AI and automationWebsitesApps and MVPsManaged IT Port Alberni Start a project
Vancouver Island

IT for First Nations administration, set up so the data stays yours.

Valley Edge is based in Port Alberni. A band office runs finance, health, social development, education, lands and housing on one small stack of systems. This page is about how that stack is built so control over the information sits with the Nation, and stays there when a provider changes.

Remote first, on site when it is physical. Tenants and domains in the Nation's name.

  • Tenants and domains in the Nation's name
  • Data governance decided by the Nation
  • A written exit from the first month
  • No named community on this page
Where the systems are

A band office is five organisations sharing one network.

Administration, health, social development, education, lands and housing sit in one building or a few buildings, on one domain, often on one internet connection. They hold very different information and answer to different rules about it. Most of the IT problems in an administration office start there rather than with a broken laptop.

Administration and finance

Payroll, accounts payable, the financial system, membership and band records, and the council and committee documents that everything else is decided in. This is where the highest-consequence records live, and it is usually where access is widest, because a small number of staff cover several jobs each and somebody once needed the folder in a hurry. Narrowing who can reach what here has the largest effect of any single change on this page, and it is a configuration decision rather than a purchase.

Health and social development

Client files, case notes, referrals, and in many communities a health information system a regional or provincial authority also touches. The obligations attached to those records usually arrive through a funding or information-sharing agreement rather than through one statute, so the workable question is which agreement covers a given record and who that agreement allows to open it.

Education

A band-operated school, tuition agreements with the school district, post-secondary sponsorship, and the enrolment reporting that funding depends on. Student and sponsorship files are personal information about minors and about families, kept for years, and they are frequently the oldest data in the building and the least looked at.

Lands, resources and referrals

Referral tracking, mapping and GIS, environmental monitoring, archaeology, and traditional-use material. Some of this is knowledge the Nation may never want copied, and how it is handled is the Nation's decision and nobody else's. What IT contributes is knowing where it currently sits, who has it synced to a laptop, and whether any of it is on somebody's personal cloud account.

Housing and public works

Tenancy records, maintenance requests, work orders, asset lists, and the water system paperwork. Usually the least computerised department and the one where a spreadsheet on a single desktop is quietly doing the job of a shared system, with no backup and one person who knows how it works.

The one connection under all of it

Most of the above depends on a single link, and in a lot of communities that link is long, thin or satellite. A design that assumes it is always there fails in a specific way: nobody can log in, files will not open, and the phone system goes with it. That constraint belongs in the design rather than in the apology afterwards.

Data sovereignty

OCAP is not a certificate a vendor can hold.

It is a statement about who information belongs to. A provider cannot be compliant with it the way a provider is compliant with a security standard. What a provider can do is build a setup that does not quietly take control away.

The First Nations principles of OCAP - ownership, control, access and possession - were developed in 1998 and are stewarded by the First Nations Information Governance Centre, which holds the registered trademark. Ownership says a First Nation owns information about its community collectively, in the way an individual owns their own personal information. Control says the Nation has the right to control how that information is collected, used, shared and managed. Access says the Nation decides who may reach it. Possession, which is the concrete one, refers to physical control of the data, and it is the mechanism that makes the other three enforceable rather than aspirational.

Possession is also the principle a badly configured system breaks first, and it breaks it silently. If the shared drive is a folder inside a provider's own cloud account, possession is not with the Nation. If the Microsoft tenant was created under a vendor's partner subscription and no member of the Nation's staff holds a global administrator account, control is not with the Nation. If the backups sit in a vendor's backup product with no export the Nation can run itself, neither is. None of those is a philosophical position. They are configuration facts, they are checkable in an afternoon, and they are the first things worth checking.

So the first job on any engagement is an inventory, and it is written down and handed over rather than kept. Which accounts exist. Which of them the Nation owns outright. Where the domain is registered and in whose name. Who currently holds global administrator, and how many of them there are. Where each department's files physically sit. What is synced to a personal device or a personal account. What renews automatically, on whose card, and what happens to it if that person leaves. Most administrations are surprised by at least one answer, and the ones that hurt are the accounts still in a former employee's name.

The privacy law question is the one most often answered wrongly, in both directions. British Columbia's Freedom of Information and Protection of Privacy Act governs provincial public bodies and the local public bodies named in it, such as municipalities and regional districts. A First Nation government is not one of those, so FOIPPA does not apply to a band administration by default. That does not make the question disappear; it moves it. Obligations arrive through the funding and information-sharing agreements covering particular programs, through federal law where a Nation's commercial activities are in scope, through the Nation's own laws and policies where it has made them, and through OCAP. It is a more scattered picture than a municipality's, not a lighter one, and the practical consequence is that the governing document for a given system has to be read rather than guessed at.

The cloud question splits into two halves that are usually collapsed into one word. Residency is where the data is stored, and the major platforms operate Canadian regions and publish which of their services keep data inside them. Sovereignty is whose law can compel access to it, and a Canadian data centre operated by a company headquartered in another country does not answer that half. Neither does a Canadian company reselling the same platform. That is not an argument against using them, and this page does not make one. It is an argument for deciding it deliberately, system by system, and writing the decision down while there is time to think about it.

Underneath all of it is ordinary managed IT: monitored and patched machines, Microsoft 365 administration, endpoint protection, backup with a restore somebody has actually run, and the network. That work is the same work described on the managed IT page. What changes here is not the technology. It is who decides, what is written down, and what has to be true before anything is switched on.

How an engagement is set up

Three lists, agreed before anything starts. The third one never moves.

Most disputes between an organisation and its IT provider are not about work quality. They are about a boundary nobody wrote down. These are written down, in the agreement, in this order.

Decided by the Nation
  • Where each category of information may be stored, and in which country
  • Who holds global administrator, and how many of those accounts exist
  • Which departments' records are separated from which, and how strictly
  • What a provider is permitted to see, and what is closed to it outright
  • Whether territorial and cultural material belongs on a general-purpose system at all
Built and kept up by us
  • The tenant, accounts, groups and permissions that carry those decisions
  • Monitoring, patching and endpoint protection on the machines
  • Backup, and a restore that has been run rather than assumed
  • Joiners and leavers handled on the day, not at the next audit
  • A written record of what was changed and when it changed
Never ours
  • The domain. Registered in the Nation's name, or it is not set up
  • The tenant. The Nation holds the top administrator account, always
  • The data. No copy sits on a provider account the Nation cannot see or delete
  • The decision to leave. A documented exit exists from the first month
Constraints that are real here

Three things shape this work before any of it is technical.

These are not difficulties to be sympathetic about. They are inputs to a design, and a provider that has not accounted for them will build something that works in Port Alberni and fails at the end of the road.

The connection is not a given

Households on reserve in this province still sit well behind the national average for service meeting the federal speed target, and several communities on the west coast of the Island are at the end of a long line, on satellite, or on a single link with nothing behind it. A cloud-only design fails there predictably. The answers are unglamorous: cached credentials so staff can still log in, local copies of what people genuinely need offline, a documented fallback for the systems that stop the office when they stop, and an honest view of what a second link is actually worth against what it costs.

Designed for the connection you have.

The reporting runs on somebody else's calendar

Program funding arrives with reporting attached, often on a fiscal year that is not the calendar year, and often in a format the funder sets rather than one your systems produce. That shapes IT twice over, and neither way is obvious in advance: capital has to be committed and spent inside a window, and the numbers a report needs have to be findable in a system nobody built to produce them. Knowing which report is due, and what it will ask for, before the month it falls in is most of the work.

Ask what the report needs, first.

Small teams, wide access, real turnover

In an office of fifteen people covering the work of thirty, everyone ends up able to reach everything, because refusing access once cost somebody a whole day. Then a term position ends and the account stays open, and the next audit finds it. The answer is not a lecture about least privilege. It is groups that match the departments as they actually are, a leaver process that runs identically every time, and a password manager so that a shared login is at least a controlled one.

Groups, not exceptions.

What this page does not claim

No community is named here. That is deliberate.

Valley Edge is based in Port Alberni, within the traditional territory of the Tseshaht and Hupacasath First Nations. This page describes how the work is set up. It names no community as a client, quotes nobody, and claims no endorsement, no certification and no completed government work, because none of those can be shown. Publishing a Nation's name as a reference without its written agreement would itself be the kind of decision the rest of this page argues against.

Before anything starts

The six questions that come up first, answered the same way here as on the phone.

Do you have to be certified in OCAP to do this work?

There is no vendor certification in OCAP, and anyone selling one is selling something else. OCAP is a set of principles asserted by First Nations and stewarded by the First Nations Information Governance Centre, which holds the registered trademark. The Centre runs a course on the fundamentals of the principles, which is training rather than accreditation. What matters on an IT engagement is narrower and checkable in an afternoon: whether the Nation owns the tenant, the domain and the data, whether it can see and revoke what a provider can reach, and whether it can leave with everything.

Does FOIPPA apply to a band administration?

Not by default. British Columbia's Freedom of Information and Protection of Privacy Act governs provincial public bodies and the local public bodies listed in it, such as municipalities and regional districts, and a First Nation government is not one of those. Obligations arrive instead through the funding or information-sharing agreement covering a particular program, through federal law where commercial activity is in scope, through a Nation's own laws and policies where it has made them, and through OCAP. That is a more scattered picture than a municipality's rather than a lighter one, and it means the governing document has to be read rather than assumed.

Can the data stay in Canada?

For most of what an administration office runs, yes, and there are two questions hiding inside that one. Residency is where the data is stored, and the major cloud platforms operate Canadian regions and publish which services keep data in them. Sovereignty is whose law can compel access to it, and a Canadian region operated by a company headquartered elsewhere does not settle that half. Both are true at once. The answer should be written down per system, because the moment somebody asks is not the moment to start looking.

What happens if we want to change providers?

You take everything, and the process was written down before you needed it. The domain is already registered in the Nation's name, the tenant is already yours, administrator accounts are yours to reassign, and the backup has an export your own staff can run without us. A handover is a day of work when it was planned for and a hostage negotiation when it was not, and which of those it will be is decided in the first month rather than the last.

The community is a long way out on a gravel road. Does this work?

Most of a managed agreement is remote and does not care where the building is. Hardware does. What matters is deciding in advance which failures need somebody physically present, how long that takes to arrange, and what the office does in the meantime. That is a conversation about the specific site and the specific link, and it is worth having before the outage rather than during it.

Do you work with the administration or with the departments?

Both, and the difference matters more here than in a business of the same size. The administration usually holds the agreement and the budget. The departments hold the actual work and the actual constraints, and health and education in particular carry obligations the administration does not see day to day. A setup designed with only the administration in the room tends to break in a health office about three months later.

Tell us what the office runs on.

Which systems, which departments, and who currently holds the keys. We will tell you what is actually in place and what it would take to put the ownership where it belongs, in writing, before anyone talks about an agreement.

info@valleyedgeconsulting.io  ·  778-488-8618