitly disclose wherein the action is a first action, and further comprising: receiving, from the first user account, at a second service, a third request to perform a second action; determining that the first user account does not have permission to perform the second action; identifying a third user account having permission to perform the second action; transmitting, to the third user account, a fourth request for approval to perform the second action; denying, based on the fourth request, performance of the second action; and notifying the first user account of denial of the third request. However, in an analogous art, Delacourt teaches wherein the action is a first action, and further comprising: receiving, from the first user account, at a second service (col. 3, lines 62-col. 4, lines 9 - As described in more detail herein, in some embodiments, the approval service may employ a notification service that is provided by the service provider system to manage actionable notification messages that include approval requests. In such embodiments, members of various approval groups may retrieve approval requests from specific message inboxes (e.g., one per approval group) and may respond to them by selecting one of several available actions (e.g., by selecting “approve”, “deny”, or “request more information”); determining that the first user account does not have permission to perform the second action (col. 32, lines 9-20 - For example, in a system that employs the actionable notification messages described herein, if an end user attempts to perform on operation that the end user does not have permission to perform (e.g., to access a service or other resource that the end user is not authorized to access), rather than just returning a denial of the request, an actionable notification message may be returned to the end user that presents multiple available actions the end user can take. In this example, those actions may include requesting permission to perform the operation, retrying the operation, or cancelling the request); identifying a third user account having permission to perform the second action (col. 3, lines 39-61 – template... single approval... For example, the IT administrator may associate an approval template with a given approval request (or with multiple requests) and may associate different approval groups (e.g., first level team leaders, IT administrators, legal team members, or second level managers) with each approval level defined in the approval template); denying, based on the fourth request, performance of the second action (col. 3, lines 39-61 – template... single approval... For example, the IT administrator may associate an approval template with a given approval request (or with multiple requests) and may associate different approval groups (e.g., first level team leaders, IT administrators, legal team members, or second level managers) with each approval level defined in the approval template and col. 3, lines 62-col. 4, lines 9 - As described in more detail herein, in some embodiments, the approval service may employ a notification service that is provided by the service provider system to manage actionable notification messages that include approval requests. In such embodiments, members of various approval groups may retrieve approval requests from specific message inboxes (e.g., one per approval group) and may respond to them by selecting one of several available actions (e.g., by selecting “approve”, “deny”, or “request more information”); and notifying the first user account of denial of the third request (col. 36, lines 22-25 - In this example, selecting the action “deny” may initiate the return of a notification to the end user (through the desktop application fulfillment platform) that the request has been denied). Therefore, it would have been obvious to one of ordinarily skill in the art before the effective filing date of the claimed invention to combine the teachings of Delacourt to the permission of Padmanabhan and Marx to include wherein the action is a first action, and further comprising: receiving, from the first user account, at a second service, a third request to perform a second action; determining that the first user account does not have permission to perform the second action; identifying a third user account having permission to perform the second action; transmitting, to the third user account, a fourth request for approval to perform the second action; denying, based on the fourth request, performance of the second action; and notifying the first user account of denial of the third request. One would have been motivated to combine the teachings of Delacourt to Padmanabhan and Marx to do so as it provides / allows an uncomplicated approach for provisioning, administering, and managing the physical computing resources (as gleaned from Delacourt, col. 1, lines 5-59). Regarding Claim 8; Padmanabhan and Marx disclose the method to Claim 1. Padmanabhan further discloses multiple users (e.g., end users, system administrators, technical support staff/personnel, etc.) to access and/or manage) ([0024]); however, Padmanabhan and Marx fail to explicitly disclose wherein identifying the second user account having permission to perform the action, comprises: determining that the second user account is an owner or contributor to a resource that is an object of the action. However, in an analogous art, Delacourt teaches wherein identifying [a] second user account having permission to perform the action, comprises: determining that the second user account is an owner or contributor to a resource that is an object of the action (col. 3, lines 39-61 – template... single approval... For example, the IT administrator may associate an approval template with a given approval request (or with multiple requests) and may associate different approval groups (e.g., first level team leaders, IT administrators, legal team members, or second level managers) with each approval level defined in the approval template). Therefore, it would have been obvious to one of ordinarily skill in the art before the effective filing date of the claimed invention to combine the teachings of Delacourt to the permission of Padmanabhan and Marx to include wherein identifying [a] second user account having permission to perform the action, comprises: determining that the second user account is an owner or contributor to a resource that is an object of the action One would have been motivated to combine the teachings of Delacourt to Padmanabhan and Marx to do so as it provides / allows an uncomplicated approach for provisioning, administering, and managing the physical computing resources (as gleaned from Delacourt, col. 1, lines 5-59). Regarding Claim 9; Padmanabhan and Marx disclose the method to Claim 1. Padmanabhan further discloses multiple users (e.g., end users, system administrators, technical support staff/personnel, etc.) to access and/or manage) ([0024]); however, Padmanabhan and Marx fail to explicitly disclose wherein a third user account corresponds to an owner of a resource that is an object of the action, and identifying the second user account having permission to perform the action, comprises: determining that the third user account has not responded to a third request to perform the action; and identifying the second user account based on the second user account being an administrator of a plurality of resources including the resource. However, in an analogous art, Delacourt teaches wherein a third user account corresponds to an owner of a resource that is an object of the action . (col. 3, lines 39-61 – template... single approval... For example, the IT administrator may associate an approval template with a given approval request (or with multiple requests) and may associate different approval groups (e.g., first level team leaders, IT administrators, legal team members, or second level managers) with each approval level defined in the approval template), and identifying [a] second user account having permission to perform the action, comprises: determining that the third user account has not responded to a third request to perform the action (col. 10, lines 25-50 - In some embodiments, the approval service may support an auto-escalation feature. In embodiments in which this feature is enabled for all approval requests (or for a given request, as specified in the associated approval template), if not enough responses to a given approval request are received from the members of the approval group associated with the given approval request to be able to determine whether the request should be approved or denied within a pre-determined time period, the approval request may be escalated to the next approval level in the sequence of approval levels defined in the associated approval template (assuming one exists)); and identifying the second user account based on the second user account being an administrator of a plurality of resources including the resource(col. 3, lines 39-61 – template... single approval... For example, the IT administrator may associate an approval template with a given approval request (or with multiple requests) and may associate different approval groups (e.g., first level team leaders, IT administrators, legal team members, or second level managers) with each approval level defined in the approval template); Therefore, it would have been obvious to one of ordinarily skill in the art before the effective filing date of the claimed invention to combine the teachings of Delacourt to the permission of Padmanabhan and Marx to include wherein a third user account corresponds to an owner of a resource that is an object of the action, and identifying [a] second user account having permission to perform the action, comprises: determining that the third user account has not responded to a third request to perform the action; and identifying the second user account based on the second user account being an administrator of a plurality of resources including the resource. One would have been motivated to combine the teachings of Delacourt to Padmanabhan and Marx to do so as it provides / allows an uncomplicated approach for provisioning, administering, and managing the physical computing resources (as gleaned from Delacourt, col. 1, lines 5-59). Regarding Claim(s) 14-16; claim(s) 14-16 is/are directed to a/an device associated with the method claimed in claim(s) 7-9. Claim(s) 14-16 is/are similar in scope to claim(s) 7-9, and is/are therefore rejected under similar rationale. Claim(s) 13, 21 and 22 is/are rejected under 35 U.S.C. 103 as being unpatentable over Padmanabhan (US 2015/0372962 A1) in view of Marx et al. (US 2014/0379576 A1) and further in view of Harb (US 2017/0228550 A1). Regarding Claim 13; Padmanabhan and Marx disclose the cloud computing platform device to Claim 10. Padmanabhan and Marx fail to explicitly disclose wherein the permission provides access to a resource for a first predetermined period of time to perform the action. the one or more processors are configured to: provide access to the resource for a second predetermined period of time that is less than the first predetermined period of time. However, in an analogous art, Harb further teaches wherein the permission provides access to a resource for a first predetermined period of time to perform the action (FIG. 5 – John has requested to watch: Game of Thrones – Allow (As noted no associated time limit)), the one or more processors are configured to: provide access to the resource for a second predetermined period of time that is less than the first predetermined period of time (FIG. 5 – John has requested to watch: Game of Thrones – Allow for two hours (As noted an associated time limit that is less than allow)). Therefore, it would have been obvious to one of ordinarily skill in the art before the effective filing date of the claimed invention to combine the teachings of Harb to the permission of Padmanabhan and Marx to include wherein the permission provides access to a resource for a first predetermined period of time to perform the action, the one or more processors are configured to: provide access to the resource for a second predetermined period of time that is less than the first predetermined period of time. One would have been motivated to combine the teachings of Harb to Padmanabhan and Marx to do so as it provides / allows enabling a user to access a blocked asset by add[ing] a layer of security (Harb, [0002]). Regarding Claim 21; Padmanabhan and Marx disclose the method to Claim 1. Marx further teaches the temporal constraint... associated with the requested action (FIG. 1 and [0013] and [0022] and [0029]). Padmanabhan and Marx fail to explicitly disclose wherein the temporal constraint includes the time limit for viewing an item associated with the requested action. However, in an analogous art, Harb further teaches wherein the temporal constraint includes the time limit for viewing an item associated with the requested action. (FIG. 5 – John has requested to watch: Game of Thrones – Allow for two hours/Allow from 8PM to 10PM). Therefore, it would have been obvious to one of ordinarily skill in the art before the effective filing date of the claimed invention to combine the teachings of Harb to the temporal constraint of Padmanabhan and Marx to include wherein the temporal constraint includes the time limit for viewing an item associated with the requested action One would have been motivated to combine the teachings of Harb to Padmanabhan and Marx to do so as it provides / allows enabling a user to access a blocked asset by add[ing] a layer of security (Harb, [0002]). Regarding Claim 22; Padmanabhan and Marx disclose the method to Claim 1. Marx further teaches the temporal constraint... associated with the requested action (FIG. 1 and [0013] and [0022] and [0029]). Padmanabhan and Marx fail to explicitly disclose wherein the temporal constraint includes the time limit for executing an instance of a deployed resource associated with the requested action. However, in an analogous art, Harb further teaches wherein the temporal constraint includes the time limit for executing an instance of a deployed resource associated with the requested action. (FIG. 5 – John has requested to watch: Game of Thrones – Allow for two hours/Allow from 8PM to 10PM and [0091] - As referred to herein, the terms “media asset” and “content” should be understood to mean an electronically consumable user asset, such as television programming, as well as pay-per-view programs, on-demand programs (as in video-on-demand (VOD) systems), Internet content (e.g., streaming content, downloadable content, Webcasts, etc.), video clips, audio, content information, pictures, rotating images, documents, playlists, websites, articles, books, electronic books, blogs, chat sessions, social media, applications, games, and/or any other media or multimedia and/or combination of the same.). Therefore, it would have been obvious to one of ordinarily skill in the art before the effective filing date of the claimed invention to combine the teachings of Harb to the temporal constraint of Padmanabhan and Marx to include wherein the temporal constraint includes the time limit for executing an instance of a deployed resource associated with the requested action. One would have been motivated to combine the teachings of Harb to Padmanabhan and Marx to do so as it provides / allows enabling a user to access a blocked asset by add[ing] a layer of security (Harb, [0002]). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. See PTO-892 attached. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to KARI L SCHMIDT whose telephone number is (571)270-1385. The examiner can normally be reached Monday-Friday 10am - 6pm (MDT). Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu Pham can be reached at (571)270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /KARI L SCHMIDT/Primary Examiner, Art Unit 2439
Read full office action

Prosecution Timeline

Show 7 earlier events
Dec 23, 2025
Request for Continued Examination
Jan 07, 2026
Response after Non-Final Action
Jan 16, 2026
Non-Final Rejection mailed — §103
Apr 14, 2026
Interview Requested
Apr 16, 2026
Applicant Interview (Telephonic)
Apr 16, 2026
Examiner Interview Summary
May 15, 2026
Response Filed
Aug 06, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705372
CONTROLLING AN INTERACTION USING ONLINE ACCOUNT OPENING INDICATORS
3y 1m to grant Granted Aug 11, 2026
Patent 12695782
UPDATING REMOTE SCAN ENGINES WITH CUSTOM VULNERABILITY CHECKS
1y 7m to grant Granted Jul 28, 2026
Patent 12689917
Determining a Subset of Base Stations in a Wireless Network
2y 3m to grant Granted Jul 21, 2026
Patent 12682026
MULTIDIMENSIONAL LOCAL LARGE LANGUAGE MODEL USER AUTHENTICATION
2y 5m to grant Granted Jul 14, 2026
Patent 12666259
Authentication of a Communications Device
5y 1m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
74%
Grant Probability
99%
With Interview (+42.4%)
3y 9m (~10m remaining)
Median Time to Grant
High
PTA Risk
Based on 752 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month