Patent attributes
A method for controlling an access to a resource is provided. The method includes receiving, from a first user, a first input that relates to a business criterion for a provision of the access to the resource; receiving, from a second user, a second input that relates to an application-specific criterion for the provision of the access to the resource; generating one or more one access-control rules based on the inputs; receiving an access request; and determining whether to grant the access request based on the rules, and any conditions that pertain to the access. The method effectively decouples the business-related criterion from the application-specific criterion for the access determination, thereby ensuring that business stakeholders and application owners each have an independent ability to provide inputs for generating access-control rules and policies.