Prosecution Insights
Last updated: August 18, 2026
Application No. 18/617,643

AUTOMATIC EFFECTIVE PERMISSIONS DISCOVERY FOR CLOUD RESOURCES

Non-Final OA §101§103
Filed
Mar 26, 2024
Examiner
ADMASU, MAHLIET TASEW
Art Unit
Tech Center
Assignee
Microsoft Technology Licensing, LLC
OA Round
1 (Non-Final)
Grant Probability
Favorable
1-2
OA Rounds

Examiner Intelligence

Grants only 0% of cases
0%
Career Allowance Rate
0 granted / 0 resolved
-60.0% vs TC avg
Minimal +0% lift
Without
With
+0.0%
Interview Lift
resolved cases with interview
Typical timeline
Avg Prosecution
14 currently pending
Career history
12
Total Applications
across all art units

Statute-Specific Performance

§101
31.5%
-8.5% vs TC avg
§103
57.4%
+17.4% vs TC avg
§112
9.3%
-30.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 0 resolved cases

Office Action

§101 §103
DETAILED ACTION This communication is in response to Application No. 18/617,643 filed on March 26, 2024 in which Claims 1-20 are presented for examination. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claim 1-20 are rejected under 35 U.S.C. 101 because these claimed inventions are directed to an abstract idea without significantly more. Regarding Claim 1: Step 1: Claim 1 is a system type claim. Therefore, Claims 1-7 fall within one of the four statutory categories (i.e., process, machine, manufacture, or composition of matter). 2A Prong 1: If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components, then it falls within the “Mental Processes” grouping of abstract ideas. If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation by mathematical calculation but for the recitation of generic computer components, then it falls within the “Mathematical Concepts” grouping of abstract ideas. create a prompt for a large language model (LLM), the prompt including (A) a role definition for a role of a role-based access control system and (B) action definitions (mental process – creating a prompt may be performed mentally or using pen and paper by a user observing/analyzing the role definitions and action definitions and accordingly using judgement/evaluation to create/write a prompt based on said analysis) […] to generate response text […] (mental process – generating response text may be performed mentally or using pen and paper by a user reading/analyzing the information and question included in the prompt and accordingly using judgment/evaluation to formulate/write a response based on said analysis) append, onto the prompt, query text that describes a question referencing the role (mental process - appending query text that describes a question referencing the role may be performed mentally or using pen and paper by a user formulating/writing a question concerning the role and adding the question to the prompt based on said analysis) Step 2A Prong 2: This judicial exception is not integrated into a practical application. a processor; (recited at a high-level of generality (i.e., a generic processor, computer-readable storage medium, a communication interface, a user interface and memory) such that it amounts to no more than mere instructions to apply the exception using generic computer components) a computer-readable medium […] (recited at a high-level of generality (i.e., a generic processor, a computer-readable medium, a communication interface, storage devices and memory) such that it amounts to no more than mere instructions to apply the exception using generic computer components) the role definition for the role including an action and effective permissions text describing a summary of permission limitations provided by the role (Field of Use – limitations that amount to merely indicating a field of use or technological environment in which to apply a judicial exception does not amount to significantly more than the exception itself, and cannot integrate a judicial exception into a practical application; in this case specifying that the role definition for the role includes an action and effective permissions text describing a summary of permission limitations provided by the role does not integrate the exception into a practical application nor amount to significantly more – See MPEP 2106.05(h)) the action definitions being in a hierarchical format and including the action(Field of Use – limitations that amount to merely indicating a field of use or technological environment in which to apply a judicial exception does not amount to significantly more than the exception itself, and cannot integrate a judicial exception into a practical application; in this case specifying that the action definitions being in a hierarchical format and including the action does not integrate the exception into a practical application nor amount to significantly more – See MPEP 2106.05(h)) submit the prompt to the LLM […] (Adding insignificant extra-solution activity to the judicial exception - see MPEP 2106.05(g)) […] from the LLM (Adding the words “apply it” (or an equivalent) with the judicial exception, or mere instructions to implement an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea - see MPEP 2106.05(f) – Examiner’s note: high level recitation of using a large language model without significantly more) Step 2B: The claim does not include additional elements considered individually and in combination that are sufficient to amount to significantly more than the judicial exception. a processor; (recited at a high-level of generality (i.e., a generic processor, computer-readable storage medium, a communication interface, a user interface and memory) such that it amounts to no more than mere instructions to apply the exception using generic computer components) a computer-readable medium […] (recited at a high-level of generality (i.e., a generic processor, a computer-readable medium, a communication interface, storage devices and memory) such that it amounts to no more than mere instructions to apply the exception using generic computer components) the role definition for the role including an action and effective permissions text describing a summary of permission limitations provided by the role (Field of Use – limitations that amount to merely indicating a field of use or technological environment in which to apply a judicial exception does not amount to significantly more than the exception itself, and cannot integrate a judicial exception into a practical application; in this case specifying that the role definition for the role includes an action and effective permissions text describing a summary of permission limitations provided by the role does not integrate the exception into a practical application nor amount to significantly more – See MPEP 2106.05(h)) the action definitions being in a hierarchical format and including the action(Field of Use – limitations that amount to merely indicating a field of use or technological environment in which to apply a judicial exception does not amount to significantly more than the exception itself, and cannot integrate a judicial exception into a practical application; in this case specifying that the action definitions being in a hierarchical format and including the action does not integrate the exception into a practical application nor amount to significantly more – See MPEP 2106.05(h)) submit the prompt to the LLM […] (MPEP 2106.05(d)(II) indicates that merely “Receiving or transmitting data over a network” is a well-understood, routine, conventional function when it is claimed in a merely generic manner (as it is in the present claim). Thereby, a conclusion that the claimed limitation is well-understood, routine, conventional activity is supported under Berkheimer) […] from the LLM (Adding the words “apply it” (or an equivalent) with the judicial exception, or mere instructions to implement an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea - see MPEP 2106.05(f) – Examiner’s note: high level recitation of using a large language model without significantly more) For the reasons above, Claim 1 is rejected as being directed to an abstract idea without significantly more. This rejection applies equally to dependent claims 1 - 7. The additional limitations of the dependent claims are addressed below. Regarding Claim 2: Step 2A Prong 1: See the rejection of Claim 1 above, which Claim 2 depends on. create the query text by populating a preconfigured query text template with the security principal and the target resource (mental process creating query text by populating a preconfigured query text template with the security principal and the target resource may be performed mentally or using pen and paper by a user reading/analyzing the identified security principal and target resource and accordingly using judgment/evaluation to insert/write said information into the designated portions of the query text template) Step 2A Prong 2 & Step 2B: receive user input, identifying a security principal and a target resource (Adding insignificant extra-solution activity to the judicial exception - see MPEP 2106.05(g) & MPEP 2106.05(d)(II) indicates that merely “Receiving or transmitting data over a network” is a well-understood, routine, conventional function when it is claimed in a merely generic manner (as it is in the present claim). Thereby, a conclusion that the claimed limitation is well-understood, routine, conventional activity is supported under Berkheimer) Accordingly, under Step 2A Prong 2 and Step 2B, this additional element does not integrate the abstract idea into practical application because it does not impose any meaningful limits on practicing the abstract idea, as discussed above in the rejection of claim 1. The claim does not include additional elements considered individually and in combination that are sufficient to amount to significantly more than the judicial exception. Regarding Claim 3: Step 2A Prong 1: See the rejection of Claim 1 above, which Claim 3 depends on. Step 2A Prong 2 & Step 2B: wherein the hierarchical format of the action definitions includes a resource type portion and an action verb portion, wherein the action identifies a resource type and an action verb (Field of Use – limitations that amount to merely indicating a field of use or technological environment in which to apply a judicial exception does not amount to significantly more than the exception itself, and cannot integrate a judicial exception into a practical application; in this case specifying that the hierarchical format of the action definitions includes a resource type portion and an action verb portion and the action identifies a resource type and an action verb does not integrate the exception into a practical application nor amount to significantly more – See MPEP 2106.05(h)) Accordingly, under Step 2A Prong 2 and Step 2B, this additional element does not integrate the abstract idea into practical application because it does not impose any meaningful limits on practicing the abstract idea, as discussed above in the rejection of claim 1. The claim does not include additional elements considered individually and in combination that are sufficient to amount to significantly more than the judicial exception. Regarding Claim 4: Step 2A Prong 1: See the rejection of Claim 1 above, which Claim 4 depends on. stores an example role definition including the role definition, the example role definition including a permitted action from the action definitions and associated effective permissions text, […] (mental process – storing an example role definition including the role definition may be performed mentally or using pen and paper by a user reading/analyzing the role definition, permitted action, action definitions, and associated effective permissions text and accordingly using judgment/evaluation to organize/write/record the example role definition based on said analysis) […] wherein creating the prompt further includes adding the example role definition to the prompt (mental process –adding the example role definition to the prompt may be performed mentally or using pen and paper by a user observing/analyzing the example role definition and the prompt and accordingly using judgment/evaluation to insert/write the example role definition into the prompt based on said analysis) Step 2A Prong 2 & Step 2B: Accordingly, under Step 2A Prong 2 and Step 2B, there are no additional elements that integrate the abstract idea into practical application. The claim does not include additional elements considered individually and in combination that are sufficient to amount to significantly more than the judicial exception. Regarding Claim 5: Step 2A Prong 1: See the rejection of Claim 1 above, which Claim 5 depends on. Step 2A Prong 2 & Step 2B: receive user input identifying another role definition, the other role definition includes another action and does not include effective permissions text (Adding insignificant extra-solution activity to the judicial exception - see MPEP 2106.05(g) & MPEP 2106.05(d)(II) indicates that merely “Receiving or transmitting data over a network” is a well-understood, routine, conventional function when it is claimed in a merely generic manner (as it is in the present claim). Thereby, a conclusion that the claimed limitation is well-understood, routine, conventional activity is supported under Berkheimer) submit another prompt to the LLM, the other prompt including the other role definition and other query text that describes a question referencing the other role (Adding insignificant extra-solution activity to the judicial exception - see MPEP 2106.05(g) & MPEP 2106.05(d)(II) indicates that merely “Receiving or transmitting data over a network” is a well-understood, routine, conventional function when it is claimed in a merely generic manner (as it is in the present claim). Thereby, a conclusion that the claimed limitation is well-understood, routine, conventional activity is supported under Berkheimer) Accordingly, under Step 2A Prong 2 and Step 2B, this additional element does not integrate the abstract idea into practical application because it does not impose any meaningful limits on practicing the abstract idea, as discussed above in the rejection of claim 1. The claim does not include additional elements considered individually and in combination that are sufficient to amount to significantly more than the judicial exception. Regarding Claim 6: Step 2A Prong 1: See the rejection of Claim 1 above, which Claim 6 depends on. Step 2A Prong 2 & Step 2B: wherein the role definition further includes an allowed action and a prohibited action (Field of Use – limitations that amount to merely indicating a field of use or technological environment in which to apply a judicial exception does not amount to significantly more than the exception itself, and cannot integrate a judicial exception into a practical application; in this case specifying that the role definition further includes an allowed action and a prohibited action does not integrate the exception into a practical application nor amount to significantly more – See MPEP 2106.05(h)) Accordingly, under Step 2A Prong 2 and Step 2B, this additional element does not integrate the abstract idea into practical application because it does not impose any meaningful limits on practicing the abstract idea, as discussed above in the rejection of claim 1. The claim does not include additional elements considered individually and in combination that are sufficient to amount to significantly more than the judicial exception. Regarding Claim 7: Step 2A Prong 1: See the rejection of Claim 1 above, which Claim 7 depends on. Step 2A Prong 2 & Step 2B: wherein the instructions are further operative to request, from the role-based access control system, the action definitions (Adding insignificant extra-solution activity to the judicial exception - see MPEP 2106.05(g) & MPEP 2106.05(d)(II) indicates that merely “Receiving or transmitting data over a network” is a well-understood, routine, conventional function when it is claimed in a merely generic manner (as it is in the present claim). Thereby, a conclusion that the claimed limitation is well-understood, routine, conventional activity is supported under Berkheimer) Accordingly, under Step 2A Prong 2 and Step 2B, this additional element does not integrate the abstract idea into practical application because it does not impose any meaningful limits on practicing the abstract idea, as discussed above in the rejection of claim 1. The claim does not include additional elements considered individually and in combination that are sufficient to amount to significantly more than the judicial exception. Regarding Claim 8: Step 1: Claim 8 is a method type claim. Therefore, Claims 8-14 fall within one of the four statutory categories (i.e., process, machine, manufacture, or composition of matter). 2A Prong 1: If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components, then it falls within the “Mental Processes” grouping of abstract ideas. If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation by mathematical calculation but for the recitation of generic computer components, then it falls within the “Mathematical Concepts” grouping of abstract ideas. creating a prompt for a large language model (LLM), the prompt including (A) a role definition for a role of a role-based access control system and (B) action definitions (mental process – creating a prompt may be performed mentally or using pen and paper by a user observing/analyzing the role definitions and action definitions and accordingly using judgement/evaluation to create/write a prompt based on said analysis) […] to generate response text (mental process – generating response text may be performed mentally or using pen and paper by a user reading/analyzing the information and question included in the prompt and accordingly using judgment/evaluation to formulate/write a response based on said analysis) adding, to the prompt, query text that includes a question about effective permissions associated with the role (mental process - adding query text that describes a question about effective permissions associated with the role may be performed mentally or using pen and paper by a user formulating/writing a question concerning the role and adding the question to the prompt based on said analysis) Step 2A Prong 2: This judicial exception is not integrated into a practical application. the role definition for the role including an action and effective permissions text describing a summary of permission limitations provided by the role (Field of Use – limitations that amount to merely indicating a field of use or technological environment in which to apply a judicial exception does not amount to significantly more than the exception itself, and cannot integrate a judicial exception into a practical application; in this case specifying that the role definition for the role includes an action and effective permissions text describing a summary of permission limitations provided by the role does not integrate the exception into a practical application nor amount to significantly more – See MPEP 2106.05(h)) the action definitions being in a hierarchical format and including the action(Field of Use – limitations that amount to merely indicating a field of use or technological environment in which to apply a judicial exception does not amount to significantly more than the exception itself, and cannot integrate a judicial exception into a practical application; in this case specifying that the action definitions being in a hierarchical format and including the action does not integrate the exception into a practical application nor amount to significantly more – See MPEP 2106.05(h)) submitting the prompt to the LLM […] (Adding insignificant extra-solution activity to the judicial exception - see MPEP 2106.05(g)) Step 2B: The claim does not include additional elements considered individually and in combination that are sufficient to amount to significantly more than the judicial exception. the role definition for the role including an action and effective permissions text describing a summary of permission limitations provided by the role (Field of Use – limitations that amount to merely indicating a field of use or technological environment in which to apply a judicial exception does not amount to significantly more than the exception itself, and cannot integrate a judicial exception into a practical application; in this case specifying that the role definition for the role includes an action and effective permissions text describing a summary of permission limitations provided by the role does not integrate the exception into a practical application nor amount to significantly more – See MPEP 2106.05(h)) the action definitions being in a hierarchical format and including the action(Field of Use – limitations that amount to merely indicating a field of use or technological environment in which to apply a judicial exception does not amount to significantly more than the exception itself, and cannot integrate a judicial exception into a practical application; in this case specifying that the action definitions being in a hierarchical format and including the action does not integrate the exception into a practical application nor amount to significantly more – See MPEP 2106.05(h)) submit the prompt to the LLM […] (MPEP 2106.05(d)(II) indicates that merely “Receiving or transmitting data over a network” is a well-understood, routine, conventional function when it is claimed in a merely generic manner (as it is in the present claim). Thereby, a conclusion that the claimed limitation is well-understood, routine, conventional activity is supported under Berkheimer) For the reasons above, Claim 8 is rejected as being directed to an abstract idea without significantly more. This rejection applies equally to dependent claims 8 - 14. The additional limitations of the dependent claims are addressed below. Regarding Claim 9: Step 2A Prong 1: See the rejection of Claim 8 above, which Claim 9 depends on. creating the query text by populating a preconfigured query text template with the security principal and the target resource (mental process - creating query text by populating a preconfigured query text template with the security principal and the target resource may be performed mentally or using pen and paper by a user reading/analyzing the identified security principal and target resource and accordingly using judgment/evaluation to insert/write said information into the designated portions of the query text template) Step 2A Prong 2 & Step 2B: receiving user input, identifying a security principal and a target resource (Adding insignificant extra-solution activity to the judicial exception - see MPEP 2106.05(g) & MPEP 2106.05(d)(II) indicates that merely “Receiving or transmitting data over a network” is a well-understood, routine, conventional function when it is claimed in a merely generic manner (as it is in the present claim). Thereby, a conclusion that the claimed limitation is well-understood, routine, conventional activity is supported under Berkheimer) Accordingly, under Step 2A Prong 2 and Step 2B, this additional element does not integrate the abstract idea into practical application because it does not impose any meaningful limits on practicing the abstract idea, as discussed above in the rejection of claim 8. The claim does not include additional elements considered individually and in combination that are sufficient to amount to significantly more than the judicial exception. Regarding Claim 10: Step 2A Prong 1: See the rejection of Claim 8 above, which Claim 10 depends on. Step 2A Prong 2 & Step 2B: wherein the hierarchical format of the action definitions includes a resource type portion and an action verb portion, wherein the action identifies a resource type and an action verb (Field of Use – limitations that amount to merely indicating a field of use or technological environment in which to apply a judicial exception does not amount to significantly more than the exception itself, and cannot integrate a judicial exception into a practical application; in this case specifying that the hierarchical format of the action definitions includes a resource type portion and an action verb portion and the action identifies a resource type and an action verb does not integrate the exception into a practical application nor amount to significantly more – See MPEP 2106.05(h)) Accordingly, under Step 2A Prong 2 and Step 2B, this additional element does not integrate the abstract idea into practical application because it does not impose any meaningful limits on practicing the abstract idea, as discussed above in the rejection of claim 8. The claim does not include additional elements considered individually and in combination that are sufficient to amount to significantly more than the judicial exception. Regarding Claim 11: Step 2A Prong 1: See the rejection of Claim 8 above, which Claim 11 depends on. storing an example role definition including the role definition, the example role definition including a permitted action from the action definitions and associated effective permissions text, […] (mental process – storing an example role definition including the role definition may be performed mentally or using pen and paper by a user reading/analyzing the role definition, permitted action, action definitions, and associated effective permissions text and accordingly using judgment/evaluation to organize/write/record the example role definition based on said analysis) […] wherein creating the prompt further includes adding the example role definition to the prompt (mental process –adding the example role definition to the prompt may be performed mentally or using pen and paper by a user observing/analyzing the example role definition and the prompt and accordingly using judgment/evaluation to insert/write the example role definition into the prompt based on said analysis) Step 2A Prong 2 & Step 2B: Accordingly, under Step 2A Prong 2 and Step 2B, there are no additional elements that integrate the abstract idea into practical application. The claim does not include additional elements considered individually and in combination that are sufficient to amount to significantly more than the judicial exception. Regarding Claim 12: Step 2A Prong 1: See the rejection of Claim 8 above, which Claim 12 depends on. Step 2A Prong 2 & Step 2B: receiving user input identifying another role definition, the other role definition includes another action and does not include effective permissions text (Adding insignificant extra-solution activity to the judicial exception - see MPEP 2106.05(g) & MPEP 2106.05(d)(II) indicates that merely “Receiving or transmitting data over a network” is a well-understood, routine, conventional function when it is claimed in a merely generic manner (as it is in the present claim). Thereby, a conclusion that the claimed limitation is well-understood, routine, conventional activity is supported under Berkheimer) submitting another prompt to the LLM, the other prompt including the other role definition and other query text that describes a question referencing the other role (Adding insignificant extra-solution activity to the judicial exception - see MPEP 2106.05(g) & MPEP 2106.05(d)(II) indicates that merely “Receiving or transmitting data over a network” is a well-understood, routine, conventional function when it is claimed in a merely generic manner (as it is in the present claim). Thereby, a conclusion that the claimed limitation is well-understood, routine, conventional activity is supported under Berkheimer) Accordingly, under Step 2A Prong 2 and Step 2B, this additional element does not integrate the abstract idea into practical application because it does not impose any meaningful limits on practicing the abstract idea, as discussed above in the rejection of claim 8. The claim does not include additional elements considered individually and in combination that are sufficient to amount to significantly more than the judicial exception. Regarding Claim 13: Step 2A Prong 1: See the rejection of Claim 8 above, which Claim 13 depends on. Step 2A Prong 2 & Step 2B: wherein the role definition further includes an allowed action and a prohibited action (Field of Use – limitations that amount to merely indicating a field of use or technological environment in which to apply a judicial exception does not amount to significantly more than the exception itself, and cannot integrate a judicial exception into a practical application; in this case specifying that the role definition further includes an allowed action and a prohibited action does not integrate the exception into a practical application nor amount to significantly more – See MPEP 2106.05(h)) Accordingly, under Step 2A Prong 2 and Step 2B, this additional element does not integrate the abstract idea into practical application because it does not impose any meaningful limits on practicing the abstract idea, as discussed above in the rejection of claim 8. The claim does not include additional elements considered individually and in combination that are sufficient to amount to significantly more than the judicial exception. Regarding Claim 14: Step 2A Prong 1: See the rejection of Claim 8 above, which Claim 14 depends on. Step 2A Prong 2 & Step 2B: receiving, from the role-based access control system, the action definitions (Adding insignificant extra-solution activity to the judicial exception - see MPEP 2106.05(g) & MPEP 2106.05(d)(II) indicates that merely “Receiving or transmitting data over a network” is a well-understood, routine, conventional function when it is claimed in a merely generic manner (as it is in the present claim). Thereby, a conclusion that the claimed limitation is well-understood, routine, conventional activity is supported under Berkheimer) Accordingly, under Step 2A Prong 2 and Step 2B, this additional element does not integrate the abstract idea into practical application because it does not impose any meaningful limits on practicing the abstract idea, as discussed above in the rejection of claim 8. The claim does not include additional elements considered individually and in combination that are sufficient to amount to significantly more than the judicial exception. Regarding Claim 15: Step 1: Claim 15 is a device type claim. Therefore, Claims 15-20 fall within one of the four statutory categories (i.e., process, machine, manufacture, or composition of matter). 2A Prong 1: If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components, then it falls within the “Mental Processes” grouping of abstract ideas. If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation by mathematical calculation but for the recitation of generic computer components, then it falls within the “Mathematical Concepts” grouping of abstract ideas. creating a prompt for a large language model (LLM), the prompt including (A) a role definition for a role of a role-based access control system and (B) action definitions (mental process – creating a prompt may be performed mentally or using pen and paper by a user observing/analyzing the role definitions and action definitions and accordingly using judgement/evaluation to create/write a prompt based on said analysis) […] to generate response text (mental process – generating response text may be performed mentally or using pen and paper by a user reading/analyzing the information and question included in the prompt and accordingly using judgment/evaluation to formulate/write a response based on said analysis) adding, to the prompt, query text that includes a question about effective permissions associated with the role (mental process - adding query text that describes a question about effective permissions associated with the role may be performed mentally or using pen and paper by a user formulating/writing a question concerning the role and adding the question to the prompt based on said analysis) Step 2A Prong 2: This judicial exception is not integrated into a practical application. the role definition for the role including an action and effective permissions text describing a summary of permission limitations provided by the role (Field of Use – limitations that amount to merely indicating a field of use or technological environment in which to apply a judicial exception does not amount to significantly more than the exception itself, and cannot integrate a judicial exception into a practical application; in this case specifying that the role definition for the role includes an action and effective permissions text describing a summary of permission limitations provided by the role does not integrate the exception into a practical application nor amount to significantly more – See MPEP 2106.05(h)) the action definitions being in a hierarchical format and including the action(Field of Use – limitations that amount to merely indicating a field of use or technological environment in which to apply a judicial exception does not amount to significantly more than the exception itself, and cannot integrate a judicial exception into a practical application; in this case specifying that the action definitions being in a hierarchical format and including the action does not integrate the exception into a practical application nor amount to significantly more – See MPEP 2106.05(h)) submitting the prompt to the LLM […] (Adding insignificant extra-solution activity to the judicial exception - see MPEP 2106.05(g)) Step 2B: The claim does not include additional elements considered individually and in combination that are sufficient to amount to significantly more than the judicial exception. the role definition for the role including an action and effective permissions text describing a summary of permission limitations provided by the role (Field of Use – limitations that amount to merely indicating a field of use or technological environment in which to apply a judicial exception does not amount to significantly more than the exception itself, and cannot integrate a judicial exception into a practical application; in this case specifying that the role definition for the role includes an action and effective permissions text describing a summary of permission limitations provided by the role does not integrate the exception into a practical application nor amount to significantly more – See MPEP 2106.05(h)) the action definitions being in a hierarchical format and including the action(Field of Use – limitations that amount to merely indicating a field of use or technological environment in which to apply a judicial exception does not amount to significantly more than the exception itself, and cannot integrate a judicial exception into a practical application; in this case specifying that the action definitions being in a hierarchical format and including the action does not integrate the exception into a practical application nor amount to significantly more – See MPEP 2106.05(h)) submit the prompt to the LLM […] (MPEP 2106.05(d)(II) indicates that merely “Receiving or transmitting data over a network” is a well-understood, routine, conventional function when it is claimed in a merely generic manner (as it is in the present claim). Thereby, a conclusion that the claimed limitation is well-understood, routine, conventional activity is supported under Berkheimer) For the reasons above, Claim 15 is rejected as being directed to an abstract idea without significantly more. This rejection applies equally to dependent claims 15 - 20. The additional limitations of the dependent claims are addressed below. Regarding Claim 16: Step 2A Prong 1: See the rejection of Claim 15 above, which Claim 16 depends on. creating the query text by populating a preconfigured query text template with the security principal and the target resource (mental process - creating query text by populating a preconfigured query text template with the security principal and the target resource may be performed mentally or using pen and paper by a user reading/analyzing the identified security principal and target resource and accordingly using judgment/evaluation to insert/write said information into the designated portions of the query text template) Step 2A Prong 2 & Step 2B: receiving user input, identifying a security principal and a target resource (Adding insignificant extra-solution activity to the judicial exception - see MPEP 2106.05(g) & MPEP 2106.05(d)(II) indicates that merely “Receiving or transmitting data over a network” is a well-understood, routine, conventional function when it is claimed in a merely generic manner (as it is in the present claim). Thereby, a conclusion that the claimed limitation is well-understood, routine, conventional activity is supported under Berkheimer) Accordingly, under Step 2A Prong 2 and Step 2B, this additional element does not integrate the abstract idea into practical application because it does not impose any meaningful limits on practicing the abstract idea, as discussed above in the rejection of claim 15. The claim does not include additional elements considered individually and in combination that are sufficient to amount to significantly more than the judicial exception. Regarding Claim 17: Step 2A Prong 1: See the rejection of Claim 15 above, which Claim 17 depends on. Step 2A Prong 2 & Step 2B: wherein the hierarchical format of the action definitions includes a resource type portion and an action verb portion, wherein the action identifies a resource type and an action verb (Field of Use – limitations that amount to merely indicating a field of use or technological environment in which to apply a judicial exception does not amount to significantly more than the exception itself, and cannot integrate a judicial exception into a practical application; in this case specifying that the hierarchical format of the action definitions includes a resource type portion and an action verb portion and the action identifies a resource type and an action verb does not integrate the exception into a practical application nor amount to significantly more – See MPEP 2106.05(h)) Accordingly, under Step 2A Prong 2 and Step 2B, this additional element does not integrate the abstract idea into practical application because it does not impose any meaningful limits on practicing the abstract idea, as discussed above in the rejection of claim 15. The claim does not include additional elements considered individually and in combination that are sufficient to amount to significantly more than the judicial exception. Regarding Claim 18: Step 2A Prong 1: See the rejection of Claim 15 above, which Claim 18 depends on. storing an example role definition including the role definition, the example role definition including a permitted action from the action definitions and associated effective permissions text, […] (mental process – storing an example role definition including the role definition may be performed mentally or using pen and paper by a user reading/analyzing the role definition, permitted action, action definitions, and associated effective permissions text and accordingly using judgment/evaluation to organize/write/record the example role definition based on said analysis) […] wherein creating the prompt further includes adding the example role definition to the prompt (mental process –adding the example role definition to the prompt may be performed mentally or using pen and paper by a user observing/analyzing the example role definition and the prompt and accordingly using judgment/evaluation to insert/write the example role definition into the prompt based on said analysis) Step 2A Prong 2 & Step 2B: Accordingly, under Step 2A Prong 2 and Step 2B, there are no additional elements that integrate the abstract idea into practical application. The claim does not include additional elements considered individually and in combination that are sufficient to amount to significantly more than the judicial exception. Regarding Claim 19: Step 2A Prong 1: See the rejection of Claim 15 above, which Claim 20 depends on. Step 2A Prong 2 & Step 2B: receiving user input identifying another role definition, the other role definition includes another action and does not include effective permissions text (Adding insignificant extra-solution activity to the judicial exception - see MPEP 2106.05(g) & MPEP 2106.05(d)(II) indicates that merely “Receiving or transmitting data over a network” is a well-understood, routine, conventional function when it is claimed in a merely generic manner (as it is in the present claim). Thereby, a conclusion that the claimed limitation is well-understood, routine, conventional activity is supported under Berkheimer) submitting another prompt to the LLM, the other prompt including the other role definition and other query text that describes a question referencing the other role (Adding insignificant extra-solution activity to the judicial exception - see MPEP 2106.05(g) & MPEP 2106.05(d)(II) indicates that merely “Receiving or transmitting data over a network” is a well-understood, routine, conventional function when it is claimed in a merely generic manner (as it is in the present claim). Thereby, a conclusion that the claimed limitation is well-understood, routine, conventional activity is supported under Berkheimer) Accordingly, under Step 2A Prong 2 and Step 2B, this additional element does not integrate the abstract idea into practical application because it does not impose any meaningful limits on practicing the abstract idea, as discussed above in the rejection of claim 15. The claim does not include additional elements considered individually and in combination that are sufficient to amount to significantly more than the judicial exception. Regarding Claim 20: Step 2A Prong 1: See the rejection of Claim 15 above, which Claim 20 depends on. Step 2A Prong 2 & Step 2B: wherein the role definition further includes an allowed action and a prohibited action (Field of Use – limitations that amount to merely indicating a field of use or technological environment in which to apply a judicial exception does not amount to significantly more than the exception itself, and cannot integrate a judicial exception into a practical application; in this case specifying that the role definition further includes an allowed action and a prohibited action does not integrate the exception into a practical application nor amount to significantly more – See MPEP 2106.05(h)) Accordingly, under Step 2A Prong 2 and Step 2B, this additional element does not integrate the abstract idea into practical application because it does not impose any meaningful limits on practicing the abstract idea, as discussed above in the rejection of claim 15. The claim does not include additional elements considered individually and in combination that are sufficient to amount to significantly more than the judicial exception. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over James et al. (hereafter James) (US 12155666) in view of Javed et al. (hereinafter Javed) (US 12299406). Regarding Claim 1, James teaches: a processor (James, Claim 13, “a processor communicatively coupled to the storage device”, thus a processor is disclosed) a computer-readable medium (James, Claim 19, “A non-transitory computer-readable medium storing instructions, the instructions”, thus a computer-readable medium is disclosed) storing instructions that are operative upon execution by the processor to: […] including (A) a role definition for a role of a role-based access control system and (B) action definitions (James, Par. [0022],“Policy database 112 can include one or more security policies, which can be referred to as a policy, associated with roles or principals. For example, policy 113a, policy 113b, and policy 113c are associated with role 113”, & Par. [0026], “Role 113 can be an identity that has specific access permissions. Role 113 can access system resources 133 based on access permissions defined by associated security policies, e.g., policy 113a, policy 113b, and policy 113c”, & Par. [0036], “policy statement 212 can include an effect statement 211, a principal statement 213, an action statement 215, a resource statement 217, a condition statement 219, or some other component statements”, & Par. [0037], “Action statement 215 can include a list of actions to be performed on the one or more system resources that the policy allows or denies. Action statement 215 can include a read-only action, a view action, an update action, a write action, a delete action, an NotAction, or some other actions”, thus […] including (A) a role definition for a role of a role-based access control system and (B) action definitions is disclosed, because James teaches an IAM role having specific access permissions defined by security policies associated with the role. James’s IAM role corresponds to a role of a role-based access control system because it is an access-control identity whose permissions to system resources are controlled by associated policies. James’s security policies correspond to a role definition because the policies associated with the role define the access permissions assigned to the role. James’s action statement and its list of read-only, view, update, write, delete, and NotAction operations correspond to action definitions because they identify the actions that the role-associated policy allows or denies on system resources) the role definition for the role including an action and effective permissions text describing a summary of permission limitations provided by the role (James, Par. [0037], “Action statement 215 can include a list of actions to be performed on the one or more system resources that the policy allows or denies. Action statement 215 can include a read-only action, a view action, an update action, a write action, a delete action, an NotAction, or some other actions”, & Par. [0035], “In some examples, security policy 210 can be specified by nature language. In some other examples, security policy 210 can be specified by one or more statements in a markup language or structured language. Security policy 210 can be contained in a document specified by a markup language, such as a JavaScript Object Notation (JSON) document, a XML document, a YAML document, or any other documents containing statements in structured languages”, & Par. [0073], “The list of lists generated by method 430 in FIG. 4C can be a useful form of representation for effective access permissions. Such group of lists, where each list is a list of policy statements associated with an allow policy statement with respect to the effective access permissions, can be operated by effective policy generator 121, while it is also readable by a human user. Such a group of lists are not simply an abstract idea of a list of lists. Instead, it is specifically tied to lists including an allow policy statement followed by a set of deny policy statements to define the effective access permissions”, thus the role definition for the role including an action and effective permissions text describing a summary of permission limitations provided by the role is disclosed, because James teaches a role-associated security policy that identifies actions permitted or denied on system resources and provides a human-readable representation of the role’s effective access permissions. James’s listed read-only, view, update, write, delete, and NotAction operations correspond to an action because they identify operations that the role-associated policy allows or denies. James’s security policy expressed in natural language or structured language corresponds to effective permissions text because it provides textual statements describing the permissions associated with the role. James’s human-readable group of lists containing an allow policy statement followed by corresponding deny policy statements corresponds to a summary of permission limitations provided by the role because it summarizes the actions and resources permitted by the role together with the restrictions that limit those permissions) the action definitions being in a hierarchical format and including the action (James, Par. [0037], “Action statement 215 can include a list of actions to be performed on the one or more system resources that the policy allows or denies. Action statement 215 can include a read-only action, a view action, an update action, a write action, a delete action, an NotAction, or some other actions”, & Par. [0035], “In some other examples, security policy 210 can be specified by one or more statements in a markup language or structured language. Security policy 210 can be contained in a document specified by a markup language, such as a JavaScript Object Notation (JSON) document, a XML document, a YAML document, or any other documents containing statements in structured languages”, & Par. [0040], “In addition, name 225 includes “confidential-data/*”, which refers to a set of system resources within the folder “confidential-data.” Therefore, a name for a system resource can refer to system resource set of the IAM system of various sizes, as shown above For example, name 227 specifies only one system resource, “example_bucket”, while name 223 specifies every system resource of the account, “*”. The set of system resources referred by a name for a system resource defines a scope of the name for the system resource”, thus the action definitions being in a hierarchical format and including the action is disclosed, because James teaches security policies expressed in structured formats, such as JSON, XML, or YAML, that contain action statements and resource statements. James’s structured security-policy format corresponds to a hierarchical format because the policy is organized into statements and component statements containing action and resource information. James’s read-only, view, update, write, delete, and NotAction operations correspond to the action because they identify the operations that the policy permits or denies. James’s folder paths, resource names, and wildcard scopes further correspond to the hierarchical arrangement because they organize resources at different levels, such as a specific resource, resources within a folder, or all resources within an account) […] referencing the role (James, Par. [0027], “Principal 111, e.g., role 113, can submit request 119 for accessing system resources such as system resources 133 which are protected by IAM system 131. Request 119 can include a request context information, which is used to evaluate and authorize the request. The request context information can include actions or operations to be performed, resources upon which the actions or operations are performed”, thus […] referencing the role is disclosed, because James teaches a request containing context information that identifies a principal, such as an IAM role, together with the actions and resources involved. James’s principal identified in the request context corresponds to the role because the principal may be the role seeking access to system resources) James does not explicitly create a prompt for a large language model (LLM), the prompt […], append, onto the prompt, query text that describes a question […], and submit the prompt to the LLM to generate response text from the LLM. However, Javed teaches: create a prompt for a large language model (LLM), the prompt […] (Javed, Par. [0073], “At 410, one or more prompts based on the prompt templates are determined. In some embodiments, a prompt may be determined by supplementing and/or modifying a prompt template based on the input text. For instance, a portion of input text may be added to a prompt template at an appropriate location”, & Par. [0046], “A prompt template may also include one or more fillable portions that may be filled based on information determined by the orchestrator 230. For instance, a prompt template may be filled based on information received from a client machine, information returned by a search query, or another information source”, thus create a prompt for a large language model (LLM), the prompt […] is disclosed, because Javed teaches determining a prompt by supplementing or modifying a prompt template based on input text and filling portions of the prompt template using information received from different sources. Javed’s determination of a prompt from a prompt template corresponds to create a prompt because the system generates the prompt by adding information to or modifying the template. Javed’s prompt template corresponds to the prompt because it provides the structure into which input information is inserted. Javed’s fillable portions and added input text correspond to the content of the prompt because they are used to populate and form the completed prompt that is provided to the large language model) append, onto the prompt, query text that describes a question […] (Javed, Par. [0073], “At 410, one or more prompts based on the prompt templates are determined. In some embodiments, a prompt may be determined by supplementing and/or modifying a prompt template based on the input text. For instance, a portion of input text may be added to a prompt template at an appropriate location”, & Par. [0125], “An example of a prompt template that may be used to generate a prompt for determining an aggregate of a set of summaries of documents is provided below: A lawyer has submitted the following question: $$QUESTION$$ {{question}} $$/QUESTION$$”, thus append, onto the prompt, query text that describes a question […] is disclosed, because Javed teaches supplementing or modifying a prompt template by adding input text at an appropriate location and provides a prompt template containing a question field. Javed’s addition of input text to the prompt template corresponds to append, onto the prompt, query text because the input text is inserted into the existing prompt template. Javed’s question field corresponds to query text that describes a question because it contains the question submitted by the user for the model to answer) submit the prompt to the LLM to generate response text from the LLM (Javed, Par. [0074], “The one or more prompts are transmitted to a text generation modeling system at 412. In some embodiments, the text generation modeling system may be implemented at a remote computing system. The text generation modeling system may be configured to implement a text generation model”, & Par. [0075], “One or more text response messages are received from the remote computing system at 414. According to various embodiments, the one or more text response messages include one or more novel text portions generated by a text generation model implemented at the remote computing system. The novel text portions may be generated based at least in part on the prompt received at the text generation modeling system, including the instructions and the input text”, thus submit the prompt to the LLM to generate response text from the LLM is disclosed, because Javed teaches transmitting a prompt to a text generation modeling system implementing a text generation model and receiving text response messages containing novel text generated based on the submitted prompt. Javed’s transmission of the prompt to the text generation modeling system corresponds to submit the prompt to the LLM because the system provides the completed prompt to the model for processing. Javed’s text generation model corresponds to the LLM because the model processes the prompt and generates text. Javed’s novel text portions contained in the received response messages correspond to response text from the LLM because the text is generated by the model based on the instructions and input text included in the prompt) It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to combine James with Javed by incorporating Javed’s LLM prompt generation and response technique into James’s IAM effective permissions system. James teaches determining and presenting a role’s effective permissions, including allowed and denied actions. Javed teaches inserting input information and a question into a prompt, submitting the prompt to an LLM, and receiving generated response text. Therefore, a POSITA would have been motivated to use James’s role definitions, action definitions, and effective permissions information as input to Javed’s prompt generation process so that a user could submit a question concerning a particular role and receive a natural language response explaining the actions permitted by the role and the limitations imposed on those permissions. This would simplify the review and interpretation of complex role associated security policies, thereby reducing the burden of manually reviewing and interpreting numerous policy statements (James, Par. [0013], “When the number of security policies associated with a principal can be in the magnitude of hundreds of thousands or millions, it becomes infeasible to evaluate the effective access permissions defined by security policies by hand or by visual inspection. Effective mechanisms are needed for an enterprise system to evaluate the effective access permissions defined by security policies associated with the principal”) Regarding Claim 2, James combined with Javed teaches all the limitations of claim 1 as cited above and James further teaches: receive user input identifying a security principal and a target resource (James, Par. [0061], “According to method 410, at 411, a user can enter a principal name. At 412, effective policy generator 121 can gather all the security policies from the IAM attached to the principal. In some examples, all the security policies attached to the principal can be a large number of security policies, e.g., millions of security policies”, & Par. [0027], “Principal 111, e.g., role 113, can submit request 119 for accessing system resources such as system resources 133 which are protected by IAM system 131. Request 119 can include a request context information, which is used to evaluate and authorize the request. The request context information can include actions or operations to be performed, resources upon which the actions or operations are performed, a principal that can be a person or an application that an entity to send request 119, environment data such as IP address, user agent, SSL enabled status, or the time of day; and resource data such as data related to the resource that is being requested. Information about the principal can include the policies that are associated with the entity that the principal used to sign in”, thus receive user input identifying a security principal and a target resource is disclosed, because James teaches receiving a principal name entered by a user and an access request containing information identifying the principal and the resource being requested. James’s user entered principal name corresponds to a security principal because it identifies the person, application, or role whose access permissions are evaluated. James’s resource data and the resource upon which the requested action is performed correspond to a target resource because they identify the system resource for which access is requested) […] with the security principal and the target resource (James, Par. [0061], “According to method 410, at 411, a user can enter a principal name”, & Par. [0027], “The request context information can include actions or operations to be performed, resources upon which the actions or operations are performed, a principal that can be a person or an application that an entity to send request 119, environment data such as IP address, user agent, SSL enabled status, or the time of day; and resource data such as data related to the resource that is being requested”, thus […] with the security principal and the target resource is disclosed, because James teaches information identifying a principal and the resource being requested. James’s user-entered principal name corresponds to the security principal because it identifies the person, role, or application whose permissions are evaluated. James’s requested resource and associated resource data correspond to the target resource) Javed further teaches: create the query text by populating a preconfigured query text template […] (Javed, Par. [0046], “A prompt template may also include one or more fillable portions that may be filled based on information determined by the orchestrator 230. For instance, a prompt template may be filled based on information received from a client machine, information returned by a search query, or another information source”, & Par. [0073], “In some embodiments, a prompt may be determined by supplementing and/or modifying a prompt template based on the input text. For instance, a portion of input text may be added to a prompt template at an appropriate location”, & Par. [0125], “An example of a prompt template that may be used to generate a prompt for determining an aggregate of a set of summaries of documents is provided below: A lawyer has submitted the following question: $$QUESTION$$ {{question}} $$/QUESTION$”, thus create the query text by populating a preconfigured query text template […] is disclosed, because Javed teaches a predefined prompt template having a fillable question field that is completed using received input information. Javed’s prompt template containing predefined question language and a fillable question field corresponds to a preconfigured query text template because it establishes the structure and location for the question information. Javed’s insertion of input text into the fillable portions of the template corresponds to populating the template because the received information is added at the designated location to form the query text) Regarding Claim 3, James combined with Javed teaches all the limitations of claim 1 as cited above and James further teaches: wherein the hierarchical format of the action definitions includes a resource type portion and an action verb portion, wherein the action identifies a resource type and an action verb (James, Par. [0035], “In some other examples, security policy 210 can be specified by one or more statements in a markup language or structured language. Security policy 210 can be contained in a document specified by a markup language, such as a JavaScript Object Notation (JSON) document, a XML document, a YAML document, or any other documents containing statements in structured languages”, & Par. [0036], “. A policy statement can further include various component statements. In some examples, policy statement 212 can include an effect statement 211, a principal statement 213, an action statement 215, a resource statement 217, a condition statement 219, or some other component statements. Policy statement 214 can include similar component statements”, & Par. [0040], “In addition, name 225 includes “confidential-data/*”, which refers to a set of system resources within the folder “confidential-data.” Therefore, a name for a system resource can refer to system resource set of the IAM system of various sizes, as shown above For example, name 227 specifies only one system resource, “example_bucket”, while name 223 specifies every system resource of the account, “*”. The set of system resources referred by a name for a system resource defines a scope of the name for the system resource”, & Par. [0037], “Action statement 215 can include a list of actions to be performed on the one or more system resources that the policy allows or denies. Action statement 215 can include a read-only action, a view action, an update action, a write action, a delete action, an NotAction, or some other actions”, thus wherein the hierarchical format of the action definitions includes a resource type portion and an action verb portion, wherein the action identifies a resource type and an action verb is disclosed, because James teaches structured security policies organized into component statements that separately identify resources and actions performed on those resources. James’s structured policy format corresponds to the hierarchical format because the policy is organized into statements and component statements containing resource and action information. James’s resource statement, resource names, folder paths, and wildcard scopes correspond to a resource type portion because they identify the resource or category of resources to which the permission applies. James’s read, view, update, write, and delete operations correspond to an action verb portion because they identify the operation performed on the resource. Together, James’s resource information and associated operations correspond to an action that identifies a resource type and an action verb) Regarding Claim 4, James combined with Javed teaches all the limitations of claim 1 as cited above and James further teaches: wherein the computer-readable medium further stores an example role definition including the role definition, the example role definition including a permitted action from the action definitions and associated effective permissions text, […] the example role definition […] (James, Par. [0022], “Enterprise system 110 can include any number of principals, e.g., principal 111, a policy database 112, and a security governance guideline 114, which can be stored in memory device 118. Policy database 112 can include one or more security policies, which can be referred to as a policy, associated with roles or principals”, & Par. [0032], “Effective policy 123 and the set of effective access permissions 125 can be saved in a storage located outside IAM system 131 and separated from IAM system 131”, & Par. [0033], “Security policy 210 can be an example of policy 113a, policy 113b, policy 113c as shown in FIG. 1. Security policy 210 can include a policy statement 212 and a policy statement 214”, & Par. [0037], “Effect statement 211 can specify either Allow or Deny to indicate whether the policy statement 212 allows or denies access. Action statement 215 can include a list of actions to be performed on the one or more system resources that the policy allows or denies”, & Par. [0073], “The list of lists generated by method 430 in FIG. 4C can be a useful form of representation for effective access permissions. Such group of lists, where each list is a list of policy statements associated with an allow policy statement with respect to the effective access permissions, can be operated by effective policy generator 121, while it is also readable by a human user”, thus wherein the computer-readable medium further stores an example role definition including the role definition, the example role definition including a permitted action from the action definitions and associated effective permissions text, […] the example role definition […] is disclosed, because James teaches storing security policies associated with roles and storing the effective access permissions generated from those policies. James’s example security policy associated with a role corresponds to an example role definition because it defines permissions assigned to the role. James’s action included in an Allow policy statement corresponds to a permitted action from the action definitions because it identifies an operation that the role is allowed to perform. James’s readable representation containing an allow policy statement and associated deny policy statements corresponds to associated effective permissions text because it describes the permitted action and the restrictions limiting that permission) Javed further teaches: […] wherein creating the prompt further includes adding […] to the prompt (Javed, Par. [0046], “A prompt template may also include one or more fillable portions that may be filled based on information determined by the orchestrator 230. For instance, a prompt template may be filled based on information received from a client machine, information returned by a search query, or another information source”, & Par. [0073], “In some embodiments, a prompt may be determined by supplementing and/or modifying a prompt template based on the input text. For instance, a portion of input text may be added to a prompt template at an appropriate location”, thus […] wherein creating the prompt further includes adding […] to the prompt is disclosed, because Javed teaches creating a prompt by adding input information to a prompt template. Javed’s input information corresponds to the information added to the prompt because it is inserted into a designated portion of the prompt template) Regarding Claim 5, James combined with Javed teaches all the limitations of claim 1 as cited above and James further teaches: receive user input identifying another role definition, the other role definition includes another action and does not include effective permissions text (James, Par. [0061], “According to method 410, at 411, a user can enter a principal name. At 412, effective policy generator 121 can gather all the security policies from the IAM attached to the principal”, & Par. [0032], “Effective policy generator 121 can be configured to receive all policies associated with a role, such as policy 113a, policy 113b, and policy 113c associated with role 113, and generate effective policy 123 from the received policies. Effective policy 123 further defines the set of effective access permissions 125”, & Par. [0037], “Action statement 215 can include a list of actions to be performed on the one or more system resources that the policy allows or denies”, thus receive user input identifying another role definition, the other role definition includes another action and does not include effective permissions text is disclosed, because James teaches receiving a principal name from a user and retrieving the security policies associated with the identified role. James’s user entered principal name corresponds to user input identifying another role definition because it identifies the role whose associated policies are retrieved. James’s retrieved security policy corresponds to the other role definition because it defines the permissions associated with that role. James’s action statement corresponds to another action because it identifies an operation permitted or denied by the policy. James’s received security policy does not include effective permissions text because the effective policy and effective access permissions are generated separately from the received policies) […] the other role definition […] referencing the other role (James, Par. [0027], “Request 119 can include a request context information, which is used to evaluate and authorize the request. The request context information can include actions or operations to be performed, resources upon which the actions or operations are performed, a principal that can be a person or an application that an entity to send request 119. Information about the principal can include the policies that are associated with the entity that the principal used to sign in”, & Par. [0036], “A policy statement can further include various component statements. In some examples, policy statement 212 can include an effect statement 211, a principal statement 213, an action statement 215, a resource statement 217, a condition statement 219, or some other component statements”, thus […] the other role definition […] referencing the other role is disclosed, because James teaches a security policy containing statements that define permissions for a principal identified in a request. James’s security policy corresponds to the other role definition because it defines the permissions associated with the identified role. James’s principal identified in the request context corresponds to the other role because it identifies the role referenced by the request) Javed further teaches: submit another prompt to the LLM, the other prompt including […] and other query text that describes a question […] (Javed, Par. [0080], “A determination is made at 422 as to whether to generate an additional prompt. According to various embodiments, the determination as to whether to generation an additional prompt may be made based in part on the text generation flow determined at 404 and in part based on the one or more text response messages received at 414 and parsed at 416”, & Par. [0073], “At 410, one or more prompts based on the prompt templates are determined. In some embodiments, a prompt may be determined by supplementing and/or modifying a prompt template based on the input text. For instance, a portion of input text may be added to a prompt template at an appropriate location”, & Par. [0125], “An example of a prompt template that may be used to generate a prompt for determining an aggregate of a set of summaries of documents is provided below: A lawyer has submitted the following question: $$QUESTION$$ {{question}} $$/QUESTION”, & Par. [0074], “The one or more prompts are transmitted to a text generation modeling system at 412”, thus submit another prompt to the LLM, the other prompt including […] and other query text that describes a question […] is disclosed, because Javed teaches generating an additional prompt, adding input text and a question to the prompt, and transmitting the prompt to a text generation modeling system. Javed’s additional prompt corresponds to another prompt because it is generated as a further prompt in the text generation flow. Javed’s question field corresponds to other query text that describes a question because it contains the question submitted for processing. Javed’s transmission of the additional prompt to the text generation modeling system corresponds to submitting another prompt to the LLM) Regarding Claim 6, James combined with Javed teaches all the limitations of claim 1 as cited above and James further teaches: wherein the role definition further includes an allowed action and a prohibited action (James, Par. [0037], “Effect statement 211 can specify either Allow or Deny to indicate whether the policy statement 212 allows or denies access. Action statement 215 can include a list of actions to be performed on the one or more system resources that the policy allows or denies. Action statement 215 can include a read only action, a view action, an update action, a write action, a delete action, an NotAction, or some other actions”, thus wherein the role definition further includes an allowed action and a prohibited action is disclosed, because James teaches security policy statements that identify actions the role is allowed or denied from performing. James’s action identified by a policy statement having an Allow effect corresponds to the allowed action because the policy permits the role to perform that action. James’s action identified by a policy statement having a Deny effect corresponds to the prohibited action because the policy prevents the role from performing that action) Regarding Claim 7, James combined with Javed teaches all the limitations of claim 1 as cited above and James further teaches: wherein the instructions are further operative to request, from the role-based access control system, the action definitions (James, Par. [0061], “At 412, effective policy generator 121 can gather all the security policies from the IAM attached to the principal”, & Par. [0062], “At 415, effective policy generator 121 can further retrieve the policy document stored in the IAM, a database, or cache. The policy document for policy 413 can contain multiple policy statements”, & Par. [0037], “Action statement 215 can include a list of actions to be performed on the one or more system resources that the policy allows or denies”, thus wherein the instructions are further operative to request, from the role-based access control system, the action definitions is disclosed, because James teaches retrieving from an IAM system the security policy documents associated with a role, including policy statements that identify actions. James’s IAM system corresponds to the role-based access control system because it controls access to resources based on permissions associated with roles. James’s retrieval of the policy documents from the IAM system corresponds to requesting information from the role-based access control system. James’s lists of actions contained in the retrieved action statements correspond to the action definitions because they identify the operations that the policies allow or deny) Regarding Claim 8, James teaches: […] including (A) a role definition for a role of a role-based access control system and (B) action definitions (James, Par. [0022],“Policy database 112 can include one or more security policies, which can be referred to as a policy, associated with roles or principals. For example, policy 113a, policy 113b, and policy 113c are associated with role 113”, & Par. [0026], “Role 113 can be an identity that has specific access permissions. Role 113 can access system resources 133 based on access permissions defined by associated security policies, e.g., policy 113a, policy 113b, and policy 113c”, & Par. [0036], “policy statement 212 can include an effect statement 211, a principal statement 213, an action statement 215, a resource statement 217, a condition statement 219, or some other component statements”, & Par. [0037], “Action statement 215 can include a list of actions to be performed on the one or more system resources that the policy allows or denies. Action statement 215 can include a read-only action, a view action, an update action, a write action, a delete action, an NotAction, or some other actions”, thus […] including (A) a role definition for a role of a role-based access control system and (B) action definitions is disclosed, because James teaches an IAM role having specific access permissions defined by security policies associated with the role. James’s IAM role corresponds to a role of a role-based access control system because it is an access-control identity whose permissions to system resources are controlled by associated policies. James’s security policies correspond to a role definition because the policies associated with the role define the access permissions assigned to the role. James’s action statement and its list of read-only, view, update, write, delete, and NotAction operations correspond to action definitions because they identify the actions that the role-associated policy allows or denies on system resources) the role definition for the role including an action and effective permissions text describing a summary of permission limitations provided by the role (James, Par. [0037], “Action statement 215 can include a list of actions to be performed on the one or more system resources that the policy allows or denies. Action statement 215 can include a read-only action, a view action, an update action, a write action, a delete action, an NotAction, or some other actions”, & Par. [0035], “In some examples, security policy 210 can be specified by nature language. In some other examples, security policy 210 can be specified by one or more statements in a markup language or structured language. Security policy 210 can be contained in a document specified by a markup language, such as a JavaScript Object Notation (JSON) document, a XML document, a YAML document, or any other documents containing statements in structured languages”, & Par. [0073], “The list of lists generated by method 430 in FIG. 4C can be a useful form of representation for effective access permissions. Such group of lists, where each list is a list of policy statements associated with an allow policy statement with respect to the effective access permissions, can be operated by effective policy generator 121, while it is also readable by a human user. Such a group of lists are not simply an abstract idea of a list of lists. Instead, it is specifically tied to lists including an allow policy statement followed by a set of deny policy statements to define the effective access permissions”, thus the role definition for the role including an action and effective permissions text describing a summary of permission limitations provided by the role is disclosed, because James teaches a role-associated security policy that identifies actions permitted or denied on system resources and provides a human-readable representation of the role’s effective access permissions. James’s listed read-only, view, update, write, delete, and NotAction operations correspond to an action because they identify operations that the role-associated policy allows or denies. James’s security policy expressed in natural language or structured language corresponds to effective permissions text because it provides textual statements describing the permissions associated with the role. James’s human-readable group of lists containing an allow policy statement followed by corresponding deny policy statements corresponds to a summary of permission limitations provided by the role because it summarizes the actions and resources permitted by the role together with the restrictions that limit those permissions) the action definitions being in a hierarchical format and including the action (James, Par. [0037], “Action statement 215 can include a list of actions to be performed on the one or more system resources that the policy allows or denies. Action statement 215 can include a read-only action, a view action, an update action, a write action, a delete action, an NotAction, or some other actions”, & Par. [0035], “In some other examples, security policy 210 can be specified by one or more statements in a markup language or structured language. Security policy 210 can be contained in a document specified by a markup language, such as a JavaScript Object Notation (JSON) document, a XML document, a YAML document, or any other documents containing statements in structured languages”, & Par. [0040], “In addition, name 225 includes “confidential-data/*”, which refers to a set of system resources within the folder “confidential-data.” Therefore, a name for a system resource can refer to system resource set of the IAM system of various sizes, as shown above For example, name 227 specifies only one system resource, “example_bucket”, while name 223 specifies every system resource of the account, “*”. The set of system resources referred by a name for a system resource defines a scope of the name for the system resource”, thus the action definitions being in a hierarchical format and including the action is disclosed, because James teaches security policies expressed in structured formats, such as JSON, XML, or YAML, that contain action statements and resource statements. James’s structured security-policy format corresponds to a hierarchical format because the policy is organized into statements and component statements containing action and resource information. James’s read-only, view, update, write, delete, and NotAction operations correspond to the action because they identify the operations that the policy permits or denies. James’s folder paths, resource names, and wildcard scopes further correspond to the hierarchical arrangement because they organize resources at different levels, such as a specific resource, resources within a folder, or all resources within an account) […] about effective permissions associated with the role (James, Par. [0028], “Combined, the security policies, e.g., policy 113a, policy 113b, or policy 113c, can generate effective policy 123, which can define a set of effective access permissions 125 by role 113 to access system resources 133. The set of effective access permissions 125 represent the actual access permissions granted to role 113 by the security policies associated with role 113”, & Par. [0073], “The list of lists generated by method 430 in FIG. 4C can be a useful form of representation for effective access permissions. Such group of lists, where each list is a list of policy statements associated with an allow policy statement with respect to the effective access permissions, can be operated by effective policy generator 121, while it is also readable by a human user”, thus […] about effective permissions associated with the role is disclosed, because James teaches determining and representing the actual access permissions granted to a role based on the security policies associated with that role. James’s effective access permissions correspond to effective permissions associated with the role because they identify the actions and resources that the role is permitted or prohibited from accessing) James does not explicitly creating a prompt for a large language model (LLM), the prompt […], adding, to the prompt, query text that includes a question […], and submitting the prompt to the LLM to generate response text. However, Javed teaches: creating a prompt for a large language model (LLM), the prompt […] (Javed, Par. [0073], “At 410, one or more prompts based on the prompt templates are determined. In some embodiments, a prompt may be determined by supplementing and/or modifying a prompt template based on the input text. For instance, a portion of input text may be added to a prompt template at an appropriate location”, & Par. [0046], “A prompt template may also include one or more fillable portions that may be filled based on information determined by the orchestrator 230. For instance, a prompt template may be filled based on information received from a client machine, information returned by a search query, or another information source”, thus creating a prompt for a large language model (LLM), the prompt […] is disclosed, because Javed teaches determining a prompt by supplementing or modifying a prompt template based on input text and filling portions of the prompt template using information received from different sources. Javed’s determination of a prompt from a prompt template corresponds to create a prompt because the system generates the prompt by adding information to or modifying the template. Javed’s prompt template corresponds to the prompt because it provides the structure into which input information is inserted. Javed’s fillable portions and added input text correspond to the content of the prompt because they are used to populate and form the completed prompt that is provided to the large language model) adding, to the prompt, query text that includes a question […] (Javed, Par. [0073], “At 410, one or more prompts based on the prompt templates are determined. In some embodiments, a prompt may be determined by supplementing and/or modifying a prompt template based on the input text. For instance, a portion of input text may be added to a prompt template at an appropriate location”, & Par. [0125], “An example of a prompt template that may be used to generate a prompt for determining an aggregate of a set of summaries of documents is provided below: A lawyer has submitted the following question: $$QUESTION$$ {{question}} $$/QUESTION$$”, thus adding, to the prompt, query text that includes a question […] is disclosed, because Javed teaches supplementing or modifying a prompt template by adding input text at an appropriate location and provides a prompt template containing a question field. Javed’s addition of input text to the prompt template corresponds to adding, to the prompt, query text because the input text is inserted into the existing prompt template. Javed’s question field corresponds to query text that describes a question because it contains the question submitted by the user for the model to answer) submitting the prompt to the LLM to generate response text (Javed, Par. [0074], “The one or more prompts are transmitted to a text generation modeling system at 412. In some embodiments, the text generation modeling system may be implemented at a remote computing system. The text generation modeling system may be configured to implement a text generation model”, & Par. [0075], “One or more text response messages are received from the remote computing system at 414. According to various embodiments, the one or more text response messages include one or more novel text portions generated by a text generation model implemented at the remote computing system. The novel text portions may be generated based at least in part on the prompt received at the text generation modeling system, including the instructions and the input text”, thus submit the prompt to the LLM to generate response text is disclosed, because Javed teaches transmitting a prompt to a text generation modeling system implementing a text generation model and receiving text response messages containing novel text generated based on the submitted prompt. Javed’s transmission of the prompt to the text generation modeling system corresponds to submit the prompt to the LLM because the system provides the completed prompt to the model for processing. Javed’s text generation model corresponds to the LLM because the model processes the prompt and generates text) It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to combine James with Javed by incorporating Javed’s LLM prompt generation and response technique into James’s IAM effective permissions system. James teaches determining and presenting a role’s effective permissions, including allowed and denied actions. Javed teaches inserting input information and a question into a prompt, submitting the prompt to an LLM, and receiving generated response text. Therefore, a POSITA would have been motivated to use James’s role definitions, action definitions, and effective permissions information as input to Javed’s prompt generation process so that a user could submit a question concerning a particular role and receive a natural language response explaining the actions permitted by the role and the limitations imposed on those permissions. This would simplify the review and interpretation of complex role associated security policies, thereby reducing the burden of manually reviewing and interpreting numerous policy statements (James, Par. [0013], “When the number of security policies associated with a principal can be in the magnitude of hundreds of thousands or millions, it becomes infeasible to evaluate the effective access permissions defined by security policies by hand or by visual inspection. Effective mechanisms are needed for an enterprise system to evaluate the effective access permissions defined by security policies associated with the principal”) Regarding Claim 9, James combined with Javed teaches all the limitations of claim 8 as cited above and James further teaches: receiving user input identifying a security principal and a target resource (James, Par. [0061], “According to method 410, at 411, a user can enter a principal name. At 412, effective policy generator 121 can gather all the security policies from the IAM attached to the principal. In some examples, all the security policies attached to the principal can be a large number of security policies, e.g., millions of security policies”, & Par. [0027], “Principal 111, e.g., role 113, can submit request 119 for accessing system resources such as system resources 133 which are protected by IAM system 131. Request 119 can include a request context information, which is used to evaluate and authorize the request. The request context information can include actions or operations to be performed, resources upon which the actions or operations are performed, a principal that can be a person or an application that an entity to send request 119, environment data such as IP address, user agent, SSL enabled status, or the time of day; and resource data such as data related to the resource that is being requested. Information about the principal can include the policies that are associated with the entity that the principal used to sign in”, thus receiving user input identifying a security principal and a target resource is disclosed, because James teaches receiving a principal name entered by a user and an access request containing information identifying the principal and the resource being requested. James’s user entered principal name corresponds to a security principal because it identifies the person, application, or role whose access permissions are evaluated. James’s resource data and the resource upon which the requested action is performed correspond to a target resource because they identify the system resource for which access is requested) […] with the security principal and the target resource (James, Par. [0061], “According to method 410, at 411, a user can enter a principal name”, & Par. [0027], “The request context information can include actions or operations to be performed, resources upon which the actions or operations are performed, a principal that can be a person or an application that an entity to send request 119, environment data such as IP address, user agent, SSL enabled status, or the time of day; and resource data such as data related to the resource that is being requested”, thus […] with the security principal and the target resource is disclosed, because James teaches information identifying a principal and the resource being requested. James’s user-entered principal name corresponds to the security principal because it identifies the person, role, or application whose permissions are evaluated. James’s requested resource and associated resource data correspond to the target resource) Javed further teaches: creating the query text by populating a preconfigured query text template […] (Javed, Par. [0046], “A prompt template may also include one or more fillable portions that may be filled based on information determined by the orchestrator 230. For instance, a prompt template may be filled based on information received from a client machine, information returned by a search query, or another information source”, & Par. [0073], “In some embodiments, a prompt may be determined by supplementing and/or modifying a prompt template based on the input text. For instance, a portion of input text may be added to a prompt template at an appropriate location”, & Par. [0125], “An example of a prompt template that may be used to generate a prompt for determining an aggregate of a set of summaries of documents is provided below: A lawyer has submitted the following question: $$QUESTION$$ {{question}} $$/QUESTION$”, thus creating the query text by populating a preconfigured query text template […] is disclosed, because Javed teaches a predefined prompt template having a fillable question field that is completed using received input information. Javed’s prompt template containing predefined question language and a fillable question field corresponds to a preconfigured query text template because it establishes the structure and location for the question information. Javed’s insertion of input text into the fillable portions of the template corresponds to populating the template because the received information is added at the designated location to form the query text) Regarding Claim 10, James combined with Javed teaches all the limitations of claim 8 as cited above and James further teaches: wherein the hierarchical format of the action definitions including a resource type portion and an action verb portion, wherein the action identifies a resource type and an action verb (James, Par. [0035], “In some other examples, security policy 210 can be specified by one or more statements in a markup language or structured language. Security policy 210 can be contained in a document specified by a markup language, such as a JavaScript Object Notation (JSON) document, a XML document, a YAML document, or any other documents containing statements in structured languages”, & Par. [0036], “. A policy statement can further include various component statements. In some examples, policy statement 212 can include an effect statement 211, a principal statement 213, an action statement 215, a resource statement 217, a condition statement 219, or some other component statements. Policy statement 214 can include similar component statements”, & Par. [0040], “In addition, name 225 includes “confidential-data/*”, which refers to a set of system resources within the folder “confidential-data.” Therefore, a name for a system resource can refer to system resource set of the IAM system of various sizes, as shown above For example, name 227 specifies only one system resource, “example_bucket”, while name 223 specifies every system resource of the account, “*”. The set of system resources referred by a name for a system resource defines a scope of the name for the system resource”, & Par. [0037], “Action statement 215 can include a list of actions to be performed on the one or more system resources that the policy allows or denies. Action statement 215 can include a read-only action, a view action, an update action, a write action, a delete action, an NotAction, or some other actions”, thus wherein the hierarchical format of the action definitions including a resource type portion and an action verb portion, wherein the action identifies a resource type and an action verb is disclosed, because James teaches structured security policies organized into component statements that separately identify resources and actions performed on those resources. James’s structured policy format corresponds to the hierarchical format because the policy is organized into statements and component statements containing resource and action information. James’s resource statement, resource names, folder paths, and wildcard scopes correspond to a resource type portion because they identify the resource or category of resources to which the permission applies. James’s read, view, update, write, and delete operations correspond to an action verb portion because they identify the operation performed on the resource. Together, James’s resource information and associated operations correspond to an action that identifies a resource type and an action verb) Regarding Claim 11, James combined with Javed teaches all the limitations of claim 8 as cited above and James further teaches: storing an example role definition including the role definition, the example role definition including a permitted action from the action definitions and associated effective permissions text, […] the example role definition […] (James, Par. [0022], “Enterprise system 110 can include any number of principals, e.g., principal 111, a policy database 112, and a security governance guideline 114, which can be stored in memory device 118. Policy database 112 can include one or more security policies, which can be referred to as a policy, associated with roles or principals”, & Par. [0032], “Effective policy 123 and the set of effective access permissions 125 can be saved in a storage located outside IAM system 131 and separated from IAM system 131”, & Par. [0033], “Security policy 210 can be an example of policy 113a, policy 113b, policy 113c as shown in FIG. 1. Security policy 210 can include a policy statement 212 and a policy statement 214”, & Par. [0037], “Effect statement 211 can specify either Allow or Deny to indicate whether the policy statement 212 allows or denies access. Action statement 215 can include a list of actions to be performed on the one or more system resources that the policy allows or denies”, & Par. [0073], “The list of lists generated by method 430 in FIG. 4C can be a useful form of representation for effective access permissions. Such group of lists, where each list is a list of policy statements associated with an allow policy statement with respect to the effective access permissions, can be operated by effective policy generator 121, while it is also readable by a human user”, thus storing an example role definition including the role definition, the example role definition including a permitted action from the action definitions and associated effective permissions text, […] the example role definition […] is disclosed, because James teaches storing security policies associated with roles and storing the effective access permissions generated from those policies. James’s example security policy associated with a role corresponds to an example role definition because it defines permissions assigned to the role. James’s action included in an Allow policy statement corresponds to a permitted action from the action definitions because it identifies an operation that the role is allowed to perform. James’s readable representation containing an allow policy statement and associated deny policy statements corresponds to associated effective permissions text because it describes the permitted action and the restrictions limiting that permission) Javed further teaches: […] wherein creating the prompt further includes adding […] to the prompt (Javed, Par. [0046], “A prompt template may also include one or more fillable portions that may be filled based on information determined by the orchestrator 230. For instance, a prompt template may be filled based on information received from a client machine, information returned by a search query, or another information source”, & Par. [0073], “In some embodiments, a prompt may be determined by supplementing and/or modifying a prompt template based on the input text. For instance, a portion of input text may be added to a prompt template at an appropriate location”, thus […] wherein creating the prompt further includes adding […] to the prompt is disclosed, because Javed teaches creating a prompt by adding input information to a prompt template. Javed’s input information corresponds to the information added to the prompt because it is inserted into a designated portion of the prompt template) Regarding Claim 12, James combined with Javed teaches all the limitations of claim 8 as cited above and James further teaches: receiving user input identifying another role definition, the other role definition includes another action and does not include effective permissions text (James, Par. [0061], “According to method 410, at 411, a user can enter a principal name. At 412, effective policy generator 121 can gather all the security policies from the IAM attached to the principal”, & Par. [0032], “Effective policy generator 121 can be configured to receive all policies associated with a role, such as policy 113a, policy 113b, and policy 113c associated with role 113, and generate effective policy 123 from the received policies. Effective policy 123 further defines the set of effective access permissions 125”, & Par. [0037], “Action statement 215 can include a list of actions to be performed on the one or more system resources that the policy allows or denies”, thus receiving user input identifying another role definition, the other role definition includes another action and does not include effective permissions text is disclosed, because James teaches receiving a principal name from a user and retrieving the security policies associated with the identified role. James’s user entered principal name corresponds to user input identifying another role definition because it identifies the role whose associated policies are retrieved. James’s retrieved security policy corresponds to the other role definition because it defines the permissions associated with that role. James’s action statement corresponds to another action because it identifies an operation permitted or denied by the policy. James’s received security policy does not include effective permissions text because the effective policy and effective access permissions are generated separately from the received policies) […] the other role definition […] referencing the other role (James, Par. [0027], “Request 119 can include a request context information, which is used to evaluate and authorize the request. The request context information can include actions or operations to be performed, resources upon which the actions or operations are performed, a principal that can be a person or an application that an entity to send request 119. Information about the principal can include the policies that are associated with the entity that the principal used to sign in”, & Par. [0036], “A policy statement can further include various component statements. In some examples, policy statement 212 can include an effect statement 211, a principal statement 213, an action statement 215, a resource statement 217, a condition statement 219, or some other component statements”, thus […] the other role definition […] referencing the other role is disclosed, because James teaches a security policy containing statements that define permissions for a principal identified in a request. James’s security policy corresponds to the other role definition because it defines the permissions associated with the identified role. James’s principal identified in the request context corresponds to the other role because it identifies the role referenced by the request) Javed further teaches: submitting another prompt to the LLM, the other prompt including […] and other query text that describes a question […] (Javed, Par. [0080], “A determination is made at 422 as to whether to generate an additional prompt. According to various embodiments, the determination as to whether to generation an additional prompt may be made based in part on the text generation flow determined at 404 and in part based on the one or more text response messages received at 414 and parsed at 416”, & Par. [0073], “At 410, one or more prompts based on the prompt templates are determined. In some embodiments, a prompt may be determined by supplementing and/or modifying a prompt template based on the input text. For instance, a portion of input text may be added to a prompt template at an appropriate location”, & Par. [0125], “An example of a prompt template that may be used to generate a prompt for determining an aggregate of a set of summaries of documents is provided below: A lawyer has submitted the following question: $$QUESTION$$ {{question}} $$/QUESTION”, & Par. [0074], “The one or more prompts are transmitted to a text generation modeling system at 412”, thus submitting another prompt to the LLM, the other prompt including […] and other query text that describes a question […] is disclosed, because Javed teaches generating an additional prompt, adding input text and a question to the prompt, and transmitting the prompt to a text generation modeling system. Javed’s additional prompt corresponds to another prompt because it is generated as a further prompt in the text generation flow. Javed’s question field corresponds to other query text that describes a question because it contains the question submitted for processing. Javed’s transmission of the additional prompt to the text generation modeling system corresponds to submitting another prompt to the LLM) Regarding Claim 13, James combined with Javed teaches all the limitations of claim 8 as cited above and James further teaches: wherein the role definition further includes an allowed action and a prohibited action (James, Par. [0037], “Effect statement 211 can specify either Allow or Deny to indicate whether the policy statement 212 allows or denies access. Action statement 215 can include a list of actions to be performed on the one or more system resources that the policy allows or denies. Action statement 215 can include a read only action, a view action, an update action, a write action, a delete action, an NotAction, or some other actions”, thus wherein the role definition further includes an allowed action and a prohibited action is disclosed, because James teaches security policy statements that identify actions the role is allowed or denied from performing. James’s action identified by a policy statement having an Allow effect corresponds to the allowed action because the policy permits the role to perform that action. James’s action identified by a policy statement having a Deny effect corresponds to the prohibited action because the policy prevents the role from performing that action) Regarding Claim 14, James combined with Javed teaches all the limitations of claim 8 as cited above and James further teaches: receiving, from the role-based access control system, the action definitions (James, Par. [0061], “At 412, effective policy generator 121 can gather all the security policies from the IAM attached to the principal”, & Par. [0062], “At 415, effective policy generator 121 can further retrieve the policy document stored in the IAM, a database, or cache. The policy document for policy 413 can contain multiple policy statements”, & Par. [0037], “Action statement 215 can include a list of actions to be performed on the one or more system resources that the policy allows or denies”, thus receiving, from the role-based access control system, the action definitions is disclosed, because James teaches retrieving from an IAM system the security policy documents associated with a role, including policy statements that identify actions. James’s IAM system corresponds to the role-based access control system because it controls access to resources based on permissions associated with roles. James’s retrieval of the policy documents from the IAM system corresponds to requesting information from the role-based access control system. James’s lists of actions contained in the retrieved action statements correspond to the action definitions because they identify the operations that the policies allow or deny) Regarding Claim 15, James teaches: […] including (A) a role definition for a role of a role-based access control system and (B) action definitions (James, Par. [0022],“Policy database 112 can include one or more security policies, which can be referred to as a policy, associated with roles or principals. For example, policy 113a, policy 113b, and policy 113c are associated with role 113”, & Par. [0026], “Role 113 can be an identity that has specific access permissions. Role 113 can access system resources 133 based on access permissions defined by associated security policies, e.g., policy 113a, policy 113b, and policy 113c”, & Par. [0036], “policy statement 212 can include an effect statement 211, a principal statement 213, an action statement 215, a resource statement 217, a condition statement 219, or some other component statements”, & Par. [0037], “Action statement 215 can include a list of actions to be performed on the one or more system resources that the policy allows or denies. Action statement 215 can include a read-only action, a view action, an update action, a write action, a delete action, an NotAction, or some other actions”, thus […] including (A) a role definition for a role of a role-based access control system and (B) action definitions is disclosed, because James teaches an IAM role having specific access permissions defined by security policies associated with the role. James’s IAM role corresponds to a role of a role-based access control system because it is an access-control identity whose permissions to system resources are controlled by associated policies. James’s security policies correspond to a role definition because the policies associated with the role define the access permissions assigned to the role. James’s action statement and its list of read-only, view, update, write, delete, and NotAction operations correspond to action definitions because they identify the actions that the role-associated policy allows or denies on system resources) the role definition for the role including an action and effective permissions text describing a summary of permission limitations provided by the role (James, Par. [0037], “Action statement 215 can include a list of actions to be performed on the one or more system resources that the policy allows or denies. Action statement 215 can include a read-only action, a view action, an update action, a write action, a delete action, an NotAction, or some other actions”, & Par. [0035], “In some examples, security policy 210 can be specified by nature language. In some other examples, security policy 210 can be specified by one or more statements in a markup language or structured language. Security policy 210 can be contained in a document specified by a markup language, such as a JavaScript Object Notation (JSON) document, a XML document, a YAML document, or any other documents containing statements in structured languages”, & Par. [0073], “The list of lists generated by method 430 in FIG. 4C can be a useful form of representation for effective access permissions. Such group of lists, where each list is a list of policy statements associated with an allow policy statement with respect to the effective access permissions, can be operated by effective policy generator 121, while it is also readable by a human user. Such a group of lists are not simply an abstract idea of a list of lists. Instead, it is specifically tied to lists including an allow policy statement followed by a set of deny policy statements to define the effective access permissions”, thus the role definition for the role including an action and effective permissions text describing a summary of permission limitations provided by the role is disclosed, because James teaches a role-associated security policy that identifies actions permitted or denied on system resources and provides a human-readable representation of the role’s effective access permissions. James’s listed read-only, view, update, write, delete, and NotAction operations correspond to an action because they identify operations that the role-associated policy allows or denies. James’s security policy expressed in natural language or structured language corresponds to effective permissions text because it provides textual statements describing the permissions associated with the role. James’s human-readable group of lists containing an allow policy statement followed by corresponding deny policy statements corresponds to a summary of permission limitations provided by the role because it summarizes the actions and resources permitted by the role together with the restrictions that limit those permissions) the action definitions being in a hierarchical format and including the action (James, Par. [0037], “Action statement 215 can include a list of actions to be performed on the one or more system resources that the policy allows or denies. Action statement 215 can include a read-only action, a view action, an update action, a write action, a delete action, an NotAction, or some other actions”, & Par. [0035], “In some other examples, security policy 210 can be specified by one or more statements in a markup language or structured language. Security policy 210 can be contained in a document specified by a markup language, such as a JavaScript Object Notation (JSON) document, a XML document, a YAML document, or any other documents containing statements in structured languages”, & Par. [0040], “In addition, name 225 includes “confidential-data/*”, which refers to a set of system resources within the folder “confidential-data.” Therefore, a name for a system resource can refer to system resource set of the IAM system of various sizes, as shown above For example, name 227 specifies only one system resource, “example_bucket”, while name 223 specifies every system resource of the account, “*”. The set of system resources referred by a name for a system resource defines a scope of the name for the system resource”, thus the action definitions being in a hierarchical format and including the action is disclosed, because James teaches security policies expressed in structured formats, such as JSON, XML, or YAML, that contain action statements and resource statements. James’s structured security-policy format corresponds to a hierarchical format because the policy is organized into statements and component statements containing action and resource information. James’s read-only, view, update, write, delete, and NotAction operations correspond to the action because they identify the operations that the policy permits or denies. James’s folder paths, resource names, and wildcard scopes further correspond to the hierarchical arrangement because they organize resources at different levels, such as a specific resource, resources within a folder, or all resources within an account) […] about effective permissions associated with the role (James, Par. [0028], “Combined, the security policies, e.g., policy 113a, policy 113b, or policy 113c, can generate effective policy 123, which can define a set of effective access permissions 125 by role 113 to access system resources 133. The set of effective access permissions 125 represent the actual access permissions granted to role 113 by the security policies associated with role 113”, & Par. [0073], “The list of lists generated by method 430 in FIG. 4C can be a useful form of representation for effective access permissions. Such group of lists, where each list is a list of policy statements associated with an allow policy statement with respect to the effective access permissions, can be operated by effective policy generator 121, while it is also readable by a human user”, thus […] about effective permissions associated with the role is disclosed, because James teaches determining and representing the actual access permissions granted to a role based on the security policies associated with that role. James’s effective access permissions correspond to effective permissions associated with the role because they identify the actions and resources that the role is permitted or prohibited from accessing) James does not explicitly creating a prompt for a large language model (LLM), the prompt […], adding, to the prompt, query text that includes a question […], and submitting the prompt to the LLM to generate response text. However, Javed teaches: creating a prompt for a large language model (LLM), the prompt […] (Javed, Par. [0073], “At 410, one or more prompts based on the prompt templates are determined. In some embodiments, a prompt may be determined by supplementing and/or modifying a prompt template based on the input text. For instance, a portion of input text may be added to a prompt template at an appropriate location”, & Par. [0046], “A prompt template may also include one or more fillable portions that may be filled based on information determined by the orchestrator 230. For instance, a prompt template may be filled based on information received from a client machine, information returned by a search query, or another information source”, thus creating a prompt for a large language model (LLM), the prompt […] is disclosed, because Javed teaches determining a prompt by supplementing or modifying a prompt template based on input text and filling portions of the prompt template using information received from different sources. Javed’s determination of a prompt from a prompt template corresponds to create a prompt because the system generates the prompt by adding information to or modifying the template. Javed’s prompt template corresponds to the prompt because it provides the structure into which input information is inserted. Javed’s fillable portions and added input text correspond to the content of the prompt because they are used to populate and form the completed prompt that is provided to the large language model) adding, to the prompt, query text that includes a question […] (Javed, Par. [0073], “At 410, one or more prompts based on the prompt templates are determined. In some embodiments, a prompt may be determined by supplementing and/or modifying a prompt template based on the input text. For instance, a portion of input text may be added to a prompt template at an appropriate location”, & Par. [0125], “An example of a prompt template that may be used to generate a prompt for determining an aggregate of a set of summaries of documents is provided below: A lawyer has submitted the following question: $$QUESTION$$ {{question}} $$/QUESTION$$”, thus adding, to the prompt, query text that includes a question […] is disclosed, because Javed teaches supplementing or modifying a prompt template by adding input text at an appropriate location and provides a prompt template containing a question field. Javed’s addition of input text to the prompt template corresponds to adding, to the prompt, query text because the input text is inserted into the existing prompt template. Javed’s question field corresponds to query text that describes a question because it contains the question submitted by the user for the model to answer) submitting the prompt to the LLM to generate response text (Javed, Par. [0074], “The one or more prompts are transmitted to a text generation modeling system at 412. In some embodiments, the text generation modeling system may be implemented at a remote computing system. The text generation modeling system may be configured to implement a text generation model”, & Par. [0075], “One or more text response messages are received from the remote computing system at 414. According to various embodiments, the one or more text response messages include one or more novel text portions generated by a text generation model implemented at the remote computing system. The novel text portions may be generated based at least in part on the prompt received at the text generation modeling system, including the instructions and the input text”, thus submit the prompt to the LLM to generate response text is disclosed, because Javed teaches transmitting a prompt to a text generation modeling system implementing a text generation model and receiving text response messages containing novel text generated based on the submitted prompt. Javed’s transmission of the prompt to the text generation modeling system corresponds to submit the prompt to the LLM because the system provides the completed prompt to the model for processing. Javed’s text generation model corresponds to the LLM because the model processes the prompt and generates text) It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to combine James with Javed by incorporating Javed’s LLM prompt generation and response technique into James’s IAM effective permissions system. James teaches determining and presenting a role’s effective permissions, including allowed and denied actions. Javed teaches inserting input information and a question into a prompt, submitting the prompt to an LLM, and receiving generated response text. Therefore, a POSITA would have been motivated to use James’s role definitions, action definitions, and effective permissions information as input to Javed’s prompt generation process so that a user could submit a question concerning a particular role and receive a natural language response explaining the actions permitted by the role and the limitations imposed on those permissions. This would simplify the review and interpretation of complex role associated security policies, thereby reducing the burden of manually reviewing and interpreting numerous policy statements (James, Par. [0013], “When the number of security policies associated with a principal can be in the magnitude of hundreds of thousands or millions, it becomes infeasible to evaluate the effective access permissions defined by security policies by hand or by visual inspection. Effective mechanisms are needed for an enterprise system to evaluate the effective access permissions defined by security policies associated with the principal”) Regarding Claim 16, James combined with Javed teaches all the limitations of claim 15 as cited above and James further teaches: receiving user input identifying a security principal and a target resource (James, Par. [0061], “According to method 410, at 411, a user can enter a principal name. At 412, effective policy generator 121 can gather all the security policies from the IAM attached to the principal. In some examples, all the security policies attached to the principal can be a large number of security policies, e.g., millions of security policies”, & Par. [0027], “Principal 111, e.g., role 113, can submit request 119 for accessing system resources such as system resources 133 which are protected by IAM system 131. Request 119 can include a request context information, which is used to evaluate and authorize the request. The request context information can include actions or operations to be performed, resources upon which the actions or operations are performed, a principal that can be a person or an application that an entity to send request 119, environment data such as IP address, user agent, SSL enabled status, or the time of day; and resource data such as data related to the resource that is being requested. Information about the principal can include the policies that are associated with the entity that the principal used to sign in”, thus receiving user input identifying a security principal and a target resource is disclosed, because James teaches receiving a principal name entered by a user and an access request containing information identifying the principal and the resource being requested. James’s user entered principal name corresponds to a security principal because it identifies the person, application, or role whose access permissions are evaluated. James’s resource data and the resource upon which the requested action is performed correspond to a target resource because they identify the system resource for which access is requested) […] with the security principal and the target resource (James, Par. [0061], “According to method 410, at 411, a user can enter a principal name”, & Par. [0027], “The request context information can include actions or operations to be performed, resources upon which the actions or operations are performed, a principal that can be a person or an application that an entity to send request 119, environment data such as IP address, user agent, SSL enabled status, or the time of day; and resource data such as data related to the resource that is being requested”, thus […] with the security principal and the target resource is disclosed, because James teaches information identifying a principal and the resource being requested. James’s user-entered principal name corresponds to the security principal because it identifies the person, role, or application whose permissions are evaluated. James’s requested resource and associated resource data correspond to the target resource) Javed further teaches: creating the query text by populating a preconfigured query text template […] (Javed, Par. [0046], “A prompt template may also include one or more fillable portions that may be filled based on information determined by the orchestrator 230. For instance, a prompt template may be filled based on information received from a client machine, information returned by a search query, or another information source”, & Par. [0073], “In some embodiments, a prompt may be determined by supplementing and/or modifying a prompt template based on the input text. For instance, a portion of input text may be added to a prompt template at an appropriate location”, & Par. [0125], “An example of a prompt template that may be used to generate a prompt for determining an aggregate of a set of summaries of documents is provided below: A lawyer has submitted the following question: $$QUESTION$$ {{question}} $$/QUESTION$”, thus creating the query text by populating a preconfigured query text template […] is disclosed, because Javed teaches a predefined prompt template having a fillable question field that is completed using received input information. Javed’s prompt template containing predefined question language and a fillable question field corresponds to a preconfigured query text template because it establishes the structure and location for the question information. Javed’s insertion of input text into the fillable portions of the template corresponds to populating the template because the received information is added at the designated location to form the query text) Regarding Claim 17, James combined with Javed teaches all the limitations of claim 15 as cited above and James further teaches: wherein the hierarchical format of the action definitions including a resource type portion and an action verb portion, wherein the action identifies a resource type and an action verb (James, Par. [0035], “In some other examples, security policy 210 can be specified by one or more statements in a markup language or structured language. Security policy 210 can be contained in a document specified by a markup language, such as a JavaScript Object Notation (JSON) document, a XML document, a YAML document, or any other documents containing statements in structured languages”, & Par. [0036], “. A policy statement can further include various component statements. In some examples, policy statement 212 can include an effect statement 211, a principal statement 213, an action statement 215, a resource statement 217, a condition statement 219, or some other component statements. Policy statement 214 can include similar component statements”, & Par. [0040], “In addition, name 225 includes “confidential-data/*”, which refers to a set of system resources within the folder “confidential-data.” Therefore, a name for a system resource can refer to system resource set of the IAM system of various sizes, as shown above For example, name 227 specifies only one system resource, “example_bucket”, while name 223 specifies every system resource of the account, “*”. The set of system resources referred by a name for a system resource defines a scope of the name for the system resource”, & Par. [0037], “Action statement 215 can include a list of actions to be performed on the one or more system resources that the policy allows or denies. Action statement 215 can include a read-only action, a view action, an update action, a write action, a delete action, an NotAction, or some other actions”, thus wherein the hierarchical format of the action definitions including a resource type portion and an action verb portion, wherein the action identifies a resource type and an action verb is disclosed, because James teaches structured security policies organized into component statements that separately identify resources and actions performed on those resources. James’s structured policy format corresponds to the hierarchical format because the policy is organized into statements and component statements containing resource and action information. James’s resource statement, resource names, folder paths, and wildcard scopes correspond to a resource type portion because they identify the resource or category of resources to which the permission applies. James’s read, view, update, write, and delete operations correspond to an action verb portion because they identify the operation performed on the resource. Together, James’s resource information and associated operations correspond to an action that identifies a resource type and an action verb) Regarding Claim 18, James combined with Javed teaches all the limitations of claim 15 as cited above and James further teaches: storing an example role definition including the role definition, the example role definition including a permitted action from the action definitions and associated effective permissions text, […] the example role definition […] (James, Par. [0022], “Enterprise system 110 can include any number of principals, e.g., principal 111, a policy database 112, and a security governance guideline 114, which can be stored in memory device 118. Policy database 112 can include one or more security policies, which can be referred to as a policy, associated with roles or principals”, & Par. [0032], “Effective policy 123 and the set of effective access permissions 125 can be saved in a storage located outside IAM system 131 and separated from IAM system 131”, & Par. [0033], “Security policy 210 can be an example of policy 113a, policy 113b, policy 113c as shown in FIG. 1. Security policy 210 can include a policy statement 212 and a policy statement 214”, & Par. [0037], “Effect statement 211 can specify either Allow or Deny to indicate whether the policy statement 212 allows or denies access. Action statement 215 can include a list of actions to be performed on the one or more system resources that the policy allows or denies”, & Par. [0073], “The list of lists generated by method 430 in FIG. 4C can be a useful form of representation for effective access permissions. Such group of lists, where each list is a list of policy statements associated with an allow policy statement with respect to the effective access permissions, can be operated by effective policy generator 121, while it is also readable by a human user”, thus storing an example role definition including the role definition, the example role definition including a permitted action from the action definitions and associated effective permissions text, […] the example role definition […] is disclosed, because James teaches storing security policies associated with roles and storing the effective access permissions generated from those policies. James’s example security policy associated with a role corresponds to an example role definition because it defines permissions assigned to the role. James’s action included in an Allow policy statement corresponds to a permitted action from the action definitions because it identifies an operation that the role is allowed to perform. James’s readable representation containing an allow policy statement and associated deny policy statements corresponds to associated effective permissions text because it describes the permitted action and the restrictions limiting that permission) Javed further teaches: […] wherein creating the prompt further includes adding […] to the prompt (Javed, Par. [0046], “A prompt template may also include one or more fillable portions that may be filled based on information determined by the orchestrator 230. For instance, a prompt template may be filled based on information received from a client machine, information returned by a search query, or another information source”, & Par. [0073], “In some embodiments, a prompt may be determined by supplementing and/or modifying a prompt template based on the input text. For instance, a portion of input text may be added to a prompt template at an appropriate location”, thus […] wherein creating the prompt further includes adding […] to the prompt is disclosed, because Javed teaches creating a prompt by adding input information to a prompt template. Javed’s input information corresponds to the information added to the prompt because it is inserted into a designated portion of the prompt template) Regarding Claim 19, James combined with Javed teaches all the limitations of claim 15 as cited above and James further teaches: receiving user input identifying another role definition, the other role definition includes another action and does not include effective permissions text (James, Par. [0061], “According to method 410, at 411, a user can enter a principal name. At 412, effective policy generator 121 can gather all the security policies from the IAM attached to the principal”, & Par. [0032], “Effective policy generator 121 can be configured to receive all policies associated with a role, such as policy 113a, policy 113b, and policy 113c associated with role 113, and generate effective policy 123 from the received policies. Effective policy 123 further defines the set of effective access permissions 125”, & Par. [0037], “Action statement 215 can include a list of actions to be performed on the one or more system resources that the policy allows or denies”, thus receiving user input identifying another role definition, the other role definition includes another action and does not include effective permissions text is disclosed, because James teaches receiving a principal name from a user and retrieving the security policies associated with the identified role. James’s user entered principal name corresponds to user input identifying another role definition because it identifies the role whose associated policies are retrieved. James’s retrieved security policy corresponds to the other role definition because it defines the permissions associated with that role. James’s action statement corresponds to another action because it identifies an operation permitted or denied by the policy. James’s received security policy does not include effective permissions text because the effective policy and effective access permissions are generated separately from the received policies) […] the other role definition […] referencing the other role (James, Par. [0027], “Request 119 can include a request context information, which is used to evaluate and authorize the request. The request context information can include actions or operations to be performed, resources upon which the actions or operations are performed, a principal that can be a person or an application that an entity to send request 119. Information about the principal can include the policies that are associated with the entity that the principal used to sign in”, & Par. [0036], “A policy statement can further include various component statements. In some examples, policy statement 212 can include an effect statement 211, a principal statement 213, an action statement 215, a resource statement 217, a condition statement 219, or some other component statements”, thus […] the other role definition […] referencing the other role is disclosed, because James teaches a security policy containing statements that define permissions for a principal identified in a request. James’s security policy corresponds to the other role definition because it defines the permissions associated with the identified role. James’s principal identified in the request context corresponds to the other role because it identifies the role referenced by the request) Javed further teaches: submitting another prompt to the LLM, the other prompt including […] and other query text that describes a question […] (Javed, Par. [0080], “A determination is made at 422 as to whether to generate an additional prompt. According to various embodiments, the determination as to whether to generation an additional prompt may be made based in part on the text generation flow determined at 404 and in part based on the one or more text response messages received at 414 and parsed at 416”, & Par. [0073], “At 410, one or more prompts based on the prompt templates are determined. In some embodiments, a prompt may be determined by supplementing and/or modifying a prompt template based on the input text. For instance, a portion of input text may be added to a prompt template at an appropriate location”, & Par. [0125], “An example of a prompt template that may be used to generate a prompt for determining an aggregate of a set of summaries of documents is provided below: A lawyer has submitted the following question: $$QUESTION$$ {{question}} $$/QUESTION”, & Par. [0074], “The one or more prompts are transmitted to a text generation modeling system at 412”, thus submitting another prompt to the LLM, the other prompt including […] and other query text that describes a question […] is disclosed, because Javed teaches generating an additional prompt, adding input text and a question to the prompt, and transmitting the prompt to a text generation modeling system. Javed’s additional prompt corresponds to another prompt because it is generated as a further prompt in the text generation flow. Javed’s question field corresponds to other query text that describes a question because it contains the question submitted for processing. Javed’s transmission of the additional prompt to the text generation modeling system corresponds to submitting another prompt to the LLM) Regarding Claim 20, James combined with Javed teaches all the limitations of claim 15 as cited above and James further teaches: wherein the role definition further includes an allowed action and a prohibited action (James, Par. [0037], “Effect statement 211 can specify either Allow or Deny to indicate whether the policy statement 212 allows or denies access. Action statement 215 can include a list of actions to be performed on the one or more system resources that the policy allows or denies. Action statement 215 can include a read only action, a view action, an update action, a write action, a delete action, an NotAction, or some other actions”, thus wherein the role definition further includes an allowed action and a prohibited action is disclosed, because James teaches security policy statements that identify actions the role is allowed or denied from performing. James’s action identified by a policy statement having an Allow effect corresponds to the allowed action because the policy permits the role to perform that action. James’s action identified by a policy statement having a Deny effect corresponds to the prohibited action because the policy prevents the role from performing that action) Conclusion The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure. US 11516220B1 is pertinent because it teaches a role-based access control system for controlling access to resources within a computer network, including creating and storing custom role definitions that associate roles with selected capabilities, actions, and privileges. The reference further teaches receiving user selections identifying a role and its associated capabilities, storing the created role in a role database, and representing capabilities and corresponding actions in hierarchical formats such as YAML or JSON. The capabilities may include actions such as create, read, update, and delete and may be organized according to resources and higher-level and dependent capabilities. Because applicant’s disclosure similarly concerns role definitions, actions associated with roles, permission limitations, and hierarchically organized action definitions in a role-based access control system, the reference is relevant to the claimed invention but is not relied upon in the rejection. Any inquiry concerning this communication or earlier communications from the examiner should be directed to MAHLIET ADMASU whose telephone number is (571)272-0034. The examiner can normally be reached Mon-Fri, 8am-5pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexey Shmatov can be reached at (571)270-3428. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /M.T.A./Examiner, Art Unit 2123 /ALEXEY SHMATOV/Supervisory Patent Examiner, Art Unit 2123
Read full office action

Prosecution Timeline

Mar 26, 2024
Application Filed
Aug 03, 2026
Non-Final Rejection mailed — §101, §103 (current)

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
Grant Probability
Low
PTA Risk
Based on 0 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month