110 likes | 199 Views
Policy Discussion Information Management of Organization Data. Common Solutions Group Meeting Winter 2008 @ Virginia Tech Bruce Vincent, Stanford University. Hypotheses. Identity Management of people and affiliations is fairly well understood and being done in practice (we claim)
E N D
Policy DiscussionInformation Management of Organization Data Common Solutions Group Meeting Winter 2008 @ Virginia Tech Bruce Vincent, Stanford University
Hypotheses • Identity Management of people and affiliations is fairly well understood and being done in practice (we claim) • Access management drives identity management broadly • Growing awareness that organizational data maintained in parallel is also important but is far less understood or maintained uniformly. Policy Discussion: Organization Data
Goals for Policy Discussion • Discuss ways to use and manage organization data • Dialogue about the need for governance of this data • Raise awareness of organization data as institutional identity information Policy Discussion: Organization Data
Characteristics of Organization Data • Representations of institutional orgs and data about them e.g. full names, abbreviations, codes, domain names • Hierarchical relationships with other organizations • Ownership of representations about orgs • Org may be financial, academic or based on other institutional role Policy Discussion: Organization Data
Sources of Organization Information • Finance/budget • HR • Academic Units/Registrar • University "yellow pages" (aka department directory) • DNS (ie, subdomains) • learning management system • Student Affairs • Identity/Role Management System • Etc. Policy Discussion: Organization Data
Example of Leveraging Org Data - Thus Spake R.L. “Bob” • Sponsorship of account for external user by a staff member • “In a sponsored account system, usually, someone acts as a sponsor. The system records that person as a sponsor, and maybe a budget number. In almost all cases the sponsored user is performing some org function like being a contractor or researcher. But what we record is ‘sponsor is user joe’. When notifications are done they're sent to joe. When joe leaves we wonder if the sponsorship should go away, or if someone should take it over, if so who? So there's expensive manual thrashing to deal with this. If the sponsorship were recorded as being by the organization, there would be continuity, the chance for linkage to org contact people, better reporting, etc.” Policy Discussion: Organization Data
Examples of Leveraging Org Data • Access control for online resources on the basis of a user’s organization or role in an org (or sub-organization) • Clinical research data • Digital library content curation based on being part of a specific department or multiple departments • Supporting distributed administration of Printed Directory data Policy Discussion: Organization Data
Open Questions to Discuss • Does your institution have central organization information management (i.e., an organization registry)? • What part of the institution owns (or would own) an org registry? • What is (or would be) the governance of an org registry? Policy Discussion: Organization Data
Open Questions to Discuss • Does (or would) your registry include organization entries from finance/budget? HR? Academic? Students? Alumni? External organizations? • Does (or would) your registry include a representation of organizational hierarchy? If so, does (would) it represent different hierarchies for finance, academic, etc? Policy Discussion: Organization Data
Open Questions to Discuss • If your organization has a large ERP deployment, is its organization management driven from an external source, and/or does it feed other systems? • Does your institution provide policy guidance for processes and applications in understanding/representing when action is taken "on behalf" of an organization and when it is taken as an individual? Policy Discussion: Organization Data
Summary • Organization data is of broad value to campus • Management of Org representations is needed • Use as access control means governance, education and policy is needed • Lifecycle and point-in-time Org views required Policy Discussion: Organization Data