HAALCENTRAAL Haal Centraal
Haal Centraal / Transition Plan

Transition Plan

This chapter explains how to make the transition to working with Haal Centraal APIs in your municipality and how to phase out administrative data warehouses and many local copies.

Read the Haal Centraal quick start guide first

This step-by-step plan is part of the Haal Centraal quick start guide. In the quick start guide we recommend starting with Haal Centraal on two tracks. The step-by-step plan is an elaboration of track 2 from the quick start guide. Read the Haal Centraal quick start guide first if you have not already done so.

Step 1 — Draw up a transition plan

The transition starts with determining the transition strategy for your municipality. We distinguish two strategies, which can be combined if desired:

Which of the two strategies you choose depends on the situation in your municipality and the costs you will have to incur. Compare the costs of strategies A and B and try to find an optimum. Map out:

Step 2 — Scaling up security in phases

As you connect more APIs, you will also scale up security. In concrete terms, you move from all security in the application to security in central municipal facilities.

Professionalizing security happens in phases. If you start with 1 privacy-sensitive API, all you need is an API gateway. Are you scaling up? Then a proxy for authorization, an identity provider, an access logging facility, and an IGA system (Identity Governance and Administration — formerly IAM) follow.

The box below describes 3 phases for scaling up security. How you work through the phases depends on the transition strategy you choose.

3 phases for scaling up security

Phase a: connecting data warehouse consumers to APIs

Haal Centraal makes connecting cheaper and reduces the number of local copies, starting with the data warehouse/distribution system. Do you want to book these savings in the short term? Then you have to connect all consumers of the administrative data warehouse to the APIs, including the legacy applications.

Until you put them out to tender again, you can set up a machine-to-machine connection for these applications (with appropriate authorization), and optionally use a 'translator' that converts the API requests and responses into the old formats. User management, authorization, and user-level logging then remain unchanged. They stay part of the legacy application.

To be able to take this step, all you need is an API gateway and a proxy for fine-grained authorization (possibly through an API gateway framework). With these facilities you can therefore already start the transition.

Phase b: identity provider and logging & access logging

The second phase is introducing an identity provider/STS and, at the same time, making a start on a central logging and access logging facility. The right moment for this is:

Start by connecting 1 application, and slowly extend this to all new (re-tendered) applications. That way you can learn and improve as you go, and let your organization professionalize further at its own pace.

Read more about logging & access logging in the security section.

Phase c: IGA system for managing roles and permissions

The third phase is managing roles and permissions centrally in an IGA system (Identity Governance and Administration — formerly IAM).

This becomes more important as the landscape contains more applications that use roles and permissions in an identity provider. The size of your municipality also plays a role here.

Ask yourself at what point provisioning your identity provider can no longer be handled properly through a form or an administrator. At how many connected applications, and with which connected applications, does it become important for the identity provider to be connected to your organization's employee lifecycle management?

Bear in mind that an IGA project is 30% technology and 70% culture. Understanding of the need, and buy-in from management and the HR department, are absolute conditions for success. Start on that in good time.

Read more about IGA systems in the security section.