A major research university needed to automate semester-based student access transitions, secure sensitive research data, enable cross-institutional faculty collaboration, and manage complex alumni access while maintaining FERPA compliance.
The Problem: Manual student provisioning and de-provisioning each semester overwhelmed IT staff. No unified governance for research data access across departments, and alumni accounts were managed inconsistently.
50,000+ students transitioning each semester required manual access updates across 100+ systems. Process took 3-4 weeks, delaying start of academic term and overwhelming IT helpdesk.
Sensitive research data across departments had inconsistent access controls. No visibility into who had access to what research projects, risking data breaches and IP leakage.
Faculty collaborating with other institutions required weeks to get guest access. No federated identity integration, forcing manual account creation for each external researcher.
Alumni needed limited access to certain systems (library, career services, email), but no consistent policy. Many retained full student access indefinitely, creating security risks.
Implementation Timeline: 10 weeks from planning to production, including integration with Student Information System (SIS), research systems, and InCommon federated identity.
SIS integration triggers automatic access changes based on enrollment status: new students receive access within 24 hours, graduated students transition to alumni access, and course enrollments grant automatic LMS access.
Policies enforce research data classification (public, internal, restricted, highly restricted) with automatic access controls based on IRB approval, research team membership, and data sensitivity levels.
InCommon federation allows external researchers from 300+ partner institutions to access resources using their home institution credentials. Guest workflows handle non-federated external collaborators.
Alumni automatically receive curated access to library resources, career services, and alumni email while losing access to academic systems. Lifecycle rules ensure proper transition upon graduation.
Prioritizing deep Banner SIS integration ensured enrollment data automatically drove access decisions, eliminating manual processes.
Involving principal investigators in defining research data access policies ensured rules matched real-world lab workflows.
Leveraging InCommon federation from the start enabled seamless external collaboration without manual account creation.
Testing with Computer Science department first refined workflows before campus-wide rollout, building confidence and buy-in.