Re: [scim] [EXTERNAL] Re: Contributors needed for HR schema

Danny Zollner <Danny.Zollner@microsoft.com> Fri, 16 September 2022 04:54 UTC

Return-Path: <Danny.Zollner@microsoft.com>
X-Original-To: scim@ietfa.amsl.com
Delivered-To: scim@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0A273C14CEFC for <scim@ietfa.amsl.com>; Thu, 15 Sep 2022 21:54:54 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.572
X-Spam-Level:
X-Spam-Status: No, score=-2.572 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.571, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, T_FILL_THIS_FORM_SHORT=0.01, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mJSo2XCBJ-IR for <scim@ietfa.amsl.com>; Thu, 15 Sep 2022 21:54:49 -0700 (PDT)
Received: from NAM06-DM3-obe.outbound.protection.outlook.com (mail-eopbgr640102.outbound.protection.outlook.com [40.107.64.102]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2B7CBC14F72A for <scim@ietf.org>; Thu, 15 Sep 2022 21:54:49 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=HE1CVVwLuBXn+6N6aW8iWnHf8QqLpn97jank8a6/95Js3F8S3ClSIggvhTcKlDQDnsGE6BvWTP7c7f1tBmTlo0lYgTh0ztCMzenp4FfI5oR4BOuU63Cg9EX2jiuC5+g+2YScYn7pItSJW0GTVJY2zY2mCnYmF3v4crcNTwxG8TY1xFWH4ja0dRIm9kCFu/zNBrRDwNWu3lQmiHpF02jKPUqeItulePpWXydRAjILgzFa8H/JimrkH69cD8vwxeKEjhwuMiJ9EmjKGkukFWpBtstw6UfLa3wFymOQTbiBrPu98jsAv5oR2aZ9LtBLR0HnQ7YygfocDZJ74BeEj2Q1aQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=pB5a4wieljLxhfixvfBnuzpVEpvUW14waaafs+tJSwM=; b=mRxpw8V+zpfBTaXbZRktXCaHI7d+lI4Bkeca2wjcQjBQhs+nlOz4PegzdCyf+RQ/O4GC/B7VZrATtwN0vi1AogJ0IQRp/QzCGUYF/PB9nGFPdY8PbZCWkGcp4BeSdeMt2F1sNrBwGUXmF+AO236APBopOCtAVI6FNuW3ghG/2uxQoyXK9NmfPbSgXnouMoin9b55ZcoxpWw+rYDBcM5Ke1w4ONZQ7q/8hOAsnE2wrkXscr19GHcdR9+VxryXjeRtdXPzbvbuoop5tHsVg7Tf9/TtQlIKx1VazmVZ33uKHgsDz6CU8uNjOS1HhKG2RkhZmqvnMHK0kfqIn66WAuA4lA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=microsoft.com; dmarc=pass action=none header.from=microsoft.com; dkim=pass header.d=microsoft.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=pB5a4wieljLxhfixvfBnuzpVEpvUW14waaafs+tJSwM=; b=NT/FIg7lp5p0mJ0QTuz8iU/tyd+3FySxo/8ryophk4In0U4bzVdNvObALQ5X9UZlPJHuf9UgPK7cRHSZyabOfHMj6NvVzRu+KQt0OlXjUmDuSGxyNlJezUQjt8dfc8VW3q2gVDPy1TVKLI6NcJlj52CPziW7C53ZibkvA1B19Pw=
Received: from MN2PR00MB0720.namprd00.prod.outlook.com (2603:10b6:208:1d8::15) by SJ0PR00MB1224.namprd00.prod.outlook.com (2603:10b6:a03:371::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5678.0; Fri, 16 Sep 2022 04:54:43 +0000
Received: from MN2PR00MB0720.namprd00.prod.outlook.com ([fe80::f1ad:f8da:b90b:68dc]) by MN2PR00MB0720.namprd00.prod.outlook.com ([fe80::f1ad:f8da:b90b:68dc%8]) with mapi id 15.20.5678.000; Fri, 16 Sep 2022 04:54:43 +0000
From: Danny Zollner <Danny.Zollner@microsoft.com>
To: Danny Mayer <mayer@pdmconsulting.net>, "scim@ietf.org" <scim@ietf.org>
Thread-Topic: [scim] [EXTERNAL] Re: Contributors needed for HR schema
Thread-Index: AQHYhop6w7PlBYSrD0e8++jXrS4PE63hfKsw
Date: Fri, 16 Sep 2022 04:54:42 +0000
Message-ID: <MN2PR00MB0720AD8F7BE8A39BD62AA190FF489@MN2PR00MB0720.namprd00.prod.outlook.com>
References: <MN2PR00MB0720A50B2E5EB355A07E5714FFAF9@MN2PR00MB0720.namprd00.prod.outlook.com> <76b2c137-9ae4-74ab-0482-80328a7db032@pdmconsulting.net> <MN2PR00MB0720CC2B7346ED47A504BC42FFB09@MN2PR00MB0720.namprd00.prod.outlook.com> <d4e9bdf7-8530-ad12-cced-892a5fd59307@pdmconsulting.net>
In-Reply-To: <d4e9bdf7-8530-ad12-cced-892a5fd59307@pdmconsulting.net>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Enabled=true; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SetDate=2022-09-16T04:54:42Z; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Method=Standard; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Name=Internal; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SiteId=72f988bf-86f1-41af-91ab-2d7cd011db47; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_ActionId=3e59813f-90d0-47f2-af1b-03964a3569b9; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_ContentBits=0
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=microsoft.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: MN2PR00MB0720:EE_|SJ0PR00MB1224:EE_
x-ms-office365-filtering-correlation-id: d9b85a7d-9115-4ed4-8f11-08da979f91f1
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: Rd10n86D0G90lWuK9oDn/SKc0xluISjCKTRmGEY2iJqTXzevAu6Cf1cbhgg1X84cE0j5g6s43dKForllccdo+kItk6dC1CXpXT4h2NUnQZ3eg9YHazOIWcRQ6PGcZdDxeXvpYF0kjKDbTW/43tj6vcA9CJXivb6GpBdtV96leGMJaD6wtnvIiiprTITFJ758Da9Y8zZOjmrsWNPVhXDkULVCW3onsiqnIO/qrO4+2CBi5FmWt6qarHHdMe0c5tgLJdvKf3vJjAkfyPV5Mj9M3OeU2hDNapapoUgsqyesezu8o4HmOXSRPkqZb/GjSViTJ5dBtWmnMNSW1SZF6OEOjTdnXE4fByEczBRN9sRE7JIjeqLI8J+ThxtNlgC2tiL4YTJlUqVTKcBEHA06JyrhtY5SfCiG2K/oQ51zja9SID44jzoOKoXe89sdmqTqhJL9PfzgI6Y0u1JW+cW3HpIhS3N/+KboU/cgbTvfuWyNZ3VEBOy5HkOiVZajsaB386i7/Dg8fz0Di4Ko8s27QsDftQv6sIKs9ffk9uN2wrCvXCl8fb3yuMSl63HpBPP5nNBzisohg0QVkyoNK3Ea4CuPQB9nMBuCDmG8+APRnzdpcWb234CetBrS9Q5dy1K3sF1jHp9+9S4SDYMviK3BNbmH7Lc2Mkme1pN9vVifpew0BkgbRVZRX45Xx14+satoLnuMONilVmrCv3/kACIEyqh9J24tEzJvAazyIbhnX6FY8rSmBtplIkjSQUh8pIJl4jASmL+hP+LDLFesEUh7Wr8q58MYaf4JIip9UwfJjt6RwaLB26lUzdwI91ReYhclmWxRanI4ImdhEgVqmsmLTweIWZxZZoUuuhmYG/lGNVT30O67SzO8ree1UKU9niQ9lSoW
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:MN2PR00MB0720.namprd00.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230022)(4636009)(136003)(39860400002)(346002)(396003)(366004)(376002)(451199015)(110136005)(966005)(71200400001)(10290500003)(55016003)(26005)(9686003)(53546011)(186003)(478600001)(6506007)(7696005)(38100700002)(82960400001)(82950400001)(86362001)(122000001)(38070700005)(166002)(83380400001)(33656002)(66899012)(5660300002)(21615005)(52536014)(8936002)(8990500004)(2906002)(316002)(41300700001)(76116006)(66946007)(66556008)(66476007)(66446008)(64756008)(8676002); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: yUWQGMAHlY8Jq8AYhaPl7if6FxaMkGmtLVDPgte1nyk05+tQonVX/2/1MLy76Pf8te4SYUpxDO/M3AE0ynYJoU5LQ4WskhVR5nzZ7rcVBedu01NpbZZVaMGAT7tt7erspNIG9F6kjvRgAxAj4KVyn810rXJVrMtITy/+TJQU+MtGid/bVQsUlfmWWXACJDnXdwuS32r18mkDvllKOYS0ycp4Ss98sfaaxVOECVHjuiSD5XnDjHWEjYRZIoHkj4RETxnIvBTCMNRmy7OZQfh+nnubQAG7cvg6vB3UG2YyfWjhHPNWhYaB9zqV50j5vzLTCiimIE1oaSb8F7Y7TCPnB54NAIi6hVH0OX6xudhKpC12i1P++a4O0GOy2yz25z8fHUXqOoVgi77ZTfUyMKIaVnGfZaHDrTikXeQ0NEkEGybTsH+SrwogFUhLtyrcdOnNp+aH+7lRqe0NskooTceijuG2L3NVufjW4AyrfRCFHmvOBFdRysdkVPwazZP6mprSTvpp3ZkJjOCwhgboZSTOHoi700mvdt7KJBWWoPDf6M1vgxGXFOhJvVGAjkfameQ2gIjTPvCDMQnQwXSj+fIanRsFN0dgDo2bIbKQTV4inYw9vZi2tUriwi8dCZ+ZE3VtnVqY1IKQyfp5C9x38CEshugizc/+ySn5wCVMSoR+/Veiz6Hj7AJ5/FLL2opwil2eZRwtByRGJJzQO/X1Qsl1whj3cpjJp/D621YUYYGuWT9iVISVpmWGo45Djd7vgvnAFNVVrrKFLNg8UrmZ4I+ElnngiiJTbC3+ahFkmONF6UHnSdFLuR9pyx88t80TR6cBDGJmvEI71FBKQLIGmMR1ZRPW9PkEW/E9jP8bERld0XN6xKwF16yU/xq3M7u05FqTYfWUdGIVhbzOZexgTiUmQmVlwNKVNa7QsQ9fN9Ej3R3NygLNi2EqKI0zVf2pS+3Pu8bA6gxfb4tlgo0U2hZtPLgW9Xw7yuY+QTj0YyQyH/Q9n+iCrh4vzMdp1R4ijaPdIfNwQJEPi2ZY6v3ef6UKxTnVCEzoYILSgW8QJ0Q7LUd4RVv0BDgAKk1oVmaEMuMbRi9I9QWiRCTF00+ZHYwy2rSW09xumfFe8PlPHyEO8VXX8WmNhTrsSKC+uX/3tT8QcSLqrCtby8vkdfUJ23i1tPMS5eShYLMCdmIacknRL/eauQLcXkG6JETSjGYa9wxcklB7ZiiUOHO10e8YpDlqwcWIUcznfrqDFB0Z2cR+NLuCRnFDDo0P7FRTkbMdK8gvdHOsxXXsgnHqgtRSFc376RkFPcAZUmbviRGyOOOVXcNxgB3nO6i9vxm/VcjHSwFWgae1mXBjRkh9vwcHDfQ5YT6RxEMFwRgLxHTk+3xGm8dA9GXVkiKi8csWzrTGYsbQ5XoObyj2sqRw9qwOjvWkZTaSNS7GBF7bqOTJQ/HzeXINzKC0zZ+TTbdBQLNWP02dip5UXzEeS0eQYCx5Y/aqLvatgAFmnkKmWnxvPj2sj+rKJBVtyC68IeDX1GiGOU/bnzorZKflWM7na/nNsIjBVYrTMDffzfjvi8CNNE8NCXXbniw9HTWMeqRungn+hfZ3
Content-Type: multipart/alternative; boundary="_000_MN2PR00MB0720AD8F7BE8A39BD62AA190FF489MN2PR00MB0720namp_"
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SJ0PR00MB1224
Archived-At: <https://mailarchive.ietf.org/arch/msg/scim/NVpn4S4--DPASTrkOm3gxfolD18>
Subject: Re: [scim] [EXTERNAL] Re: Contributors needed for HR schema
X-BeenThere: scim@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Simple Cloud Identity Management BOF <scim.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/scim>, <mailto:scim-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/scim/>
List-Post: <mailto:scim@ietf.org>
List-Help: <mailto:scim-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/scim>, <mailto:scim-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 16 Sep 2022 04:54:54 -0000

Apologies for the several month delay.

Danny Mayer: I don't think the angle that you are approaching this from is the same as the one I am. I'd argue it isn't the problem that was being thought of when the item mentioning an enhanced schema to support exchanging of human resources data was added to the charter, either.

Looking at this from the perspective of consuming HR data from multiple HR sources, the #1 problem is that every HR source today has its own API with its own schema. Most HR providers have not adopted SCIM, and I believe the primary contributing factor is the lack of an appropriate schema. The SCIM 2.0 user schema (core/enterprise) doesn't overlap enough with the types of information present in HR systems. Creating a set of schemas for those that consume HR data would help with the problem of sending HR-related data to other systems but doesn't solve the problem I described.

I took the name "Worker" from the implementations of some of the most prominent HR systems. A worker is typically a higher-level classification that represents full-time employees, contractors, interns, and other types of workers. The status of the employment is defined in an attribute on the object.


  *   Workday has a Get_Worker API (Cannot locate documentation - may be customer only)
  *   Oracle Fusion Cloud HCM has a Workers API (https://docs.oracle.com/en/cloud/saas/human-resources/22c/farws/api-workers.html)
  *   ADP has a Workers API (https://developers.adp.com/articles/api/hcm-offrg-wfn/hcm-offrg-wfn-hr-workers-v2-workers/apiexplorer)

Also, to address this: 'The bigger question, as usual is how much do you want to make "public" in other applications and how do you make sure you limit the data that the HR organization is prepared to share with other parts of the company.' - I think the question of data security is an important one but should be taken on separately from the discussion of an HR schema, as the work here would be likely agnostic to any given schema. I'll also say that currently, responsibility for restricting access to sensitive data rests on the SCIM service provider.

Specific to data security concerns regarding an HR schema, I think input is needed from players in the HR/HCM industry on if it would be wise to include extremely sensitive information such as salaries and social security numbers in a worker resource. Looking at APIs for the Oracle and ADP APIs I mentioned above, they have separate salaries/compensation APIs. This leads me to think that salaries should not be included on the Worker resource, and if exposed via SCIM would perhaps be better suited for a separate resource.

Thanks,

Danny Zollner (He/Him)

From: scim <scim-bounces@ietf.org> On Behalf Of Danny Mayer
Sent: Wednesday, June 22, 2022 5:50 PM
To: Danny Zollner <Danny.Zollner@microsoft.com>; scim@ietf.org
Subject: Re: [scim] [EXTERNAL] Re: Contributors needed for HR schema


I think you have it the wrong way round. The schemas need to be targeted at the applications that need to use it. Let me lay out at least 4 different types of target applications. There may be more but that's what I can think of off the top of my head. Note that I didn't like the use of the word 'Worker' and used 'Resource' instead though that may be too vague for SCIM. Suggestions welcome. Note that a 'Resource' may be an employee, contractor, intern, board member, auditor, etc. Each schema would need to be clear on the type of resource being referenced.
1) Authorization applications

Examples of this are Active Directory, Credential Authorization, Card Readers. There are others where authorizations for a resource needs to be configured. Information that needs to be provided include the type of resource, various groups like department and division, office location, office email, etc. Card Readers are often forgotten as needing some information as some office areas, or even building may be restricted, either by type of person or the hours.

2) Payment and benefits systems

These require personal information about a person, including their national ID, home address, banking information, etc. needed to process payroll. In addition, benefits like insurance require items like beneficiaries and dependents, home address, etc. Savings plans require similar information. This is usually only for Employees, but there can be exceptions for contractors performing work with these systems.

3) Other applications

These include requirements like their general information of their cost center, profit center, manager, division, department, etc. Examples of this are Timesheet and Expense applications. Usually Employees and Contractors need access to these systems to enter their hours and expenses. In addition some people in the finance department may require some sort of 'super' access to these systems to perform their job.

4) Ticketing applications

These systems don't need any special information about a person but there are likely to be contractors involved in helping with the tickets and need additional access.

I hope this helps in getting this rolling.

Danny
On 6/20/22 7:41 PM, Danny Zollner wrote:
Would it make sense to split these into separate items? Defining the HR schema being one piece - possibly into different sub-schemas(is that a word?) for different classes of data -  i.e.: general organizational data vs some set of data that would serve other purposes such as salary data (NOT saying we include that..) for easier boundary lines for applying access control? And then for the second piece, I think this sub-bullet from the charter:

    * Per-attribute schema negotiation

May cover the topics you mentioned on limiting what parts of the schema are available to what parties. Part of why I suggest splitting this apart is that the topic of limiting access to data looks like it aligns with that that charter item, but it's also applicable outside of the HR schema scenario and should be solved separately and then applied across the board.

Does that sound OK, or am I missing something and completely off base..?

Thanks,

Danny

From: Danny Mayer <mayer@pdmconsulting.net><mailto:mayer@pdmconsulting.net>
Sent: Monday, June 20, 2022 1:34 PM
To: Danny Zollner <Danny.Zollner@microsoft.com><mailto:Danny.Zollner@microsoft.com>; scim@ietf.org<mailto:scim@ietf.org>
Subject: [EXTERNAL] Re: [scim] Contributors needed for HR schema


I have plenty of experience fetching non-privacy data from HR. The bigger question, as usual is how much do you want to make "public" in other applications and how do you make sure you limit the data that the HR organization is prepared to share with other parts of the company.

Danny
On 6/17/22 4:35 PM, Danny Zollner wrote:
Hi SCIM-ers,

One of the items on the charter for the SCIM working group is to design a human resources-centric schema for SCIM. For this to be successful, we'll need contributors that are knowledgeable on HR and HCM services and concepts. If anyone has background on this area - ideally previously or currently working for an organization involved in this space - and can contribute, please respond to this thread and let us know of your interest.

I've had some discussions with folks more knowledgeable on these sort of things than I am already, and here are a few things I took away from that that I'd like to put out there as ideas up for discussion:


  1.  We should create a new resource, "Worker", rather than make an HR schema on a user resource. HR data is likely to feed into a logic engine of some sort that then ultimately decides what needs to happen, and HR systems generally should not be directly turning HR data into users in other systems without some middle layer.



  2.  Some attributes in this schema may have a finite list of acceptable values - think locations, departments, cost centers. Extending other new resources, i.e.: /CostCenters, may be helpful for discovery's sake to allow a client interacting with an HR/HCM SCIM service provider to GET a list of allowed locations, departments, cost centers, etc.. and more efficiently generate requests where the values of these attributes can be predetermined to be valid or not ahead of an operation to create/update a worker.

Thanks,

Thanks,

Danny Zollner




_______________________________________________

scim mailing list

scim@ietf.org<mailto:scim@ietf.org>

https://www.ietf.org/mailman/listinfo/scim<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Fmailman%2Flistinfo%2Fscim&data=05%7C01%7Cdanny.zollner%40microsoft.com%7C6e92102c73904396c43e08da54a19917%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637915350325187932%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=3fMCqnAL8V7%2BDGHLommvL9UNVAUalA4Fxc%2F%2Bq2ZtNrU%3D&reserved=0>