We are a user experience design and software development firm
Hire us to design your site, build your application, serve billions of users and solve real problems.

"Only administrators can add users-- no exceptions! ...except Bob in accounting, but that's because he's covering for Sally. But only until February. And this sort of arrangement might happen again. But most of the time, it won't. I mean.. ninety-nine point nine percent of the time. But there might be exceptions... ".
Sound like a requirement you've heard before? How did you handle it?
In an earlier post, I stated that all security models are idiosyncratic, and that the way you go about designing for security must reflect the nuances and -isms of your organization. You might mistake the form used to express the model (HR records, existing databases, or some XML schema) as your security model, but you risk an uphill battle getting your organization (and I mean the people here, not boxes and circles on an org chart) to accept the result.
All of this has less to do with how we design software and everything to do with the way people organize into groups..
Continue reading »
Topics: authorization, modeling, Security
Hire us to design your site, build your application, serve billions of users and solve real problems.