Conversation
Google lets only a Super Admin read who holds which admin role, so the 2026-09-26 "report only" plan could never have read what it was to report on. Decided with Rachel on 2026-10-02: Help Desk Admin is the only delegated role; it is carried by a security group computed from Mentor_Admin_Roles (Active Mentor, CORI current); every change to that group is a click; any other admin Google flags is reported. Groups Admin is no longer given out, and Slack administrators are a step of their own. Docs only. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Docs only. Re-scopes lifecycle step 8 (capability G) after we found the original plan could not work.
Why. The 2026-09-26 plan had hawk-mod report who holds which delegated admin role. Google lets only a Super Admin see role assignments, and no custom-role privilege changes that, so
hawk-mod@could never have read them.Decided with Rachel on 2026-10-02 (now in
docs/lifecycle-sync.md, step 8):Mentor_Admin_Roles: Active Mentors whose CORI is current.Still open (listed in the doc): who may click the group's change (any Slack admin, or only Google Super Admins), and the group's name. Before anything depends on them, two things must be proven with a real call: whether
hawk-mod@can change the members of a group that carries an admin role, and whether Google then flags those members as admins.Also updates
google-setup.md(step 8 now adds no delegated scope) andlifecycle-sheet.md(Help Desk Admin is the only dropdown value; Rachel changes the sheet'sReference_Lists).🤖 Generated with Claude Code