Error!

Spaces has been migrated to the cloud. Please go to https://ucla-confluence.atlassian.net to update your space/s.

IT Services has migrated the content of spaces.ais.ucla.edu to Atlassian Confluence Cloud. Please visit https://ucla-confluence.atlassian.net to update your space/s. Spaces.ais.ucla.edu is now in read-only mode through July 31st, 2024
Child pages
  • UC San Diego HR Payroll and IAM

Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

UCSD Identity Management

Identities

New identities are created primarily through three core mainframe applications: payroll(PPS), financial(IFIS), and student(ISIS) systems.  This data may be entered via terminal emulators connected directly to the mainframe or web front ends using screen scraping, web services, etc.  Some of this data is fed via file extracts into our email and Active Directory provisioning systems.  All of these identities are then synchronized and merged nightly into a relational DB schema we call affiliates_db.  This nightly load job also attempts to join the identities with the email and Active Directory accounts which were created separately.  For certain affiliate types which are not entered into the three core systems, data can be entered from a web front end and saved directly into affiliates_db.

...

Several campus wide roles have been identified which require common access provisioning across many applications.  In order to improve efficiency and speed of provisioning we implemented a role based access model to store permissions which applications can consume for their own internal purposes.  These enterprise roles are not in wide use yet as we have many legacy applications which would need to be rewritten to support them.

Diagram

Image Added