| CPC H04L 63/101 (2013.01) [G06F 21/6209 (2013.01); H04L 63/20 (2013.01)] | 20 Claims | 

| 
               1. A method comprising: 
            receiving, with a controller, a request to create an access control policy that permits a role to perform one or more functions associated with management or configuration of a network; 
                determining, with the controller, one or more specific operations performed on one or more specific identified network objects in the network, the one or more specific identified network objects including a configuration object for configuring the network, and the one or more specific operations being performed on the one or more specific identified network objects to perform the one or more functions in response to receiving the request, based at least in part on tracking performance of the one or more functions in the network; and 
                creating, with the controller, the access control policy that permits the role to perform the one or more specific operations on the one or more specific identified network objects in the network. 
               |