IT for First Nations administration, owned by the Nation.
Finance, health, social development, education, lands and housing usually share one small set of systems. We build and run that set so control over the information sits with the Nation, and stays there if a provider ever changes.
Remote first, on site when the problem is physical. Tenants and domains in the Nation's name from day one.
- Sign-in blocked, all sessions revoked9:14 am
- Mailbox converted to shared, office manager given access9:16 am
- Licence removed, back in the pool9:21 am
- Tenant and domain in the Nation's name
- Data governance set by the Nation
- A written exit plan from the first month
- No community named without its consent
One office, five departments, one network underneath.
Administration, health, social development, education, lands and housing often share a building, a domain and an internet connection. Each holds different information under different rules. That shared footing is where most administration IT problems begin, well before any laptop breaks.
Administration and finance
Payroll, payables, the financial system, membership and band records, and the council documents everything else is decided in. These are the highest-consequence records, and access is usually widest here because a few staff cover several jobs. Narrowing who can reach what is the single biggest improvement on this page, and it costs a configuration change, not a purchase.
Health and social development
Client files, case notes, referrals, and often a health information system a regional or provincial authority also touches. The obligations usually arrive through a funding or information-sharing agreement rather than one statute. So the useful question is which agreement covers a record, and who it allows to open it.
Education
A band-operated school, tuition agreements with the district, post-secondary sponsorship and the enrolment reporting funding depends on. These files hold personal information about minors and families, kept for years. They are often the oldest data in the building and the least looked at.
Lands, resources and referrals
Referral tracking, GIS, environmental monitoring, archaeology and traditional-use material. Some of it the Nation may never want copied, and that call belongs to the Nation alone. Our part is knowing where it sits today, who has it synced to a laptop, and whether any of it lives in a personal cloud account.
Housing and public works
Tenancy records, maintenance requests, work orders, asset lists and water system paperwork. Often the least computerised department, where one spreadsheet on one desktop quietly does the job of a shared system, with no backup and one person who understands it.
The one connection under all of it
Nearly all of it rides on one link, and in many communities that link is long, thin or satellite. A design that assumes the link is always up fails in a predictable way: nobody can sign in, files will not open, and the phones go too. We design around the connection you have.
OCAP is not a certificate a vendor can hold.
OCAP describes who information belongs to. A provider cannot be compliant with it the way it can pass a security standard. What a provider can do is build a setup that never quietly takes control away, and we build to that line.
The First Nations principles of OCAP - ownership, control, access and possession - were developed in 1998 and are stewarded by the First Nations Information Governance Centre, which holds the registered trademark. Ownership says a First Nation owns information about its community collectively, in the way an individual owns their own personal information. Control says the Nation has the right to control how that information is collected, used, shared and managed. Access says the Nation decides who may reach it. Possession, which is the concrete one, refers to physical control of the data, and it is the mechanism that makes the other three enforceable rather than aspirational.
Possession is also the principle a badly configured system breaks first, and it breaks silently. A shared drive inside a provider's own cloud account means possession is not with the Nation. A Microsoft tenant created under a vendor's partner subscription, with no Nation staff holding global administrator, means control is not either. Backups in a vendor product with no export the Nation can run itself fail both. These are configuration facts, checkable in an afternoon, and we check them first.
So every engagement opens with an inventory, written down and handed to the Nation. Which accounts exist and which the Nation owns outright. Where the domain is registered, and in whose name. Who holds global administrator, and how many do. Where each department's files physically sit, what is synced to personal devices or accounts, and what renews automatically on whose card. Almost every office finds at least one surprise, and the painful ones are accounts still in a former employee's name.
The privacy law question is often answered wrongly in both directions. British Columbia's Freedom of Information and Protection of Privacy Act covers provincial public bodies and the local public bodies named in it, such as municipalities and regional districts. A First Nation government is not one of them, so FOIPPA does not apply to a band administration by default. The obligations still exist; they arrive through program funding and information-sharing agreements, through federal law where a Nation's commercial activity is in scope, through the Nation's own laws and policies, and through OCAP. The picture is more scattered than a municipality's, not lighter, so the governing document for each system gets read rather than guessed at.
The cloud question has two halves that usually get collapsed into one word. Residency is where data is stored, and the major platforms run Canadian regions and publish which services stay inside them. Sovereignty is whose law can compel access, and a Canadian data centre run by a company headquartered elsewhere does not settle that half. Neither does a Canadian reseller of the same platform. That is no argument against using them. It is an argument for deciding deliberately, system by system, and writing the decision down while there is time to think.
Underneath all of it is solid managed IT: monitored and patched machines, Microsoft 365 administration, endpoint protection, backups with a restore that has actually been run, and the network. That work is the same as on the managed IT page . What changes here is who decides, what gets written down, and what has to be true before anything is switched on.
Three lists, agreed up front. The third one never changes.
Most disputes between an organisation and its IT provider come from a boundary nobody wrote down. We write these into the agreement, in this order, before any work starts.
Decided by the Nation
- Where each category of information may be stored, and in which country
- Who holds global administrator, and how many of those accounts exist
- Which departments' records are separated from which, and how strictly
- What a provider is permitted to see, and what is closed to it outright
- Whether territorial and cultural material belongs on a general-purpose system at all
Built and kept up by us
- The tenant, accounts, groups and permissions that carry those decisions
- Monitoring, patching and endpoint protection on the machines
- Backup, and a restore that has been run rather than assumed
- Joiners and leavers handled on the day, not at the next audit
- A written record of what was changed and when it changed
Never ours
- The domain. Registered in the Nation's name, or it is not set up
- The tenant. The Nation holds the top administrator account, always
- The data. No copy sits on a provider account the Nation cannot see or delete
- The decision to leave. A documented exit exists from the first month
Three things shape this work before the technology does.
We treat these as design inputs. A setup that ignores them works in Port Alberni and fails at the end of the road.
Designed for the connection you have.
Ask what the report needs, first.
Groups, not exceptions.
No community is named here. That is deliberate.
We are based in Port Alberni, within the traditional territory of the Tseshaht and Hupacasath First Nations. This page explains how the work is set up. It names no community as a client, quotes no one, and claims no endorsement or certification. Publishing a Nation's name as a reference without its written agreement would be exactly the kind of decision this page argues against.
Before anything starts
The questions that come up first, answered the way we answer them on a call.
Do you have to be certified in OCAP to do this work?
No vendor certification in OCAP exists, and anyone selling one is selling something else. OCAP is a set of principles asserted by First Nations and stewarded by the First Nations Information Governance Centre, which holds the registered trademark and runs a fundamentals course that is training, not accreditation. What matters on an IT engagement is checkable in an afternoon: whether the Nation owns the tenant, the domain and the data, whether it can see and revoke what a provider can reach, and whether it can leave with everything.
Does FOIPPA apply to a band administration?
Not by default. British Columbia's Freedom of Information and Protection of Privacy Act covers provincial public bodies and the local public bodies listed in it, such as municipalities and regional districts, and a First Nation government is not one of them. Obligations arrive instead through the funding or information-sharing agreement for a program, through federal law where commercial activity is in scope, through the Nation's own laws and policies, and through OCAP. So we read the governing document for each system rather than assume it.
Can the data stay in Canada?
For most of what an administration office runs, yes. Two questions hide inside that one. Residency is where data is stored, and the major platforms run Canadian regions and publish which services keep data there. Sovereignty is whose law can compel access, and a Canadian region run by a company headquartered elsewhere does not settle it. We write the answer down per system, so it is ready before anyone asks.
What happens if we want to change providers?
You take everything, and the process is written down before you need it. The domain is already registered to the Nation, the tenant is already yours, administrator accounts are yours to reassign, and the backup has an export your own staff can run without us. A planned handover takes a day. We plan it in the first month.
The community is a long way out on a gravel road. Does this work?
Most of a managed agreement is remote and does not care where the building is. Hardware does. We decide in advance which failures need someone on site, how long that takes to arrange, and what the office does meanwhile. That plan is specific to your site and your link, and we make it before the outage, not during it.
Do you work with the administration or with the departments?
Both, and here it matters more than in a business of the same size. The administration usually holds the agreement and the budget. The departments hold the actual work and its constraints, and health and education carry obligations the administration rarely sees day to day. So we design with the departments in the room, because a setup built without them tends to break in the health office three months later.
Tell us what the office runs on.
Which systems, which departments, and who holds the keys today. We come back with what is actually in place and what it takes to put ownership with the Nation, in writing, before any agreement is discussed.
Book a call