Conversation
Help Desk Admin is carried by the security group grp-helpdesk, computed from Mentor_Admin_Roles: Active Mentors with a Help Desk Admin row and CORI current, by RHR Email. planHelpdesk diffs that against the group. Apply adds, and removes anyone else (row gone, CORI lapsed, an address the sheet does not have), except someone leaving the team, who is held for their own Remove from groups. It also lists who cannot be added yet and Help Desk rows left on people who left. decideHelpdesk refuses a missing or wrong group; there is no "refused" plan, since every change is a click. planAdmins lists the Super Admins, any delegated admin grp-helpdesk does not explain (never hawk-mod@), and members Google does not flag as admins, which is how the dry run will show whether Google flags a role that comes through a group. Groups Admin is no longer an admin role the sheet may name; a row still naming it is a sheet problem saying so. Pure; nothing reads Google yet, and grp-helpdesk has no ID yet. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Step 8, part 1 of 4: the pure planner. Nothing reads or changes Google yet. The scope is in #64; this PR does not depend on it.
src/domain/lifecycle/helpdesk.tsplanHelpdesk: who should be ingrp-helpdesk(Active Mentor,Help Desk Adminrow onMentor_Admin_Roles, CORI current), against who is.decideHelpdesk: applies nothing to a missing group or an ID that leads to another group. There is no "refused" plan: the group is a handful of people, emptying it is legitimate, and every change is a click.planAdmins: every Super Admin (with suspended ones marked); every delegated admin thatgrp-helpdeskdoesn't explain, neverhawk-mod@itself; and members Google does not flag as admins. That last list is how the dry run (PR 2) will show whether Google flags a role that comes through a group.sheet.ts:Groups Adminis no longer an admin role. A row still naming it is a sheet problem: "Groups Admin is no longer given out; delete the row".Tests: 22 new, 863 in total, using plain objects. They cover each add, remove, hold and wait case; matching by an account's primary address when the RHR Email is an alias; the wrong and missing group; and each admin case.
Next: PR 2 reads
grp-helpdeskby ID and keeps Google's two admin flags apart (today they're merged into one), behind a/hawkmod lifecycle helpdeskdry run. It needs the group's ID from Rachel's Google setup.🤖 Generated with Claude Code