The HarvardKey Application Integration Policy gives application owners a six-month window to bring their applications into compliance. This process will unfold in two phases:
Phase 1. HKAR Data Clean-up
Department Liaisons and App Liaisons should plan to complete the following data clean-up activities for their applications and registrations in HKAR:
Step 1. Locate your Applications and Registrations
-
Find your applications and registrations on the Applications and Registrations Dashboards.
Step 2. Review and Update your Application and Registration Information
-
Ensure all applications and registrations in HKAR are active and linked correctly
-
Request to delete or disable registrations that are no longer in use
-
Inactivate applications that are no longer in use by updating the status on the Application Details page
-
Notify the IAM team of incorrectly linked registrations
-
-
For each application, review the following fields on the Application Details page and modify if the data is inaccurate or incomplete:
-
Name
-
Purpose
-
Department (Please note: the owning department listed in HKAR should be the technical department responsible for maintaining and supporting the app rather than the business owner)
-
User Population
-
Primary Authorization Method
-
-
Review and update contacts associated with your applications
-
Review contacts associated with your applications in bulk using the Applications, Registrations, Contacts Report
-
Add new contacts and update the contact type for all contacts to accurately represent their relationship to the application. The IAM team will add all contacts to our Authentication Services mailing list.
-
Ensure all applications have at least one contact of type Registration Manager. This individual will be responsible for attestation of policy compliance for the application.
-
Phase 2. Policy Compliance (By January 31st, 2023)
Department Liaisons and App Liaisons should plan to complete the following compliance activities for their applications and registrations by January 31, 2023:
-
Ensure all registrations have an appropriate authorization filter in alignment with the affiliation and assurance tiers
-
Ensure attributes released during authentication are being used in alignment with the HarvardKey Application Integration Policy
Need help?
- For information about HKAR features and links to knowledge articles, please visit the HKAR index page in the IT Help Portal.
- IAM hosts weekly Office Hours on Tuesdays from 1-2 pm to answer any questions related to Authentication and Authorization services including how to complete data clean-up and compliance tasks. Come with questions about HKAR, HarvardKey, HarvardKey Light, or Group Authorization.