Tech Eval ODS Security Overview 2019-07-23 Meeting notes

Date

Attendees

Goals

  • Get a more in depth review of the Ed-Fi ODS Security Model

Discussion items

Play recording

TimeItemWhoNotes
Ed-Fi ODS Overview
  • Accessing Data:
    • Direct DB access, no mechanism for accessing data this way from the ODS. One project is on the works from YesPrep that will be shared via the Exchange.
    • Analytics Visualization Data mart tier: Security is enforced via access to the data mart.
    • API layer provides a security layer.

 Questions
  1. Ed-Fi ODS security is application focused. 
  2. Data Out for the ODS API SIG is looking for Use Cases to see how the API should be enhanced to get data out. Might be worth reviewing their work to see what use cases have been captured and limitations identified.
  3. User level authentication has been considered, but there hasn't been a clear use case to run through.  The direction so far has been to pull data out to a separate data mart and let that application/data source handle user level security.
  4. Using GraphQL might be something that we should look into to be able to use java script libraries.
  5. Current ODS functionality and beyond:
    1. The work group could propose that the ODS provides a downstream data mart that unlocks reporting and visualization.
    2. The way the ODS exists now is not necessarily how it should continue to grow. The analysis and recommendations from this work can also influence the direction of the ODS and the Analytics Middle Tier.

Next Steps
  1. Share presentation and recording with group so we can start gathering ideas for how best to handle user level security.
  2. Review the ODS Data Out special interest group use case analysis and see if there are cases that we can learn from or contribute based on the needs or our work group.

Action items

  •