Join InCommon

University of California, Santa Barbara

InCommon Collaboration Success Program Case Study
(September 2023)

Executive summary

The University of California, Santa Barbara (UCSB), saw the Collaboration Success Program (CSP) as an opportunity to get multiple teams on the same page about how identity and access management (IAM) are managed on its campus. Two primary goals UCSB pursued towards this aim were (1) upgrading Shibboleth and adjusting the SSO pod architecture and (2) implementing and exploring Grouper applications. While more work remains to fulfill UCSB’s vision of a unified, more modernized IAM framework, participating in the CSP gave UCSB clarity around how to eliminate existing redundancies, structure a new enterprise team, and merge data more effectively.

Collaboration Success Program logo

Solution summary

Since 2018, UCSB has worked to restructure and replace separate technology teams (Campus Identity Operations, Student Affairs (SA), and Identity Developers), all dealing directly or indirectly with cloud identity. UCSB’s goal is to create a broader, modernized, more cohesive framework under the main heading of Information Technology Services (ITS). Participating in the CSP gave UCSB clarity around how to eliminate existing redundancies, structure the new ITS team, and merge data.

Trusted Access Platform features supported

Shibboleth/CAS, Grouper

The project

UCSB focused mainly on upgrading its cloud identity services under the broader restructuring of the IAM teams. The CSP project team faced challenging objectives when working with each of the original four tech teams, from separate departments, to identify IAM issues to address. The scope of folding these four separate entities into one system has required a slow and steady approach.

Graphic displaying University of California Santa Barbara before and after.

UCSB used the CSP program to explore its current lifecycle principles. Match/merge challenges were examined to reconcile multiple sources of record sources. The team sought to define identifiers in identity. Human resources, for instance, used DOB and employeeID, while SA used PermNumber and applicantID. The question of folding the large student affairs identity into the identity and access management mix was a main focus. Student affairs, alone, manages, 26 business departments, more than 40 developers, and about 200 applications and systems. 

The challenge

During the CSP, as UCSB was actively merging different IAM teams, the new united team began to question existing lifecycle principles while negotiating multiple systems of record. For years, these four IT teams were operating independently of one another and creating separate solutions. Each of the four original teams brought their own challenges to the CSP:

Goals

UCSB hoped to create a broader, modernized, more cohesive framework under the main heading of Information Technology Services (ITS). Joining the CSP gave UCSB clarity around how to eliminate existing redundancies, structure the new ITS team, and merge data.

  1. Upgrade Shibboleth and adjust the SSO pod architecture.
  2. Implement and explore Grouper applications.
  3. Question our assumptions.
  4. Coalesce into a single team.

The result

Grouper Progress:

Shibboleth Upgrade Progress: UCSB is working to upgrade Shibboleth from 3.4.6 to 4.3.1. In the development environment, 4.3.1 is running. There is work, however, to be done.

Plans and remaining questions for the new version of Shibboleth: 

Lessons learned

The CSP, according to UCSB’s IAM team, allowed the group to get “in sync.” Conversations around the existing identity systems and practices were initiated. In addition, UCSB used the CSP as an opportunity to review the existing possibilities/solutions using the InCommon tools and vendor resources. 

For future CSP participants, UCSB offers the following suggestions:

About the University of California, Santa Barbara

UCSB is an R1 public institution, part of the University of California (UC) system, with enrollment around 24,000 undergraduate students and 3,000 graduate students.

CSP Project Team: 

Jim Woods, Director of Cloud and Identity Services
Farah Tahmasbi, IAM Developer
Dean Welch, Technical Project Manager
Noah Baker, Senior Collaboration Engineer
Scott Gilbert, System Administrator
LouisTourtellotte, IAM Operations (50 percent)
James Kinneavy, Enterprise Architect
Yaheya Quazi, Enterprise Architect


Back to Collaboration Success Program Alumni Case Studies