Sourced open data and public reuse context
Source records, publishing, and corrections: SAP Security & GRC
Open Data BR provides City-Parish data for public analysis, web visualizations, applications, department coordination, and resident access. Connect the operating setting to business roles, technical roles, Fiori catalogs, privileged access, and segregation-of-duties risks. Ask how the consultant balances least privilege with work completion. A public-data service needs named owners for source records, publication rules, refresh timing, metadata, legal review, corrections, and downstream applications that the publishing team does not control.
Evidence to request: Use a role-design exercise with business tasks, sensitive access, Fiori content, conflict analysis, and approval ownership. Identify each source system, dataset owner, publication test, refresh schedule, restricted field, correction route, consumer, and support handoff connected to the role.
Sourced enterprise applications and infrastructure context
Shared services across departments: SAP Security & GRC
Baton Rouge Information Services lists application development, server administration, network management, and consolidation of department technology among its responsibilities. Define request, approval, provisioning, emergency access, review, and removal workflows. Require evidence from GRC rule sets, mitigating controls, identity tools, or manual processes that match the environment. A shared service may support departments with separate case records, approvals, retention rules, operating hours, budgets, and legacy systems while one central team owns infrastructure and support.
Evidence to request: Review an access request or emergency-access workflow with rules, logs, reviewer action, exceptions, and closure. Name the departments, user groups, service owner, application and hosting boundary, approval path, maintenance window, legacy connections, and acceptance evidence.
Sourced cybersecurity and geographic data context
Identity, location, and disclosure boundaries: SAP Security & GRC
The Information Services department identifies cybersecurity and geographic information systems as City-Parish functions and describes work on maps, data, and applications. Set audit and change ownership. Candidates should explain how they investigate conflicts, document remediation, test transports, retain evidence, and verify access after organizational or system change. Constituent and location records can cross identity, field access, map layers, integrations, operational use, audit logs, and public-disclosure rules that require separate review owners.
Evidence to request: Ask for an audit finding the consultant resolved, including evidence, configuration or role change, testing, and follow-up review. Define the identity authority, protected records, geographic layers, access groups, public boundary, retained logs, incident route, and review required after a system change.