Chattanooga.Digital needs a process for
evaluating and selecting software. We also need identity and
access management software, which is a key element of our core
infrastructure. More fundamentally, we need to decide
how/whether to provide digital identity services.
Our general, short-term requirements,
that I'm aware of, are:
- Must have single sign-on to all/most
apps, with options/practices for dealing with apps that don't
support relevant protocols.
- Must be able to remove or suspend
access to some or all apps without deleting a user/account.
- Should have multi-level or
multi-tenant functionality so that a user can control/own
their portion of IAM; organization members, in particular,
should have full control over the IAM.
- Should be portable; the more so, the
better.
Some persons using members' apps —
employees or family, for examples — may not be members of the
coop. How and whether they might use our IAM services is to be
determined. They may have accounts on one or more apps or one or
more members but not SSO. Members may need to manage these
accounts separately or run their own IAM services (on C.D or
otherwise).
An underlying issue is how/whether C.D provides digital identity
services, particularly decentralized identifiers, self-sovereign
identities, and verifiable credentials. I personally think this is
critical but a lot of it is (a) evolving and (b) rather
complicated so probably isn't practical in the short-term.
My thought about the process for evaluating software for core (to
run the coop) or standard (for members) purposes is that it
should:
- Require an anchor user/sponsor.
- Be carried out by an application/purpose-specific task force
or a software evaluation working group; regardless, some
member(s) need to own the process.
- Start with analyzing the requirements, including scope of
application and use cases.
- Methodically identify and evaluate options based on consistent
criteria & metrics. I'm not sure what these should be,
though... functionality, maturity, etc., but more specific.
- Generate a recommendation and high-level implementation &
management plan for staff and board review and approval
(depending on specifics of our charter, which is in the works).
- Include acceptance testing with members, particularly by the
sponsor(s).
- Result in a deployable, replicable, working version (ideally a
Docker image) that can be migrated to production upon
acceptance.
What do y'all think? Let us know!