Pages

Saturday, January 20, 2007

The Value of Co-Creation

I have been reading Wikinomics by Don Tapscott and Anthony Williams. Overall, it is a good book. One of the arguments the authors make is that corporations need highly permeable boundaries to foster innovation in their organizations and be successful. In the software industry, we have seen how IBM and others have leveraged the open source movement to co-create and drive innovation in the industry. IBM for instance estimates that it saves in R&D around $1 billion a year by investing in the Linux community. And in its hardware business alone, IBM sold $2 billion worth of Linux based hardware in 2006. Those make strong arguments for the value of co-creation, right? Well, wait to hear how P&G leverages co-creation. In the late 1990's, P&G realized that out of a $1.5 billion R&D budget, generating a lot of patents, less than 10% of the produced patents resulted in products. So P&G's CEO, A. G. Lafley, set out a pretty aggressive goal: that 50% of P&G new products and service ideas come from outside the company by 2010. We aren't talking about outsourcing here, but true co-creation. Identify most promising ideas out there that help P&G innovate and incorporate them into P&G R&D.

The result is big time dividend as mentioned in P&G's New Innovation Model in March 2006, by Larry Huston and Nabil Sakkab on HBS Working Knowledge.

More than 35 percent of our new products in market have elements that originated from outside P&G, up from about 15 percent in 2000. And 45 percent of the initiatives in our product development portfolio have key elements that were discovered externally. Through connect and develop—along with improvements in other aspects of innovation related to product cost, design, and marketing—our R&D productivity has increased by nearly 60 percent. Our innovation success rate has more than doubled, while the cost of innovation has fallen. R&D investment as a percentage of sales is down from 4.8 percent in 2000 to 3.4 percent today. And, in the last two years, we've launched more than 100 new products for which some aspect of execution came from outside the company. Five years after the company's stock collapse in 2000, we have doubled our share price and have a portfolio of twenty-two billion-dollar brands.


That's pretty amazing and should be a call for action for any executive out there. Co-creation works in a big way!

Saturday, January 13, 2007

What do the "Out There" People in Your Organization Think?

The Attention Company posted an interesting survey on what it calls the "Out There" people. See the "Out There" survey and the "Out There" reactions.

In a nutshell, the survey makes the following points as described below:
  • The "Out There" people are the ones "participating in online communities"
    • 20% of your organization population very active
    • 32% are somehow active
  • They are the winners in your organization
  • Information is everything:
    • Employees at the bottom levels of an organization have most of the knowledge
    • Transparency in decision making increases the likelihood of success
Out There Survey
These points are particularly interesting when put in context with organizations and how better information sharing techniques can help organization perform better. This shows the benefits of having a strategy to best disseminate information and knowledge within a company.

Monday, January 08, 2007

Confluence: A Nice Product Evolution

I have been tracking Confluence for a little while now, I have to give credit to their team for a nice product evolution.
In 2.0 in November 2005, they added label or tagging support with cloud display and improved their dashboard display. See their 2.0 release notes.



More screenshots are available in this slide show.

In April 2006, in their 2.2 version, they added support for personal spaces. See the 2.2 release notes.



And, this January, they are adding people directories in 2.3. See their 2.3 release notes.



For those interested in getting in touch with their developers, some of their personal spaces are available online.

Thursday, December 07, 2006

Who Likes Peanut Butter Anyway?

I never liked peanut butter, so that may be the reason why Brad Garlinghouse's memo resonnated with me. His Peanut Butter Manifesto gives us a lesson in leadership. It is the responsibility of senior management to lead the march for change and to clearly articulate why it is happening. I found Brad's manifesto effective at doing so. Ironically enough, it would probably resonnate true with quite a few organizations were you to replace the product names. Organizations often tend to spread peanut butter when they are reluctant to refocus their business and align it with clearly articulated strategic direction. To be successuful, every organization should have:

  • A focused, cohesive vision
  • Clarity of ownership and accountability
  • Decisiveness
The drama of working out internal company issues in public is unusual but quite entertaining. I am not sure what are the benefits for a Yahoo! executive to do so. But, his call for change should be applauded. Too many executives often do so too late. Knowing when is the right time to call for change is hard, looks like that time has come at Yahoo!. Now, let's see how successfully, Yahoo! can refocus its business. Will Brad lead the charge?

Wednesday, December 06, 2006

Why Kodak’s Strategy Will Work…

The November 27th issue of Business week had a very interesting article about Kodak and some of the tough choices and strategy shifts it had to undertake over the past 10 years. Over the past ten years, Kodak had to re-invent itself from a film company to a print company to a digital technology provider illustrated by its recent deal with Motorola. So what's behind Kodak's transformation? First, despite the resistance to change that any strategy shift entails, is the recognition of a true identity and business purpose. Kodak is an image company and as such, it is able to adjust, though painfully, through the value chain of the image business.

In a sense, this is a classical illustration of Clayton Christensen's "Law of Conservation of Attractive Profits". The law of conservation of attractive profits states that in the value chain there is a requisite juxtaposition of modular and interdependent commoditization, that exists in order to optimize the performance of what is not good enough. When modularity and commoditization cause attractive profits to disappear at one stage in the value chain, the opportunity to earn attractive profits with proprietary products will usually emerge at an adjacent stage (quote from The Innovator's Solution). This happened to the computer industry (see Intel) and is happening to the image industry. Kodak's bet that the growth of digital photography will happen in mobile phone and that profits margins for sensor chips will be twice those of the digital camera business aligns with the above law. Kodak is identifying new revenue opportunity in the image value chain and aggressively pursuing the shift in the value chain. That's true leadership and it will pay off. Good luck Mr Perez.

Saturday, December 02, 2006

Meridio Records Management with SharePoint

I came across this interesting presentation from Meridio a couple days ago. Meridio positions itself as the leading worldwide provider of enterprise Document and Records Management (eDRM) software, engineered for Microsoft .NET platforms.

As a result, Meridio is naturally embracing SharePoint and identifying both how to position itself and provide value-added to SharePoint 2007. Meridio recognizes one of the weaknesses of the SharePoint architecture with the risk of proliferation of a large number of sites which in return makes the SharePoint infrastructure difficult to manage (if not unmanageable) for large organizations. SharePoint's approach to Records Management relies heavily on the site archictecture as well. See the Web Seminar with AIIM and Microsoft: Records Management in Microsoft Office SharePoint Server 2007 for a good overview.

Meridio is positioning itself as an enterprise policy management solution for SharePoint 2007 which can act as an enterprise records management repository for SharePoint and legacy systems as well.

Meridio And Office 2007
Enterprise Policy Management
Here is a screenshot of Meridio’s policy management user interface in a SharePoint environment.

Policy Mgt UI
Meridio's architecture seems to start positioning Meridio as a potential virtual records management repository for the enterprise which is undoubtedly the right direction for them to remain relevant.

Architecture
It is an interesting and promising extension to SharePoint. Remains to be seen how successful they will be now that SharePoint is positioning itself as a platform that can provide basic Records Management capabilities.

Sunday, June 25, 2006

Interesting Open Source WSRP Consumers/Producers Compatibility Analysis

A colleague of mine recently pointed out an interesting presentation from CCLRC Daresbury Laboratory (University of Portsmouth) comparing experiences with open source portals WSRP development and testing.

By standardizing presentation-oriented web services, WSRP makes it possible to construct web portals in "plug-and-play" mode. This presentation compares WSRP support for the eXo Platform, Liferay, StringBeans and uPortal. WSRP4J, which is not a portal framework but a reference implementation of the WSRP 1.0 specification and the basis of WSRP support in many portal frameworks, is also discussed. In summary, WSRP Open Source implementations are still in early stages. From a producer standpoint, WSRP4J is clearly the most compatible of all and can be accessed by all the reviewed WSRP consumers. From a consumer standpoint, none of the consumers are fully functional. From Xiaobo Yang, Xiao Dong Wang and Rob Allan presentation, the test summary is shown below.

WSRP Testing Summary

Saturday, May 13, 2006

Jetspeed-2 Desktop: Client Side Portlet Aggregation

I have not had much time to get involved with Jetspeed lately, but when I read Steve Milek post on the development list last Monday, I figured I had to check out the new Jetspeed-2 desktop mode. And I have to say, this is shaping out quite nicely.

Essentially, the Jetspeed j2o Desktop mode combines Jetspeed server-side portal services with client side ajax services. Traditionally, Jetspeed has been a server centric application where every request is processed by the server request pipeline. In Jetspeed j2o desktop the page aggregation is controlled by the client services. This makes for a pretty sleek client experience. The Jetspeed j2o implementation significantly leverages the DOJO library and essentially implements a client side JSR 168 compliant portlet rendering engine. Some screenshots are enclosed below.

Jetspeed-2 Desktop View

Desktop View
Jetspeed-2 Desktop Portlet Drag and Drop

Drag And Drop
Jetspeed-2 Back in Normal Portal View

Users can switch back to the traditional Jetspeed view:

J2 in Normal View
For more details, read Steve's post on the Jetspeed-2 dev list. Great job from the jetspeed team!

Saturday, April 22, 2006

Wikis: New Trend For Consumer Oriented Web Sites?

Wikis have been around for a while. The open source community has long been using them as a means of communicating project updates and documentation. The Wikipedia phenomenon has played a significant role in increasing awareness and demonstrating the power of Wikis. Now it is time for consumer oriented web sites to jump on the band wagon and leverage Wikis as a means to provide better alignment and customer focus for their web sites. How much customer focused can you be? There seems to be a trend for a new generation of consumer web sites to leverage Wikis as a way to foster their community involvement and provide better customer focus. Granted customer reviews have been around for a while; just select one product on Amazon and consumer reviews usually abound. The paradigm shift here? The entire site content is driven by the community. This has the potential for early adopters to disrupt their industry business models. Some examples:
  • Trip Advisor: This is probably the best example. Trip Advisor is opening its travel guides content to the community at large. If this takes off, this could be quite disruptive to the travel guide industry. No more outdated content; get to read about the not so-well known places to visit. Leverage millions of tourists and local inhabitants to participate in writing Trip Advisor travel guides content. Look at what Wikipedia did to the Encyclopedia industry...
  • Product Wiki: Another good example of what consumer shopping web sites could become. Let your community decide what you should sell and talk about. This could be fairly disruptive as well. Sell what your customers are looking for and develop micro communities of shopping web sites where customers drive what should be on the product catalog. The risk here is that, third party resellers figure out the trick to push and promote their own products. But with the proper controls in place, this concept has some potential.
  • Wet Paint: Provide a framework to create Wikis focused on specific consumer areas. Check out Wiki XBox 360 for the XBox fans.
This is just a small subset of the next generation of consumer web sites and still very much a work in progress. But well worth a few minutes of blogging...

Sunday, March 26, 2006

Market Dynamics For Idea Validation

Here is an interesting idea. Use market dynamics to weed the good ideas from the bad ones. I just happened to read an interesting article from today's New York Times ("Here's an Idea: Let Everyone Have Ideas" by William C. Taylor) that outlines just that. I personally find the idea quite appealing. The premises go as follows:
  • Allow anyone in your company to have Initial Public Offerings (IPOs) for their ideas.
  • Have every employee allowed to trade $10,000 of those idea stocks.
  • Let the market dynamics decide.
This is not a completely novel idea but Rite-Solutions has a product (The Innovation Engine) that does just that. A modern take on the suggestion box...

Saturday, March 04, 2006

Yahoo! Mail Beta - I am loving it...

I finally got access to the new Yahoo! Mail Beta and I am loving it. My favorite feature? The RSS reader. My Yahoo! already offered the ability to add RSS feed to your personal pages; well now even better, you can read your RSS feeds in your mail client with indicators of whether or not new items are available. I look forward to Yahoo! integrating RSS with Messenger next...

RSS Reader

Sunday, February 05, 2006

An Interesting SOA Platfom Reference Model

I came accross a white paper from IDC that presented an interesting SOA platform reference model. According to IDC, any SOA platform should be made of:
Core Services
  • Deployment services. To host and manage the operational, runtime functions
  • Integration services. Data and process-style integration across operating environments and platforms with support for demand-driven (request/reply) or event-driven interoperation
  • Process orchestration. Organizes and aggregates services into flows to automate system and business processes
  • Policy. A business policy or systems rule or condition that governs an action (Business rules are the foundation of business processes.)
  • State management. The ability to recognize, support, and manage entity state, thereby providing support for processing governed by state transitions
Supporting Services
  • Access services. Reliable and secure system and people-based access to services and necessary system artifacts within the SOA
  • Development facilities. Full life-cycle support and versioning of services and messages, including modeling, coding, debugging, testing, deployment, and change control
  • Security and management services. Service and process monitoring, management, security, and ID management
  • Application and data services. Services built around the supporting data persistence and data semantics
SOA Reference Model It shows the level of completness that application frameworks must provide in order to address the various requirements of SOA.

Saturday, December 10, 2005

Jetspeed-2.0 has been released!

Two years in the making and a busy couple last months and there it is. Jetspeed 2.0 final release is out! From the release announcement:

The Apache Portals Jetspeed Team is pleased to announce the final release of the Jetspeed 2.0 Open Source Enterprise Portal. This final release is fully-compliant with the Portlet Specification 1.0 (JSR-168). Jetspeed-2 has passed the TCK (Test Compatibility Kit) suite and is fully CERTIFIED to the Java Portlet Standard.
The Jetspeed team will be presenting the new 2.0 release at ApacheCon US 2005 on December 10th in San Diego.
Jetspeed is a full implementation of the Java Portlet API. Notable features include security components backed by LDAP and database implementations and some robust administration interfaces. Custom portals can be built and deployed using the Jetspeed plugin for Maven. Developers can use the Jetspeed PSML language to assemble portlets and the Apache Portals Bridges project to 'bridge' portals with existing technologies including Struts, JSF, PHP, Perl. For GUI designers, Jetspeed comes with several built-in templates used to decorate portals and portlets. Join the growing community of Jetspeed users and developers at ApacheCon. David Sean Taylor will be presenting a Jetspeed tutorial that shouldn't be missed by anyone interested in the technology.


Features of the Final Release Include:

Standardized:
  • Fully compliant with Java Portlet API Standard 1.0 (JSR 168)
  • Passed JSR-168 TCK Compatibility Test Suite
  • J2EE Security based on JAAS Standard, JAAS DB Portal Security Policy
  • LDAP Support for User Authentication
Foundation Component Architecture:
  • Spring-based Components and Scalable Architecture
  • Configurable Pipeline Request Processor
  • Auto Deployment of Portlet Applications
  • Jetspeed Component Java API
  • Jetspeed AJAX XML API
  • PSML: Extended Portlet Site Markup Language
    • Database Persistent
    • Content Management Facilities
    • Security Constraints
Portal Core Features:
  • Declarative Security Constraints and JAAS Database Security Policy
  • Runtime Portlet API Standard Role-based Security
  • Portal Content Management and Navigations: Pages, Menus, Folders, Links
  • Multithreaded Aggregation Engine
  • PSML Folder CMS Navigations, Menus, Links
  • Jetspeed SSO (Single Sign-on)
  • Rules-based Profiler for page and resource location
  • Integrates with most popular databases including: Derby, MySQL, MS SQL, Oracle, Postgres, DB2
  • Client independent capability engine (HTML, XHTML, WML, VML)
  • Internationalization: Localized Portal Resources in 12 Languages
  • Statistics Logging Engine
  • Portlet Registry
  • Full Text Search of Portlet Resources with Lucene
  • User Registration
  • Forgotten Password
  • Rich Login and Password Configuration Management
Administrative Portlets:
  • User, Role, Group, Password, and Profile Management
  • JSR 168 Generic User Attributes Editor:
    • JSR 168 Preferences Editor
    • Site Manager
    • SSO Manager
    • Portlet Application and Lifecycle Management
    • Profiler Administration
    • Statistics Reports
Web Framework Support and Sample Portlets:
  • Bridges to other Web Frameworks: JSF, Struts, PHP, Perl, Velocity
  • Sample Portlets:
    • RSS, IFrame, Calendar XSLT, Bookmark, Database Browser
    • Integration with Display Tags, Spring MVC
Customization Features:
  • Administrative Site Manager
  • Page Customizer
Portal Design Features:
  • Deployment Jetspeed Portlet and Page Skins (Decorators) CSS Components
  • Configurable CSS Page Layouts
  • Easy to Use Velocity Macro Language for Skin and Layout Components
Development Tools
  • Automated Maven Build
  • Jetspeed-2 Maven Plugin for Custom Portal Development
  • AutoDeployment of Portlet Applications, Portal Resources
  • Deployment Tools
  • Plugin Goals integrated with Auto Deployment Feature
Application Servers Supported:
  • Tomcat 5.0.x
  • Tomcat 5.5.x
  • Websphere 5.1, 6.0
  • JBoss

The release is available for download from the Apache Download Mirrors:
http://portals.apache.org/jetspeed-2/download.html
We hope you enjoy using Jetspeed! Documentation is available at: http://portals.apache.org/jetspeed-2/.

Wednesday, November 09, 2005

Embedding Apache Directory Server

Apache directory server is an embeddable LDAP server written in Java. It is now embedded in Jetspeed-2 which fully supports LDAP for authentication and partially for authorization. The Jetspeed-2 security SPI has been implemented to support LDAP. Embedding Apache directory server has been overall quite a pleasant experience.
The first step consisted in integrating Apache DS with Jetspeed-2 Maven Plugin:
<goal name="j2:_start.ldap">
...
<java classname="org.apache.ldap.server.ServerMain" fork="yes">
<classpath>
<pathelement
path="${maven.repo.local}/${plugin.groupId}/
jars/jetspeed-security-schema-${jetspeed.version}.jar"/>
<pathelement
path="${plugin.getDependencyPath('directory:apacheds-main')}"/>
</classpath>
<arg value="${org.apache.jetspeed.plugin.ldap.conf}"/>
</java>
</goal>
The above code invokes Apache DS ServerMain startup class with the server.xml configuration file parametrized through ${org.apache.jetspeed.plugin.ldap.conf}. As illustrated above, Apache DS is also started with the Jetspeed schema extensions. The pathelement element references jetspeed-security-schema which holds the Jetspeed specific schema extensions. The schema extensions java code is generated using the Apache DS Maven Plugin directory:schema goal. The classes are then compiled and archived as a referencable artifact for the LDAP server. Once the server is started, it is now time to bind to the LDAP server. Jetspeed-2 uses the Sun JDK LdapCtxFactory for its default binding configuration.

Saturday, October 29, 2005

Fostering Tools Communication: Eclipse Application Lifecycle Framework

A few weeks ago, I wrote a blog post comparing both Microsoft Visual Studio Team Server and Eclipse development environments. Since then, I found out about a new Eclipse project that seems quite promising. Eclipse is hosting a new project to develop an Application Lifecycle Framework. A good overview was given by Ali Kheirolomoom at Eclipse World this August. The eclipse ALF purpose is too:
Create a technology framework that will enable a diverse set of vendor tools, irrespective of architecture or platform, to exchange user data, manage business processes and collaborate in support the chosen ALM infrastructure technologies in use by development communities.

The ALF project plans to create a common and extensible domain specific vocabulary to facilitate domain modeling and provide an events and service flows model to enable loosely coupled tools integration. The technology will create a SOA leveraging web
services and web services orchestration to integrate disparate tools sets.
ALF Overview
ALF is designed to build upon the other eclipse tools and to provide additional support for security, web service orchestration, service flow and meta models as illustrated below:
ALF Stack
One example of how ALF could be used is illustrated below:
ALF Use Case
A user adds an issue to an issue tracking system which triggers an event that launches a service flow and determines whether the issue should be added to the Requirement Management System and Project Management System.

ALF plans to develop a meta model vocabulary based on the Zachman framework. The initial focus of the ALF will be on subject areas that cover:
  • Requirements management,
  • Request and issue management,
  • Configuration management and versioning,
  • Business process models
ALF Detailed Meta Model
The ALF appears to me as a key Eclipse initiative which will provide better integrations between disparate tools. It will also go a long way in offering better visibility and metrics at various levels of the application lifecycle.

Saturday, October 15, 2005

Integrating BIRT with Your Application

I recently started to explore BIRT - Eclipse Business Intelligence and Reporting Tool. As illustrated in the following examples available on BIRT's web site, it provides a wide range of reporting and charting capabilities.

One of the features, that I find quite promising is the ability to easily embed the BIRT engine in custom applications. This can easily be illustrated through a basic unit test. The code below illustrates the key elements required to get started:
    /**
     * @see junit.framework.TestCase#setUp()
     */
    protected void setUp() throws Exception
    {
        super.setUp();
        // The directory where the key plugins are located.
        System.setProperty("BIRT_HOME", "C:/.../src/main/resources");
    }

    ...

    /**
     * @throws Exception Throws exception.
     */
    public void testRunReport() throws Exception
    {
        String[] args = {
            // The format
            "-f",
            "html",
            // The output directory
            "-o",
            "C:/.../target",
            // The locale
            "-l",
            "en_US",
            // The encoding
            "-e",
            "UTF-8",
            // The file to generate the report from.
            "C:/.../src/test/resources/helloworld.rptdesign"    
            };
        ReportRunner.main(args);
    }
The BIRT_HOME directory should contains the following runtime plugins required for the embedded engine:
BIRT Plugins

Wednesday, October 05, 2005

Managing the Software Development Process: Microsoft is Getting it Right.

I recently attended a presentation on the upcoming Microsoft Visual Studio Team Suite (MVSTS) and I must say: what Microsoft is coming up with looks very much like an aggregation of the best practices that everyone preaches, all bundled into one very cohesive package. I decided to run a comparison between the tools available as Open Source and how an Open Source stack would compare to MVSTS.

First the Microsoft stack: I found two good resources for describing MVSTS roadmap and getting an overview of MVSTS.
Visual Studio Team Overview

Second the Open Source stack: I decided to focus on the Eclipse set of tools (see references below) and Apache Maven for software project management.
J2EE Open Source Tools

After integrating all the tools out there, the Open Source stack comes fairly close functionally to the MVSTS stack. Unfortunately, integrating all those technologies into one cohesive package requires a good amount of work. I personally feel that this is unfortunate. In my mind it raises some fundamental questions:
  • What purpose are open source foundations fulfilling when developing their product offerings? Is it technology adoption, industry cooperation, technology innovation? Providing a cohesive offering requires making some choices that are difficult in foundations with members with sometimes competing interests. Here Microsoft has a clear advantage. So how can the open source community provide a cohesive tool kit for managing the software development process? Is it a desirable outcome?
  • Can commercial entities leverage a common offering and maintain a coherent strategy and competitive advantage? A lot of the value in commercial offerings comes from the integration of diverse technologies into a cohesive offer. If open source foundations fulfill this role, can commercial entities' offerings still remain attractive? Does this cannibalize product offerings in favor of services?
The answer to most of those questions depends on the type of technology. With regards to tools supporting the software development process; I feel it makes sense to foster collaboration. Providing a more integrated open source offering would serve as a foundation to the open source development ecosystem. The Eclipse foundation has done a wonderful job at doing so, but in a fragmented fashion. This is what Microsoft achieves by investing in its development tool suite. It fosters the adoption of its technology and platform and nurtures its technological ecosystem. I feel that all commercial vendors could benefit with what amounts to a fairly minimal investment. Most of the technology building blocks are already available.

Eclipse References:
- Eclipse UML2 tools
- Test and performance tools
- Testing tools
- Monitoring tools
- Web tools
- SDO tools.

Saturday, September 24, 2005

Idiosyncrasies of java.security.AccessController

As part of cleaning up Jetspeed 2 JAAS RdbmsPolicy, i ran into some not so obvious idiosyncrasies of java.security.AccessController and the differences between doAs(), doAsPrivileged() and whether to pass the AccessControlContext or not.
On the differences between doAs() and doAsPrivileged(), I found a good post of Sun Java Forums:
doAsPrivileged effectively means you are granting
the calling stack your [code's] privileges when executing the code in question. Whereas doAs only associates the subject with the current access control context, all the calling code still requires the permission to be assigned to it (under the subject in question).

Where it gets interesting, is that when implementing a custom policy, and assessing whether the caller is authorized to access the callee, in implies(ProtectionDomain protectionDomain, Permission permission) the protectionDomain does not contain the principals when performing a doAs check. As mentioned in this post on the Java Forum, when the permission check is concerned about the principals in the subject (call to protectionDomain.getPrincipals()) for the security check, the security check should be performed as:
doAsPrivileged(theSubject, anAction, null)

By passing in a null access control context, the caller is essentially saying: "I don't care who called me, the only important thing is whether I have permission when associated with the given subject".

Subtle differences...

Wednesday, September 14, 2005

Making Sense of Identity Management

With the rise of service oriented architecture, maintaining a consistent user identity across multiple enterprise systems is becoming increasingly difficult. In an attempt to address the pain that many large IT organizations go through, the software industry has given birth to an onslaught of standards with the purpose of maintaining a common identity across the enterprise. Jason Rouault from HP has written a great paper that sheds some light on that space: Making sense of the federation protocol landscape. As an introductory reading, I strongly recommend An introduction to identity management as well. I like the following definition for identity management:
The set of processes, tools and social contracts surrounding the creation, maintenance, utilization and termination of a digital identity for people or, more generally, for systems and services to enable secure access to an expanding set of systems and applications.

The following pictures sums it up well from a conceptual standpoint:
Identity Management Overview
In my views, a right identity management strategy can provide a strong competitive advantage to an organization as distributed application or services can leverage a much better known user and therefore increasingly build value added to address their employees, customers, partners, and suppliers needs. As organizations consider service oriented architectures, it is critical to craft an identity management strategy in line with such distributed services.

Monday, September 05, 2005

Key Reports for Monitoring Application Development - Need for Historical Data

When managing distributed software development teams with wide ranging skills sets, code base intelligence becomes critical to ensure the quality of the ongoing development effort. Here are some lessons learned worthwhile sharing:
  • Unit test code coverage should be put in historical context: Tools like Cobertura and Clover provide great unit test coverage reports; however, most default reports provide point in time coverage and as a result become difficult to use as a metrics for the development effort. To create a successful developer testing practice, developers activities should be measured against specific targets. Setting developers unit testing targets is a great practice to foster the creation and development of unit tests as an implicit and routine part of their activity. Historical measurement is critical to be able to manage such activity efficiently. Clover provides such historical coverage report.
  • Unit tests are necessary but beware of bad tests: Enforcing unit test coverage is important to facilitate future development work and improve code quality (see previous post), however poorly written unit tests can provide a fall sense of confidence that proper checks are in place. Unit tests that provide poor assertions checks will result in reasonable code coverage but will not provide the proper checks for guaranteeing the code base quality. In addition to unit test reports, and code coverage reports, unit test code should comply to a specific set of rules as illustrated by the PMD Junit rules.
  • Measure your developers activities: Activity reports measuring development activity can provide great insight on the evolution of a code base and the activity level of various contributors. StatCVS provides a very detailed set of statistic that can be useful to understand and monitor the activities of a large and distributed team.
  • Dashboard and code quality indexes: Dashboard are critical for management to be able to measure and assess the evolution of various components of a large project. Maven provides a flexible plugin for a point in time dashboard. However, in order to properly follow the evolution of a large development project, historical data is important as it provides the ability to identify key areas of improvement as well as measurable targets. Continuous improvement and continuous refactoring often advocated by agile development methodology advocates requires good metrics to measure improvement and justify the benefits.
Those reports provide a sample set of tools that can be useful when managing development teams. However, one key issue for management is to be able to correlate metrics improvement with critical business metrics such as development effort cost savings (shortened features development time lines, decrease bug level, shortened quality control, etc). More thoughts to come on that subject...