Prosecution Insights
Last updated: October 04, 2026
Application No. 19/027,128

SYSTEM AND METHOD FOR HANDLING DIGITAL CONTENT GOVERNANCE IN AN ORGANIZATION

Final Rejection §101§103§112
Filed
Jan 17, 2025
Priority
Sep 04, 2018 — continuation of 11/353,039 +2 more
Examiner
LE, UYEN T
Art Unit
2156
Tech Center
2100 — Computer Architecture & Software
Assignee
Hyland UK Operations Limited
OA Round
2 (Final)
84%
Grant Probability
Favorable
3-4
OA Rounds
12m
Est. Remaining
93%
With Interview

Examiner Intelligence

Grants 84% — above average
84%
Career Allowance Rate
683 granted / 814 resolved
+28.9% vs TC avg
Moderate +10% lift
Without
With
+9.5%
Interview Lift
resolved cases with interview
Typical timeline
2y 8m
Avg Prosecution
10 currently pending
Career history
832
Total Applications
across all art units

Statute-Specific Performance

§101
16.1%
-23.9% vs TC avg
§103
29.8%
-10.2% vs TC avg
§102
17.5%
-22.5% vs TC avg
§112
22.9%
-17.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 814 resolved cases

Office Action

§101 §103 §112
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claims 21-40 are pending. It is noted that applicant incorrectly stated at page 6 of 11 of the response filed 29 May 2026 that allowable subject matter was indicated for claims 27-35. The examiner points out no allowable subject matter was indicated in the Office action mailed 28 January 2026. Applicant also inadvertently refers to independent claims as 1, 7 and 15 at page 7 of the response. Response to Amendment Applicant’s amendment filed 29 May 2026 is not sufficient to overcome the rejection of all the pending claims under 35 U.S.C. 101 discussed below. Applicant’s amendment to claims 21, 27-29 to address the 112 issues is acknowledged. However the amendment introduces new issues of U.S.C. 112 discussed below. Applicant’s submission of a Terminal Disclaimer on 14 May 2026 is acknowledged. The non-statutory double patenting rejection is withdrawn. Response to Arguments Applicant's arguments filed 29 May 2026 regarding the 103 rejection over Turner and Wilson references have been fully considered but they are not persuasive. Applicant argues at page 9 of 11 of the response: “second, claim 21 is amended to recite that the detecting is by an application on the server system. This is not addressed in the rejection” In response the examiner points out applicant argues the claim as amended. However the specification as originally filed does not support such feature. Nevertheless Turner clearly suggests the application is on the server system (see at least paragraph [0065]:” FIG. 7 is a simplified flow chart 269 of one possible embodiment of a process of the invention to identify and alert or warn of physical perimeter breaches by an electronic document(s) or information. The process shown in FIG. 20 unlike the process shown in FIG. 10 is resident on computers, networks, devices, or domains of networks not authorized for the classified document content and are outside of the physical perimeter securing classified or sensitive information. The process monitors file or media events of the systems operating system 210 and 220, or document development host application events of software applications that may be resident on an operating system”. Applicant argues at page 9 of 11 of the response: “third, the citation to Wilson merely provides the practice of putting files in folders with different permissions. This does not detect classification per se”. In response the examiner is not persuaded. Wilson was merely cited as teaching removing a file based on its classification. Turner already teaches detecting the classification of a file at least at paragraphs [0013], [0065], [0066]. Applicant presents no further argument regarding the dependent claims. For all the reasons discussed above, the 103 rejection of claims 21-40 using Turner and Wilson is maintained. Regarding claim 27, the now added “wherein the first and second class are related to user access permissions” is not supported by the specification as originally filed. Nevertheless Turner clearly teaches such features when Turner shows the process monitors file or media events for unauthorized classification (see at least [0065]) and controls access and storage of electronic documents (see at least [0013]). Regarding the rejection under 35 U.S.C. 101, applicant argues at page 7 of 11 of the response: “Even if, arguendo, it can be said that the claims are directed to a judicial exception, then, under Step 2B analysis, the claims include additional elements that amount to significantly more than a judicial exception. The elements enumerate particular transactions between the server and client that, when performed in sequence, achieve a desired technical result-the protection of classified, such as secret or top secret content by remotely setting permissions for the content on a client computer”. In response the examiner is not persuaded. The protection of classified content is merely performed by a generic content management system having a generic server system. As written the sequence of operations does not include additional element that amount to significantly more than the judicial exception. For all the reasons discussed above, the 101 rejection is maintained. Claim Rejections - 35 USC § 112 The following is a quotation of the first paragraph of 35 U.S.C. 112(a): (a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112: The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention. Claims 21-40 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. The specification as originally filed does not support the amended features of “detecting by an application on the server system” recited in claim 21, “wherein the first and second class are related to user access permission” recited in claim 27. The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 21-40 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. The specification as originally filed does not support the amended features of “detecting by an application on the server system” recited in claim 21, “wherein the first and second class are related to user access permission” recited in claim 27. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 21-40 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Analysis of patent eligibility of claim 21: Step 1: claim 21 recites a "method for..."; thus seems to be directed to a process Step 2A Prong One: claim 21 recites the limitations: Detecting... classified by a user as a classified file Detecting... declared as a permanent record by the user; Nothing in the claim element precludes the steps from practically being performed by a human mind or with pen and paper. The criteria of classified as a classified file or declared as a permanent record are mere attributes of any data file, The recited detecting falls within the mental process grouping of abstract ideas (concepts performed in the human mind including observation, judgment, evaluation). Note the recited content management system, server system, an application on the server system are no more than mere tools to apply the exception using a generic computer component. Step 2A Prong Two: the judicial exception is not integrated into a practical application. The claim recites the additional elements of an application and a client computing recited at a high level of generality, is simply utilizing a generic computer and associated software as a tool to perform an abstract idea thus does not provide an inventive concept because the recited elements amount to mere insignificant extra solution activity (MPEP 2106.05(g), do not impose any meaningful limits on practicing the abstract idea, do not provide an inventive concept, do not improve any technology or technical field, do not apply the judicial exception with or by use of a particular machine, do not add specific limitation other than what is well-understood, routine, conventional activity in the field, do not add unconventional steps that confine the claim to a particular useful application, do not include other meaningful limitations beyond linking the use of the judicial exception to a particular technological environment. Accordingly, the claim as a whole does not integrate the abstract idea into a practical application. Step 2B: the claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. The claimed "based on detecting of the classification. removing the classified file from a client computing system" and "based on detecting of the declaration preventing editing by the client computing system of a file declared as a permanent record" are recognized by the courts as well- understood, routine, and conventional activities when they are claimed in a merely generic manner. (See MPEP 2106.05(d)(II) (iv). Note any data file has to be processed according to its classification attributes. Claim 22 merely further describes the classification process, considered insignificant extra solution activity (MPEP 2106.05(g). Claims 23, 25 merely further describe the declaration process, considered insignificant extra solution activity (MPEP 2106.05(g). Claim 24 merely adds queueing permanent files, considered insignificant extra solution activity (MPEP 2106.05(g). Claim 26 merely further describes the server is cloud-based, considered insignificant extra solution activity (MPEP 2106.05(g). Claims 36-39 essentially recite limitations similar to claims 21-24 with a slight difference in wordings in form of non-transitory computer readable program product thus are not patent eligible for the same reasons discussed above. Claim 40 merely adds one or more files are associated with an application to create, edit or manage records, considered insignificant extra solution activity (MPEP 2106.05(g). Although the dependent claims are more detailed, none amounts to significantly more than the abstract idea recited in their parent claims. No claim is patent eligible. Analysis of patent eligibility of claim 27: Step 1: claim 27 recites a system comprising server and computing device thus seems to be directed to a machine. Step 2A Prong One: claim 27 recites the limitations: Detecting a synchronization event client computing device Nothing in the claim element precludes the steps from practically being performed by a human mind. The recited detecting falls within the mental process grouping of abstract ideas (concepts performed in the human mind including observation, judgment, evaluation). Note the recited cloud-based server and client computing device are no more than mere tools to apply the exception using generic computer components. Step 2A Prong Two: the judicial exception is not integrated into a practical application. The claim merely recites the additional elements of a mathematical algorithm in the form of IF THEN ELSE scenario regarding records processing according to their respective classifications. The recited mathematical algorithm does not provide an inventive concept because it is merely a tool to process records in a client/server system, considered insignificant extra solution activity (MPEP 2106.05(g), Accordingly, the claim as a whole does not integrate the abstract idea into a practical application. Step 2B: the claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. The added “wherein the first and second class are related to user access permission” merely describes content access authorization depends on the classification of the content. The claimed system merely includes generic components of a cloud-based server and client computer devices that do not impose any meaningful limits on practicing the abstract idea, do not provide an inventive concept, do not improve any technology or technical field, do not apply the judicial exception with or by use of a particular machine, do not add specific limitation other than what is well-understood, routine, conventional activity in the field, do not add unconventional steps that confine the claim to a particular useful application, do not include other meaningful limitations beyond linking the use of the judicial exception to a particular technological environment. Claim 27 is not patent eligible. Claim 28 merely adds registering the client device, considered insignificant extra solution activity (MPEP 2106.05(g). Claim 29 merely adds an application to create, edit and/or manage records, considered insignificant extra solution activity (MPEP 2106.05(g). Claim 30 merely adds the user to set classifications, considered insignificant extra solution activity (MPEP 2106.05(g). Claim 31 merely adds the first records are managed by a first policy, considered insignificant extra solution activity (MPEP 2106.05(g). Claim 32 merely adds a content management system associated with the server and communicating over a network, considered insignificant extra solution activity (MPEP 2106.05(g). Claim 33 merely adds access control lists and API for setting permissions, considered insignificant extra solution activity (MPEP 2106.05(g). Claim 34 merely adds the role of an administrator, considered insignificant extra solution activity (MPEP 2106.05(g). Claim 35 merely adds queueing a record for transfer to client device, considered insignificant extra solution activity (MPEP 2106.05(g). Although the dependent claims are more detailed, none amounts to significantly more than the abstract idea recited in their parent claims. No claim is patent eligible. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 21-23, 25, 36-38, 40 is/are rejected under 35 U.S.C. 103 as being unpatentable over Turner et al (US 20100186091 A1) of record, provided by the applicant, in view of Wilson et al (AU 2014259536 A1) of record. Regarding claim 21, Turner substantially discloses a computer- implemented method for records management and classification of one or more files in a content management system having a server system that stores one or more files, the method comprising: detecting, by an application on the server system, when one or more of the files is classified by a user as a classified file (see at least Turner [0013] The invention's processes and methods to reliably obtain the full or complete classification determination for an electronic document as well as embedding and associating unique codes in the electronic shell of a document representing the complete classification determination, provides a reliable basis for further methods and processes of the invention to control document movement, access and storage of electronic documents within classified or sensitive computers, computer networks or domains of networks as well as methods and processes to identify and immediately alert on a security breach by an electronic document or its storage media of a physical security perimeter between computer networks or domains of networks operating at different sensitivity or classification levels without compromising or otherwise providing insight into the individual classification regimes resident on networks or domains of computer networks operating at the higher classification or sensitivity level). Note Turner clearly suggests the application is on the server system (see at least paragraph [0065]:” FIG. 7 is a simplified flow chart 269 of one possible embodiment of a process of the invention to identify and alert or warn of physical perimeter breaches by an electronic document(s) or information. The process shown in FIG. 20 unlike the process shown in FIG. 10 is resident on computers, networks, devices, or domains of networks not authorized for the classified document content and are outside of the physical perimeter securing classified or sensitive information. The process monitors file or media events of the systems operating system 210 and 220, or document development host application events of software applications that may be resident on an operating system”). Turner does not specifically show: based on the detecting of the classification of the one or more files, removing, by the application, the classified file from a client computing system; detecting, by the application, when at least one of the one or more files is declared as a permanent record by the user; and based on the detecting of the declaration as a permanent record, preventing, by the application, editing by the client computing system of a file declared as a permanent record. However it is customary in the art to classify records as permanent as shown by Wilson and to process the records according to their attributes (see Wilson [222] In one example, individuals can save documents in a number of folders, with the folders having separate permissions, allowing the folders to be used for different purposes. For example, a folder that cannot be deleted or changed by the user can be used for securely storing important information, such as tax returns, associated receipts or the like. However, other folder configurations can be used. For example, shared document folders can be provided allowing multiple parties to sign and maintain a document (such as a contract), with all changes being recorded and noted. Wilson [223] Any documents stored can be time-stamped, ensuring that a permanent record is maintained as to the content of the document at the specified date, and in one example, folders and documents can be read only to thereby prevent the documents being subsequently altered after submission). it would have been obvious to one of ordinary skill in the art the effective filing date of the claimed invention to include such features while implementing the method of Turner in order to properly handle records according to their classification attributes. Regarding claim 22, Turner/Wilson further teaches or suggests the method in accordance with claim 21, wherein the classification of the one or more files is done by the application on the client computing system remotely from the content management system (see Wilson [013] Typically the server processing system is configured to: receive, from the user processing system, authorisation data indicative of a third party authorised by the entity to read-only access at least a portion of the registry). Note the client computing system reads on the user processing system of Wilson. Regarding claim 23, Turner/Wilson further teaches or suggests the method in accordance with claim 21, wherein the declaration of the one or more files as a permanent record is done by the application on the client computing system remotely from the content management system (see Wilson [013] Typically the server processing system is configured to: receive, from the user processing system, authorisation data indicative of a third party authorised by the entity to read-only access at least a portion of the registry). Note the client computing system reads on the user processing system of Wilson. Regarding claim 25, Turner/Wilson further teaches or suggests the method in accordance with claim 21, wherein the declaration of the one or more files as a permanent record is made via an application being executed on a client computing system (see Wilson [013] Typically the server processing system is configured to: receive, from the user processing system, authorisation data indicative of a third party authorised by the entity to read-only access at least a portion of the registry). Note the client computing system reads on the user processing system of Wilson. Claims 36-38 essentially recite limitations similar to claims 21-23 in form of computer program product thus are rejected for the same reasons discussed in claims 21-23 above. Regarding claim 40, Turner/Wilson further teaches or suggests the non-transitory data storage medium in accordance with claim 36, wherein the one or more files are associated with an application configured for creating, editing, and/or managing a plurality of records (see Turner [[0008] The establishment of reliable security access controls for electronic documents/information based upon a document's or storage media's associated complete or full classification code(s), as well as similar unique classification regime code assignments to the security clearance level or access authority of users of the network; to elements of a computer operating system's file management system on a computer; to computers on a network; to networks and to domains of networks in real-time.). Note the limitations are recited in the alternatives. Claim(s) 24, 39 is/are rejected under 35 U.S.C. 103 as being unpatentable over Turner et al (US 20100186091 A1) of record, provided by the applicant, in view of Wilson et al (AU 2014259536 A1) of record, further in view of Christensen et al (US 8688823 B1) of record. Regarding claim 24, Turner/Wilson teaches the method in accordance with claim 21, further comprising generating an event after one or more files are classified or declared as a permanent record (see at least Wilson [223}: Any documents stored can be time-stamped, ensuring that a permanent record is maintained as to the content of the document at the specified date, and in one example, folders and documents can be read only to thereby prevent the documents being subsequently altered after submission). Turner/Wilson does not specifically show “queuing the event for retrieval by the application on the client system, processing the event and synchronizing the one or more files to be the permanent record or the classified file based on the event”. However it is customary in the art as shown by Christensen to add data to a queue for subsequent delivery (see Christensen col.5 lines 25-31: Once the user originating the transaction has been uniquely identified, at 220 the Windows service 245 constructs a record of the TCP/IP connection details, data and time and originating user for the transaction and adds the user/connection binding data to a queue for subsequent delivery to the UAE 260 running within the remote packet monitor system 255). it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include such features while implementing the method of Turner/Wilson in order to orderly process communications between server and clients. Regarding claim 39, Turner/Wilson does not specifically show the non-statutory data storage medium in accordance with claim 36, wherein the one or more files declared as a permanent record are queued by the cloud-based server for delivery to the client computing system. However it is customary in the art as shown by Christensen to add data to a queue for subsequent delivery (see Christensen col.5 lines 25-31: Once the user originating the transaction has been uniquely identified, at 220 the Windows service 245 constructs a record of the TCP/IP connection details, data and time and originating user for the transaction and adds the user/connection binding data to a queue for subsequent delivery to the UAE 260 running within the remote packet monitor system 255). it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include such features while implementing the non-statutory data storage medium of Turner/Wilson for the profit of orderly processing communications between server and clients. Claim(s) 26 is/are rejected under 35 U.S.C. 103 as being unpatentable over Turner et al (US 20100186091 A1) of record, provided by the applicant, in view of Wilson et al (AU 2014259536 A1) of record, further in view of Sinha (US 20120240183 A1) of record. Regarding claim 26, Turner/Wilson does not specifically show the method in accordance with claim 21, wherein the server system is a cloud- based server system. However it is customary in the art to do so as shown by Sinha (see at least [0005]: a cloud network configured to perform mobile device security and policy enforcement includes a plurality of cloud nodes communicatively coupled to a network, each of the plurality of cloud nodes is configured to: communicate with a mobile device; and perform mobile device policy and security enforcement of the mobile device while concurrently providing access to the network.). it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed inventio to include such feature while implementing the method of Turner/Wilson in order to benefit from the cloud-based security for mobile devices. Claim(s) 27-32, 35 is/are rejected under 35 U.S.C. 103 as being unpatentable over Vesper et al (US 20110110568 A1), in view of Turner et al (US 20100186091 A1) of record, provided by the applicant. Regarding claim 27, Vesper substantially teaches a cloud-based computer-implemented system comprising a cloud-based server and a client computing device (see at least [0310] [0310] In one embodiment, image copies can be provided. Each gateway device can stage a copy of each registered image for upload to a highly redundant cloud storage facility using strongly authenticated web services. Each gateway device contains sufficient local storage to hold a copy of each registered and uploaded image for a user-specified period of time, for instance three months, six months, twelve months, or some other period of time. A timestamp can be placed on each copied image.), the cloud-based server and the client computing device comprising one or more processors configured to perform a plurality of computing operations comprising: detecting a synchronization event between the cloud-based server system and the client computing device (see at least [0134] Storage manager 52 stores and manages the records on the local nodes. Storage manager 52 synchronizes the information between the local node and the central network to keep track of the available records on the node. Storage manager 52, in conjunction with security manager 250, administers the access to the stripped records and the headers based on the current user logged into the user application, Storage manager 52, in conjunction with communication manager 42, receives new studies from the local node manager.) and Vesper does not specifically show: if a first record is not set to a first class, then synchronizing the record with the client computing device; if the first record is set to a first class, then removing the record from the client computing device, or not synchronizing the first record with the client computing device; however it is customary in the art as shown by Turner to do so (see at least [0065]... The process monitors file or media events of the systems operating system 210 and 220, or document development host application events of software applications that may be resident on an operating system. On a file or media event 210 the invention evaluates the embedded classification or sensitivity codes of documents and or media introduced to the system 220. If the file or the media does not contain unauthorized classification or media codes 160 then the process ends and the initial file or media event is completed). It would have been obvious to one of ordinary skill in the art to include such features while implementing the system of Vesper in order to enforce storage policies of related records; The claimed “or if a second record is set to a second class, preventing the client computing system from editing the record” is recited in the alternative thus not required for examination. wherein the first and second class are related to user access permissions (see at least Vesper [0221]). Regarding claim 28, Vesper/Turner further teaches the system of claim 27, further comprising registering the client computing device with the cloud-based server (see at least Vesper [0310]). Regarding claim 29, Vesper/Turner further teaches the system of claim 27, wherein the client computing device or cloud-based server comprises an application configured for creating, editing, and/or managing a plurality of records (see at least Vesper Fig,1 item 18). Regarding claim 30, Vesper/Turner further teaches the system of claim 27, wherein setting to the first and second class is performed by user instructions provided to the client computing device remotely communicating with the cloud-based server (see at least Vesper [0156]). Regarding claim 31, Vesper/Turner further teaches the system of claim 27, wherein the first record is managed according to a first policy, in response to being set to the first class (see at least Vesper [0221]). Regarding claim 32, Vesper/Turner further teaches the system of claim 27, wherein the client computing device is remotely connected, via a communications network, to a content management system associated with the cloud-based server (see at least Vesper [0018]). Regarding claim 35, Vesper/Turner further teaches the system of claim 27, further comprising queuing a third record for transfer to the client computing device, in response to detecting the synchronization event (see at least Vesper [0131]). Claim(s) 33, 34 is/are rejected under 35 U.S.C. 103 as being unpatentable over Vesper et al (US 20110110568 A1), in view of Turner et al (US 20100186091 A1) of record, provided by the applicant, in view of Tucker et al (US 20160078247 A1) of record, cited by the examiner in the previous Office action. Regarding claim 33, Vesper/Turner further teaches the system of claim 32, wherein the client computing device replicates a permissions set in the content management system for the first record and second record, in response to detecting the synchronization event (see at least Vesper [0156]). The difference is Vesper/Turner does not specifically show “using one or more access control lists (ALSs) in association with one or more application programming interfaces (APIs)” However it is customary in the art to do so as shown by Tucker (see at least [0007]) in order to specify permission levels of each application; It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include such features while implementing the system of Vesper/Turner in order to benefit from a standardized control technique. Regarding claim 34, Vesper/Turner/Tucker further teaches the system of claim 33, wherein the first record and second record are monitored and attempts to override the permissions set in the content management system are prevented, including when a user has administrator control of the client computing system (see at least Tucker [0031], Vesper [0073], [0100]). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Bird et al (US 20060059567 A1) teach a data processing system having memory stores data elements, and includes an access control system that controls user access to the stored data elements using security label components. Each stored data element is associated with a set of data security label components, and each user is associated with a set of user security label components. The access control system receives a user request to access the stored data elements, compares the set of user security label components to the set of data security label components associated with the users, and based on the comparison result, determines whether or not to permit access to the stored data. Cremonini, Marco, Ernesto Damiani, and Pierangela Samarati. "Semantics-aware perimeter protection." Data and Applications Security XVII: Status and Prospects. Boston, MA: Springer US, 2004. 229-242. Abstract-Web services security is becoming a critical concern for any organization adopting the XML-based Web services approach to application integration. While many access control techniques for Web services are becoming available, several issues still need to be solved in order to correctly split the burden of securing Web services between the perimetral and the service level. In this paper, a technique is presented able to make perimetral defences semantics-aware. Application-level semantics aware firewalls enforce filtering rules directly on SOAP messages based on the nature of the services they request. Our semantics-aware firewalls rules are written using a flexible XML-based syntax that allows sharing metadata concepts with service level access control policies, supporting complex security policies that integrate perimetral defences with access control. Moreover, they can be quickly integrated into organizations’ existing infrastructure, deployed rapidly and scaled as needed. Also, they integrate easily with existing infrastructure and can be operated by current staff, potentially achieving a low total cost of ownership with respect to service level solutions. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to UYEN T LE whose telephone number is (571)272-4021. The examiner can normally be reached M-F 9-5. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ajay M Bhatia can be reached at 5712723906. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /UYEN T LE/Primary Examiner, Art Unit 2156 11 August 2026
Read full office action

Prosecution Timeline

Jan 17, 2025
Application Filed
Apr 07, 2025
Response after Non-Final Action
Jan 28, 2026
Non-Final Rejection mailed — §101, §103, §112
May 14, 2026
Response after Non-Final Action
May 14, 2026
Response Filed
May 29, 2026
Response Filed
Aug 13, 2026
Final Rejection mailed — §101, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12749013
MACHINE LEARNING TRAINING APPARATUS AND OPERATING METHOD THEREOF
3y 8m to grant Granted Sep 29, 2026
Patent 12711269
HIGH-RISK PASSAGE AUTOMATION IN A DIGITAL TRANSACTION MANAGEMENT PLATFORM
2y 6m to grant Granted Aug 18, 2026
Patent 12705392
HIGH RISK PASSAGE AUTOMATION IN A DIGITAL TRANSACTION MANAGEMENT PLATFORM
2y 6m to grant Granted Aug 11, 2026
Patent 12699677
TECHNIQUES FOR OPTIMIZING PROJECT DATA STORAGE
1y 8m to grant Granted Aug 04, 2026
Patent 12681913
DYNAMIC INTERNAL SERVICE/FUNCTION DISCOVERY IN TELECOM CLOUD ARCHITECTURE
3y 6m to grant Granted Jul 14, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
84%
Grant Probability
93%
With Interview (+9.5%)
2y 8m (~12m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 814 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month