Meeting info
Zoom: https://zoom.us/j/488543197
Attendees
Maura Byrne
Jana Freytag
jackie.gottlieb@duke.edu (Deactivated)
Uschi Klute
Philip Robinson
Annika Schröer
Stefanie Sußmann
Todd Wallwork
Goals
Discussion items
Time | Item | Who | Notes |
---|
| Use cases for teams | Group | Use cases for teams - Permission related:
- Current acq use-case, have only members of a specific team edit a certain resource
- Worflow related:
- Assign a but to a team (if someone is on vacation/sick leave/…)
- Contact information related, this would need to have some kind of team app frontend:
- Who is working at a specific location?
- Who is responsible for eResources, acquisitions, etc.
One user needs to be in several teams -> |
| What would be useful for descriptive error messages | | Need more specifics to answer this questions. What kind of error messages? → Carry over to one of next meetings |
| What are templates and how would they be used? | | Different kinds of “templates” relevant for user-related tasks - assigning permissions (and other
- provide limited views to records / limited actions:
- Use case: Student workers helping with checkout should not be able to see patron address data
- → Annika Schröer: It already is possible in Folio to hide information in the frontend. The data is being sent to the browser (and can be seen quite easily in the network traffic), but the FOLIO fields can be blanked out. So this is no secure solution at all but might be sufficient for some small use-cases.
It is also possible to have the apps define distinct APIs for confidential fields, if there are not too many combinations of what people should be able to see and not see. Permissions are possible at API level.
|
| Ideas to discuss around permissions | | Ideas to discuss around permissions - each permission set contains the atomic permissions necessary to do the task
- permission sets can easiliy be assigned to a userjust by knowing the work he will have to do, without detailed knowledge about atomic (technical…) FOLIO permissions
- A user can get by being member of a specific team
- Permissions for teams plus extra permissions for single persons
- Template with certain permissions for certain groups, vs. permissions for teams
- Are permissions additive?
- → Permissions should double, that would not be very clean, but an easy way to work with changing permissions
|