Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update ILM Playbook for Detailee Use Case #390

Open
idmken opened this issue Jul 12, 2022 · 2 comments
Open

Update ILM Playbook for Detailee Use Case #390

idmken opened this issue Jul 12, 2022 · 2 comments
Assignees

Comments

@idmken
Copy link
Contributor

idmken commented Jul 12, 2022

Placeholder to update the ILM Playbook for a detailed use case. Under step 4 integrate, we can update to include other use cases on integration.

Detailee use case - An Agency A employee is detailed to Agency B. How can Agency B use their ILM system for this existing Agency A employee, but short-term Agency B employee. Can Agency A share HR data to do birth-right provisioning in Agency B? I think the corpus of this use case is how Agency B can provision Agency A employee without issuing them an Agency A piv card and an Agency A email.

claytonjbarnette referenced this issue in claytonjbarnette/ficam-playbooks Aug 26, 2022
Add use case from issues #591 above Summary section
@claytonjbarnette
Copy link
Member

@idmken I started working on this and sent @JBPayne007 an email with an outline before doing a PR.

claytonjbarnette referenced this issue in GSA/ficam-playbooks Nov 23, 2022
Added use case from issue #591
@idmken idmken reopened this May 23, 2023
@claytonjbarnette claytonjbarnette transferred this issue from GSA/ficam-playbooks Jul 24, 2023
@idmken
Copy link
Contributor Author

idmken commented Mar 18, 2024

The detailee use case is dependent on the detailed agency system accepting a outside Agency PIV card for all required physical or logical access.

Two examples

  1. The most simplest is the agency issues their own PIV card, but mark it the same as a contractor. While the federal employee isn't a contractor they are also not an employee of the detailed agency. They would retain the PIV card of the home agency.

More thorough response, we will attempt to import the existing PIV for granting physical access. If they require systems access (logical access) and we cannot load the detailed agency certs onto the existing PIV, the detailed agency may issue an alternate credential for logical access. However, some agency PIV annotate level of access for restricted areas, if the individual requires regular access to our restricted areas, we will either issue a detailed agency PIV with access area number or issue a temp badge which annotates the individual is cleared for restricted access.”

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants