ministryofjustice / modernisation-platform

A place for the core work of the Modernisation Platform • This repository is defined and managed in Terraform
https://user-guide.modernisation-platform.service.justice.gov.uk
MIT License
683 stars 291 forks source link

Ability for HMPPS digital teams to access Nomis application #2396

Closed nimphal closed 1 year ago

nimphal commented 2 years ago

User Story

User Type(s)

Value

As part of the Nomis migration to MP, this functionality needs to be retained and modified to work with the MP way of managing access.

Questions / Assumptions / Hypothesis

A lot of these users are not developers who will need to register for GH accounts.

This will likely be a new IAM role attached to a new GH team. Potentially two teams actually, one who has access only to dev and test and one who has access to production. The latter may not be needed.

Definition of done

Reference

How to write good user stories

dms1981 commented 1 year ago

@Nimphal - Can you help us to understand this request better please? I'm not sure what the story is here (As an X, I need Y, so I can Z).

nimphal commented 1 year ago

Let's try

As an HMPPS service team member I need to be able to access the nomis remote desktop instance so I can do data exploration.

Practically, currently there's a studio operations team on GH which has extended permissions on MP when they authenticate. We don't want every dev form HMPPS to have the same, so we need a role/user setup that allows people to use SSM but doesn't give them full admin permissions.

github-actions[bot] commented 1 year ago

This issue is stale because it has been open 90 days with no activity.

SimonPPledger commented 1 year ago

Requestor has left and digital teams must have access