Skip to content

Lifecycle step 7 (4/5): offboarding alerts, Suspend and Restore - #57

Merged
rachmo merged 1 commit into
mainfrom
claude/offboarding-alerts
Sep 29, 2026
Merged

rachmo merged 1 commit into
mainfrom
claude/offboarding-alerts

Conversation

@rachmo

@rachmo rachmo commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Step 7, part 4 of 5 (capability I, docs/lifecycle-sync.md). The alerts and buttons, after reading two dry runs with Rachel. Needs Google setup Part 4 (now in docs/google-setup.md) — Rachel did it on 2026-09-29.

What it adds

  • offboarding_accounts — one alert per person leaving with a Google or Slack account left, in the alert channel:
    • Suspend Google account while the account is active and holds no admin role. Google lets only a Super Admin change an admin's account (Help Desk Admin and custom roles included), so an admin's alert says so and offers no button.
    • a line asking an admin to deactivate their Slack account in Manage members (https://frc2713.slack.com/admin, checked live: signed out, it lands on "Sign in to RedHawkRobotics" and returns to /admin). Slack Pro gives hawk-mod no way to do it.
    • closes by itself once Google and Slack show both done.
  • Restore Google account on the existing onboarding request for an Active mentor whose account is suspended (someone who came back), replacing I'm on it there. It reminds that admin roles are not restored.
  • Remove from groups reaches every group in the Workspace. Someone leaving who is still in grp-orders, Kitchens and the like is gathered into their group_member_held alert (or gets one), with their role there — owners and managers included — and the click re-reads and removes them from those too.
  • Warnings, never removals: google_account_unknown for an active Google account no RHR Email reaches (hawk-mod@ itself aside), and group_outsider, one per address, for an address the sheet does not have in one of the other groups. Acknowledge once for a shared account or a collaborator.
  • The dry run now says whether the Suspend delegation is in place.

The rules it keeps

  • Every button is gated on administrator() and re-reads the sheet and Google at the click; nothing acts on what the alert said an hour ago.
  • Nothing deletes an account. Suspend and Restore are recorded against the clicker, with their reason, in account_changes (migration 0011) — Google's own log only names hawk-mod@.
  • A run closes only what a successful read shows done: an unreadable Google or unreadable groups never read as "all done", and Remove from groups is never called finished if the other groups could not be read.
  • No summary carries a student's address: an outsider is partly hidden, a student's alert names their Person ID and name only. Summaries keep verbatim, so no group handle pings anyone.

Tests

16 new in test/lifecycleOffboardingAlerts.test.ts (wording, which button each alert offers, the widened Remove from groups, the Google calls and their errors). npm run typecheck && npm test && npm run format:check && npm run build pass (834 tests).

After deploy: the test (step 7 is not finished until it passes)

On a throwaway mentor row and Google account: join → set Inactive → Remove from groups (its first real use) → Suspend → set Active → Restore → clean up by hand. Checked in the Admin console and audit log at each click. Then part 5 records the result in the docs.

🤖 Generated with Claude Code

The alerts and buttons for capability I (docs/lifecycle-sync.md, step 7):

- offboarding_accounts: one alert per person leaving with a Google or
  Slack account left. Suspend Google account while the account is active
  and holds no admin role (only a Super Admin can change an admin's
  account); a line asking an admin to deactivate their Slack account in
  Manage members, which Slack Pro gives hawk-mod no way to do. Closes by
  itself once Google and Slack show both done.
- Restore Google account on the existing onboarding request for an Active
  mentor whose account is suspended, replacing I'm on it there.
- Remove from groups reaches every group in the Workspace: someone leaving
  who is still in grp-orders and the like is gathered into their
  group_member_held alert (or gets one), owners and managers included, and
  the click re-reads and removes them there too.
- google_account_unknown and group_outsider: warnings, never removals, for
  an active Google account no RHR Email reaches (hawk-mod@ aside) and an
  address the sheet does not have in one of the other groups, one per
  address. Acknowledged once for a shared account or a collaborator.

Every button is gated on administrator(), re-reads the sheet and Google
at the click, and never deletes anything. Suspensions and restorations are
recorded against the clicker in account_changes (migration 0011). The
hourly job and sync now run the offboarding check, which closes only what
a successful read shows done. The dry run now says whether the Suspend
delegation is in place. google-setup.md gains Part 4.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@rachmo
rachmo merged commit 72f1cd4 into main Sep 29, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants