Access & runbooks
/people/runbooks, and a plans panel on a person’s Account & groups tab.
A change in the school’s SIS — a new starter, a role change, somebody leaving
— plans a runbook: disable, revoke sessions, licences, groups, mailbox
delegation, device and loan recovery. Nothing runs, and nothing is deleted,
until somebody approves it.
The queue
Section titled “The queue”Three tabs: Waiting for approval, Scheduled, Finished. Each plan is a row coloured by what triggered it. Opening a plan shows every step’s before and after, when it runs, how it is approved, its status, any error, the plan’s own warnings, and who approved or cancelled it — so nobody approves a runbook without seeing what it actually does.
A sync’s cohort is reviewed as one batch: tick who is included, see how many will be left out, then one step-up approval covers the batch. A leaver batch that trips the school’s leaver cap is locked from being run until somebody looks at it; capped syncs can still be planned individually.
Approving and running
Section titled “Approving and running”Run now, Approve and Undo all go through step-up authentication. Undo reads Re-enable when the step it is reversing disabled an account.
A temporary access pass, where a plan needs one, appears once in a dialog, is held only in that dialog’s own state, and is cleared the moment it closes — it is never written down anywhere else.
Leftovers
Section titled “Leftovers”A list of leavers who are still holding something — a device, a loan — 30
days after their runbook finished. It needs identity.view. There is no
button here to raise a recovery; that is a step on the leaver plan itself.
What this needs
Section titled “What this needs”The plans panel on a person’s page only appears where Account & groups
does, which needs that person to have an email and needs identity.view on
your role. A leaver with no email on file is visible in the queue, but has no
plans panel to open.