Count Active Employee Access Grants
Reported by candidates from IBM's online assessment. Pattern, common pitfall, and the honest play if you blank under the timer.
The mistake that sinks a first attempt on this IBM question, reported September 2026, is treating each event as a fresh grant. It isn't. Once an employee has a gap, they're dead for good, even if a later event lands inside what would've been a valid window. The task is a single pass over the event stream with a hash map tracking each employee's expiration and a validity flag. If you blank on the edge cases during the OA, StealthCoder runs invisibly on your desktop as a safety net. Know the half-open interval rule before you start, because that's where the off-by-one lives.
The problem
Each employee has an access duration. An event (employeeId, time) starts or renews that employee's access through time + duration. Access intervals are half-open: an expiration equal to a timestamp is inactive at that timestamp unless a renewal occurs exactly then. After an employee first receives access, every later event for that employee must occur no later than the current expiration. If an event arrives after a gap, that employee becomes permanently invalid and later events cannot restore access. Given the employee definitions and a nondecreasing event stream, return how many employees remain valid and active at the timestamp of the final event. Function countActiveAccess(employeeIds: String[], durations: int[], eventEmployeeIds: String[], eventTimes: int[]) → int Examples Example 1 employeeIds = ["a","b"] durations = [5,2] eventEmployeeIds = ["a","b","a"] eventTimes = [1,3,5] return = 1 At time 5, employee a is active until 10. Employee b expires exactly at 5 and is inactive. Example 2 employeeIds = ["x","y"] durations = [3,10] eventEmployeeIds = ["x","y"] eventTimes = [2,4] return = 2 At the final time 4, the grants expire at 5 and 14. Example 3 employeeIds = ["x"] durations = [4] eventEmployeeIds = ["x","x"] eventTimes = [1,3] return = 1 The second event extends the expiration from 5 to 7. Example 4 employeeIds = ["x"] durations = [2] eventEmployeeIds = ["x","x","x"] eventTimes = [1,4,5] return = 0 The first grant expires at time 3. The event at time 4 follows a gap, so employee x is permanently invalid and the event at time 5 cannot restore access. Constraints 1 <= employeeIds.length = durations.length <= 200000. Employee identifiers are unique non-empty strings. 1 <= durations[i] <= 10^9. 1 <= eventEmployeeIds.length = eventTimes.length <= 200000. Every event employee exists in employeeIds, and eventTimes is nondecreasing. A renewal at the exact current expiration is continuous; a later renewal permanently invalidates that employee. Each expiration fits in a signed 64-bit integer.
Reported by candidates. Source: FastPrep
Pattern and pitfall
The pattern is hash-table plus simulation. Map each employee id to its duration, then keep two things per employee: current expiration and an invalid flag. For each event, if the employee has no expiration yet, set expiration to time + duration. Otherwise, if time > expiration, mark invalid permanently. If time <= expiration, set expiration to time + duration. Note a renewal exactly at expiration is continuous, so use strictly greater for the gap check. At the end, count employees who are not invalid, have an expiration, and whose expiration is strictly greater than the final event time. That last strict comparison is the half-open rule from Example 1. Pitfalls: using >= for the gap check, forgetting that an invalid employee stays invalid, and overflow, so use 64-bit. It's O(n + m) time. StealthCoder is your hedge in the live OA if the invalid-flag logic slips under pressure.
If you see this problem in your OA tomorrow, the play is to recognize the pattern in 30 seconds. StealthCoder buys you that recognition.
You can drill Count Active Employee Access Grants cold, or you can hedge it. StealthCoder runs invisibly during screen share and surfaces a working solution in under 2 seconds. The proctor sees the IDE. They don't see what's behind it. Built by an Amazon engineer who passed his OA cold and still thinks the filter is broken.
Get StealthCoderRelated leaked OAs
You've seen the question.
Make sure you actually pass IBM's OA.
IBM reuses patterns across OAs. Built by an Amazon engineer who passed his OA cold and still thinks the filter is broken. Works on HackerRank, CodeSignal, CoderPad, and Karat.
Count Active Employee Access Grants FAQ
What's the trick in the IBM Count Active Employee Access Grants problem?+
Track expiration and a permanent invalid flag per employee in a hash map. The gap check is strict: a renewal at time equal to expiration is fine, anything later kills the employee forever. Then count only those valid with expiration strictly greater than the final timestamp.
How hard is this one really?+
Easy to medium. There's no fancy data structure, just one pass and a hash map. The difficulty is in the edge rules: half-open intervals, permanent invalidation, and never reviving an employee after a gap. Most failures are off-by-one comparisons.
Why does Example 4 return 0?+
Employee x gets access at time 1 with duration 2, so it expires at 3. The event at time 4 comes after that gap, so x becomes permanently invalid. The event at time 5 can't restore it, so the answer is 0.
Do I need to worry about overflow?+
Yes. Durations go up to 10^9 and times can be large too, so time + duration can exceed a 32-bit int. Use a 64-bit type for expirations. The problem states expirations fit in a signed 64-bit integer.
How do I prepare for this in 48 hours?+
Write the solution once from scratch and hand-trace all four examples, especially Examples 1 and 4. Test the boundary where time equals expiration. Practice hash-map simulation problems where state per key changes over a stream of events. That covers this pattern.