Skip to content

Lifecycle step 7 (5/5): tested end to end; docs as built - #61

Merged
rachmo merged 1 commit into
mainfrom
claude/step7-done
Sep 30, 2026
Merged

rachmo merged 1 commit into
mainfrom
claude/step7-done

Conversation

@rachmo

@rachmo rachmo commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Step 7, part 5 of 5. Records the end-to-end test and closes out the step.

The test (2026-09-30)

On P0074, a throwaway mentor row, and offboarding-test@, a throwaway account Rachel created:

  • joined grp-mentors and grp-all-team from the sheet, grp-orders by hand;
  • set Inactive → End monitoring, the accounts alert with Suspend, and Remove from groups listing all three groups — wording as intended;
  • Remove from groups, its first use in production: "Google Groups: Applied: 0 added, 2 removed. Other groups: removed from grp-orders." — confirmed in Google;
  • Suspend: refused at first (below); then worked, and the alert closed; the Admin console showed the user suspended;
  • set Active → the "suspended account" request came with Restore Google account; it restored the account, the Slack invite request came back (it is held while the RHR Email reaches a suspended account), and the groups run re-added them to grp-mentors and grp-all-team — not grp-orders, which hawk-mod never adds to.

The Slack half (the deactivation reminder) was not tested: the test person was never put in Slack.

The privilege

Suspend was refused ("Not Authorized to access this resource/api") with only Users → Update → Suspend users on hawk-mod@'s role, and still refused with Organizational Units → Read added (which Google's role-to-privilege table lists beside it). Rachel decided to give the role the full Users → Update — not Create or Delete — accepting that it can also reset a non-admin's password. hawk-mod's code only ever changes suspended. docs/google-setup.md Part 4 now says exactly that, and the refusal message names Users → Update.

Also

npm run typecheck && npm test && npm run format:check && npm run build pass (842 tests).

🤖 Generated with Claude Code

The test on 2026-09-30 (a throwaway mentor row, P0074, and account)
passed: Remove from groups, in production for the first time, took them
out of grp-mentors, grp-all-team and grp-orders; Suspend and Restore
worked; the groups run re-added them when Active again.

Suspend was refused with only Users → Update → Suspend users on
hawk-mod@'s role, and with Organizational Units → Read added. Rachel gave
the role the full Users → Update (not Create or Delete), accepting that it
could also reset a non-admin's password. google-setup.md Part 4 says so,
and the refusal message now names Users → Update.

Also: "Clicking Suspend Google account suspends it" in the accounts alert;
step 7 as built and the test in lifecycle-sync.md (status: steps 0-7
deployed); a step 7 paragraph in CLAUDE.md.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@rachmo
rachmo merged commit 48f3e09 into main Sep 30, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants