Identity and Access Management Services
Chattanooga.Digital needs a process for evaluating and selecting software. We also need identity and access management software, which is a key element of our core infrastructure. More fundamentally, we need to decide how/whether to provide digital identity services. Our general, short-term requirements, that I'm aware of, are: 1. Must have single sign-on to all/most apps, with options/practices for dealing with apps that don't support relevant protocols. 2. Must be able to remove or suspend access to some or all apps without deleting a user/account. 3. Should have multi-level or multi-tenant functionality so that a user can control/own their portion of IAM; organization members, in particular, should have full control over the IAM. 4. Should be portable; the more so, the better. Some persons using members' apps — employees or family, for examples — may not be members of the coop. How and whether they might use our IAM services is to be determined. They may have accounts on one or more apps or one or more members but not SSO. Members may need to manage these accounts separately or run their own IAM services (on C.D or otherwise). An underlying issue is how/whether C.D provides digital identity services, particularly decentralized identifiers, self-sovereign identities, and verifiable credentials. I personally think this is critical but a lot of it is (a) evolving and (b) rather complicated so probably isn't practical in the short-term. My thought about the process for evaluating software for core (to run the coop) or standard (for members) purposes is that it should: 1. Require an anchor user/sponsor. 2. Be carried out by an application/purpose-specific task force or a software evaluation working group; regardless, some member(s) need to own the process. 3. Start with analyzing the requirements, including scope of application and use cases. 4. Methodically identify and evaluate options based on consistent criteria & metrics. I'm not sure what these should be, though... functionality, maturity, etc., but more specific. 5. Generate a recommendation and high-level implementation & management plan for staff and board review and approval (depending on specifics of our charter, which is in the works). 6. Include acceptance testing with members, particularly by the sponsor(s). 7. Result in a deployable, replicable, working version (ideally a Docker image) that can be migrated to production upon acceptance. What do y'all think? Let us know! -- Greg Laudeman, Ed.D., Instigator Chattanooga.Digital <https://chattanooga.digital/> greg@chattanooga.digital <mailto:greg.laudeman@chattanooga.digital> 706-271-5521
participants (1)
-
Greg Laudeman