Transition Plan
This chapter explains how to make the transition to working with Haal Centraal APIs in your municipality and how to phase out administrative data warehouses and many local copies.
Read the Haal Centraal quick start guide first
This step-by-step plan is part of the Haal Centraal quick start guide. In the quick start guide we recommend starting with Haal Centraal on two tracks. The step-by-step plan is an elaboration of track 2 from the quick start guide. Read the Haal Centraal quick start guide first if you have not already done so.
Step 1 — Draw up a transition plan
The transition starts with determining the transition strategy for your municipality. We distinguish two strategies, which can be combined if desired:
- Strategy A — actively phasing out the administrative data warehouse. In this strategy you actively connect all consumers of the data warehouse to the APIs within a short period.
- Strategy B — a wind-down approach, in which you build a new infrastructure alongside the old one and leave the old situation unchanged until all of those applications have been put out to tender again.
Which of the two strategies you choose depends on the situation in your municipality and the costs you will have to incur. Compare the costs of strategies A and B and try to find an optimum. Map out:
- the annual costs of managing and maintaining the administrative data warehouse;
- how many consumers are connected to it;
- when the connected applications are due for replacement;
- the costs and options for a consuming application to migrate to APIs, with or without a 'translator'.
Step 2 — Scaling up security in phases
As you connect more APIs, you will also scale up security. In concrete terms, you move from all security in the application to security in central municipal facilities.
Professionalizing security happens in phases. If you start with 1 privacy-sensitive API, all you need is an API gateway. Are you scaling up? Then a proxy for authorization, an identity provider, an access logging facility, and an IGA system (Identity Governance and Administration — formerly IAM) follow.
The box below describes 3 phases for scaling up security. How you work through the phases depends on the transition strategy you choose.
- If you opt for active phase-out (strategy A): you can work through phases a, b, and c below.
- If you opt for a wind-down approach (strategy B), you first have to purchase and set up the facilities from phases a and b below. After that you can work through the phases.
3 phases for scaling up security
Phase a: connecting data warehouse consumers to APIs
Haal Centraal makes connecting cheaper and reduces the number of local copies, starting with the data warehouse/distribution system. Do you want to book these savings in the short term? Then you have to connect all consumers of the administrative data warehouse to the APIs, including the legacy applications.
Until you put them out to tender again, you can set up a machine-to-machine connection for these applications (with appropriate authorization), and optionally use a 'translator' that converts the API requests and responses into the old formats. User management, authorization, and user-level logging then remain unchanged. They stay part of the legacy application.
To be able to take this step, all you need is an API gateway and a proxy for fine-grained authorization (possibly through an API gateway framework). With these facilities you can therefore already start the transition.
Phase b: identity provider and logging & access logging
The second phase is introducing an identity provider/STS and, at the same time, making a start on a central logging and access logging facility. The right moment for this is:
- When you are putting out to tender again an application that fits the Common Ground vision
- When you are going to use a modern SaaS solution that uses Haal Centraal APIs, for example a generic viewer for all municipal staff.
Start by connecting 1 application, and slowly extend this to all new (re-tendered) applications. That way you can learn and improve as you go, and let your organization professionalize further at its own pace.
Read more about logging & access logging in the security section.
Phase c: IGA system for managing roles and permissions
The third phase is managing roles and permissions centrally in an IGA system (Identity Governance and Administration — formerly IAM).
This becomes more important as the landscape contains more applications that use roles and permissions in an identity provider. The size of your municipality also plays a role here.
Ask yourself at what point provisioning your identity provider can no longer be handled properly through a form or an administrator. At how many connected applications, and with which connected applications, does it become important for the identity provider to be connected to your organization's employee lifecycle management?
Bear in mind that an IGA project is 30% technology and 70% culture. Understanding of the need, and buy-in from management and the HR department, are absolute conditions for success. Start on that in good time.
Read more about IGA systems in the security section.