ministryofjustice / analytical-platform

Analytical Platform • This repository is defined and managed in Terraform
https://docs.analytical-platform.service.justice.gov.uk
MIT License
12 stars 4 forks source link

Propose, agree and document a scheme to map users to permissions #1814

Closed julialawrence closed 3 months ago

julialawrence commented 1 year ago

User Story

We need a scheme for mapping users' AAD identities to permissions across data platform, including tools access, catalogue access and role as well as access to the data directly, preferentially stored in AWS but as a stretch, also in Azure or on prem.

Value / Purpose

Before we can implement a proof of concept for permissions management, we need to agree on the process of mapping these permissions to users. Currently, we use a number of approaches, depending on the tool.

Useful Contacts

No response

User Types

Devs, DP/AP users, data management personas

Hypothesis

If we are able to implement a unified solution that is simple for people to use and understand, we will improve the overall security posture of the platform as well as disincentive users/owners/operators from granting overly broad permissions to minimise effort.

Proposal

No response

Additional Information

No response

Definition of Done

ymao2 commented 1 year ago

discussion here https://github.com/ministryofjustice/data-platform/discussions/2154

ymao2 commented 1 year ago

@julialawrence , any plan for this? wanting to share some thoughts and things troubling me regarding the permissions,

was thinking you run a workshop thing?