Lifecycle step 7 (4/5): offboarding alerts, Suspend and Restore - #57
Merged
Merged
Conversation
The alerts and buttons for capability I (docs/lifecycle-sync.md, step 7): - offboarding_accounts: one alert per person leaving with a Google or Slack account left. Suspend Google account while the account is active and holds no admin role (only a Super Admin can change an admin's account); a line asking an admin to deactivate their Slack account in Manage members, which Slack Pro gives hawk-mod no way to do. Closes by itself once Google and Slack show both done. - Restore Google account on the existing onboarding request for an Active mentor whose account is suspended, replacing I'm on it there. - Remove from groups reaches every group in the Workspace: someone leaving who is still in grp-orders and the like is gathered into their group_member_held alert (or gets one), owners and managers included, and the click re-reads and removes them there too. - google_account_unknown and group_outsider: warnings, never removals, for an active Google account no RHR Email reaches (hawk-mod@ aside) and an address the sheet does not have in one of the other groups, one per address. Acknowledged once for a shared account or a collaborator. Every button is gated on administrator(), re-reads the sheet and Google at the click, and never deletes anything. Suspensions and restorations are recorded against the clicker in account_changes (migration 0011). The hourly job and sync now run the offboarding check, which closes only what a successful read shows done. The dry run now says whether the Suspend delegation is in place. google-setup.md gains Part 4. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
willtoth
approved these changes
Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Step 7, part 4 of 5 (capability I, docs/lifecycle-sync.md). The alerts and buttons, after reading two dry runs with Rachel. Needs Google setup Part 4 (now in
docs/google-setup.md) — Rachel did it on 2026-09-29.What it adds
offboarding_accounts— one alert per person leaving with a Google or Slack account left, in the alert channel:https://frc2713.slack.com/admin, checked live: signed out, it lands on "Sign in to RedHawkRobotics" and returns to/admin). Slack Pro gives hawk-mod no way to do it.grp-orders,Kitchensand the like is gathered into theirgroup_member_heldalert (or gets one), with their role there — owners and managers included — and the click re-reads and removes them from those too.google_account_unknownfor an active Google account no RHR Email reaches (hawk-mod@ itself aside), andgroup_outsider, one per address, for an address the sheet does not have in one of the other groups. Acknowledge once for a shared account or a collaborator.The rules it keeps
administrator()and re-reads the sheet and Google at the click; nothing acts on what the alert said an hour ago.account_changes(migration 0011) — Google's own log only names hawk-mod@.verbatim, so no group handle pings anyone.Tests
16 new in
test/lifecycleOffboardingAlerts.test.ts(wording, which button each alert offers, the widened Remove from groups, the Google calls and their errors).npm run typecheck && npm test && npm run format:check && npm run buildpass (834 tests).After deploy: the test (step 7 is not finished until it passes)
On a throwaway mentor row and Google account: join → set Inactive → Remove from groups (its first real use) → Suspend → set Active → Restore → clean up by hand. Checked in the Admin console and audit log at each click. Then part 5 records the result in the docs.
🤖 Generated with Claude Code