009. ADR: ACL Workflow Architecture Change
Date: 29-01-2026
State: Proposed/Accepted/Deprecated/Superseded
Status: Approved
Context
The current ACL workflow in ADME, responsible for creating data and user groups, is implemented as a GitHub Actions pipeline. Currently, data office groups are generated by iterating through a static list.
With SMDA now publishing all data office groups as a kind in OSDU, we propose updating the workflow to:
- Read and create data office groups directly from this kind.
- Establish the OSDU kind as the definitive source of truth for data office groups.
Main Proposed Changes
- Configure the workflow to perform an initial run on new ADME instance creation.
- Create a new workflow that pulls from the
eqnr:dataoffice:entraidgroup:1.0.0kind instead of the static list.
As-Is Architecture Diagram
Proposed Architecture Diagram
Impacts and Risks
Risk Level: Medium
- Backend changes for data office groups should not affect end users.
Considerations
- Investigate how Entra ID integration in ADME would operate; it may not require user groups.
- Multiple user groups currently correspond to a single data office group. The Entra ID kind does not provide these mappings.
- Ensure data office group names match the static list to avoid creating similarly named groups, which may cause confusion.
- Dependency on SMDA: the OSDU kind must be available before all data office groups can be created. Currently, Data Office does not provide an API endpoint outside OSDU. They may provide an Excel file, but updates cannot be guaranteed.
Consequences
- The updated ACL workflow will dynamically create data office groups based on the list provided by Data Office instead of using a static list.
- Reduces the risk of outdated or mismatched group definitions in ADME.
Last update:
2026-09-14