An issue has been raised, not for the first time, regarding sensitive data being stored on Nextcloud, which we give every Exploring Member access to regardless of whether or not they become Associate Members. Specifically, this concerns the Members Registry, which includes everyone’s address, phone number and NRN. However, it may be worth thinking about in terms of other data that we have on there, e.g. potential site information.
One way to approach this would be to give limited access to certain documents, in the same way that only Ugne currently has access to the confesseur info. Or this could just apply to certain information, e.g. NRNs.
Another way to approach this is to only give access to Nextcloud to Associate Members, with the exception of certain documents (as we already do on the ‘Key documents’ thread on Edgeryders). It’s unlikely that many people go that deeply into the furthest corners of Nextclound during the exploring phase. However, this may have an impact on when things like the ‘Presentation fiches’ and ‘Skills and experiences’ docs get filled in.
It doesn’t seem like a particularly complicated issue to solve, but I’m not sure what’s best to do so. Which is why I’m tagging:
@reef-governance
@reef-it
@alberto (as the person who currently collects the NRNs for the GA minutes)