Jump to content

Recommended Posts

Posted

Can anyone give me some advice?

 

I'm fairly certain I know the answer but need to convince the unenlightened.

 

We buy in a spreadsheet attendance tracker -- long story -- and this year the report definition that pulls the data from SIMS uses a student ID field only available if the user has Third Party Reporting added to their permissions. It would normally use the Admission Number of the student which is available without any additional permissions.

 

The tracker is just a spreadsheet with a bit of VB, it's manually updated by copying and pasting in the results of a report run at point of use from SIMS, there is no system to system transfer of data. There is no need for any special ID field, an admission number will work with both the report and spreadsheet.

 

The person who built the tracker does not understand SIMS permissions and likes to be right, the person who built the extract report doesn't seem to understand SIMS permissions either. Both are trying to convince management that it's perfectly fine to give Third Party Reporting as an additional permission. I disagree and have offered to update the report definition for them, for free.

 

From what I understand after more than a decade of playing in SIMS, Third Party Reporting is not a user level permission. It's not listed on the permissions map supplied by Capita and in System Manager it's unclear what specific permissions it grants when assigned. We do use it, but only for system to system transfer of data like our cashless catering and payroll systems where there is some control of what leaves SIMS and within the destination system. Having seen the fields in the reports that feed our linked systems, it's not a level of access suitable for the average user.

 

Am I right in refusing to give Third Party Reporting to a user?

Posted

I would support you here. If there is no need for the report to have any additional fields then I’d want to change it.

From what I recall third party reporting is for exactly that purpose and I believe the intention was it gave access to additional fields like built in table indexes like pupilID etc. for the purposes of linking to other systems.

I wouldn’t want to give this to a lay user.

If in doubt, double check with your support provider.

 

The question is, who is running the report? Is it a member of staff, or the external company/tool/system account.

If it’s the company and you have a contract detailing how they will use / protect your data then you’re probably covered.

 

Without knowing what you’re granting a regular user, you’re right to be precautious.

Can you set up a service account to run the report and schedule it. Or use commandreporter as a work around.

Or just edit the report as you say, as long as the system doesn’t break because of it.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...