William C. Larson -  March 26th, 2002

MWImageLink Technical Director, Developer, Evangelist 

MWImageLink is a subsidiary of Mail-Well, Inc, a global corporation consolidating over 100 printing, envelope and pre-press companies. MWImageLink provides customized, internet-based asset management.

Technical Direction

Ours is a small group of dedicated asp/VB programmers and network support staff. I strive to assure the uninterrupted provision of our products to our customers - negotiating the 'winding road' of customer requirements and software development (internal and contract) consistent with sound budget management.

Current product and service

I specified, purchased, installed and configured our platform servers, running 3 tier IIS and COM+, using a Compaq (AL) fiber channel based SAN for asset storage. My design allows n additional remote machines to be added, each controlled by the master web server- allowing our single enterprise license for MediaBin to apply across all of Mail-Well, exposing remote assets (many terabytes) over the internet. 

We 'brand' the user interface on behalf of each of our customers and we back up the SAN on an HP4/40 DLT Library via the fiber switch.

I specified and contracted for development of custom web services, managed our partner development and negotiated the contract for the core engine, MediaBin, which provides cataloging and on-demand repurposing of the customer's digital assets.

Security by design - 'controlled empowerment'

An optimal security model extends beyond the permission required to access a server- it penetrates to the core of the applications running there, optimally an integral part of the workflow. Consequently, in the manner of a 'flat' organization, I defined the security of our application away from the classic 'stair-step' model of Worker to Middle Manager, to Executive. I call our security philosophy 'controlled empowerment' as it allows any user to be given any permission; no stereotypes. This design returns administrative tasks to the workgroup level, where a flexible (eclectic?) mix of permissions are often manage best, and are in turn best managed.

To achieve this, several simple rules must apply. Users must join functional groups (such as photographers, sales, web related, Australia, etc.) to find assets (they are all owned by groups). Users with the right to assign permissions to other users may only assign permissions they themselves have, and may only assign them to the other members of their group(s).

The most significant of assignable user permissions are:

  1. Permission to 'Edit Myself': a user has/hasn't full control of their permission profile;
  2. Permission to 'Edit Others': allows a user to add or remove another group member's permissions, provided they themselves have it;
  3. Permission to 'Add to Groups': allows a user to add themselves to a group or approve others for membership in a group to which they belong.

By preventing a user from joining a group without approval from a group member, and by limiting assignable permissions to the members of their groups and to permissions the assignor already has, the administration of workgroups can be delegated to certain of it's members without fear of inappropriate access to unauthorized groups, or concern for anonymous assignment of permissions.

Assets and available Tasks are assigned to these groups and are also administered in the users permission profile, preventing unauthorized viewing, costly or inappropriate re-purposing, unauthorized uploading, assignment of assets to workgroups, etc.

As Evangelist

I characterize and present the value of our products to our customers. System features such as single image paradigms, hi-resolution images, autonomous permission groups, upload via the internet,  and much more create a world class brand management solution at an affordable price. In addition to the many companies using our product for brand-asset management, our service is used as a print sample library, an asset organizer by print-on-demand firms and as a thumbnail vendor for an inventory management package (third party integration to Sand Hill Systems).

Footnote

Ours is a most versatile product, able to pick up content in multiple cities, upload and catalog content over the internet, manage thousands of users, and on and on. I have enjoyed working with it from early design brainstorming, to hardware installation, to deliverable service - and I believe in it. I am confident that our customers are receiving great value for their money and time.