Prosecution Insights
Last updated: August 17, 2026
Application No. 18/604,168

AUTOMATED POLICY MANAGEMENT

Non-Final OA §101§103
Filed
Mar 13, 2024
Examiner
BOND, REED MADISON
Art Unit
3624
Tech Center
3600 — Transportation & Electronic Commerce
Assignee
Wells Fargo Bank N A
OA Round
3 (Non-Final)
9%
Grant Probability
At Risk
3-4
OA Rounds
2m
Est. Remaining
28%
With Interview

Examiner Intelligence

Grants only 9% of cases
9%
Career Allowance Rate
2 granted / 22 resolved
-42.9% vs TC avg
Strong +19% interview lift
Without
With
+19.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 8m
Avg Prosecution
29 currently pending
Career history
63
Total Applications
across all art units

Statute-Specific Performance

§101
42.5%
+2.5% vs TC avg
§103
40.8%
+0.8% vs TC avg
§102
8.2%
-31.8% vs TC avg
§112
6.8%
-33.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 22 resolved cases

Office Action

§101 §103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. DETAILED ACTION The following NON-FINAL Office Action is in response communication filed on 3/16/2026. Status of Claims Claims 1, 3, 6-7, 9-11, 13, 16-17, 19-20 are currently pending. Claims 1, 3, 6-7, 9-11 are currently amended. Claims 2, 4-5, 8, 12, 14-15, 18 are cancelled. Claims 1, 3, 6-7, 9-11, 13, 16-17, 19-20 are currently under examination and have been rejected as follows. Continued Examination under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 03/16/2026 has been entered. IDS The information disclosure statement filed on 3/13/2024 complies with the provisions of 37 CFR 1.97, 1.98 and MPEP § 609 and is considered by the Examiner. ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- Response to Amendment The previously pending rejections under 35 USC 101 will be maintained. The 101 rejection is updated in view of the amendments. New grounds for rejection under 35 USC 103 are applied as necessitated by the amendments. ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- Response to Arguments Regarding Applicant’s remarks pertaining to 35 USC 101: Step 2A Prong 2: Applicant argues on page 2 of 6 of remarks 3/16/2026: “Amended claim 1 recites sufficient technological details demonstrating a specific improvement over existing systems, directly addressing the concerns raised in the advisory action…. “Amended claim 1 now specifies that the system trains multiple models corresponding to specific pairings of source and target programming languages. The claim recites identifying types of target policy execution endpoints associated with specific programming language requirements. The claim recites determining which programming languages are required based on those endpoint types and using artificial intelligence to select a model corresponding to the specific pairing. This directly addresses the advisory action's statement that insufficient details as to which models would be selected and for which specific criteria are recited in the claims… thereby providing the specific technical criteria driving the model selection process. Examiner respectfully finds the argument unpersuasive. The amended descriptions of identifying types of target policy execution endpoints associated with specific programming language requirements, determining which programming languages are required based on those endpoint types, and using artificial intelligence to select a model corresponding to the specific pairing add some specificity to the claims as previously presented. However, the amendments remain insufficient to demonstrate technological improvement over existing systems. The amended claim limitations elaborate on the decision-making criteria for model selection, i.e. which programming languages are involved in the policy translation; but technological detail of the artificial intelligence used in the determination is still insufficient. Further, it is unclear from the claims or specification why AI would be necessary to identify programming languages of endpoints or how this would be implemented in a manner demonstrating technological improvement. The claims as amended do not appear to have any newly-added additional computer-based elements. The original additional elements are recited at a high level of generality because they describe a generic computer performing functions of identifying hardware and software; translating, reformatting, and distributing data, etc. such that they amount to no more than mere instructions to apply the exception using generic computer components. Applicant argues on page 2 of 6 of remarks 3/16/2026: “Applicant respectfully submits that the amended claims now provide specific technical details analogous to Example 47. Claim 3 of Example 47 recites specific steps of detecting malicious network packets using a trained artificial neural network, detecting a source address associated with the malicious packets, dropping the malicious packets, and blocking future traffic from the source address. This combination of detection and remediation steps improves network security.” Examine respectfully disagrees. Included in claim 3 of Example 47 are specific technological steps of how the solution is accomplished, including training the artificial neural network with backpropagation and gradient descent algorithms to detect anomalies in network traffic and further analyze for malicious intent. To the extent Applicant’s amended claims invoke artificial intelligence, it is used to select an appropriate model based on which programming language the endpoints use, but little additional detail on how the selection is performed is included in the claims or the specification (see Applicant specification ¶ [0029]). The amended claims invocation of additional element “models” is similarly limited to translating policy code from one programming language to another with insufficient detail of how the translation is accomplished (see Applicant specification ¶ [0029]). Applicant argues on page 3 of 6 of remarks 3/16/2026: “Similarly, amended claim 1 recites training multiple models for policy code translation corresponding to specific pairings of source and target programming languages. The claim recites identifying types of target policy execution endpoints with their associated programming language requirements and determining which programming languages are required for the endpoints. The claim recites selecting using artificial intelligence based upon the identified endpoint types a model corresponding to the specific language pairing, translating the policy code using the selected model, validating both source and target formats, and distributing via pipelines to the appropriate endpoints. This combination reflects the improvement described in the specification, which explains that the policy pipeline provides checks and balances to assure policies are standardized before distribution and that the translator allows automation of policy generation, permitting a user with expertise in a single policy format to write a policy once and deploy it anywhere in an environment containing multiple policy engines operating on multiple policy formats. Specification at [0011] and [0012].” Examiner respectfully disagrees. MPEP 2106.05(f)(1) states (1) Whether the claim recites only the idea of a solution or outcome i.e., the claim fails to recite details of how a solution to a problem is accomplished. The recitation of claim limitations that attempt to cover any solution to an identified problem with no restriction on how the result is accomplished and no description of the mechanism for accomplishing the result, does not integrate a judicial exception into a practical application or provide significantly more because this type of recitation is equivalent to the words “apply it”. Therefore, it is reasonable to infer from Applicants specification (¶ [0029]) that the above additional elements are generic. Thus, these additional limitations, considered individually and in combination, amount to mere instructions to implement an abstract idea on a general purpose computer or use the computer as a tool to perform an abstract idea and therefore do not integrate the judicial exception into a practical application because they do not impose any meaningful limits on practicing the abstract idea. Applicant argues on page 3 of 6 of remarks 3/16/2026: “The specification explains that the translation engine is programmed to identify the types of each of the policy engines and based upon the types, the translation engine determines which policy languages are needed. Specification at [0033]. This demonstrates that the artificial intelligence does not select models arbitrarily or based on generic criteria. Instead, the artificial intelligence performs a specific technical analysis of endpoint characteristics to determine programming language requirements and then selects the appropriate translation model based on those determined requirements. “The claim recites this specific technical process by requiring that the system identify types of target policy execution endpoints wherein the types are associated with specific programming language requirements. The claim recites determining based upon the types which programming languages are required. The claim recites selecting using artificial intelligence based upon the types one model corresponding to the specific pairing of programming languages. “Amended claim 1 therefore satisfies Step 2A Prong Two by integrating the judicial exception into a practical application through improvements to automated policy management technology.” Examiner respectfully disagrees. Applicant specification ¶ [0033] states: “In some examples, the translation engine 204 is programmed to identify the type(s) of each of the policy engines. Based upon the types, the translation engine 204 determines which policy languages are needed and thereupon translates the policy code into the relevant policy languages”. As submitted above, neither claim recitation nor specification include sufficient specific technologic details of how the artificial intelligence performs the analysis of endpoint characteristics to determine programming language requirements; nor how the translation engine or models perform the translation. ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- Regarding Applicant’s remarks pertaining to 35 USC 103: Applicant argues on page 5 of 6 of remarks 3/16/2026: “Lim does not teach or suggest the limitations added to amended claim 1. Lim teaches deploying policies in different forms depending on the capability of policy engine at the target. Lim at [0108]. However, Lim does not teach training multiple models corresponding to specific pairings of source and target programming languages, identifying types of target policy execution endpoints with associated programming language requirements, determining which programming languages are required based on endpoint types, or using artificial intelligence to select a model based on endpoint types where the model corresponds to a specific pairing of programming languages. “Wright does not remedy these shortcomings.” Examiner respectfully disagrees. The amended claim limitations which include “training multiple models to perform translation of policy code, wherein the multiple models correspond to specific pairings of a source programming language and a target programming language; select, using artificial intelligence based upon the types of the target policy execution endpoints, one model of the multiple models” is further disclosed with additional support by secondary reference Wright at Figure 2 steps 5-7, ¶ [0022] and ¶ [0024]. The amended claim limitations which include “identify types of target policy execution endpoints, wherein the types of the target policy execution endpoints are associated with specific programming language requirements” is further supported by primary reference Lim at ¶ [0288]; and “determine, based upon the types of the target policy execution endpoints, which programming languages are required for the target policy execution endpoints” is further supported by primary reference Lim at ¶ [0108]. See 103 rejection section below for citations and further details. Applicant argues on page 5 of 6 of remarks 3/16/2026: “Goel also does not teach or suggest the limitations added to amended claim 1.” Examiner respectfully finds the argument moot. Goel addresses the independent claim limitation “validate the policy code in the first format and the second format before distribution” at ¶ [0020], [0062]. However, Goel is not relied upon for teaching any of the presently amended limitations. Accordingly, new grounds for rejection under 35 USC 103 are applied as necessitated by the amendments. ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1, 3, 6-7, 9-11, 13, 16-17, 19-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Claims 1, 3, 6-7, 9-10 are directed to a system or machine which is a statutory category. Claims 11, 13, 16-17, 19-20 are directed to a method or process which is a statutory category. Step 2A Prong One: The claims recite, describe, or set forth a judicial exception of an abstract idea (see MPEP 2106.04(a)). Specifically, the claims recite, describe or set forth mitigating risk; agreements in the form of contracts; and legal obligations including: “perform translation of policy code”, “take policy code in a first format and translate the policy code to a second format”, and “distribute the policy code in the first format to a first policy engine and distribute the policy code in the second format to a second policy engine”. Additionally, the claims recite, describe or set forth concepts performed in the human mind (including observation, evaluation, judgement), including: “identify types of target policy execution endpoints, wherein the types of the target policy execution endpoints are associated with specific programming language requirements” (observation), “determine, based upon the types of the target policy execution endpoints, which programming languages are required for the target policy execution endpoints” (evaluation), “select… based upon the types of the target policy execution endpoints, one model of the multiple models for the translation of the policy code from a first format to a second format, wherein the first format is a first programming language, and wherein the second format is a second programming language different from the first programming language” (judgement). Standardizing an organization’s policy and governance format and disseminating standardized policies to various branches of the organization fall within mitigating risk as it pertains to fundamental economic principles; and agreements in the form of contracts and legal obligations as they pertain to commercial or legal interactions, each under the larger abstract grouping of Certain Methods of Organizing Human Activity (MPEP 2106.04(a)(2) II). Furthermore, Identifying types of information technology, evaluating programming language requirements, and selecting appropriate models for policy code format translation fall within the abstract grouping of Mental Processes1 (MPEP 2106.04(a)(2) III). Examiner also points to MPEP2106.04(a)(2) III C finding that computer aided processes such as: 1. Performing a mental process on a generic computer, 2. Performing a mental process in a computer environment, 3. Using a computer as a tool to perform a mental process can still be considered to recite a mental process. Accordingly, the claims recite an abstract idea. Step 2A Prong Two: Independent claims 1, 11 recite the following additional elements: “computer system”, “processors”, “non-transitory computer-readable storage media”, “translation engine”, “pipeline engine”, “policy engine”, “artificial intelligence”, and “model”. The functions of these additional elements include examples such as “training models”, “identify types of target policy execution endpoints”, “determine… which programming languages are required for the target policy execution endpoints”, “select… models for the translation of the policy code”, “automating policy management”, “encoding instructions”, “translate the policy code”, and “distribute the policy code”. The additional elements are recited at a high level of generality (i.e. as a generic computer performing functions of identifying hardware and software; translating, reformatting, and distributing data and code, etc.) such that they amount to no more than mere instructions to apply the exception using generic computer components. Therefore, these functions can be viewed as not meaningfully different than a business method or mathematical algorithm being applied on a general-purpose computer as tested per MPEP 2106.05(f)(2)(i). The claims are directed to an abstract idea and the judicial exception does not integrate the abstract idea into a practical application. MPEP 2106.05(f)(1) states (1) Whether the claim recites only the idea of a solution or outcome i.e., the claim fails to recite details of how a solution to a problem is accomplished. The recitation of claim limitations that attempt to cover any solution to an identified problem with no restriction on how the result is accomplished and no description of the mechanism for accomplishing the result, does not integrate a judicial exception into a practical application or provide significantly more because this type of recitation is equivalent to the words “apply it”. Thus, these additional limitations, considered individually and in combination, amount to mere instructions to implement an abstract idea on a general purpose computer or use the computer as a tool to perform an abstract idea and therefore do not integrate the judicial exception into a practical application because they do not impose any meaningful limits on practicing the abstract idea. Further, the additional element “artificial intelligence”; and “train multiple models” and “select… one model of the multiple models” language merely requires execution of an algorithm that can be performed by a generic computer component and provides no detail regarding the operation of that algorithm. As such, the claim requirement amounts to mere instructions to implement the abstract idea on a computer, and, therefore, is not sufficient to make the claim patent eligible. See Alice, 573 U.S. at 226 (determining that the claim limitations “data processing system,” “communications controller,” and “data storage unit” were generic computer components that amounted to mere instructions to implement the abstract idea on a computer); October 2019 Guidance Update at 11–12 (recitation of generic computer limitations for implementing the abstract idea “would not be sufficient to demonstrate integration of a judicial exception into a practical application”). Such a generic recitation of “train multiple models” and “select… one model of the multiple models” is insufficient to show a practical application of the recited abstract idea. Step 2B: According to MPEP 2106.05(f)(1), considering whether the claim recites only the idea of a solution or outcome i.e., the claims fail to recite the technological details of how the actual technological solution to the actual technological problem is accomplished. The recitation of claim limitations that attempt to cover an entrepreneurial and thus abstract solution to an entrepreneurial problem with no technological details on how the technological result is accomplished and no description of the mechanism for accomplishing the result do not provide significantly more than the judicial exception. Dependent claims 6, 16 recite the additional elements “development engine” and “database”. Dependent claims 9, 19 recite the additional element “logging engine”. Dependent claims 10, 20 recite the additional elements “reporting engine” and “dashboard”. The functions of these additional elements include examples such as “translate the policy code”, “accept the policy code”, “store the policy code”, “log the policy management actions performed”, and “provide[s] various metrics”. The additional elements are also recited at a high level of generality (i.e. as a generic computer performing functions of translating, reformatting, distributing, storing, and communicating data and code, etc.) such that they amount to no more than mere instructions to apply the exception using generic computer components. Finally, dependent claims 3, 7, 13, 17 merely incorporate the additional elements recited in claims 1, 11 along with further narrowing of the abstract idea of claims 1, 11 along with their execution of the abstract idea. Specifically, the dependent claims narrow the “computer system”, “processors”, “non-transitory computer-readable storage media”, “translation engine”, “pipeline engine”, and “policy engine” to capabilities such as translate, apply, select, validate, and distribute various forms of data such as policy, code, languages, formats, engine types, etc. which, when evaluated per MPEP 2106.05(f)(2) represent mere invocation of computers to perform existing processes. Therefore, the additional elements recited in the claimed invention individually and in combination fail to integrate a judicial exception into a practical application (Step 2A prong two) and for the same reasons they also fail to provide significantly more (Step 2B). Thus, claims 1, 3, 6-7, 9-11, 13, 16-17, 19-20 are reasoned to be patent ineligible. ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- REJECTIONS BASED ON PRIOR ART Examiner Note: Some rejections will contain bracketed comments preceded by an “EN” that will denote an examiner note. This will be placed to further explain a rejection. ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1, 3, 6-7, 9-11, 13, 16-17, 19-20 are rejected under 35 U.S.C. 103 as being unpatentable over: Lim US 20070156659 A1, hereinafter Lim in view of Wright et al. US 20220131904 A1, hereinafter Wright, and in further view of Goel et al. US 20250106256 A1, hereinafter Goel. As per, Regarding Claims 1, 11: Lim teaches: (Claim 1) A computer system for automating policy management, comprising: one or more processors; and non-transitory computer-readable storage media encoding instructions which, when executed by the one or more processors, causes the computer system to: / (Claim 11) A method for automating policy management, comprising: [..] identify types of target policy execution endpoints, wherein the types of the target policy execution endpoints are associated with specific programming language requirements (Lim ¶ [0288]: In an implementation, one or more policy deployment directives can be specified in a policy to designate at least one target [EN: endpoint], target type or target group that the policy should be deployed or transferred to. Some examples of a target includes a "Microsoft Exchange Server," [EN: C++ and C# programming languages] or "Apache HTTP Server" [EN: C programming language]. A target type may include a laptop computer, personal digital assistant, e-mail server, or instant messenger. A target group includes "marketing computers." If both policy deployment directives and automatic target binding are implemented, the combined benefit of user guided deployment and automatic deployment can be achieved); determine, based upon the types of the target policy execution endpoints, which programming languages are required for the target policy execution endpoints (Lim ¶ [0108]: In a further implementation, the policy deployment module can deploy policies in different forms depending on the capability [EN: type] of policy engine at the target [EN: endpoint]. For example, the set of policies that is transmitted from the policy server to a policy enforcer (or target) may take one of the following forms: (1) ASCII text, (2) binary (e.g., code or data), (3) XML (e.g., in Extensible Access Control Markup Language XACML format), or (4) translated or compiled including policies represented in binary form, polices translated into tables (in binary or text form) or policies translated into programming language (such as XML, Java, C#, Perl, or Python in source code format or compiled binaries), or a combination of these. CH is an object-oriented programming language developed by Microsoft as part of their .NET initiative. C# is based on C++and Java); [..] translation of the policy code from a first format to a second format, wherein the first format is a first programming language, and wherein the second format is a second programming language different from the first programming language, and wherein the one model corresponds to one specific pairing of the first programming language and the second programming language; (Claim 1) take the policy code in the first format and translate [..] the policy code to the second format / (claim 11) translating the policy code in the first format to the second format (Lim ¶ [0055]: In an implementation, the invention includes a method of managing information of a network including providing a server handling a first policy language having access to a policy database; providing a first device having a decision engine to manage information accessible via the device according to a first set of policies stored on the device, where the first set of policies is associated with the first policy language; and providing a second device that handles a second policy language. The method includes translating a first policy of the policy database into the second policy language and transferring the first policy in the second policy language to the second device. End-¶ [0297]: Collectively, these policy components, component services, abstraction engine, component interface, and component packaging service make up a policy component model which corresponds to the abstraction object layer of the layer description of a policy language system); [..]; and (claim 1) automatically distribute / (claim 11) distributing, by at least one pipeline, the policy code in the first format to a first policy execution endpoint of the target policy execution endpoints and distribute the policy code in the second format to a second policy execution endpoint of the target policy execution endpoints (Lim ¶ [0107]: In a policy system architecture that distributes full sets of policies to all policy enforcers, the policy deployment module [EN: pipeline] takes a complete set of policies and sends it to a policy enforcer [EN: policy execution]. In a policy system architecture that organizes policies based on one or more specific policy enforcers or policies targets [EN: endpoints], the policy deployment module receives or locates a policy enforcer's information and delivers the set of policies or a set of differences relevant to that [EN: first or second] policy enforcer. ¶ [0588]: In a specific implementation, a policy server performs optimization in the policies, or policy abstractions, or both, in the policy bundle and transfers the optimized policies, or policy abstractions, or both, in a policy bundle along with all supporting information to the client workstation. The optimized policies and policy abstractions may have the same policies format as the preoptimized policies or may be transformed to a different policy format). Although Lim teaches translating policy code, Lim does not specifically teach doing so using AI to select and train a model, nor validating the policy code in both formats. However, Wright in analogous art of policy management systems teaches or suggests: (claim 1) train / (claim 11) training multiple models to perform translation of policy code, wherein the multiple models correspond to specific pairings of a source programming language and a target programming language; (claim 1) select / (claim 11) selecting, using artificial intelligence based upon the types of the target policy execution endpoints, one model of the multiple models for the [..] (See Wright Fig. 2 steps involving the “AI Engine”, including step 5: “supplies policy engine with implementation data for the technology that the policy is targeting”; step 6: “apply implementation data against the technologies to understand policy coverage”; and step 7: “generate technical implementation requirements per technology, per policy” [EN: pairings]. Wright ¶ [0022]: The target technology platform may be one of a plurality of target technology platforms. The AI engine may translate human-readable policy requirements associated with a first technology platform into technical requirements for each of the plurality of target technology platforms [EN: target policy execution endpoints]. The AI engine may configure each of the plurality of target technology platforms in accordance with the technical requirements [EN: for each type] generated based on the translating. ¶ [0024]: The AI engine may utilize any suitable machine learning algorithm [EN: plurality of models]. Exemplary algorithms may include one or of the following machine learning algorithms: Naïve Bayes Classifier Algorithm, K Means Clustering Algorithm, Support Vector Machine Algorithm, Apriori Algorithm, Linear Regression, Logistic Regression, Artificial Neural Networks, Nearest Neighbors, Random Forests and/or Decision Trees. Any suitable machine learning algorithm may be utilized. By utilizing machine learning algorithms, the AI engine may analyze a security policy that is complex and documented in one or more formats). Wright and Lim are found as analogous art of intelligent policy management systems. It would have been obvious to one skilled in the art, before the effective filing date of the invention, to have modified Lim’s intelligent policy deployment system and method to have included Wright’s teachings around using AI to translate policy. The benefit of these additional features would have increased levels of consistency; reduced risks of cyber security breaches, inadvertent adverse policy changes, and omission of key policy considerations; and decreased technical debt (Wright ¶ [0007]). The predictability of such modifications and/or variations, would have been corroborated by the broad level of skill of one of ordinary skills in the art as articulated by Lim in view of Wright (see MPEP 2143 G). Further, the claimed invention could have also been viewed as a mere combination of old elements in a similar field of intelligent policy management systems. In such combination each element would have merely performed the same function as it did separately. Thus, one of ordinary skill in the art would have recognized that, given existing technical ability to combine the elements, as evidenced by Lim in view of Wright above, the to- be combined elements would have fit together like pieces of a puzzle in a logical, complementary, technologically feasible and/or economically desirable manner. Thus, it would have been reasoned that the results of the combination would have been predictable (see MPEP 2143 A). Furthermore, Goel in analogous art of policy management systems teaches or suggests: (claim 1) validate / (claim 11) validating the policy code in the first format and the second format before distribution (Goel mid-¶ [0020]: Besides converting policies into this target language for automated analysis, some techniques employ an automated differential testing method. This method validates the accuracy of the compiled provider network policies into the target policy language. This automated differential testing process generates access requests to ensure both the source policies and the translated policy consistently allow or deny access. ¶ [0062]: FIG. 5 illustrates an example of using differential testing to systematically validate that a compiler has translated a source access control policy into a target language without altering its behavior…. The suite of access requests are used by differential tester 480 as the inputs that are fed to both the source access control policy 482 and the target access control policy 484. Differential tester 480 processes each access request of the suite against the source access control policy 482 and records whether the access requests source access control policy 482 permits or denies the access requests. Differential tester 480 uses the same suite of access requests to evaluate how the target access control policy 484 reacts). Goel, Wright and Lim are found as analogous art of intelligent policy management systems. It would have been obvious to one skilled in the art, before the effective filing date of the invention, to have modified Lim / Wright’s intelligent policy deployment system and method to have included Goel’s teachings around validating policy code in both original and target formats. The benefit of these additional features would have centralized and streamlined multi-provider network management (Goel ¶ [0002]). The predictability of such modifications and/or variations, would have been corroborated by the broad level of skill of one of ordinary skills in the art as articulated by Lim in view of Wright and Goel (see MPEP 2143 G). Further, the claimed invention could have also been viewed as a mere combination of old elements in a similar field of intelligent policy management systems. In such combination each element would have merely performed the same function as it did separately. Thus, one of ordinary skill in the art would have recognized that, given existing technical ability to combine the elements, as evidenced by Lim in view of Wright and Goel above, the to- be combined elements would have fit together like pieces of a puzzle in a logical, complementary, technologically feasible and/or economically desirable manner. Thus, it would have been reasoned that the results of the combination would have been predictable (see MPEP 2143 A). Regarding Claims 3, 13: Lim / Wright / Goel teaches all the limitations of claims 1, 11 above. Lim further teaches: automatically (claim 3) translate / (claim 13) translating the policy code based upon a type of the second policy execution endpoint (Lim ¶ [0108]: In a further implementation, the policy deployment module can deploy policies in different forms depending on the capability [EN: type] of policy engine at the target [EN: second policy execution endpoint]. For example, the set of policies that is transmitted from the policy server to a policy enforcer (or target) may take one of the following forms: (1) ASCII text, (2) binary (e.g., code or data), (3) XML (e.g., in Extensible Access Control Markup Language XACML format), or (4) translated or compiled including policies represented in binary form, polices translated into tables (in binary or text form) or policies translated into programming language (such as XML, Java, C#, Perl, or Python in source code format or compiled binaries), or a combination of these. CH is an object-oriented programming language developed by Microsoft as part of their .NET initiative. C# is based on C++and Java). Regarding Claims 6, 16: Lim / Wright / Goel teaches all the limitations of claims 1, 11 above. Lim further teaches: (claim 6) accept / (claim 16) accepting the policy code in the first format and store the policy code in a database (Lim ¶ [0063]: Referring to FIG. 4, policies are created and managed by a policy server 401 [EN: development engine]. As discussed below, a policy may define to whom and under what conditions (or conditions) access to a document is granted or denied. The policies are stored and manipulated by the policy author and policy administrator in the policy repository 402 [EN: database]. Policies or subsets of policies, or both, are transmitted to workstations 403 and document servers 405 to control local and remote document accesses and information usage). Regarding Claims 7, 17: Lim / Wright / Goel teaches all the limitations of claims 1, 11 above. Lim further teaches: (claim 7) apply / (claim 17) applying the policy code across multiple policy engines by selecting a code format for each of the multiple policy engines (Lim ¶ [0174]: Depending on what policy system architecture is selected, the implementation of the policy engine can vary significantly. Some examples include distributing full sets of policies to policy enforcers, organizing policies based on the type of policy enforcer the policies target, using policies defined in XACML format, or using policies defined in Blue Jungle's Compliant Enterprise Active Control Policy Language (ACPL) format that uses a declarative approach to policy specification). Regarding Claims 9, 19: Lim / Wright / Goel teaches all the limitations of claims 1, 11 above. Lim further teaches: (claim 9) log / (claim 19) logging the policy management actions performed by the computer system (Lim ¶ [0123]: …a policy enforcer can carry out audit (or log) function, and obligation and remediation tasks (described below). ¶ [0126]: Since policy enforcers have access to information regarding document access and information usage. Such activity information (or audit information) can be logged by a policy enforcer to a local or central database. The activity data collected by one or more policy enforcers can be correlated, analyzed, and applied to many applications including: (1) auditing or compliance; (2) investigation; (3) detecting information fraud; (4) detecting information misuse; (5) detecting anomalies; (6) understanding and optimizing resource utilization; and (7) understanding and improving workforce productivity). Regarding Claims 10, 20: Lim / Wright / Goel teaches all the limitations of claims 1, 11 above. Lim further teaches: [..] provide[s] various metrics for the computer system (Lim ¶ [0113]: The reporting module 804 [EN: reporting engine] is responsible for providing support to the reporting and analysis tool 502. Its main function is report generation. ¶ [0115] (1) Summary Analysis-document access activity, information usage activity or policy enforcement activity summarized by user, document, host, policy, location, time (e.g., day or week), organization, and more. ¶ [0116] (2) Trend Analysis-document access activity, information usage activity, or policy enforcement activity for a given period of time. ¶ [0117] (3) Detailed Event Forensics-detailed listing of activities for specific user actions or policy enforcement actions. Detailed reports showing event-level details for document access activity, information usage activity, or policy enforcement activity) Although Lim teaches reporting policy management data, Lim does not specifically teach generating a dashboard. However, Wright in analogous art of intelligent policy management systems teaches or suggests: [..] generate a dashboard [..] (See Wright: Policy Implementation Dashboard at Figs. 5-7 and related text. Wright ¶ [0113]: Based on responses to test inputs 401, AI engine 211 may generate additional human-readable policy output 403. Human-readable policy output 403 may advise user 207 on machine generated changes to configuration settings currently applied to software applications 309-311. Human-readable output 403 may be presented via editor/GUI 303). Wright and Lim are found as analogous art of intelligent policy management systems. It would have been obvious to one skilled in the art, before the effective filing date of the invention, to have modified Lim’s intelligent policy deployment system and method to have included Wright’s teachings around displaying policy management data on a dashboard. The benefit of these additional features would have increased levels of consistency; reduced risks of cyber security breaches, inadvertent adverse policy changes, and omission of key policy considerations; and decreased technical debt (Wright ¶ [0007]). The predictability of such modifications and/or variations, would have been corroborated by the broad level of skill of one of ordinary skills in the art as articulated by Lim in view of Wright (see MPEP 2143 G). Further, the claimed invention could have also been viewed as a mere combination of old elements in a similar field of intelligent policy management systems. In such combination each element would have merely performed the same function as it did separately. Thus, one of ordinary skill in the art would have recognized that, given existing technical ability to combine the elements, as evidenced by Lim in view of Wright above, the to- be combined elements would have fit together like pieces of a puzzle in a logical, complementary, technologically feasible and/or economically desirable manner. Thus, it would have been reasoned that the results of the combination would have been predictable (see MPEP 2143 A). ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ Conclusion The following art is made of record and considered pertinent to Applicant’s disclosure: Kaminsky; David L. Et al. US 20090049508 A1, Language-agnostic policy management. Neal; Ryan et al. US 20220358240 A1, Adaptive data privacy platform. Banerjee; Moushmi et al. US 20250112961 A1, Techniques for generating policy recommendations and insights using generative AI. Litvin; Moshe et al. US 20090249472 A1, Hierarchical firewalls. Schneider; Christopher Ian et al. US 20250013441 A1, Automated policy compliance using large language models. Channabasavaiah; Kishore et al. US 20100251327 A1, SOA policy engine framework. Boling; Eli et al. US 20210042100 A1, System and method for translating mapping policy into code. Maes; Stephane H. US 8141125 B2, Orchestration of policy engines and format technologies. Hinchey; Michael G. Et al. US 7886273 B2, Systems, methods and apparatus for generation and verification of policies in autonomic computing systems. OLDEN; ERIC MICHAEL et al. US 20220318416 A1, Identity query language systems and methods. Perich; Filip et al. US 20080163334 A1, Method and device for policy-based control of radio. Roth; Gregory Branchek et al. US 9083749 B1, Managing multiple security policy representations in a distributed environment. Chett Hafeesmon et al. IL 311244 A, Systems and methods for policy management. Mohun, J. and A. Roberts (2020), “Cracking the code: Rulemaking for humans and machines”, OECD Working Papers on Public Governance, No. 42, OECD Publishing, Paris, https://doi.org/10.1787/3afe6ba5-en. ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ Any inquiry concerning this communication or earlier communications from the examiner should be directed to REED M. BOND whose telephone number is (571) 270-0585. The examiner can normally be reached Monday - Friday 8:00 am - 5:00 pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Patricia Munson can be reached at (571) 270-5396. The fax phone number for the organization where this application or proceeding is assigned is (571) 273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /REED M. BOND/Examiner, Art Unit 3624 July 9, 2026 /HAMZEH OBAID/Primary Examiner, Art Unit 3624 1 MPEP 2106.04(a): “examiners should identify at least one abstract idea grouping, but preferably identify all groupings to the extent possible”.
Read full office action

Prosecution Timeline

Show 6 earlier events
Sep 29, 2025
Applicant Interview (Telephonic)
Sep 29, 2025
Examiner Interview Summary
Oct 03, 2025
Response Filed
Dec 15, 2025
Final Rejection mailed — §101, §103
Feb 10, 2026
Response after Non-Final Action
Mar 16, 2026
Request for Continued Examination
Mar 27, 2026
Response after Non-Final Action
Jul 16, 2026
Non-Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12586012
PROVIDING UNINTERRUPTED REMOTE CONTROL OF A PRODUCTION DEVICE VIA VIRTUAL REALITY DEVICES
2y 8m to grant Granted Mar 24, 2026
Study what changed to get past this examiner. Based on 1 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
9%
Grant Probability
28%
With Interview (+19.4%)
2y 8m (~2m remaining)
Median Time to Grant
High
PTA Risk
Based on 22 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month