Open Authentication and duplicate management

Options

Hi Casey,

Thanks so much for the product panel today. I look forward to being invited to more in the future!

I actually just set up Gigya yesterday and I want to clarify the following:

- BEFORE a person is able to log in with one of the available sites (FB, twitter, yahoo, etc) they need to log into their Convio account FIRST in order to link them? What if they do not have a Convio record? Or think they don't but actually do? I'm worried about new and duplicate records being created.

- Does Open Auth utilize the email address from the available social sites at all? How?

Thanks, Casey!

Shana

--

Shana Masterson

Lead Manager, Online Campaigns

National Brain Tumor Society

smasterson@braintumor.org

Twitter: @npshana

Tagged:

Comments

  • Shana,

    All the social sites we work with provide back the users email address EXCEPT for Twitter.

    So lets say that the email I have associated with Facebook is cflinn@convio.com. And I already have a consID on your Convio site with this as the email address.

    When I come to your site, and use OA to login with my Facebook account:

    - The convio site will see that the Facebook email that was retreived via the API is actually already in the system.

    - Because we want to ensure that nobody can poach an constituent record, we require that user to enter their Convio site credentials

    - The user will be prompted to enter their convio site username and password

    - We expect people to not know this so there is a process being kicked off in the background to send a password reminder to that email address on file for that consID

    - Once the user enters their Convio site credentials, the system will then link the social account to the Convio site account.

    - The critical step here is to ensure that people are who they say they are so they need to possess both credentials for their social site and for their Convio site at the same time.

    Thanks,

    Casey

  • Casey Flinn:

    Shana,

    All the social sites we work with provide back the users email address EXCEPT for Twitter.

    So lets say that the email I have associated with Facebook is cflinn@convio.com. And I already have a consID on your Convio site with this as the email address.

    When I come to your site, and use OA to login with my Facebook account:

    - The convio site will see that the Facebook email that was retreived via the API is actually already in the system.

    - Because we want to ensure that nobody can poach an constituent record, we require that user to enter their Convio site credentials

    - The user will be prompted to enter their convio site username and password

    - We expect people to not know this so there is a process being kicked off in the background to send a password reminder to that email address on file for that consID

    - Once the user enters their Convio site credentials, the system will then link the social account to the Convio site account.

    - The critical step here is to ensure that people are who they say they are so they need to possess both credentials for their social site and for their Convio site at the same time.

    Thanks,

    Casey

    Thanks, Casey! This makes me feel much better about Open Auth as far as avoiding duplicates, rather than creating a new one!

    One additional question though - what happens if someone logs into a Facebook account (for example) that has a different email address than the one associated with their convio constituent record?

    Thanks,

    Shana

  • Shana Masterson:

    Thanks, Casey! This makes me feel much better about Open Auth as far as avoiding duplicates, rather than creating a new one!

    One additional question though - what happens if someone logs into a Facebook account (for example) that has a different email address than the one associated with their convio constituent record?

    Thanks,

    Shana

    Shana,

    In that case it will create a new record in the on the CONS360 database.

    I know this sounds like "oh, no more dupes!" but the power of OA is that you can get vaild email addresses and account creation quickly - and because most social sites give limited info, the email address is really the only reliable thing that Convio can validate against. The other thing to consider is that the value of a email address delivered via a social site is VERY high. For example if you get the email address that is associated with my Facebook account this is where im likley paying a lot of attention since all my FB notifcations are coming there. The nice thing is that with Automated Duplicate Management (also released in summer 2010) you can easily merge and unmerge these accounts.

    Thanks,

    Casey

Categories