| Name | Stats | Manager | Project Overview |
|---|---|---|---|
| Faculty Information System Transition – FRPA Implementation | Priority 3 - Normal Start 6/29/26 Percent Complete 0% Status Name On Hold |
Jamie Mclandsborough | DescriptionFollowing completion of the discovery and vendor selection phase[SM1.1][CG1.2][SM1.3], CU Boulder will begin implementation of a modern Faculty Information System (FIS) to replace the current legacy ecosystem. This project implementation focuses on the FRPA. This phase focuses on initial implementation, pilot deployment, and transition planning, with particular emphasis on: • Standing up the selected vendor solution (SaaS-based) • Supporting a pilot implementation of FRPA, with optional inclusion of tenure and promotion workflows (led by OFA) • Designing and implementing bi-directional or downstream integrations to support a period of dual-system operation • Transitioning Symplectic Elements from on-premises to vendor-hosted cloud deployment • Establishing data integration patterns to ensure continuity of operations during transition Due to operational and reporting dependencies, the legacy FIS will remain in use during an interim period. This requires reliable mechanisms to ingest and synchronize data from the new system back into legacy systems to maintain institutional reporting and compliance. This phase will lay the foundation for full system migration in subsequent phases. Key Drivers (updated from discovery phase): • Urgent need to reduce reliance on unsupported legacy Oracle systems • Eliminate redundant manual data entry and improve integrations • Enable modern APIs and data sharing capabilities • Support improved faculty workflows and user experience Customer BenefitPilot-based rollout reduces risk before full deployment Reduced operational disruption via dual-system strategy Improved data quality via centralized ingestion patterns and/or the use of AI Cloud-hosted Elements reduces infrastructure burden Foundation for future legacy FIS decommissioning |
| Graph Enablement & Access Reform (GEAR) | Priority 3 - Normal Start 7/13/26 Percent Complete 0% Status Name On Hold |
TBD PM | DescriptionThe project addresses a historical gap in oversight created by user-consented Microsoft Graph API permissions by systematically reviewing existing enterprise applications, removing unnecessary or high-risk access, and implementing a sustainable approval and governance framework for all future requests. Building on prior analysis of over 2,500 enterprise applications and their associated permissions, this effort will execute a structured remediation strategy that includes permission risk classification, application rationalization, and enforcement of appropriate consent models (user vs. admin). In parallel, the project will design and operationalize a formal approval process aligned with institutional security practices and informed by peer models such as the University of Washington’s OAuth consent governance approach. The future-state model will introduce a tiered approval framework based on permission sensitivity, data access scope, and business purpose. Low-risk permissions may remain eligible for controlled user consent, while moderate and high-risk permissions will require escalating levels of review involving Service Owners, Messaging & Collaboration, the Azure Working Group, and OIT Security. This structured intake and approval process will be integrated into existing ICT workflows to ensure that application access is evaluated proactively, consistently, and transparently before being granted. Customer BenefitReduction of institutional data exposure by removing unnecessary or high-risk permissions Improved visibility into application access to M365 data Standardized and transparent approval process for application access Clear ownership and accountability for permission decisions Faster, more predictable onboarding of new applications through defined workflows Alignment with Microsoft security model and peer institutions |
| Pre-Procurement Processes Project Phase 2 | Priority 3 - Normal Start 7/17/26 Percent Complete 0% Status Name On Hold |
TBD PM | DescriptionPhase one of PPP revealed that the process of acquiring IT commodities is confusing, unclear and often inefficient and lengthy. Process improvement is greatly needed, but before processes can be improved, they must be better understood and documented. Since the first phase of this project ended, the PSC has introduced additional training requirements for IT purchases on p-cards resulting in campus units contacting OIT for help and/or further guidance on the proper protocol for ensuring risk reviews are complete while continuing to make IT purchases in a timely manner. Additionally, CU’s Internal Audit Team recommended increased awareness of IT purchasing policies and processes following the March 2026 completion of an audit of IT acquisitions on procurement cards. Furthermore, OIT continues to receive complaints from campus units related to the small dollar contract process for IT commodity purchases particularly because of the necessary and required risk reviews. This phase of the project aims to systematically document and clarify the ideal-future state request and approval process (including ICT – security and accessibility reviews as well as exception waivers) utilized by service/product owners or end-users in the Office of Information Technology and select IT-intensive campus departments for four distinct categories of acquisitions made via CU Marketplace: 1.) New acquisitions that fall under the small dollar designation. 2.) New acquisitions that fall below PSC’s solicitation thresholds and above small dollar thresholds. 3.) Renewals or new acquisitions under existing agreements between CU and respective suppliers. 4.) Acquisitions requiring solicitation by way of a documented quote or request for proposals. NOTE: Acquisitions made by OIT’s software team for the Software catalog will be excluded from the scope of this project. Once these processes are fully documented, two steps will be taken:
Customer BenefitStreamlined and simplified procurement process is well understood with greater user agency for decision making before engagement with the PSC, allowing efficiencies in timing, planning, resources, risk reviews, etc. Reduced IT Sprawl |
| MFA Entra Policy Improvements | Priority 1 - Extreme Start 4/14/25 Percent Complete 75% Status Name Green |
Mikal Brusby | DescriptionThe University currently uses Microsoft Entra as one of its two Multi-Factor Authentication (MFA) solutions. Entra MFA is implemented for users of Microsoft Office 365 (O365), Teams, and Microsoft Exchange (e.g. Outlook Email and Calendar), as well as any applications integrated with Microsoft for its MFA solution for Federated Authentication (FedAuth). What users with appropriate licensing (A5, A3) have for MFA is risk-based conditional access (CA). When originally set up, the lowest frequency implementation of Entra MFA was put in place. All users are low risk (prompted only at set up), but can move to medium risk (prompted for a new device) or high risk (prompted frequently) automatically. Password resets can move a user back to a lower risk level. Unless you are high risk (either associated with a high risk application, of which there are few with typically audiences restricted to OIT administrators) or have engaged in an identified high risk behavior (failed login attempts + impossible travel + new device), a University constituent will effectively never receive an MFA challenge/prompt from Microsoft. MFA allows OIT’s Security Team to provide a timeout on compromised devices and accounts. By not prompting for MFA, we are not taking advantage of the benefits of strong MFA. Additionally, by not providing greater granularity to our audience – we could divide the audience into different buckets, or personas, to apply different rules to different user types – we are providing blanket protection across all risk, instead of providing greater protection to higher risk audiences. Additionally, in an effort to unify our MFA experience and offering to the campus, we will move the shibboleth service (fedauth) to authenticate using Entra ID and Microsoft MFA, moving away from on-prem AD authentication and DUO MFA. This project proposes: • performing a policy review and data driven analysis on a test-audience (OIT) before rolling out to campus to implement a stronger baseline security where prompts are more likely to occur, and security is strengthened • This will also deliver a repeatable process for the involved OIT teams to propose, test, review, seek approval for and introduce these changes going forward in a repeatable fashion for introducing further layers • Performing a similar review and data driven analysis to introduce “layers” of conditional security requirements depending on audience/persona and situation. • Migrate shibboleth to proxy authentication to Microsoft Entra and enable a baseline policy for all fedauth authentications. Customer BenefitSecurity benefit – MFA reduces the ability to compromise an account with just a password, and provides a forced timeout Privacy benefit – this has the ability to raise the barrier of entry to sensitive data for specific users Grant and research bonus – by having higher security controls, we can demonstrate more systems compliant with stricter security standards, which means more ability to meet system requirements more broadly for grants tied to sensitive or controlled data handling Compliance benefit – GLBA, SOC, ISO 27001K, PCI, and NIST 800-171 standards all expect MFA. It is easier and less expensive to meet requirements from these types of audits with a central authentication system protecting data and access with MFA. |
| Buff Experience Transformation – Core Foundation Build | Priority 2 - High Start 9/2/25 Percent Complete 35% Status Name Green |
Alicia Torres de Lozano | DescriptionThe University of Colorado (CU) system serves over 67,000 students and employs 28,000 faculty and staff across its campuses. As Colorado’s flagship public research institution, CU is committed to delivering high-quality, accessible, and innovative education that meets the evolving needs of learners and supports the state and nation with graduates who are prepared to fill critical workforce roles. Over time, CU Boulder’s CRM, web, data, and integrations ecosystem has grown organically across various units, resulting in a fragmented landscape of tools, platforms, and processes. This complexity has created challenges in delivering a unified, data-informed, and learner-centered experience, causing problems for students and their support staff who need to navigate across our silos to be successful. In August 2023, CU Boulder’s executive leadership approved a multi-year Constituent Relationship Management (CRM) Strategic Roadmap to address these challenges. A formal business case was developed and approved in December 2023, setting the stage for a phased transformation of the university’s CRM infrastructure. Customer BenefitUnified Learner Experience Across the Lifecycle Students will have access to a more cohesive, personalized, and accessible experience from recruitment through graduation and beyond. This includes improved visibility into their academic journey, support services, and communications. Consolidated and Actionable Data for Staff and Advisors Staff and advisors will gain a 360-degree view of each learner through integrated data from SIS, LMS, Degree Audit, and Slate. This enables more proactive, personalized, and efficient support. Retirement of Legacy Systems and Reduction of Technical Debt By decommissioning CRM01 and consolidating CRM functionality into Education Cloud, the university reduces redundancy, simplifies support, and improves long-term maintainability. Improved Communication and Engagement Capabilities Marketing Cloud will enable targeted, automated, and data-driven communications to prospective and current learners, improving recruitment, retention, and engagement. |
| ChatGPT Edu Deployment | Priority 2 - High Start 2/13/26 Percent Complete 30% Status Name Green |
Christie Drovdal | DescriptionThe objective of this project is to coordinate and implement the onboarding of ChatGPT Edu, OpenAI’s education–specific version of ChatGPT, at the University of Colorado Boulder thanks to the CU system-wide agreement finalized late fall 2025. The project will establish the operational, governance, and support structures necessary for long-term sustainability and compliance, while enabling students, faculty, and staff to leverage AI responsibly in teaching & learning, research, and administration. The project aims to: • Identify and structure OIT support resources, including a service manager and support team. • Define roles and responsibilities across existing OIT units (Architecture, Security, Academic Technology, IAM, Software Engineering, Software Sales, etc.). • Develop and formalize a governance structure around data handling, model usage, and access control in partnership with CU System. • Coordinate with CU System to ensure alignment with systemwide licensing, deployment, and communication plans. • Create a support and training framework to ensure users understand responsible and effective use of ChatGPT Edu. • Develop a deployment roadmap, including optimal phases and milestones • Assess the opportunity to build specific CustomGPT or AI agents for our campus to showcase possible uses and benefits of the platform. • Initiate conversations with governance groups and high touch stakeholders Customer BenefitEstablishes a unified, secure, and supported AI platform for campus use by the most used and well-known Large Language Model (LLM) vendor. Reduces shadow IT and unauthorized AI tool usage and thereby data leakage risk. Provides a foundation for deployment by preparing structure and support around a coming deployment across system. Strengthens coordination and ensures alignment between CU Boulder and CU System to ensure our needs and preferences are being represented. |
| Google Provisioner | Priority 2 - High Start 1/30/26 Percent Complete 50% Status Name Green |
Melinda Easter | DescriptionThe Google Provisioner project will modernize CU Boulder’s Google Workspace account provisioning by replacing Oracle Identity Manager (OIM) with Grouper, Azure, or a hybrid approach to manage entitlements. This change will allow for more granular provisioning beyond the current “Active” or “Suspended” statuses, supporting stepped licensing, timed transitions, and retention policies based on user affiliation. By automating manual processes and aligning with the approach developed in the MOLR project, this effort will improve accuracy, reduce administrative overhead, and resolve issues for returning students whose accounts are not automatically reactivated. The project will also evaluate authentication practices for Colorado.edu logins to the Google tenant, with the potential to enable multi-factor authentication (MFA) to strengthen account security. Customer BenefitMore granular provisioning (beyond just “Active/Suspended”) enabling stepped licensing and retention Automated account reactivation for returning students Reduced manual provisioning and error-prone processes Improved license alignment and cost efficiency Enhanced account security through possible MFA adoption Scalable and sustainable provisioning process aligned with MOLR and Grouper |
| MOLR Automation Project | Priority 2 - High Start 3/19/25 Percent Complete 95% Status Name Green |
Melinda Easter | DescriptionThis is a multi-phase project focused on automating the provisioning and deprovisioning of Microsoft Office 365 licenses. Currently, some of the processes are automated while others are entirely manual. The manual processes are labor intensive and error prone that results in O365 licenses not being assigned properly based on the license entitlements. The MOLR project assisted with the development of Grouper license entitlements groups and identified uses cases for the provisioning and deprovisioning of O365 licenses. These include the following license types: • Faculty A5 • Faculty A1 • Student A5 • Alumni Exchange Plan 1 • Retire Exchange Plan 1 The work completed on the MOLR project was an important enabling step toward automating the processes. The scope of this project includes designing, developing, testing, and deploying the automation for the provisioning, deprovisioning, and reprovisioning of the O365 licenses. The project includes the following phases. • Phase 1 – P/r for Faculty, staff, and student licences. MS licenses were removed for unentitled users, but users' accounts were not fully deprovisioned. • Phase 2 – Automated p/r/d for System Office employees, litigation holds, Alumni, and Retirees. Full deprovisioning for unentitled users. Tech debt, communications for all changes in licensing, and more. Remaining scope: secondary accounts, transitioning to operations/service, and potentially testing the structure with another service (e.g., Google Provisioner). Customer BenefitManages audit risk for lack of compliance with Microsoft O365 license contract. Reduces manual processes Manages cost of Microsoft O365 licenses |
| Alpine CMMC Level 1 Certification | Priority 2 - High Start 6/1/26 Percent Complete 45% Status Name Green |
Na'Tima Harrison | DescriptionIn meeting with an external consultant, we have determined that we should be able to make Alpine and PetaLibrary CMMC Level 1 compliant for any researchers requiring HPC to manage FCI. This project would be to tighten up the remaining items to get us to a point where we are comfortable meeting the requirements of a self-assessment and can attest that Alpine is compliant. Customer BenefitResearchers will have an on-prem system to handle their needs and would be able to get contracts that have this as a requirement. |
| Coursera Security Remediation & Enrollment Integrity Initiative (Jan–June 2026) | Priority 3 - Normal Start 12/10/25 Percent Complete 81% Status Name Green |
Alicia Torres de Lozano | DescriptionIn Fall 2025, CU Boulder identified fraudulent activity within Coursera enrollment workflows, resulting in compromised learner identity integrity and potential reputational risk. Immediate mitigation steps (Phase 0) were executed prior to January 5, 2026. This project charter defines the scope of OIT-led work from January through June 2026 to implement sustainable technical and operational controls, ensuring secure enrollment processes and compliance with institutional standards. Objectives
Customer BenefitEnhanced Enrollment Security – Prevent fraudulent Coursera registrations through identity verification. Improved Institutional Reputation – Demonstrates proactive measures to protect learner data and uphold trust in CU Boulder’s online. Operational Efficiency – Streamlined monitoring and escalation processes reduce manual intervention and risk exposure. Data Integrity & Compliance – Ensures alignment with FERPA and institutional security standards for third-party platforms. Role Clarity & Sustainability – Transition ownership to Technical Enrollment Manager for long-term continuity and reduced dependency on CRM leadership. Foundation for Future Integration – Prepares Coursera workflows for Phase 2. Financial Impact – Reduces costs associated with fraudulent enrollments. Vendor Partnership Strengthening – Improves collaboration and trust with Coursera through enhanced security. Alignment with OIT Strategic Priorities – Supports OIT’s strategic priorities for security, compliance, and learner experience. |
| Security Technology Transition | Priority 3 - Normal Start 2/20/26 Percent Complete 55% Status Name Green |
Christie Drovdal | DescriptionThis project transitions oversight, administration, and operational support of campus-wide physical security systems from Infrastructure & Resiliency (I&R) to the Division of Public Safety (DPS). The transition establishes a centralized governance and support model for access control and video management systems, ensuring uninterrupted operations, compliance with manufacturer requirements, and long-term sustainability through certified DPS staffing and integrator support. Customer BenefitCentralized governance and accountability for physical security systems Improved system reliability and compliance Reduced operational redundancy and ambiguity Sustainable staffing, certification, and support model |
| SPSC N190 Data Center Transition | Priority 3 - Normal Start 3/28/24 Percent Complete 41% Status Name Green |
Christie Drovdal | DescriptionIn response to the CU-Boulder data center assessment, it was determined that SPSC N190 data center is to be vacated. To accomplish this declaration, there are two distinct activities that need to occur:
Customer BenefitLowers risk of data center component failure Provides more geographical separation between data centers |
| Sustainable Storage | Priority 3 - Normal Start 2/7/24 Percent Complete 38% Status Name Green |
Christie Drovdal | DescriptionThe need for this project is from internal and external forces that are working together to change the landscape of data storage in higher education. CU Boulder’s storage vendors, Google and Microsoft, have each determined that unlimited storage for high education users is an unsustainable business model. Google implemented storage quotas, which kicked off the storage war, with Microsoft following suit in the summer of 2023. CU’s current Microsoft multi-campus contract runs through 9/31/2025, allowing a short runway to create and implement a storage strategic plan. In addition to the changes made by our vendors, our Federal and State research and grant partners have begun migrating towards stricter Data Lifecycle Management (DLM) and Data Loss Prevention (DLP) standards, meaning CU Boulder must adapt, or potentially lose research grants and researchers. To addresses these changes, OIT is proposing a broad ranging effort that hopes to establish a strategic plan and roadmap for the storage of data of all classifications, origination sources and retention periods on the CU Boulder campus. In addition to the strategic plan, known tactical and operational deliverables to communicate and enforce the strategic plan are also in scope. Currently unknown tactical and operations deliverables may spawn future projects as part of the roadmap deliverable. Customer BenefitUnified storage strategy, regardless of vendor, or affiliation type Enhanced and unified view into data loss prevention and data classification labeling Campus wide plan for data lifecycle management Campus education of data classification levels, DLP policies, data related policies and the enterprise storage options available to meet CU business requirements |
| CU Boulder Name Change – Phase Two | Priority 3 - Normal Start 1/7/26 Percent Complete 12% Status Name Green |
Jamie Mclandsborough | DescriptionIn the second phase of the CU Boulder name change initiative, the project team will continue to strengthen cross-office partnerships and engage subject matter experts to guide strategic decisions and system improvements. The second phase of the project will focus on mapping downstream integrations from source systems to bring awareness to the complexities of this process and allow the development of a project plan to execute the roadmap and improve the experience of the users of those systems. Customer BenefitUser testing to be certain changes are clear, meaningful, accessible, and sustainable Improvement in time spent correcting names in university systems described by staff council resolution Mitigate daily harm caused by incorrectly displayed information described by staff council resolution. |
| Identikey Site Rebuild | Priority 3 - Normal Start 3/9/26 Percent Complete 15% Status Name Green |
Jamie Mclandsborough | DescriptionThis project aims to modernize and secure the University’s identity self‑service capabilities by redesigning the user experience, rebuilding the backend architecture, and remediating critical security vulnerabilities within the current account management platform. The effort will deliver a modern, intuitive, secure, and scalable framework that supports the full lifecycle of identities and secondary accounts
Customer BenefitModernize the account claim process and create a better user experience for self service Design allows for future expansion for self-service attribute management I.e. name changes Secure processes around privileged account management (PAM) |
| Secure Computing | Priority 3 - Normal Start 10/1/21 Percent Complete 90% Status Name Green |
Jamie Mclandsborough | DescriptionTo better ensure the integrity of the shared information technology environment as it relates to end-user devices, all university-owned end-user devices, and personally-owned end-user devices that access or store university data, must meet the following conditions: For university-owned devices: • Enrollment in an approved endpoint management tool that reports security posture, such as MECM or Jamf Pro • Hardware and software asset tracking using the campus standard asset tracking tool (Eracent) • Public safety emergency notification client software (Alertus) • Up-to-date antivirus and anti-malware software • Full disk encryption • University data stored on enterprise standard cloud storage (OneDrive) For personally-owned devices: • Up-to-date antivirus and anti-malware software • Full disk encryption • University data stored on enterprise standard cloud storage (OneDrive) There are three overarching objectives of this project to reach this goal:
Customer BenefitIncreased security of university computing assets including personal and university owned data Reduce risk to university intellectual property Simplicity and consistency to procure and deploy Lays groundwork for consistency in support Visibility into enterprise procurement practices to drive efficiencies and cost savings |
| Academic Technology Tool Data Integration into Snowflake Data Mart | Priority 3 - Normal Start 6/4/25 Percent Complete 93% Status Name Green |
Justin Bailey | DescriptionWe have identified a strong need for uniform, easily accessible, and accurate usage data across more than a dozen technology tools within the OIT Academic Technology (AT) team umbrella, such as Canvas and Zoom. Improved access to this data will ultimately enhance our ability to support student success and will help us better connect the campus’ needs for technology with the most relevant solutions. In the current state, we have limited and extremely variable reporting (e.g. non-standard personnel identifiers, different ways to access and present data, etc.), and don’t have a way to combine the data across tools in an easy and useful way. Each tool’s usage data comes from a different place making it difficult to determine important metrics like comparative usage (e.g., number of instructors using each tool) and cross-usage (if student A uses Canvas, does student A also use Zoom, etc.). Without regular data importing, the time to refresh data for current week, month, or even semester and year is time-consuming. Current data reporting sources across AT Tools: • Canvas: Canvas Data 2 Database, API • Zoom: Looker Dashboard updated through D&A git script, API • Lecture and Classroom Capture: self-reporting, internal logs • Canvas Studio: API • iClicker: vendor sends report • Enrollment Statistics: CU Data • Course/Faculty Statistics: CU Data • Employment Tables: HCM Personnel Roster • Affiliation Tables: D&A request In this project, AT and D&A will develop the initial data connection and maintenance of service and tool data belonging to the Academic Technology (AT) Team into the Snowflake data mart, managed by the Data and Analytics (DA) Data Engineering Team. This will include usage data and other available tool data for applications supported by AT including but not limited to Canvas (Canvas data ETL integration), Zoom, MediaSite Lecture and Classroom Capture, iClickers, Canvas Studio, PlayPosit, Digication, and Qualtrics, etc. To keep the scope of the initial phase manageable, we will define a limited set of high-priority data points and tools to integrate first. This will include only the most essential metrics needed to demonstrate value and support decision-making. Once the foundational connections are in place and validated, we will iterate and expand the dataset incrementally—guided by team capacity, evolving needs, and feedback—by incorporating additional tools and metrics over time. Customer BenefitData consolidation and regular refreshes. One stop reporting and dashboard tool Efficiencies in data management. Greater understanding of data available to us from different tools AT supports and other datasets and metrics available to us from Campus via the Data Mart. |
| Implementation & Adoption of HAM Tool | Priority 3 - Normal Start 1/16/26 Percent Complete 21% Status Name Green |
Justin Bailey | DescriptionThe goal of this project is to establish ServiceNow, with the new Hardware Asset Management updates, as the single, consistent platform for tracking all University-owned property types in OIT, including capital assets, operating equipment, inventory, and consumables across OIT teams, personnel, consultants, and any other situation where hardware is purchased by OIT. This initiative will standardize asset management processes across the organization and will focus on ensuring that the newly integrated HAM tool is embedded in all hardware tracking processes. It will improve data integrity and enhance lifecycle tracking visibility, from when it is purchased through surplus. The IT Asset management team must be informed of any OIT hardware purchase and acquisition, and enable tracking in ServiceNow to ensure lifecycle tracking across OIT assets, equipment, and inventory. This would require collaboration between the IT Asset Management team and other teams within OIT. The project team will ensure this outcome by reviewing all other teams in OIT to determine hardware purchasing and will review and/or establish processes to enable HAM tracking in ServiceNow. Customer BenefitAll OIT asset types tracked in ServiceNow allows for centralized audit support that is complete and accurate. Financial transparency based on accurate asset management Successful integration with PCR360 will support accurate and complete asset data in ServiceNow. Teams trained and actively using ServiceNow HAM tool for asset updates. They will better know where the equipment is, amounts of hardware, and increased visibility into assets. |
| Automated Direct Billing Tool Discovery Project | Priority 3 - Normal Start 1/7/26 Percent Complete 25% Status Name Green |
Mikal Brusby | DescriptionThe Automated Direct Billing Discovery project will evaluate solutions for implementing an automated billing and provisioning system for enterprise storage services at CU Boulder. Rising pressures from Microsoft’s proposed costly storage quotas, as well as the need for a sustainable model for on-prem storage (UCB-Files), have highlighted the need for a transparent, consistent, sustainable, and scalable chargeback system. At the same time, recent proposals to modify Research Facilities & Administrative (F&A) rates have increased the importance of ensuring that certain allowable IT costs can be accurately allocated and recovered through grant/sponsored project funding. Currently, CU Boulder relies on manual, personnel-heavy processes for departmental chargebacks, requiring effort from service owners as well as campus-wide financial analysts. The proposed system would automate and improve accuracy in these processes by: • Providing a user-friendly portal for requesting additional storage across platforms including, but not limited to, Google, UCB-Files, Office 365, and PetaLibrary. • Automating approval workflows, provisioning, and billing through direct integration with CU Boulder’s PeopleSoft financial and HCM systems. • Provision the requested service or feature for the requestor via automated integrations where feasible (provide also for manual provisioning) • Supporting clear auditability and compliance through standardized reporting, dashboards, and notifications. While the initial focus is on enterprise storage platforms, the long-term vision is to create an automated internal billing framework adaptable to other OIT services that require expense pass-throughs, chargebacks, or rate-based recoveries. By addressing both immediate storage management needs and broader cost-recovery challenges, this project will enable CU Boulder to advance financial sustainability, support compliance with current and future research grant requirements, and improve the overall user experience for faculty, staff, and researchers. Customer BenefitClear documentation of business and technical requirements for automated storage usage, billing and provisioning Identification of feasible technical solutions and integration approaches (PeopleSoft, storage APIs, approval workflows) Alignment of needs across storage platforms (Google, O365, UCB-Files, PetaLibrary) into a unified framework Early assessment of financial models and grant cost-recovery implications (F&A) Improved understanding of user expectations for self-service, transparency, and notifications Risk identification before committing resources to implementation Roadmap and recommendations to guide potential future expansion. |
| Explore OIT Notification and Alerting Solutions | Priority 3 - Normal Start 11/1/25 Percent Complete 20% Status Name Green |
Mikal Brusby | DescriptionThis project will evaluate and recommend a centralized notification and alerting solution to support timely, automated communication across OIT services. This initiative responds to several recent service interruptions where OIT struggled to quickly and effectively identify and notify the appropriate service teams and support groups. The current notification system is aging, difficult to maintain, and lacks the flexibility needed to meet modern operational demands. The project will involve gathering technical and functional requirements from OIT service teams, identifying and piloting potential solutions, estimating costs (including training and implementation), and determining long-term ownership and governance. The effort will also produce a migration and documentation plan to support eventual implementation. For clarity, the following definitions apply within the scope of this project: • Alert: A system-generated message produced by an existing monitoring tool in response to a detected issue or condition. • Notification: A communication (such as an email, page, or similar message) sent to users or support teams to inform them of an issue identified by a monitoring system. This project does not include any changes to, or development of, monitoring systems. It is focused solely on evaluating and recommending solutions for distributing alerts and notifications generated by those existing systems. Important Note: This project will not include the procurement or implementation of the selected solution. Those activities will be handled through a separate project charter once a recommendation is finalized. Customer BenefitImproved incident response and reduced downtime. Increased visibility and accountability in service operations. Potential cost savings through tool consolidation and license management. Better support for hybrid work and learning environments. Standardization of alert processes and governance. |
| OIT Service Catalog – Phase 2 | Priority 3 - Normal Start 3/27/26 Percent Complete 22% Status Name Green |
Mikal Brusby | DescriptionPhase 2 of the Service Catalog project builds upon the foundational outputs delivered in Phase 1. The primary objective of this phase is to ensure that all relevant attributes (e.g., Service Name, Eligibility) for OIT services listed in the catalog are identified and documented. These attributes will need to be provided by designated OIT Service Owners and Managers. The project team will work to learn and understand the attributes that exist in ServiceNow to inform future processes such as how to keep the SN attributes updated. This phase will also establish processes to maintain the accuracy and integrity of the catalog information, ensuring it becomes a trusted and authoritative source for service-related information across the organization. Additionally, this phase will include a series of user tests (with ITPs, Students, and Staff/Faculty) to review and hear feedback on the list of services, labels and groupings of services created in Phase 1 to inform the final categories of services. Lastly, this phase will explore and then determine the best platform for the public-facing Service Catalog. Customer BenefitPhase 2 will significantly enhance service management capabilities by ensuring the catalog contains complete and accurate service attributes and a way to keep that information updated. In the future, this will enable more effective self-service functionality, reduce resolution times, and streamline the overall service experience. The UX Information Architecture Studies in Phase 2 will help us create a set of categories for the services that are intelligible to all users on campus. Phase 2 will also determine the best platform for the future public-facing Service Catalog, which will help OIT start to plan for the next phase of work to implement this. Continue to work towards improving access to service information and faster issue resolution. Continue to work towards streamlined support processes and better visibility into available services. Continue to work towards enhanced self-service options and quicker turnaround on service requests. |
| Red Hat 7 Offramp | Priority 3 - Normal Start 6/24/24 Percent Complete 90% Status Name Green |
Mikal Brusby | DescriptionThis project will address the ~113 Red Hat Enterprise Linux (RHEL) 7 servers within OIT that will reach end-of-life support on June 30, 2024. RHEL 7 will no longer receive stability patches and security updates after June 30, 2024. As such, the services on these servers must either be migrated to new servers, migrated to other platforms (cloud native or containers), or retired/decommissioned. The breakdown of these systems and the service teams responsible for them are as follows: Group RHEL 7 Systems Description DATA 15 Data driven services (Data + Analytics, including EDB) AS 31 Academics and Student Services (FIS, ATAP, Buff Portal) SEC 36 Security, IAM, M&C NEO 15 NEO, Data Center, VOIP, Paging PE 5 Platform Engineering LNX 11 Linux Platform Engineering As part of the project, we will document the systems that have campus border firewall exceptions and how many do not. We will also determine which systems will require Red Hat Enterprise Linux Extended Lifecycle Support. Failing to Customer BenefitReduce our security risk as an organization. Services migrated to supportable platforms allowing for continued development/improvement of the service if desired by service managers. |
| Collaboration Suite CMMC Level 1 Assessment | Priority 3 - Normal Start 2/26/26 Percent Complete 80% Status Name Green |
Na'Tima Harrison | DescriptionThis project will assess the University of Colorado Boulder’s Microsoft O365 and endpoint environment against CMMC Level 1 (Foundational) requirements to determine readiness to support systems handling CMMC Level 1 data. The assessment will identify which of the 17 required controls are currently met, unmet, or partially met; document existing control implementations; verify service provider responsibilities; and identify and remediate gaps to the extent feasible. The outcome of this effort will be a documented control posture and supporting evidence sufficient to support system authorization decisions for CMMC Level 1 data use, provider responsibilities; and identify and remediate gaps to the extent feasible. Background: When the CMMC Final Rule (32 CFR Part 170) became effective on November 10, 2025, among other requirements, it established the requirement to formally attest to compliance via the Department of Defense (DOD) Supplier Performance Risk System (SPRS) when CMMC Level 1 is included in a DOD solicitation stipulating that Federal Contract Information (FCI) be safeguarded per FAR 52.204-21. At this time (2/10/26), CU Boulder has identified 10 contracts requiring FCI safeguards under FAR 52.204-21 safeguarding requirements with an additional proposal request that, if awarded, will require FCI be handled under CMMC Level 1 safeguards. OCG identified the following services, in priority order, that currently support existing FCI contract information workflows within OCG:
Customer BenefitDocumented understanding of O365 & endpoint alignment with CMMC Level 1 controls Ability to authorize O365 systems to handle CMMC Level 1 data Reduced compliance and audit risk through documented controls and evidence Clear identification of gaps and ownership (OIT vs. Microsoft) |
| Contract Administration Suite CMMC Level 1 Authorization | Priority 3 - Normal Start 7/17/26 Percent Complete 35% Status Name Green |
Na'Tima Harrison | DescriptionA needs assessment this Spring (2026) concluded that current contract administration tools will need to be assessed and authorized to handle FCI, which is subject to CMMC Level 1 requirements. The 3rd party assessor recommended that we bundle the contract administration tools into a “suite” for the purposes of streamlining documentation and compliance tracking. This project will assess the following systems: InfoEd, OnBase, DocuSign, and Adobe Sign, to determine readiness for handling CMMC Level 1 data. The assessment will identify which of the 17 required controls are currently met, unmet, or partially met; document existing control implementations; verify service provider responsibilities and identify and remediate gaps to the extent feasible. The outcome of this effort will be a documented effective control posture and supporting evidence sufficient to support system affirmation decisions for CMMC Level 1 data use, responsibilities; and identify and remediate gaps to the extent feasible. InfoEd remains an unknown regarding the ability to meet Level 1 requirements; the vendor has stated that they are not striving to make their product compliant and we are unaware of any peers who have authorized InfoEd for handling FCI. CMMC Level 1 does not allow a Plan of Action & Milestones (POAM), so all controls must be fully met. The assessments are complicated by shared responsibilities and inherited controls: CU System Office’s UIS is the service provider for InfoEd and OnBase hosted locally, DocuSign is hosted by the SaaS provider in the cloud, and Adobe Sign is a local software product. Customer BenefitContract administrators can continue to use their existing systems to handle routine work on contracts subject to FCI requirements CU Boulder handles FCI in accordance with contractual requirements Reduced compliance and audit risk through documented controls and evidence Clear identification of gaps and ownership (OIT vs. UIS vs. Service Provider) |
| Canvas – Campus Solution Integration Re‑Architecture Project | Priority 3 - Normal Start 7/12/26 Percent Complete 0% Status Name Green |
Alicia Torres de Lozano | DescriptionThe Canvas Integration Re-Architecture Project aims to modernize course data integration between CU Boulder's Campus Solutions and Canvas. The existing setup, which has been in place for over a decade, relies on multiple complex and inefficient integration applications that are prone to failures. This has negatively impacted both student and faculty experiences with the LMS, added strain on OIT resources, and limited opportunities for innovation. This project will establish a strong foundation for continued optimization of the LMS development ecosystem. Customer BenefitReduced institutional risk of course provisioning failures that directly impact student access, academic continuity, and retention An efficient, accurate, reliable, and timely course[VO1.1][KH1.2] provisioning solution. Reduced troubleshooting time due to better logging and simpler architecture. Ability to use off the shelf Canvas features and vendor supports [VO2.1](AI tools, Level 1 support). Long term sustainability through a modern, maintainable integration architecture that establishes scalable patterns reusable across enterprise systems, supporting institutional agility. Rubric-based POC evaluation supports data-driven decision making, improving decision quality, transparency, and alignment with priorities and requirements Better position for potential future innovation. Implementation of Boomi POC presents an opportunity for this project to set the foundation for future implementations using Boomi. |
| Enterprise Slack Service Implementation | Priority 3 - Normal Start 7/21/26 Percent Complete 0% Status Name Green |
Alicia Torres de Lozano | DescriptionThe Enterprise Slack Service Implementation project will establish a centrally managed Slack Enterprise environment for the University of Colorado Boulder. The initiative is driven by both immediate Athletics requirements and a broader institutional need to provide a governed, supportable, and security-reviewed Slack service for university affiliates. The initial deployment is enabled through an Athletics-funded contract providing approximately 1,000-1,200 licensed seats beginning July 1, 2026. Athletics requires Slack to support critical business applications and workflows that do not integrate with Microsoft Teams, while select research groups require Slack to collaborate with external partners who utilize Slack as their primary collaboration platform. In addition, Salesforce has informed the university that Slack licensing will no longer be sold to individual colleges, departments, or organizations and that an Enterprise Agreement is required for continued use of Colorado.edu-affiliated Slack workspaces. As a result, the university must establish a centrally governed service to support existing Slack users and provide a sustainable path forward for departments and organizations that rely on Slack for approved business needs. The project will implement the technical infrastructure, governance model, security controls, identity integrations, licensing processes, support procedures, and operational practices necessary to offer Slack as an approved collaboration service. Slack will be classified as a Common Service, providing a centrally managed platform that can be shared across multiple colleges, schools, departments, and administrative units while remaining distinct from the university's foundational collaboration platforms. Messaging & Collaboration (M&C) will serve as the service owner, with Software Asset Management (SAM) responsible for license management and administration. The service will be supported through a shared operational model that includes the IT Service Center (ITSC) for Tier 1 support and escalation to M&C as needed. The scope of ongoing support will focus on access management, permissions, licensing, and approved integrations. Slack will not be promoted as a replacement for Microsoft Teams, and OIT will not actively encourage migration from Teams to Slack. Instead, growth of the service will be intentionally managed and prioritized around: • Athletics business requirements. • Existing paid Colorado.edu Slack workspaces requiring transition to the enterprise tenant. • Research collaboration requirements involving external partners. • Other approved business use cases where Slack provides capabilities not available through existing university-supported collaboration platforms. Customer BenefitEnables Athletics applications and workflows that require Slack integration Supports collaboration with external research partners who use Slack Provides centralized governance for existing university-affiliated Slack usage Reduces costs by consolidating departmental and individually funded Slack subscriptions Improves visibility and management of university-affiliated Slack environments Enables centralized identity management, SSO, and lifecycle controls Reduces risk associated with unmanaged Slack workspaces and shadow IT Enables Athletics applications and workflows that require Slack integration |
| CIRES Dashboard Expansion Tool | Priority 3 - Normal Start 7/17/26 Percent Complete 0% Status Name None |
Jamie Mclandsborough | DescriptionThe CIRES Dashboard Expansion Tool project addresses a longstanding, campuswide need for a unified, modern research financial management solution. Since 2019, campus units have reported persistent pain points managing sponsored research finances, fragmented data across systems, heavy manual reconciliation, and risks to accuracy and compliance. Formal surveys, committees, and an RFI concluded that no commercial solution adequately met CU Boulder’s needs. In contrast, the CIRES built dashboard has already demonstrated effectiveness and positive user feedback in departments such as Physics and ICS, making it the best foundation for a scalable campuswide service. This project scales the CIRES tool into an enterprise service by: (1) hiring two full time OIT developers to stabilize, enhance, and scale the app; (2) funding two CIRES pay lines (0.15 FTE each, Year 1) for knowledge transfer and onboarding; (3) completing OIT code and security audits; (4) selecting hosting (OIT VM or public cloud) and establishing monitoring; and (5) executing a phased rollout with outreach, beta recruitment, enhancement gathering, MVP delivery, and campus expansion. The outcome is a sustainable, secure, and scalable platform that reduces administrative burden, strengthens financial stewardship, and supports CU Boulder’s research mission. Customer BenefitAddresses a recognized, long standing campus need for a unified research financial tool Proven effectiveness of the CIRES tool (Physics, ICS) accelerates time to value Rapid, cost-efficient deployment leveraging the existing CIRES solution and expertise Scalable support model: OIT developers + BFI product ownership; CIRES knowledge transfer in Year 1 Efficiency and transparency via automation and improved documentation Security and compliance through OIT code and security audits Cross unit collaboration via the Finance Dashboard Professionals Group Alignment with OIT strategic priorities (service delivery, cyber risk, learner success/efficiency, research enablement, data maturity, and workplace culture) |