Banjo Posted October 12, 2017 Posted October 12, 2017 Can't poke Tableau public at SQL - only Excel \ CSVs etc. And would you want too? Seems like a nice way to expose sensitive data I know North Yorks has done some amazing things as has Ark I'm sure you can buy it and run it locally on your own network. I've used it at FFT conferences, dragging and dropping to make some fancy chart and graphs. Once you get the hang of it then it's very powerful. I think you can link it to SQL, see below. https://www.tableau.com/learn/tutorials/on-demand/connect-databases - Watch this video to learn how to connect Tableau Desktop to relational databases. This training covers connecting to multiple tables via Tableau’s interface or using custom SQL as well as how to share these connections with others.
PhilNeal Posted October 12, 2017 Posted October 12, 2017 I do worry about the privacy aspects of the approach being suggested in this thread. To completely by-pass the permissions system of your MIS seems to be exposing schools to massive risk of breaking GDPR requirements.
vikpaw Posted October 12, 2017 Posted October 12, 2017 I do worry about the privacy aspects of the approach being suggested in this thread. To completely by-pass the permissions system of your MIS seems to be exposing schools to massive risk of breaking GDPR requirements. The person doing it will have to be quite technically minded, so probably the 'IT Geek', and they can't be the DPO, so the DPO will be there to make sure they are doing everything safely. So, how can it possibly go wrong?
PhilNeal Posted October 12, 2017 Posted October 12, 2017 Indeed! Complete access to highly sensitive information.
matt40k Posted October 12, 2017 Posted October 12, 2017 Free version is only public stuff - ie you publicly publish the data. The paid for version, yes, can connect to alot of data sources including SQL Server, but have you seen the prices?As Phil points out - like any third party tool that "links" into your MIS, make sure you get permission before you start playing and you all understand the risks. @PhilNeal would love to see Capita statement on how it's going to support GDPR, especially the 'the right to be forgotten’
bigdannyb79 Posted October 12, 2017 Posted October 12, 2017 (edited) Indeed! Complete access to highly sensitive information. Disagree with your generalisation - a lot of what people would be presenting wouldn't be sensitive and you wouldnt be giving complete access. Many of what would be wanted would be summative analysis of numbers so not personal - much in the same way schools say they have a basics measure of 56% isnt a violation of GDPR. its quite easy to know if your exposing personal info - its not like you would publish some assessment analysis and people drill to the students behind it unless you specifically configured it. Its just a reporting tool - you wouldnt stick names and addresses on your website so you wouldnt publish then in your reporting tool either ? Edited October 12, 2017 by bigdannyb79
vikpaw Posted October 12, 2017 Posted October 12, 2017 I think the point was that the person doing the setup, if they access the raw SQL and / or are making DB connections could expose data they should not have access to, even before it's analysed. For example, salaries, personal contact details etc. If you don't go through the software interface you're given, then it's a pretty big breach ...
matt40k Posted October 12, 2017 Posted October 12, 2017 Disagree with your generalisation - a lot of what people would be presenting wouldn't be sensitive and you wouldnt be giving complete access. Many of what would be wanted would be summative analysis of numbers so not personal - much in the same way schools say they have a basics measure of 56% isnt a violation of GDPR. its quite easy to know if your exposing personal info - its not like you would publish some assessment analysis and people drill to the students behind it unless you specifically configured it. Its just a reporting tool - you wouldnt stick names and addresses on your website so you wouldnt publish then in your reporting tool either ? If you can't drill into analysis - it's worthless. For example, 56% of students are failing English. Pointless unless you can action it, ie who are the 56%. It's also not quite as easy as you think - you need a ID to define a person and you need to ensure you can't filter down to just 1 - otherwise people could find out who it was - thus those fields become "sensitive".
bigdannyb79 Posted October 12, 2017 Posted October 12, 2017 I think the point was that the person doing the setup, if they access the raw SQL and / or are making DB connections could expose data they should not have access to, even before it's analysed. For example, salaries, personal contact details etc. If you don't go through the software interface you're given, then it's a pretty big breach ... No different to the MIS lead in the school having an admin account to the MIS then - in a school the person analyzing the data is likely to be one and same so there isnt any increase in risk ? I think they should be exploring how they could interface with a leading BI product like tableau rather than scaremongering its use on the basis of GDPR . . .
vikpaw Posted October 12, 2017 Posted October 12, 2017 (edited) Well you might have logs that show use of the admin account or secured data access by anyone for that matter. If done the 'proper' way. MIS leads shouldn't just have an admin account without controls in place on how they are used. Many admin accounts don't even have access to all the data, only the ability to put people into groups that can have access. System manager should allow you to put staff into the Personnel group, not give you access to salaries. The point is there is an interface and a process for this, hopefully with auditing and logs. Forget the analysing issue. You are right there should be better ways to interface and analyse the data. It should be controlled and enforce privacy / DP rules. Ignoring best practice and exploring the raw data isn't a good idea. The ability to select * on any table although convenient isn't something to take lightly. It's wrong and dangerous under current pre-GDPR rules. I think the point holds value. As professionals we shouldn't be advocating this sort of workaround, especially when someone without your skills and experience may read this and think ooh, I'll give this a go because my head wants the data quick. Each system is different and how well they interface / allow analysis is different. We can appreciate how we could supply data to various systems but actually doing it safely is another matter. I'd be interested to know how Progresso works with this? Also, on a side note, do the tools like Discover start to provide the sort of analysis required? Should they be developed to give more options? Arbor MIS purported to do lots of analysis automatically out of the box but we don't hear much about them these days. Engage has an Analytics engine but the tables exposed to it are limited. It can produce good data on the pipeline of students through admission to leaving, and student population analysis which is useful. Edited October 12, 2017 by vikpaw
bigdannyb79 Posted October 13, 2017 Posted October 13, 2017 Yeah I was just reacting to the blanket 'this is bad, think of GDPR' - when as you say GDPR doesn't really change any of the considerations here over and above what you should be thinking about under current DP law. And appropriate use of a reporting solution would be no less contentious than appropriate use of the MIS product itself. When your customers are talking about how they are trying to plug gaps in the reporting output of your product I'd be taking a different approach. Progresso does, in theory, handle this aspect well and the reporting model inherits the permissions of the account used to log into the MIS - there's the occasional blip and some glaring holes popped up from time to time but the principles are there in that the access given to roles in the MIS are mirrored in the reporting side. They also dabbled with proving a direct plug into pyramid analytics - however as with Progresso generally the idea was right but the implementation was way off. It had limited datasets available to it and ended up being close to useless as you always ended up needing something you could find. Prob could have been made to work if feedback was taken on. I see arbor were one of the companies selected to be able to provide national analysis alongside ASP so they are definitely still interested in the market just don't seem to be getting growth. 1
Ditto Posted October 14, 2017 Posted October 14, 2017 Arbor MIS purported to do lots of analysis automatically out of the box but we don't hear much about them these days. Perhaps that's a good thing, if their product just quietly works!? We did have a look at them last term and felt they were well worth a second look next year. Very much looking to see the next round of MIS market share to see if they're picking up more schools.
Geoff Posted October 15, 2017 Posted October 15, 2017 (edited) I do worry about the privacy aspects of the approach being suggested in this thread. To completely by-pass the permissions system of your MIS seems to be exposing schools to massive risk of breaking GDPR requirements. As I said, if you are doing full ETL with analysis services you can create roles that mirror the MIS roles and apply them to your cube dimensions. Work on a principle of least privilege and it would be fine. https://docs.microsoft.com/en-us/sql/analysis-services/multidimensional-models/grant-custom-access-to-dimension-data-analysis-services Edited October 15, 2017 by Geoff
pcstru Posted October 16, 2017 Posted October 16, 2017 Yeah I was just reacting to the blanket 'this is bad, think of GDPR' - when as you say GDPR doesn't really change any of the considerations here over and above what you should be thinking about under current DP law. And appropriate use of a reporting solution would be no less contentious than appropriate use of the MIS product itself. In terms of liability arising out of any breach, you are likely to face questions of competency. You could look at use of an MIS as essentially managing the risk by offloading it to the MIS supplier. As experts in the field of both developing and the use of a vertical market MIS, it is likely to be seen as reasonable that they should have such competency. A tech in a school, a couple of developers in a MAT - with the best will in the world - probably not so much. As with all 'risk' - it's only a problem if "stuff" happens to you. Mostly "stuff" happens to other people so folks don't worry. It's almost ... Bayesian. The real problem for everyone is very simple. Technology is a bit rubbish - the miracle isn't that it comes with built in machine learning driven BI cube sharding & partitioned to deliver Value insight straight to the executive dashboard, the miracle is that any of it works at all. If you expect an MIS to allow you to manage the information that is needed by a school in a vaguely reasonable fashion (if you squint a little - it helps a lot), your expectations might be met. If you expect an MIS to put on a plate, everything you need to meet the expectations of a typical large secondary schools SLT, right now, that is probably unrealistic. A bit of work is needed to make the reality of an MIS and the needs of the individual customer meet in the middle. Usually, quite a bit of work.
vikpaw Posted October 17, 2017 Posted October 17, 2017 A bit of work is needed to make the reality of an MIS and the needs of the individual customer meet in the middle. Usually' date=' quite a bit of work.[/quote'] Thankfully, cos it pays our rents! [emoji850]🤣
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now