Jump to content

Recommended Posts

Posted

The 'attitude' part is meant as a response to the 'sucking up the SIMS data' complaint from ovek; I've had the same 'just grant access to everything' from you guys as Wonde gives, even though the applications we have linked in to Xporter/whatever Wonde call their software don't use some of those data items. I don't like that approach; although it's by no means just you two that do it. Practically every integration guide I've seen for setting up API access to an MIS for some software either says or implies "Just grant access to everything".

 

Understood. Just for clarity, we don’t load the entire MIS dataset into XoD. While some services might do that, XoD is dynamic in what it retrieves in respect to Personally Identifiable Information from SIMS and that’s based on the net total of data areas have been authorised across the partners you use XoD with.

 

I think you have to think about it from the technical and practical point of view - we have a single integration with the MIS and so to service everything your schools needs from all the different third party applications; to keep this straightforward for the majority of school customers we have a recommended set of permissions that give potential to access the wider scope of data that XoD could be authorised by you to provide to third party applications.

 

This is access too though - it DOES NOT mean that by default we read it all. What we actually do is process the data areas that are within the collective data areas that your school has authorised for all of the third parties you permit to access your data via XoD.

 

Here is the key though - for each third party, we only process those data areas based on.

 

So - yes there is an element of trust you have to have in Groupcall and the XOD management platform, there is no practical way around this (having an integration, and a SIMS permissions account, for each third party is not practical for you or us - we have look at this previously). However, this platform is your tool to control the data, think of it as a parent of the security layer you control in SIMS. It is absolutely not in our interest to take anything more for each partner than needed, and ultimately you control this - even if it makes the third party not work properly or fully, you are still in complete control of that. Want to revoke it completely - done. And when that is the case, data items only concerned with that party are no longer taken. You could reduce the permissions on the SIMS user account down to what you believe is represented by your current authorisations, but if you then authorised a new third party at XoD that introduced a new scope of data that wasn’t permitted by the SIMS user permissions then you’d have to adjust those and resync the relevant data with XoD before that third party was able to work fully.

 

Summary - you can grant access to just the things you want taken out in SIMS if you want to, using SIMS permissions as long as what you reduce it to still covers the areas you have authorised for third parties. Each time you add a third party you may then need to change these permisisons. The 'better' and most flexible way is to have a SIMS account that allow all the data needed by all third parties, and then let XOD divi up the data using the authorisations you have set in XOD, which is absolutely abided by - no partner will get any data you have not authorised them to have. period.

 

It’s worth adding too that the reason the partner is in the mix at all is because your school has purchased their software and signed a data sharing agreement with them, the XoD authorisation and even the SIMS permissions themselves, are technical controls on the implementation of that data sharing agreement and we believe that the authorisation model in XoD is robust in that respect. In fact XoD goes beyond what you can achieve in SIMS permissions because we also fully support inclusion/exclusion of individual data subjects in the feed to a third party service (where such services aren’t marked as Safeguarding products)

 

Perhaps the instructions our team give are a little general - in that we ask for a user account with the permissions to everything that any of our partners might require - so without knowing exactly what partners you have not and might have in the future, and means you don't have to adjust the permissions in the future. Again, you can do if you want, but is easier to allow XOD to manage this as this is what it is built for.

 

If you want a further discussion on this then we’re happy to arrange a call, PM me and we can get something set up.

 

For further reading, check out our GDPR compliance resource centre https://www.groupcall.com/our-gdpr-compliance

  • Thanks 1
Posted
Summary - you can grant access to just the things you want taken out in SIMS if you want to, using SIMS permissions as long as what you reduce it to still covers the areas you have authorised for third parties. Each time you add a third party you may then need to change these permisisons. The 'better' and most flexible way is to have a SIMS account that allow all the data needed by all third parties, and then let XOD divi up the data using the authorisations you have set in XOD

 

So this is really the only point of contention. The method of withholding access in the MIS doesn't necessarily work with Progresso, and I'm of the opinion that convenience to me doesn't justify granting access to Groupcall to see data like salaries and health information that may or may not in the future be passed on by XoD to some 3rd party who's services we buy. I recognize however that a) lots of people probably disagree with me and think being able to just set it up and forget about it is totally worth it and b) the necessity for the guidance you issue to be appropriate to school staff with a wide range of technical capabilities makes this a very difficult balance to draw. I also acknowledge that:

 

 

This is access too though - it DOES NOT mean that by default we read it all.

 

But it doesn't make me feel much better about granting access :p

  • Thanks 1
Posted
So this is really the only point of contention. The method of withholding access in the MIS doesn't necessarily work with Progresso, and I'm of the opinion that convenience to me doesn't justify granting access to Groupcall to see data like salaries and health information that may or may not in the future be passed on by XoD to some 3rd party who's services we buy. I recognize however that a) lots of people probably disagree with me and think being able to just set it up and forget about it is totally worth it and b) the necessity for the guidance you issue to be appropriate to school staff with a wide range of technical capabilities makes this a very difficult balance to draw.

 

We've had a good private chat, and have taken on board that we could perhaps be offering 'advanced' advice/instructions around this to schools where they want to not use Groupcall's security controls, and use the MIS security controls instead/as first line - which is totally acceptable. I'll share this with the rest of out senior leadership team and look to appropriately implement in future installations/onboarding. We stand by our approach given that you (the royal you) have data sharing agreements with every third party just as you do with your MIS provider that they and we are all bound by, and that approach we feel gives the right balance between convenience and access control. However we happily take onboard feedback as we have here to see how we might better cater for these requests on a platform and requirements set that are continually shifting. Very pleased to have explored this with you too @djrscally

  • Thanks 1
Posted
I recognize however that a) lots of people probably disagree with me and think being able to just set it up and forget about it is totally worth it and b) the necessity for the guidance you issue to be appropriate to school staff with a wide range of technical capabilities makes this a very difficult balance to draw. I also acknowledge that:

 

I'm in the group that agree with you. I've seen similar with progresso and Wonde for an EEDI project and providing parent account/finance data when it's not used is just not acceptable". Even if I had 100% trust in the parties, I still would not want that data going out - it's a risk call and my call is to play if safe.

Posted

You're relying on them to keep the data they do take safe.

 

You're either relying on them to not take data they say they're not, or you're relying on the permissions on your database

 

If they do take data they say they weren't going to, they're breeching their GDPR requirements, is that the school's fault at all?

Posted
If they do take data they say they weren't going to, they're breeching their GDPR requirements, is that the school's fault at all?

 

It's not a question of whose fault it is. If you leave your door unlocked and someone walks in and steals all your stuff, they're the ones committing a crime; however it's smarter to lock your door to make it harder for thieves.

Posted
it's easy to unlock a door without a key, but it's not smarter to brick up your house exit every time you leave. Also you can smash a window, or send a robot through the letter box, or a drone down the chimney
Posted
We've had a good private chat, and have taken on board that we could perhaps be offering 'advanced' advice/instructions around this to schools where they want to not use Groupcall's security controls, and use the MIS security controls instead/as first line - which is totally acceptable. I'll share this with the rest of out senior leadership team and look to appropriately implement in future installations/onboarding. We stand by our approach given that you (the royal you) have data sharing agreements with every third party just as you do with your MIS provider that they and we are all bound by, and that approach we feel gives the right balance between convenience and access control. However we happily take onboard feedback as we have here to see how we might better cater for these requests on a platform and requirements set that are continually shifting. Very pleased to have explored this with you too @djrscally

 

 

 

Awesome, thank you.

  • Thanks 1
Posted
it's easy to unlock a door without a key, but it's not smarter to brick up your house exit every time you leave. Also you can smash a window, or send a robot through the letter box, or a drone down the chimney

 

So, leave the door open because thieves could always use another route?

Posted
No, strike a balance of convenience and security to fit the value of the data and the likelihood anyone will try to steal it
  • Thanks 1
  • 1 year later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...