Tuesday, August 08, 2006

Solutions innovation in a product driven company

Creating software solutions to business problems is an enjoyable, creative and fulfilling process. The full lifecycle of creating a true solution from nothing requires a range of skills that can only be successfully be contributed by a team with people from different backgrounds.

I'm writing this post for two reasons. Firstly, I'd like to lay out (38,000 feet view) for discussion how my team works to create commercial solutions from a blank page (much like the Account Opening solution I talk about on this blog). Secondly, the organization I'm in is rapidly evolving so I'm hoping that writing this down will help me absorb and respond to how I best fit. When there are changes to the people around me it still unsettles me, making it hard to concentrate on my real job - this is not fear of change, more the primeval fight or flight response kicking in.

What is a solution?

I work in a group that produces what Gartner seems to call Composite Process Solutions. For us these are solutions that exploit the strengths of the Vignette product set and competencies, more directly addressing business problems than the components can alone.

For a quick background, Vignette is an ECM vendor with core products offering best of breed web content management, portal, collaboration, document imaging, workflow and records management, so there are a lot of components to play with. At the same time, we acknowledge that we can't do everything, so we team with partners to help us create more complete solutions.

Account Opening

Account Opening for high-value financial services products is a solution that is being pushed through the lifecycle at Vignette. Few vendors can present a solution to the many business problems that financial institutions experience during account opening. Even the large consultancies and systems integrators are not presenting a clean, well defined story of what to do in this space, especially for high-value and high-risk products like annuities and mutual funds.

Perhaps the most complete vision that is out there right now is IBM with a heavy focus on banking. This was strengthened on August 2nd by its acquisition of Webify, strengthening IBM's online and SOA capabilities with Webify's prebuilt adapters and toolkits, alongside the standard IBM BPM and WebSphere 'integration' base. Smaller companies have reasonable solution sets for specific market segements. Fineos (from Ireland) have well packaged solutions for retail insurance, CashEdge has specific point components for banking.

Surprisingly the ECM/BPM vendors have not done a good job of leveraging their past experience in handling paper applications for finserv and insurance to address the new online world.

Rearing baby solutions

How do we create net-new solutions and raise them til they have flown the nest? I don't believe that there is anything proprietary in here and the process pulls from influences like Geoffrey Moore's Crossing the Chasm, Deloitte's PILM, Accenture's innovation strategies and our own thinking. Certainly at this level you wouldn't guess what it is that we are doing that is particularly novel. And not being in a consultancy firm, I'm not in a position to tell you the particularly smart things we do!

Imagine a rough view of a solution lifecycle, starting at nothing and progressing (hopefully) through to being a fully commercial contributor to the company's bottom line:




I know that there are many ways to run through this process and many people will have their own view on this type of 'innovation lifecycle'.

My group is responsible for developing ideas from the many feeds we have, creating business cases and seeking funding for those solutions that appear to have real market requirement that we can address, so that eventually we can produce a commercial solution or two that provides an ROI on our investment. Then we "repeat as necessary".

Its all a fairly intuitive thing: you create new ideas, filtering them as they pass through a funnel so that those that don't fit your profile drop out, giving the best ideas that are potentially most profitable a chance to be developed and commercialized. At each stage the filter focuses on different things, ensuring that the company doesn't just keep pouring resources into a money pit if earlier observations or assumptions prove to be incorrect.

The non-intuitive piece is learning how to sell the best solutions to your own company. Not only do you need to sell to the executive team to gain investment (a good business case is essential), you also need to convince the field sales, marketing, product management, services, licensing, engineering, and others I may have forgotten to mention, that the solution is worth their effort to pay attention to. Without the support of the rest of the corporate world even the best solutions will just fade away without ever being seen by a potential customer.

My experience

In the last 18 months I have built out business cases for a range of compliance, governance, business improvement and online b2b solution use cases. Not all made it through the funnel - commercialization is our objective for the best-fit solutions only.

For several potential solutions we could not demonstrate that this group could provide value in developing the solutions further. That does not mean that they are not good opportunities for per-customer engagements. Most of our solutions are available to the field salesforce to chase on specific deals if they choose, so although our run rate may not be high on 'commercialized' solutions, little we produce is absolutely wasted.

And that is the joy of risk-taking. Choosing to bury a solution late in the process may be the most appropriate thing to do, given new priorities, new findings, or an unexpected response from the market segment you have selected.

An essential thing to bear in mind is that it is important not to become emotionally attached to any one pet solution. The strong opinions, weakly held approach is essential here, both when convincing the salesforce of the merit of what you are asking them to chase, as well as when making your own decisions about where to go next.

Teams are important

The group I work with I consider to be partially intrapreneurial - see Scott Gatz for an interesting post or two on this subject and my thoughts on it. We were, until last monday, a group of four, with a range of experience and skills: business analysis, accounting, product marketing, professional services, training, management, software development, systems architecture, sales. I fill the Solutions Architect role based on the broad but shallow set of skills I have within this set.

In the true spirit of intrapreneurship we accept a degree of risk that is unusual within the organization (outside of field sales maybe). We are all dependent on one another. An article from Pinchot & Company says this:
The purest intrapreneurial team consists of volunteers recruited to the idea by one or more lead intrapreneur(s). They form a core team which stays with the project from its early stages, well past its initial commercialization or implementation.

Because of the influence the 'lead' has and the requirement to work closely together as a tight group for quite a period of time, the team and especially the attitudes of the people within it, is extemely important.

Being honest to yourselves is essential.
Don't fall for your own hype. We are not entrepreneurs after all - my house and health are not riding on this one solution, so I can perhaps show a little more than blind faith in my approach being right. Being honest with those around me and assuming that it is mutual, is essential to what we are doing.

What next?

As I have hinted at all through, solutions are enjoyable beasts to work with, but they are truly wild animals. They are tamed by the people that lead them and refine them.

Right now my group is facing a lot of upheaval in terms of organizational change. This is distracting in terms of knowing what to focus on in the near term. This post has been tough to write, although its been useful to help me to get myself balanced for the next big shift. My apologies if its also been tough to read.

Either way, I hope that it has been a little insight into the world of solutions innovation, inside a company that is better at pure product technology innovation. We are all learning this stuff, and I hope we can continue to help the company truly capitalize on its investment.

Technorati tags:

Monday, August 07, 2006

Electronic signatures - physical tokens are coming

Last week I was talking about the different mechanisms that could be used by financial institutions to provide electronic signatures for users.

It seems that adoption of some of the more secure mechanisms for authenticating users and signing transactions is accelerating, to supplement the all too easy to obtain username and password credentials.

Electronic signatures replace the traditional wet signature on paper in several scenarios, when the customer:

  • Submits an application form for a new financial product or service
  • Acknowledges consent for a transaction
  • Requests access to online management of the account through a secure web-site
As I discussed in a background post, one of the hardest components of an electronic signature is not so much its use, but its initial creation with the identity of the customer. Once the customer is known and trusted by the institution there are many mechanisms that can be used to provide secure electronic signatures, the complexity and strength required is dependent on the value and risk of the transactions being performed.

Since username/password combinations are not considered particularly strong, either for transaction signatures or for online access to secure web-sites, biometric and smart-card type tokens were discussed. It seems that as they strive for greater online security, two UK banks are introducing token based systems to supplement username/password credential for access to their online banking secure sites and therefore providing more effective non-repudiation of transactions.

Bankwatch discusses two banks, Barclays and Lloyds TSB that are approaching the security issue with security tokens. In addition, the source of the Bankwatch information, the Scotsman.com: Banks introduce electronic password gadget to beat rise in internet fraud mentions that other UK banks are looking to distribute secure, one time password generation devices, to crack down on the GBP 23 million (approx. USD 40 million) in online fraud, and probably the more worrying abandonment of online services.

The additional security relies on the customer's possession of a physical token that enables him or her to generate a one-time password that is used for access to a specific account. The one-time password prevents phishing-scams, such as an official looking email from a scammer that directs a users to an official looking website requesting the user to log in to manage their account, thus capturing their online credentials, and trojans that read passwords entered into a browser. Even if a scammer gets hold of a user's credentials they are invalid.

Lloyds TSB and Barclays are approaching the tokens from different directions, although aiming to produce the same result:

  • Barclays: Bank card 'chip' reader, where the user pushes their card into a device that confirms their card is valid and generates a password for the web-site
  • Lloyds TSB: Rotating random password generator, key-fob with an LCD display
Both approaches ensure that the customer has the security token in their possession at the time of accessing the web-site.

The bank card approach relies on the European 'chip and PIN' technology that has a secure chip embedded in all credit and debit cards, and does not rely on the easily cloneable magnetic stripe. A single reader could be used by with cards for multiple accounts and provides a familiar approach to most UK and European card users.




The key-fob approach does not need a card reader device to be provided to customers, but does require distribution of battery powered key-fobs that will need to be periodically replaced, and will potentially require a fob to be provided for each account to be serviced online. These devices, like the SecurID from RSA have been trusted for access to secure IT systems for many years.



In the US, the FFIEC has mandated two-factor authentication, recognizing that a username and password pair is not enough security and is subject to trojans and phishing. At this moment the US banks have provided online approaches, not physical devices. Instead they try and offer a second customer visual or memory driven approach to recognizing secure sites.

As with many financial security issues in the US, the cost of infrastructure is often cited as a barrier to change. Perhaps the cost of online fraud and customer mistrust of online services are bigger drivers. By addressing the security of online banking style web-sites with physical tokens, financial institutions also provide an instant solution to providing secure electronic signatures for high value/risk transaction consent.

Technorati tags:

Thursday, August 03, 2006

Google AdSense to enhance corporate knowledge searching

Google AdSense is the technology that enables web publishers to present advertisements that are relevant to the content of the site and page. According to Google, the technology can understand the context of words on a page, to achieve more targeted ads. The assumption is that readers are most likely to be interested in, and therefore click on, ads that are most relevant to the text they are reading.


This is not a 'how to make money from blogging' post

You'll see I have experimented with some low-key ads at the top and bottom of each page, and have some thoughts about the technology -- I'm not qualified to suggest how to manipulate readers and Google ads in combination to achieve click through revenue (I'm not likely to become rich, or even moderately better off, through ads on this blog).

Instead I believe that the AdSense technology has some applicability to enterprise knowledge management applications, to facilitate the discovery of hidden information within and across enterprise knowledge stores, document libraries, intranet portals and other information resources. Let's call this capability KSense (K is for Knowledge...).



A use case
Imagine the following use case...

I'm sitting in Boston Logan airport, and have finally got my battered old T40 laptop's WiFi to connect. It's 6:30am (I'm not a morning person so I'm sitting close to Starbucks) and I'm doing a quick last minute piece of research around the use of enterprise portals in the federal government. I'll be flying down to see a certain potential customer with offices in a large, unusually shaped building in DC ('I could tell you, but I'd have to kill you' jokes get old fast).

I go to my corporate collaboration and knowledge management site (yes, Vignette my employer actually uses its own software, and its good), login and search for 'federal portal'. It returns me a list of workspaces and documents that meet the criteria: IRS, USPS, NASA...

As I click in to any of these items the system allows me to drill deeper and deeper into the information in that customer workspace. When a trail goes cold I come back up to the search results and traverse a different route.

What I really need is KSense.


Corporate knowledge AdSense

As I click through the corporate knowledge store I would like to see suggestions of related documents and workspaces, much like I see Google ads. These suggestions, KSense ads, would be based on the content of the current page or document I was viewing. Ads would be selected based on the content of other documents and workspaces, as well as their attributes or tags.

KSense ads related to my current view would allow me to follow my research trail by meandering across workspaces, libraries and information resources, gradually refining my context. WIth search I typically drill-down until I hit dead-ends then return to my search results to try again.

Some of the other ideas that drive AdSense could also be applicable. Document and workspace owners could rank the importance of their content for specific search terms, much like Google advertisers do, to promote ideas, or make common information easier to find from a single search.

For example, a product launch for new intranet portal capabilities could be tagged to appear in an ad banner at the top of search results for 'intranet portal', or through KSense relevant ads on a page containing portal information. For specific periods of time users' attention could be drawn to new information they may otherwise not be aware of. This enhances current search and subscription mechanisms significantly, and enables organizations to promote new information and products more effectively with their own employees.


Extending KSense

Although AdSense may present ads most relevant to the text on the page, it takes no account of the actual role of the reader. On this blog (here is an example page addressing BPM) the CIO of a major finserv organization may in fact be interested by the ad:

Improve your processes
A free guide to Business Process Management (BPM) solutions.
Ads by Phil

Despite the fact that the ad is well matched to the context of the page it is unlikely that a more typical reader will be so inclined to click, unless he or she is doing some serious research of BPM vendors.

For example, if AdSense knew that the profile of the user was 'software developer; gamer; Boston, age 26', and that she had just landed at this blog having clicked through from the Scobleizer (yeah, I'm dreaming), the following advertisement may be more likely to earn some click-through revenue:


WiCkEd-FaSt GrApHicS CaRd
Render 128 million pixels / sec for incredible Red-Sox gaming realism.
Ads by Phil

Without using nasty click-tracking and spyware on users' PCs this is not likely to happen in the web-world. In the corporate world its in big-brother's interest to know its users a little better, so KSense could benefit from user profiles and viewing habits.

For example, within Vignette it could be that my profile says 'Solutions Architect; product experience: EDRMS, BPM;recently viewed: federal portal, DoD, intranet'. This should drive a different set of KSense ads for both search and browsing than my boss 'VP; product / solution marketing; management; recently viewed: vacation policy, competitive analysis'.


Summary

Enterprise search tools such as Endeca provide the ability to be presented with human classified categories to further refine search results. This is powerful, but it seems very tightly controlled through human categorization (for an example, see Forrester's view of search). Categories within search results can be used to drill down to the information you are hoping to find.

I would like to see the more freeform capabilities of KSense used in organizations. I think that the context aware and 'advertising' paradigm could help users find more useful information that would be otherwise lost in the cloud of traditional search results, and the typical route where users are forced to drill-down deeper at every click. The ability to meander across workspace and library boundaries through KSense ads seems to open up a lot of corporate knowledge and information.

Electronic signatures for financial services - management and mechanisms

In my previous post, Electronic signatures for financial services - a background, I laid out some of the issues that surround electronic signatures and identity when a customer attempts to open a new account for a financial services product.

The request for a customer's signature at the point of applicationis not a one off event just to confirm agreement with the terms. It is the mechanism that a customer uses to confirm that he is the same 'Mr X' that owns the account (not the other 'Mr X' who could be posing to be him). Signing a document is the ceremony that represents his acceptance of terms or consent to perform a transaction, and may be compared to the original if Mr X ever tries to claim an incorrect or fraudulent transaction.

In an online world it is tough to ensure the security and integrity of electronic signatures. For different scenarios something stronger than username and password is required, since the agreements and transaction consents may high value and high risk to both institution and customer.

Electronic signature approaches

For higher value or higher risk accounts, such as annuities, mutual funds, etc, the identification, profiling and signature requirements for opening the account are greater than those for a simple financial product. The customer needs to provide more profile information to enable product suitability to be assessed and is needs to demonstrate understanding of the product terms more effectively.

From a signature standpoint a simple username and password is not considered strong enough for authentication of identity, so other approaches to collecting signatures are being used or investigated by organizations:

1) Digital pen signature pad
2) Physical token
3) Biometric identification

Digital pen signature pad

The digital pen signature pad enables an institution to use a traditional written signature in an electronic form. It captures not only the signature shape, but also the pressure and velocity of the pen, enabling forensic proof to be applied to signatures if required.

To my mind this type of signature seems hard to validate automatically, although I have not really researched software that has been proven to do this. The limitations of 'sampled validation' performed by organizations with wet signatures may apply, where they only check a sample of set of signatures, since it could be impossible to reasonably check every signature.

The availability of signature pads may also limit its widespread adoption, especially since these devices are unlikely to be easily portable between PCs, limiting the mobility of online transactions, for example where a customer uses a home and office PC for financial matters.

One advantage of this type of signature is that it can be used to record the appearance of a traditional signature, where the institution may need a comparison for a wet signature in the future. An example is where an organization provides checks or plastic cards and needs to keep a 'signature card' for validating signed checks or debit/credit card slips.


Physical Token

The second option, using a physical token, has been deployed in some environments, requiring a customer to hold some type of smart card or electronic tag. The physical possession and use of the token only represents part of the signature, and is completed when combined with a traditional password.

Some tokens are limited by the need to swipe them over a reader, again limiting mobility of the usage to PCs with an appropriate reader. Tokens that provide an updating passcode display enable them to be used without being attached to a PC, promoting mobility. These devices have been trusted for remote administrative access to IT systems for several years and as such should be recognized by an organization's IT/IS group as being reliable.

The effectiveness of this approach as a signature comes from the possession of a token that is unique to the user. It ensures a far greater degree of certainty than a password alone, but must be used in combination with a password, much like you would expect to use a bank card in an ATM with a PIN. Pure possession of the token does not guarantee that the unseen user is the person that really owns the token, due to possible loss or theft.

A drawback of this approach is that it requires the physical distribution of a token by the financial institution, or the requirement that a customer already possess an accepted token from a third party.

Physical distribution (i.e. snail-mail) injects a lag into the account setup process, but also adds the opportunity to confirm the customer’s address is correct, since otherwise the token would be difficult to receive. In some circumstances snail-mail or other trusted delivery (FedEx, UPS) of a token, bank card or PIN is the only way to ensure that the customer's address is what they claimed on the application.


Biometric identification

Biometrics are a hot topic at the moment, and devices for reading fingerprints are becoming more common, as PC manufacturers (such as Lenovo) build them in to promote access security. This may be encouraging to financial services firms, since it enables them access to an authentication mechanism that is becoming widespread, and does not carry the distribution lag or cost associated with physical tokens.

In much the same way that a customer could sign up with Fidelity and select a username and password for their online identity, the customer could also just swipe their fingertip over a sensor on their laptop to be recorded on their digital signature card. In future, this fingerprint swipe acts as a signature consenting to a transaction.

Unfortunately, biometrics typically rely on identification markers on a human being that are readily visible, and therefore subject to spoofing. The Electronic Frontier Foundation has raised concerns around the use of biometrics.

When used in combination with a password (an attribute that is not visible), the security of the signature for non-repudiation purposes may be considered sufficient. Financial services institutions should be tracking this technology, and its effectiveness.


Managing identity and recording signature transactions

Some Business Process Management (BPM) and document management systems support signature of actions (for FDA regulation 21 CFR part 11), and to sign the accuracy of documents for non-repudiation. In broader systems a third-party signature management capability may be required. An example of this is SignatureOne from CIC, which manages signature administration, authentication and transaction logs for a range of signature mechanisms as described above.

Special attention will be required to handle the sharing of signatures, signed transactions and documents. This will be maybe the toughest area to solve without standards in place.

In general, I need to do much more research in this area, but hopefully this short introduction provides a placeholder for future analysis. As ever, any feedback from anyone with experience in this area would be appreciated.

Summary

Financial service institutions need to be looking both at their own requirements for electronic signatures for high value and high risk accounts, as well as what the marketplace in general is likely to adopt. Widespread adoption of an approach will most likely lead to the most cost-effective and hopefully trusted mechanism for online signatures for authentication and non-repudiation.

There are a range of other issues to be addressed, from the recording of signatures against actions, to digitally signing documents to ensure accuracy, I have not addressed fully. Hopefully I will get round to doing this soon.

As ever, any feedback on the ideas and information I have presented here is welcome.

Technorati tags:

Wednesday, August 02, 2006

Electronic signatures for financial services - a background

Electronic signatures are core requirements for new account opening for financial services products. I certainly do not claim to be an expert in this area so I’m hoping to use this as a starting point, by laying out some of the issues that need to be addressed, and laying out a little of what I know as background.


What is a signature?

In simple terms a signature is a proof of identity or used to represent the intention of informed consent. Signing a document or contract is surrounded by a certain ceremony to reinforce the ‘will’ of the agreement – a signature is really not enforceable if the signing process was disguised or the agreement terms were hidden.

Wikipedia has some background on the meanings and traditions surrounding signatures.


A use case

Imagine that I go to Fidelity’s web site to apply for a new account. As a customer without a history with the institution there are various challenges to me opening a new account and signing an agreement as to my rights and obligations for running it.

Fidelity needs to enforce several steps:

  • Create a reusable identity for me
  • Ensure that I am who I say I am, and live where I say I live
  • Create a customer profile to enforce risk and Anti-Money Laundering controls
  • Gain and prove my acceptance of their agreement terms

In this online world they need to do all of this without ever seeing me in person, or seeing any physical evidence of who I claim to be. In the future, ensuring that I do not deny ownership of the account or agreement with its term is essential to the institution. Unfortunately non-repudiation is hard to achieve when an institution doesn’t already have a relationship me. In this case a signature without a valid and verifiable profile is worthless, either in the manual or online world.

Creating and confirming identity

The first step when setting up a relationship with a new customer is for the financial institution to create and confirm the customer’s identity. In its most basic form this is a set of some uniquely identifiable information about the customer, name, date of birth, residential address, social security number, etc. This provides a base identity for the person. A signature is then assigned to enable the customer to in future confirm they are who they say they are, for contracts and transactions, without having to re-examine their details in more depth.

In the paper application world, I would walk into a branch of Bank of America, fill in a form, present three forms of identification to the customer services rep and sign a ‘signature card’. The signature card provides a record of the customer’s signature for future reference if ever required to confirm the customer’s identity. In the US this signature card is rarely ever used. In France, for example, a certain percentage of checks written and signed by a customer must be compared to the signature on the signature card (a good reason why banks have been encouraging the use of plastic / electronic payment for years).

In the online world things work slightly differently, but the principles are the same. In this world I’ll go back to the Fidelity web site. I fill in a series of personal details that enables them to uniquely identify me. This enables Fidelity to pull my credit report from Equifax. Here I am presented a series of questions to confirm the providers of certain services that are listed on my report over the last few years. The combination of correct answers for these questions enables Fidelity to be reasonably sure that I am who I say I am, especially as the credit report is tied to my social security number and mailing address. After filling some more information I have to select a username and password for access to my new online account. For low value or low risk accounts (standard brokerage accounts being one), this is considered enough identification to authenticate my agreements and transactions with the username / password combination as my signature.


Legal background

For commercial consumer, especially financial services transactions, there are two key laws addressing the issue of electronic signature.

The Uniform Electronic Transactions Act (UETA) provides a uniform state legal framework for electronic transactions. This gives them the same legal weight as equivalent paper based processes and wet signatures.

The Electronic Signatures in Global and National Commerce Act (E-SIGN) provides a federal backdrop for electronic signatures, governing situations where there is an absence of state law, or states make changes to UETA.

Special provisions have been put in place to protect consumers, controlling when organizations can demand the use of electronic transactions and documents and how organizations ensure that customers have the facilities to accept electronic delivery of documents.

The financial services industry has looked at providing best practices and rules, combining electronic records and signatures issues. This is the Standards and Procedures for Electronic Records and Signatures (SPeRS).

Wikipedia refers to additional laws.


Summary

As you can see, many of the issues in financial services related to signatures are tightly coupled with validating, managing and authenticating the identity of an individual. The approaches that organizations take to perform this in an online world mirrors what is required in a paper world. For higher value and higher risk products the current online model is considered insufficient and much work is needed to strengthen both the signature and general identity management issues.


More to come

In the next post I will address some of the deeper issues around electronic signatures as they relate to higher value or higher risk accounts, as well as the hot topic of biometrics.


Technorati tags:

Monday, July 31, 2006

Email archiving and the Big Belly solar trash compactor

I ran across one of the shiny new Big Belly solar trash compactors in Boston this evening. As Mayor Menino is demonstrating in the photo, it swallows trash through a drawer in the front. Its big so that it can hold a lot of the stuff. And the innovative guys and girls at Seahorse Power Company have added a solar panel on the top to power a built in compactor, enabling Big Belly to hold even more, and without it needing to be plugged in to a nearby streetlight to power the compactor. This gives it an air of environmental friendliness that probably fools some of Boston's residents into believing that they are being very 'green' by feeding the thing. But its real reason for doing this is to save on the frequently overflowing trash cans scattered around the city, being picked up by an overstretched workforce.

I want to compare Big Belly with email archiving. Email archiving technology is only successful because of the need to overcome the issue that email, as written about by Keith Harrison-Broninski, is not suitable for business use. The fundamental reason for archiving emails was obscured long ago: ensure an auditable record of all communications. Now these systems sell on their capability to consume more email than the email server can sensibly store.

To me, Big Belly and email archiving both represent an underlying problem that we are trying to hide by their use. We create too much trash and too much email. And this was sadly reinforced when I was finishing up my stroll round the city. There was a guy wheeling a shopping cart full to overflowing with glass and metal containers that earlier in the day were holding beverages of different varieties. As a power user of his chariot he deftly ignored the 4 lanes of traffic he was steering across, maneuvering the empty cans and bottles towards an unknown (to me) destination that would presumably pay him a few cents for each pound of waste material he wheeled in.

In my mind the 'green' veneer of the Big Belly solar trash compactor was wearing off, probably as fast as its shiny paint will when attacked by Boston's road grit and salt this winter. Sure, it chews a lot of stuff up, requiring less maintenance, but none of that stuff is recycled. Boston, unlike other more progressive cities, has not really recognized the value of recycling on the street. And the people that do, like the shopping cart guy, will have an important source of revenue crushed up inside a large green box.

Along similar lines, email archiving enables the IT group to continue to operate the inefficient and ineffective business communication mechanism, requiring less emptying, while trapping all of the information value inside individual user mailboxes.

As Microsoft pushes its ECM strategy and other vendors are forced to respond, many more users will become familiar with collaborative tools for sharing documents and capturing discussions. These capabilities are offered today by MS Sharepoint, Vignette Collaboration, Documentum eRoom, amongst others. When used as most users do these tools at least provide a sensible collection point for what would otherwise have been trashed email attachments and messages, which is a start.

Hopefully the enterprise will also embrace the technologies that could really reduce email trash: blogs, wikis, RSS and IM. Only then can the email archive return to what it was really intended for, to capture auditable copies of valuable email communications, thus enabling far more effective legal discovery processes and significantly reduced storage costs.

As for the Big Belly trash compactor, I fear it may be here to stay. Good luck shopping cart guy!

Technorati tags:

Sunday, July 30, 2006

ECM in a post Microsoft world

A recurring theme is the threat that Microsoft is posing to the Enterprise Content Management (ECM) industry with its upcoming release of Sharepoint 2007, packaged with Office 2007. This release is likely to bring Sharepoint to the desktops of more Windows users than ever before, enabling them to experience first hand the advantages of using ECM technologies in their day to day business.

The key things that most users will be exposed to are:

  • Metadata for the identification and classification of documents enabling them to be searched more easily within a business context
  • A portal for seamless access to a range of data sources
  • Saving documents to a records repository for lifecycle management
  • Collaborative working environments enabling multiple users to share and create documents and knowledge
And all of this will be performed seamlessly in a familiar user environment.


Threat to the ECM industry

Microsoft has a huge marketing budget (some say $500 million) to bring awareness to their ECM offerings. This will obviously be a cause for concern, since the majority of ECM companies are not in a position to compete at this level. This has been discussed by several industry observers including:
Much of their attention has been turned to Filenet as a prime example and how it will cope with this threat, or whether it will just become another acquisition target like Hummingbird.

The fear for many ECM vendors is that Microsoft will swallow up market share and will commoditize ECM offerings so that there is no value for anyone else to compete (except maybe the open-source players).


Its not all over yet

Microsoft will release Sharepoint 2007 early next year, meaning that many organizations will not be in a position to update most of their office suite to really benefit from it for another 18 months at least. As I suggested in Vista in 2007 v. improved New Account Opening now, some organizations probably have budgets in place and demonstrable ROIs from actually deploying much before then. But really that is just a stay of execution.

In Dear Mr CIO - don't hold off buying ECM I talked about how the players targeting different levels in the market could cope with the Microsoft invasion, suggesting that for the enterprise vendors there is still a light at the end of the tunnel. The four serious points I made here were that the enterprise vendors could:

  • Extend and enhance in-house technology with the MS capabilities
  • Build business solutions on top MS and in-house technology
  • Embrace the user facing components, like Office 2007 with strong integrations and value-adds
  • Identify and enhance enterprise technology requirements that MS can not easily deploy
One major thing that I have not seen discussed is this: Microsoft is not typically adopted by corporations to provide enterprise-wide capabilities.

In my experience, most MS deployments are targeted and implemented at the departmental level, a strategy that meets the architecture of the products. Very large deployments of MS technology require federation, deploying multiple servers and additional technology to tie them together into a whole. So it is far easier to just deploy departmental level systems and track them as independent instances, which is ideal when each department has different requirements for its systems.

E is for Enterprise

Let us focus on ECM and get back to basics: E is for Enterprise.

A major selling point for the true enterprise-level ECM vendors is the ability to deploy a single system, capable of managing the whole enterprise’s content. Especially when it comes to records management, defining records lifecycle policies centrally is essential for effective management of enterprise records through to destruction.

In the Microsoft model, having multiple instances of records management systems spread throughout the enterprise, to match the federated nature of the Microsoft Sharepoint architecture makes true enterprise content and records management complex to track and control. Microsoft is rarely truly enterprise level.


Everything has its place

Remember that $500 million that Microsoft is expected to spend on marketing its ECM vision?

Not only will that bring awareness to the MS products, but it will actually finally awaken the recognition that ECM has been struggling for years to achieve, despite the efforts of vendors, and organizations like AIIM. This should drive demand for ECM products at all levels.

For the ECM vendors, this is a golden opportunity to keep Microsoft in its place – confined to individual departments. To capitalize effectively though, there are some things that the vendors will have to do:

  • Partner with Microsoft to give the appearance of embracing its model
  • Integrate with the MS Office/Sharepoint 2007 suite fully and completely
  • Embrace the strengths of Sharepoint and its pervasiveness to the vendor's advantage
  • Identify gaps in the suite and fill them with value added features
  • Estimate, measure and demonstrate the value of true enterprise centralized ECM capabilities, including records management, web content management and business process management

Act now

In my opinion, all of these items are essential as long as vendors acknowledge that eventually Microsoft will copy many of the best capabilities, functionality and arguments that an independent vendor has. Acting now will help to ensure a firm footprint, and a model that the market can take as the de-facto architecture. Investing too much will be a waste long-term. But being adaptable and a vendor can provide a long-term profitable solution.

My view (and its not an expert opinion) is that vendors can more than survive, rather thrive, in the post MS ECM world. But they need to play to their strengths, and show flexibility that few Filenet, Vignette, EMC and other companies of their type have.

[UPDATE: correction to URL for Russ Stalter's post]

Technorati tags:

Friday, July 28, 2006

BPM could drive online office applications

Business processes automated by a BPMS require human interaction at points in the process, like exception handling and knowledge working. In this post I want to share my opinions on how these human steps could benefit from the new generation of online word-processing and spreadsheet tools by embedding them directly into the user’s processing application. Tools like Google Spreadsheet, Zoho Writer and Office Suite represent the available capabilities. The IT|Redux blog provides a good listing of online office tools.


Use desktop tools for collaborative 'processes'

My post Collaborating in structured business processes talked about the extreme case where a dedicated collaborative application is required to enable users to complete a complex set of human driven tasks at specific steps in the process. I illustrated an example where extensive anti-money laundering reviews were required during the account opening process for a new high-risk financial customer.

In scenarios like this, collaboration enables a set of users to work together using the tools that are most convenient to them. Typically they will produce documents using MS Office products, research tools and business specific application. The users record their working and final decisions as text documents and spreadsheets, stored within a specific collaborative workplace. Due to the lengthy and varied work that the users are performing this is probably the best approach to improving their effectiveness.


Knowledge workers and other human interaction

More commonly occurring than full collaborative requirements are the steps in a business process that require input from a single knowledge worker, to process a case and make decisions based on information presented to them.

An example is an insurance new business process, where at certain steps an underwriter is required to assess policy terms. The underwriter is delivered the work, being presented the customer details and full application form to assist in the assessment. At this point, typical systems will leave the user to utilize external workbench tools to make their decisions. More often than not this requires that the underwriter re-key information from the original application form into a spreadsheet that enables him to determine risk and policy value. At the end of his manual processing he saves any documents that assisted in the decision to his desktop and attaches them manually to the customer case file or a shared file system.


Online productivity tools provide just enough

This is where I believe that online productivity applications like word-processors and spreadsheets could be valuable. Despite the fact that the functionality in these tools is probably insufficient for power-users, what is available right now is ideal for the specific tasks required at human steps in business processes, like the one described above.

Most online email users or bloggers will attest to the fact that the editing and formatting capabilities of these tools are sufficient for everyday document production, and that the vast majority of MS Word capabilities are left untouched. Especially where there are targeted requirements for document production, like customer correspondence, documenting basic research findings, and so on, more extensive features just get in the way.


Value to the user

By embedding online applications into an underwriter’s BPM application the key tools of a basic underwriter workbench can be presented seamlessly alongside the customer information and application form. For the user this has many possible advantages:

  • Seamless access to key applications in a single browser application
  • Ability to open template documents with data transferred directly from the application form and customer information data, avoiding re-keying
  • Direct and enforced storage of documents back to a central repository, not requiring additional steps storing to the desktop first
  • Simple, easy to use features appropriate to the limited user requirements

Value to the Business

From the point of view of the business, there are many advantages, including:

  • Reduced cost per desktop, by not requiring expensive MS Office installations, and reduced hardware requirements due to the editing applications not being bloated with unnecessary features
  • Improved audit and compliance through enforced recordkeeping of process related documents
  • Improved accuracy of human processing due to the reduced requirement for re-keying information
  • Improved user efficiency by using tailored, streamlined applications appropriate to the user requirements

Value to IT

The IT group will see benefits that enhance the savings the business may see:

  • Zero desktop installation and upgrade requirement
  • Reduced risk of macro viruses
  • Ability to more effectively lock down user desktops, since no documents or files need to written locally
  • User support calls reduced due to simplified application usage and no 'lost' files saved to an unknown directory

Summary

BPMS driven processes have always offered the option of tailoring the user facing applications used for delivery of work. In more mature customer systems these will integrate business systems specific to the users' work, but will rarely take into account the desktop tools that they must use to complete their tasks.

By including online word-processing and spreadsheet capabilities directly in the user interface there are many advantages to user, business and IT. It could be that this ability to embed seamlessly into the user process 'workbench' becomes a strong driver for this new breed of office tools.

Technorati tags:

Wednesday, July 26, 2006

How to mix users and forms

"It looks far too complex"

was the phrase that introduced my previous post about browser based forms and the perception of application that include them. The phrase illustrates a common issue that faces many software developers, sales engineers and anyone that demonstrates software that includes a browser-based form for capturing data and attributes. Software applications that need users to enter structured data are typically poorly received.

In that previous post I suggested some opinions as to why users hate forms and more broadly any applications that attempt to impose structure. In this post I'm going to offer some opinions that represent my non-expert status in "user experience" design, to help encourage less of the original response that "it looks far too complex", and more of the "when can we start using it!".


How to fix the problem

I am not a "user experience" consultant of great repute, so my thoughts are just observations - that I'm going to write down anyway. The following lucky seven short sections describe how we might approach making data entry less odious to the user.

1) Try the MS Office 2007 approach

MS Office 2007 introduces a new approach to capturing document attributes or properties , along with other usability enhancements. The experts at MS have also noticed that users hate entering data, so they have provided a new novel approach to the problem. These are some suggestions that I have drawn from observing the new application (Office 2007 beta 2)
  • Constantly display the document or case attributes in an information panel, so it becomes less of a big surprise and threat
  • Allow the user to enter the information at any time that suits them, without having to artificially navigate through a new dialog or form
  • Only bully the user for entry of information when they have failed to enter it in the information panel, as late as possible
The lesson here is that users might actually add structured data if it doesn't break up their other work processes with annoying dialogs, and may actually provide them with some informational value.

2) Avoid the traditional forms display

Many forms on websites and enterprise applications alike are long and linear, since this easiest to design and implement. Even LinkedIn, a popular application designed to encourage you to register confronts new users in this way (although their form is at least segmented). This is because vVertically oriented forms may appear more lengthy than necessary. Also, when a form is positioned in a vertical panel to the left of a document it appears more urgent, as western users read left to right.

Here are some thoughts to improve this with a different orientation:
  • MS Office 2003 used vertical panels on the right, maybe for this reason
  • MS Office 2007 uses a horizontally oriented document information panel at the top of a document. It seems to be accepted by the eye as a more integral part of the application task ribbon (the new Office approach to toolbars) than other approaches, and does not carry the issue of appearing unnecessarily lengthy
3) Just In Time data entry

Capturing information across several screens, at relevant points in the process breaks up the appearance of a lengthy form and the monotony of entering all that data. The amount of information required at any one time is less overwhelming to the user. A key design point is that it helps the designer ensure that only relevant information entry is presented to particular a user.

4) Don't make it look like a tax return

Use a very clean, modern, friendly forms design. Investing in the best look possible will help it appeal to the user visually and will avoid clutter, making the usage more streamlined, which is essential if users are expected to return to the form in the future.

5) Know your user

Presenting the form in a presentation format most appropriate to the user profile is essential, and one item that I believe is regularly overlooked by applications. Here are some key thoughts around this:
  • Know the size of the screen, and use it in a way appropriate to the application. Blog applications like Blogger are often terrible at this, presenting an editor that is too small to reasonably write and review lengthy posts.
  • If the user doesn't need accessibility features, or keyboard shortcuts for productivity, avoid showing them them this information. It just leads to clutter and confusion.
  • Where possible pick up the user profile automatically, so that accessibility features can be display only if needed.

6) Trick the user

Fool the user into believing that they are not entering information into a form, so that they are not threatened by it. This may also help the designer find more effective ways of collecting the information required. Try:
  • Presenting the form as a series of friendly questions can be less threatening, and can hide unnecessary attributes that are not required
  • If information entry is not enforced, experienced users will not enter it even if you show them textboxes for it
  • Allow users to enter information over the course of their usage, not in a single enforced form or lengthy wizard

7) Share the burden

This is my favorite. The assumption in applicaitons that collect and share information, in either a collaborative or process driven tool, is that all data must be collected up front. Data entry is often performed right outside the mailroom in enterprise BPM processes. In more field based processes, the person initiating a request or document may be unfairly penalized with all of the data entry to identify the item. I would try and bear these points in mind:
  • Don't make the case initiator (e.g. the salesman that creates the request for a new contract) enter all of the information. That salesman has a job to do, and its selling your stuff, not filling in forms.
  • If the user can not see the advantage to them of entering the data, they are unlikely to take the care to fill it in correctly.
Let's think about the example in the previous post of Legal Contracts Management. If some of the information on the form is just there to make the legal department's job easier when it comes to searching for contracts, have them enter the information, not the salesman. For him or her the legal department's search requirements are invisible and certainly not valued.

At the end of the day

For any application utilizing data entry by typical users, some novel ideas may be required. Otherwise a typical user can often become defensive at the sight of a single data entry form, runing the impression of an otherwise incredibly usable application. Despite this issue the application requires attributes to be entered for it to work correctly or deliver its full value. A balance needs to be struck.

As with any software application, get the buy in of some positive business champions early on in the design. They can help to guide your requirements, and diffuse negative feedback out on the shop floor.

When deploying a generally accessible web application, or an internal enterprise application, training and championing is impossible on a large scale. In these scenraios you need to work harder on the design to make it really appealing to a mass audience using the application with minimal guidance, training or change management.

Take as many tips as you can from the best online web businesses and apply some of the lucky seven ideas above. With luck you will hear less of the the original response that "it looks far too complex", and more of the "when can we start using it!".

Technorati tags:

Forms and users just don't mix

"It looks far too complex"

is a common phrase heard by software consultants and professional services people when proudly presenting the new prototype UI for a document centric application. It might be a great collaborative, document management or BPM based application, but either way the business users just don't like the look of it.

Attributes for classification

Many simple automated business processes, collaborative environments and document centric applications benefit greatly from an appropriate level of structured attributes or metadata to identify documents. Otherwise it is no easier to find your documents than a large folder on a shared file system on a Windows server.

A nice example of a business process centered around documents is legal contracts authoring, negotiation and management. This is a use case that is relevant to most organizations, so I'll talk about it as its easy to understand. It uses a document-based collaborative application to facilitate the interactions between lawyers inside the company and the basic processes that they must go through to write new contracts, negotiate with external organizations, keep records of executed contracts and handle the expiration and renewal processes around their agreements.

In a reasonable sized company, to enable effective legal contracts management some attributes need to be applied to the contract package (a folder, workspace or some other object collecting all contract documents). These are there to facilitate:

  • Search
  • Audit
  • Process enforcement (review/approval and expiration/renewal processes)
Most of the required information is entered up front, such as contract value, type, company name, expiration date, etc. On seeing the nice, structured browser-based form for capturing this information (or right at the end of the presentation) a user will come out with the comment I started with: "It looks far too complex".

A sad story

I have experienced this reaction with this type of application and more complex BPM applications for new business processes and just assumed it was my lacklustre demonstrations skills that had failed yet again to wow the users. Colleagues regularly tried to reassure me that "its the application, its just too ugly/complex [select as appropriate]". I was never entirely convinced until just last week when I stepped in to help show a new document-centric use case, based on a typically very well received collaboration product. Again, at the end of the process I got the 'too complex' line, something that I was just not expecting.

Thinking that I could not blame the application I probed a little deeper. What was the source of the problem? Surprise, surprise it was the presentation of a nice browser-based form to capture a limited set of attributes at the start of the process. Comments included:
  • Users will find it too complex
  • Users won't fill it in correctly
  • Users will just enter random key-strokes quickly to cheat the system
  • Users will just refuse to use it

What is the issue with these users?!

Why is it that users that do not typically work with structured applications become hesitant or plain defensive when they see a structured form designed to capture attributes quickly, accurately and efficiently? I have taken some guesses, and would love feedback from anyone that has more ideas or can point me at other valuable resources. My guess is that users are threatened by forms due to:

  • Previous bad experiences with badly designed forms
  • Overwhelming appearance of lengthy forms
  • Belief that too much information is being captured
  • There is no understanding of how the information is used
  • The information requested is not relevant to this user or at this stage in the process
  • Belief that 'data entry is not my job'
The crazy thing seems to be that many users would be happy to hammer in a freeform email that contains most of the same information and send it through to another person describing what they mean.


Not placing blame

The outstanding acceptance of document collaboration tools by users provides some insight into what a typical untrained user will accept from an application, with the common features that:

  • Shy away from structured data
  • Dictate little enforcement of process, defined usage patterns, document formats, styles or layouts
  • Encourage freeform communications
  • Do not enforce the entry of any attributes
The tools reinforce the proposition that it is good to capture unstructured documents such as the freeform email my crazy user was happy to write in my example above. The problem is that this information is often not obviously reusable in this format for the next user that needs it.

I'm not blaming collaborative tools for the problem, but they do highlight how much users hate entering data. By introducing just a small structured form and process into these tools leads to the original user feedback, as my sad story recounts.


Placing blame

There is only one place to look. I can no longer entirely beat myself up for demonstrating so many applications so badly. Rightly or wrongly I'm going to blame the forms UI. Not just the one in this application, but the whole concept of data capture forms UIs.

Many applications and business processes can benefit from a bit of data entry, and in structured business processes (like new account opening) this is even more necessary. So it is hard to escape this 'new evil', the forms UI.

In the next post I'm going to offer some opinions that represent my non-expert status in user experience design, to help encourage less of the original response that "it looks far too complex", and more of the "when can we start using it!".


Technorati tags: