Jump to content

Recommended Posts

Posted
We've been told that we that we will be using mathematic mastery software next year. This requires an sims connector from assembly.education. On reading the install instructions it requires a user that has more access rights that some admins. ie personnel officer , SLT,admin assistant. I am deeply concerned that this app has access , on read at the moment , to all data. I am not sure why that require all this access . Has any body else had to set this up ?
Posted

Hi Sarge (I'm director of Assembly btw),

 

It's a fair question. We should probably document why we ask for this better on our support site.

 

It's important to start by explaining that the data that flows to the Assembly platform from your MIS is controlled by you within the Assembly platform. By connecting your MIS to Assembly platform with a MIS login (the step you're currently undertaking), you don't actually send any sensitive data to us; you just set the parameters by which data could be transferred at a later date. We ask for this range of permissions because it covers the wide range of use cases that we expect to see - and we don't want you to have to keep adjusting or adding SIMS permissions whenever you use a new app.

 

BUT, the key thing is that for data to flow, an app needs to make a data access request within the Assembly platform, which a school then authorises. This support guide shows the Data Access Request screen for the Mathematics Matery app. The Data Access Request clearly shows the scopes of data that the app will pull. No sensitive data can flow until you grant your first Data Access Request, and we can only extract those scopes you've authorised. So you can be confident that no sensitive data can flow to Assembly without you first authorising a data access request, regardless of the SIMS permissions you set. We also give you the ability to see what scopes have been authorised for which apps in our admin UI.

 

Another way of thinking of it is that there are two "taps" between the school and an app: one within the MIS (i.e. via the user's permissions) and one within the Assembly platform (via the Data Access Request). Both need to be open for data to flow. But we think it's much easier to control, limit and explain what data is flowing through the Assembly tap. So we ask for you to open the MIS tap, safe in the knowledge that the Assembly tap gives you everything you need to control data flows in a secure and reliable way.

 

I hope that explains it. Do say if you have any further questions - or feel free to email [email protected]ion.

  • Thanks 1
Posted
Also, there's one other thing I should have mentioned: we tried a range of permission options before we arrived at the current recommended set for SIMS. What we found was that narrower permissions led to some unexpected data blockages within the SIMS API. I.E. certain scopes of data weren't being extracted as expected on some versions of SIMS. So we've settled on the current recommended set because they've worked in all cases so far. I hope that helps to explain our approach!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...