Skip to content

Re-scope step 8: Help Desk Admin through a group - #64

Open
rachmo wants to merge 4 commits into
mainfrom
claude/step8-scope
Open

rachmo wants to merge 4 commits into
mainfrom
claude/step8-scope

Conversation

@rachmo

@rachmo rachmo commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Docs only. Re-scopes lifecycle step 8 (capability G) after we found the original plan could not work.

Why. The 2026-09-26 plan had hawk-mod report who holds which delegated admin role. Google lets only a Super Admin see role assignments, and no custom-role privilege changes that, so hawk-mod@ could never have read them.

Decided with Rachel on 2026-10-02 (now in docs/lifecycle-sync.md, step 8):

  • Help Desk Admin (password resets) is the only delegated role. Groups Admin is no longer given out, because group membership comes from the sheet.
  • The role is carried by a new security group, computed from Mentor_Admin_Roles: Active Mentors whose CORI is current.
  • Every change to that group is a click, re-read at the click. Leavers are taken out by their existing Remove from groups.
  • Any other account Google flags as an admin is reported. Each Super Admin is acknowledged once.
  • Slack administrators get a step of their own.

Still open (listed in the doc): who may click the group's change (any Slack admin, or only Google Super Admins), and the group's name. Before anything depends on them, two things must be proven with a real call: whether hawk-mod@ can change the members of a group that carries an admin role, and whether Google then flags those members as admins.

Also updates google-setup.md (step 8 now adds no delegated scope) and lifecycle-sheet.md (Help Desk Admin is the only dropdown value; Rachel changes the sheet's Reference_Lists).

🤖 Generated with Claude Code

Rachel Moore and others added 4 commits October 2, 2026 14:37
Google lets only a Super Admin read who holds which admin role, so the
2026-09-26 "report only" plan could never have read what it was to report
on. Decided with Rachel on 2026-10-02: Help Desk Admin is the only delegated
role; it is carried by a security group computed from Mentor_Admin_Roles
(Active Mentor, CORI current); every change to that group is a click; any
other admin Google flags is reported. Groups Admin is no longer given out,
and Slack administrators are a step of their own. Docs only.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant