So you have been working on delivering the perfect SharePoint implementation for your client. The architecture is good, search is working like a charm, the home page is attractive and has an intelligent, user-friendly layout. The developers have done a great job with those web parts and custom forms. The client is "blown away" by the whole thing.
Their business processes are ready to receive that all important technological injection. The BA feels proud of what she/he's done (let me just stick to "he/him" from here on; less trouble :P). The PM is making arrangements for the team's celebratory outing or dinner. The client has signed off, and everyone is invited to the SharePoint launch. Free food, free drinks...
Following week, back in the office, the PM, BA and developers gets assigned to a new project, the developers sit around, waiting for more work. Everyone is looking forward to June when its bonus time. Overall, a good job done by the team.
2 Months later the PM receives a phone call from the client. They some issues with regards to permissions on certain sites. The site administrators are finding it difficult to figure out who has what permissions and what is visible to whom. They need some assistance. So you send out a BA to have a look at what they've done. The BA can't figure out what is going on and calls in a "SharePoint guy". The "SharePoint guy" has a look and the first question he asks is: "Who set up the permissions on these sites?" (quietly hoping that it's not his colleagues who spent 3 months on site). "Well, your guys did..." says the client. "No they did..." says the BA. Aah... I see, says the "SharePoint guy, sarcastically.
So what happened here? Well, everything was set up correctly architecturally, but then it was handed over to end-users who probably have never or very seldom worked in SharePoint. Yes, they know how to upload documents, they know how to start a workflow, they even figured out how to retrieve site usage information. But where things gets "iffy" is where site administrators has to configure permissions for their sites.
I have seen this too many times where projects are completed, but the Site Administrators are not identified, involved and trained on all aspects related to Site Administration. I constantly find myself having to defend SharePoint as far as permissions management is concerned. We all know that if people cannot figure out how something should be done, they tend to blame the technology. Training site administrators should be part of any SharePoint project or -site delivery strategy. This will ensure that all administrators are trained and has a more or less uniform manner in which they manage their sites and permissions. Training is an important step, because if people don't know any better, they will do whatever it takes to get the job done, and I can almost guarantee that they will not take the best practice approach.
I always encourage site admins to make use of SharePoint groups. SharePoint groups just keeps things nice and clean, making it easier to figure out why Joe Soap cannot see that web part, or why he cannot add documents to that library. Perhaps he is in the Visitors group as opposed to the Members group. Adding users directly to a site will cause you endless headaches further down the line. yes, it may seem like a nice quick fix. The manager just wants Joe to have access to that site or that library. He does not care about the management and the "other stuff" and he wants it done now. So adding the user directly to the site may seem like a quick action to satisfy the manager who is so difficult. But there are a few questions that should be asked. What happens if someone's role changes? What happens if they leave? What happens if I (the site admin) leaves? Will the next guy be able to just carry on?
This becomes even more scary when admins create custom permission levels. We need to try and make things as easy as possible for end-users (which includes site admins). If we don't, they are bound to mess things up. Your beautifully created site collection with it's wonderful sub-sites and libraries will soon become a headache and you end up having to kill fires all over the place. i have seen people creating a sub-site to host a single document library, because they just can't get the permissions thing right on the other site, so they just create a new site, do the permissions on the site level and "create the document library in there". This happens because "we can't figure out what's going on with the permissions on the top-level site. Some users are in groups, others are not, others are in groups and added directly. and we don't have time to investigate".
Sound familiar? Do us all (and yourself) a favor, train the site admins before hand-over. Empower them and you will have a happy client and you can tend to real issues.
Your thoughts are welcome...
No comments:
Post a Comment