Skip to content

Access & runbooks

/people/runbooks, and a plans panel on a person’s Account & groups tab. A change in the school’s SIS — a new starter, a role change, somebody leaving — plans a runbook: disable, revoke sessions, licences, groups, mailbox delegation, device and loan recovery. Nothing runs, and nothing is deleted, until somebody approves it.

Three tabs: Waiting for approval, Scheduled, Finished. Each plan is a row coloured by what triggered it. Opening a plan shows every step’s before and after, when it runs, how it is approved, its status, any error, the plan’s own warnings, and who approved or cancelled it — so nobody approves a runbook without seeing what it actually does.

A sync’s cohort is reviewed as one batch: tick who is included, see how many will be left out, then one step-up approval covers the batch. A leaver batch that trips the school’s leaver cap is locked from being run until somebody looks at it; capped syncs can still be planned individually.

Run now, Approve and Undo all go through step-up authentication. Undo reads Re-enable when the step it is reversing disabled an account.

A temporary access pass, where a plan needs one, appears once in a dialog, is held only in that dialog’s own state, and is cleared the moment it closes — it is never written down anywhere else.

A list of leavers who are still holding something — a device, a loan — 30 days after their runbook finished. It needs identity.view. There is no button here to raise a recovery; that is a step on the leaver plan itself.

The plans panel on a person’s page only appears where Account & groups does, which needs that person to have an email and needs identity.view on your role. A leaver with no email on file is visible in the queue, but has no plans panel to open.