We would love to talk to you. Give us a call, visit us or just send an email.

Support

Whether you're looking for some
assistance or further information
regarding your solution, we're here
to help. Yes, take me there!

 

Sweden

Headquarters, Stockholm

Formpipe Software AB
Sveavägen 168, Stockholm
Box 231 31, 104 35 Stockholm
SE – Sverige
Tel: +46 8 555 290 60
Email

Linköping

Gasverksgränd 2, 582 22 Linköping
Tel: +46 8 500 072 25
Email

Västerås

Metallverksgatan 6, 721 30 Västerås

Örebro

Engelbrektsgatan 6, 702 12 Örebro

Denmark

Lautrupvang 1
2750 Ballerup
Tel: +45 3325 6555
Email

More contant info for the Danish office?

Germany

Formpipe Lasernet GmbH
THE SQUAIRE 12
Am Flughafen
60549 Frankfurt am Main
Email

 

UK, Cambridge

First Floor, Block A, Harston Mill,
Cambridge – CB22 7GG
Tel: +44 1223 872747
Email

 

UK, Nottingham

Unit 1, Isaac Newton Centre 
Nottingham Science Park
Nottingham – NG7 2RH
Tel: +44 115 924 8475
Email

 

USA

Formpipe, inc.
1200 US Highway 22 E Suite 2000
Bridgewater, NJ 08807
Tel : +1 908 200 7937
Email

Follow us
Linkedin
20 July 2020 Blog Long-Term Archive Application Digital Preservation Information Security Privacy & Personal Data

Are your employees seeing too much?

Within the Formpipe Preservation team, we talk a lot, probably every day, about access structure or a permission matrix within our electronic systems.

For our delivery teams, it is part of their day to day lives, so much so that we made a video on it to showcase what our product can do. To watch the video, please click here. Long-Term Archive can set permissions on users, groups and archives then content types, search criteria and individual item level so we can meet any organisation’s permissions.

But…

A regular mistake we see is that the permission structure mirrors that of the source system providing the content. This is often a legacy of thinking of an archive as an ‘add on’ to an EDMS or other business-critical system. With an e-archive or preservation platform, I would always encourage prospects and clients to consider that the majority of the information is not for day to day consumption and therefore a more limited set of permissions are required.

I would encourage you to group permissions into the following 3 sets;

1). Who can post into the archive

This will most likely be the largest set of users. You will encourage users to send data or documents that need preserving out of the everyday system and post into the archive. Where you are interfacing something like an ERP or CRM then you can adopt the permission structure of the source system, where the ingestion is triggered manually you can apply workflows to manage that process. Allow the ingestion metadata schema to care for the content structure, location, file type and permissions. The user posting simply needs to initiate the move to the archive

2). Who can search and retrieve

Depending on the way you want to work this is either;

  • an individual who can search and retrieve content, OR
  • a user who can place a request for an archivist to search and retrieve.

We would strongly encourage this set of users to be limited, this is historic data and has been classed as not required within a business as a usual system. Where documents are stored, allowing any user the ability to see a previous version of a document could be damaging. Those few that you do grant permissions to should only be able to access archives they need to see following an existing corporate organisational structure detailing areas of responsibility. Where required you can set an archival search and retrieval function, meaning you can still hide the content from users whilst allowing them the ability to retrieve

3). Administration

Split this group into two areas as they will have different access requirements and you should where possible avoid one single user having both archive and system admin rights.

Archive Admin

Archive admin will need to be those who care about true preservation needs. They will manage retention policy, archive structure and the general use of the system. Where an archive team manages requests or data management workflows they will responsible for the execution of these and be looking for the ability to report accordingly. They will set the metadata schema and archive rules that create the structure and permissions. These people should also be the ones who host any audit activity with an understanding of the logs and audit trails required. Such user rights will be governed by their qualifications, experience and area of responsibility.

IT admin

Your system administrators will sit separate from the archive function and will be more focused on system performance, user access and storage locations. They have a limited requirement to actually access archives or the content within but will oversee the system overall and most likely the vendor contract if applicable.

Please do not struggle, get in touch today and allow us to help with creating a permission matrix that works for your organisation, meets your compliance needs and creates an efficient preservation platform.