Student data visibility review
We test what a sample of users in each office can see: grades, disability accommodations, financial aid notes, conduct flags and advising case notes. Sharing rules and report folders are compared against each role's actual need. We pay particular attention to shared reports built years ago and forgotten, since those are a common route by which sensitive student details reach people who should not have them.
Term-based user lifecycle
Student workers and adjuncts are often provisioned quickly at the start of term and never removed. We list inactive and orphaned accounts, users with administrator permissions they no longer need, and shared logins used by front desk or call center staff. We also review whether identity provider sign-on is enforced and whether deprovisioning is tied to enrollment or employment status.
Departmental sprawl inventory
Each department's build is catalogued: record types, custom objects, installed packages and flows. We identify where two offices track the same thing differently, such as events or interactions, and where one office's automation changes a record another office relies on. The result is a map of shared and owned components that governance committees can use to agree on standards going forward.
Constituent record integrity
A person may be a prospect, applicant, student, alumnus and donor across many years. We measure duplicate people, mismatched identifiers from the student information system and broken links between student and alumni records. Findings show how often an advancement officer or advisor is looking at an incomplete history, and which matching rules would reduce new duplicates without merging distinct people by mistake.