Purpose
Synchronize Aeries-derived student identity and school-context data into Active Directory for student account lifecycle readiness.
Current state
This Atlas record now represents the student-only Active Directory sync path. Current production evidence is strongest for the recurring Aeries-driven roster push and post-processing flow that keeps student AD state aligned, while staff lifecycle handling is now documented separately under Staff AD Account Management.
Next step
Publish the active scheduler inventory, service-account governance, and student-path exception-handling runbook.
Interfaces
Inputs- Aeries student data
- directory sync configuration
Outputs- updated student Active Directory state
- directory sync inputs
- password initialization and related student account artifacts
Reality to Action trace
Reality IngestionContributes in this stage.
Canonical StorageNot in scope.
Automation EnginesContributes in this stage.
Human InterfacesNot in scope.
Operational AdoptionContributes in this stage.
Core workflow
TBD. Document the 5-10 steps that define the core workflow.
Data integrity and contracts
Source of truth rules
- Aeries is canonical for student identity and school context.
- Active Directory is the managed target state for student account objects.
Safe handling
- Protect directory credentials, snapshots, and generated exports.
- Restrict student and staff identity logs to authorized administrators.
Operational notes
Reliability posture
Production evidence is strong across both Integr8r and Aether cron paths, but scheduler inventory and exception rules still need a formal runbook.
Observability
- Integr8r logs
- minimum-line and diff checks
- PowerShell post-processing logs
- cron-driven shell output
Security and privacy
Restricted staff and student identity data; internal only.
Dependencies
Upstream- Aeries
- AD permissions
- Linux and local runtime paths
Downstream- Active Directory
- Google directory sync path
- downstream student account state
Ownership
OwnersTechnology Services
UsersTechnology Services, district identity stakeholders, Josh Barton (owner)
Student Active Directory Sync
Operational Notes
- Production evidence spans the recurring student roster path and local post-processing that apply Aeries-driven changes into Active Directory.
- Staff lifecycle handling, preferred-name logic, non-HR intake, and onboarding notices now live under Staff AD Account Management.
- Failure delays or corrupts directory state and pushes identity teams into manual correction work.
Registry Alignment
- Mapped registry entry:
INT-041 - Registry clarified: this page is now the student AD sync only. Staff-side registry scope formerly blended here is now documented under Staff AD Account Management.
- Validation gaps: document scheduler inventory, service-account governance, and exception-handling rules for the student path.