How Ideas2IT Built the Role-Aware Analytics Platform That Lets Lehigh University's Campus Run on QuickSight Instead of Tableau

Lehigh University was ready to move its campus analytics from Tableau to Amazon QuickSight. The missing piece was a governed, role-aware entry point that enforced access controls across colleges, departments, and financial data before campus-wide rollout could begin.

Client

Lehigh University

Industry

Education

Service

BI & Analytics

Stack

AWS · QuickSight · Redshift Engagement Model

Engagement

Fixed-bid + T&M Advisory

01 Challenge

Lehigh's analytics practice ran on Tableau, but licensing costs were escalating and access was limited to senior leadership and select departments. Moving to QuickSight campus-wide required more than a tool migration: financial, academic, and departmental data carried strict visibility rules, and without a governed access architecture enforcing RLS from Redshift through to the dashboard layer, broader rollout would create data exposure risk and unmanageable report fragmentation.

02 Solution

Ideas2IT designed and built two parallel workstreams: a fixed-scope Analytics Home Dashboard integrating Lehigh's SSO with QuickSight's API to enforce role-based access and RLS-governed dashboard routing for campus users, and an embedded T&M advisory model working directly with Lehigh's internal teams on dashboard development, governance standards, and self-service enablement.

03 Outcome

A governed QuickSight portal with SSO-integrated role resolution and RLS enforcement is in delivery for campus-wide rollout, replacing select-department Tableau access with a scalable analytics foundation Lehigh's teams can maintain independently.

Phase 01

Setting the access model before anything was built

Access Architecture and Portal Foundation: establishing SSO-integrated role resolution before the dashboard layer was designed

The first decision was confirmatory, not creative: the SSO integration approach and university identity provider configuration had to be locked before the navigation structure was designed.

  1. Lehigh's SSO user roles and QuickSight groups did not map directly, so role resolution required backend services calling the QuickSight API to translate group membership into dashboard routing logic at login.
  2. RLS enforcement was confirmed flowing from Redshift through to each dashboard's dataset configuration.
  3. A Dev, QA, and Prod environment strategy was defined as a governance structure, not standard scaffolding, to keep access controls auditable as roles and datasets expanded. The assessment of existing dashboards, datasets, and reports in this phase also

Deliverables

  • SSO integration assessment and identity provider configuration
  • QuickSight API backend for user group resolution
  • RLS-enforced dataset and access configuration
  • Dev / QA / Prod environment strategy
  • Role-to-dashboard navigation taxonomy

Phase 02

Building the governed analytics portal Lehigh's campus would actually use

Analytics Home Dashboard Build: role-aware navigation and branded campus entry point on QuickSight

With the access model confirmed, Ideas2IT built the Analytics Home Dashboard as Lehigh's single campus-wide entry point into QuickSight.

  1. The dashboard was branded to Lehigh's UI and UX standards and integrated into the university web portal as a navigation action, so users accessing analytics followed a path consistent with the rest of their campus experience.
  2. Navigation tiles were organised by role category, with QuickSight API routing directing each authenticated user to the dashboard set their group membership resolved to. Role-aware content visibility was configured at the dashboard level so no tile appeared for a role without access rights to the underlying data.
  3. Knowledge transfer documentation was built as a delivery requirement, covering configuration, extension, and independent maintenance so Lehigh's team could govern and grow the portal without engineering dependency after handoff.

Deliverables:

  • Lehigh-branded QuickSight Analytics Home Dashboard
  • Role-aware navigation tile structure
  • QuickSight API routing and group membership resolution
  • RLS-enforced dashboard visibility
  • University portal integration
  • Knowledge transfer sessions and documentation

Phase 03

Making the internal team self-sufficient on QuickSight at scale

Embedded Advisory and Enablement: QuickSight design patterns and governance for Lehigh's internal analytics teams

The T&M advisory workstream runs alongside the platform build, embedded with Lehigh's internal analytics teams across three functions. The core pattern addressed is the Tableau-to-QuickSight translation problem: calculated fields, drill-down configurations, and advanced visual design work differently enough in QuickSight that Tableau-trained users hit friction on practical tasks.

Advisory support works through these patterns as they arise rather than delivering a training curriculum. Governance consulting covers dashboard design standards, access control best practices, and duplication prevention as data lake access expands to more of the campus.

The objective is capability transfer, not dashboard delivery: the internal teams are the long-term owners of the QuickSight environment, and the advisory engagement is designed so that dependency on external support decreases as the team's QuickSight fluency increases.

Deliverables:

  • Calculated field and advanced visual design guidance
  • Drill-down and navigation design patterns
  • Performance optimisation recommendations
  • Dashboard governance and duplication prevention framework
  • Access control best practices
  • Ongoing technical consulting and design reviews

The Outcome

A governed QuickSight platform built to scale campus analytics beyond Tableau's reach

Category Metric Description
Analytics access Campus rollout Governed QuickSight access replacing select-department Tableau licensing
Delivery timeline 1 — 6 weeks Analytics Home Dashboard from discovery to production deployment
Access model Role tiers at launch SSO-integrated role resolution enforcing RLS from Redshift to dashboard
Engagement model Advisory retainer Embedded support for dashboard development, governance, and team enablement
Stack AWS · QuickSight · Redshift Bronze-silver-gold Redshift model with SageMaker Unified Studio and row and column-level security
Campus-wide analytics access became possible because the access architecture was designed before the dashboards were. The SSO integration, the QuickSight API role resolution layer, and the RLS enforcement running from Redshift through to each dashboard's dataset configuration meant that opening access to more of the campus did not require rebuilding the governance model around each new user group. That foundation is what the Analytics Home Dashboard sits on and what the advisory workstream is extending, one team at a time.