Using Shibboleth within a Multi-Campus Institution

Like many similar institutions, the University of California assigns a great deal of autonomy to each of its campuses.  In particular, each campus has operational responsibility for the identity management of its community, as well as for the vast majority of network-based services provided to those communities.  There are, however, notable system-wide services that require access to identity information.  UC is developing a prototype federation of its campuses in a way that can be trusted to manage access to its centrally-provided self-service employee benefits system.  This has "raised the bar" with respect to what is required of each campus's identity management practices to create the environment of inter-campus (but intra-institutional) trust that is required to enable broad sharing of services among the campuses.