Purpose
Keep staff Active Directory accounts accurate and timely because that account lifecycle drives most downstream staff access and identity state.
Current state
This is the parent production integration for staff Active Directory lifecycle handling. The live path combines HR-driven provisioning and deactivation, approved non-HR request intake, preferred-name propagation, and embedded onboarding email delivery. Because staff AD is the source account for many downstream systems, changes here affect Google Workspace and other dependent staff-account workflows.
Next step
Publish one consolidated runbook covering scheduler ownership, service-account governance, request approvals, downstream system inventory, and rollback expectations.
Interfaces
Inputs- OCDE HR 2.0 staff data
- preferred-name and legal-name HR fields
- Google Sheets non-HR request intake
- staff provisioning and notification rules
Outputs- updated staff Active Directory state
- directory sync inputs for downstream systems
- staff onboarding notification artifacts
Reality to Action trace
Reality IngestionContributes in this stage.
Canonical StorageNot in scope.
Automation EnginesContributes in this stage.
Human InterfacesNot in scope.
Operational AdoptionContributes in this stage.
Core workflow
TBD. Document the 5-10 steps that define the core workflow.
Data integrity and contracts
Source of truth rules
- OCDE HR 2.0 is canonical for staff employment attributes and preferred-name source fields.
- Approved request sheets are authoritative for non-HR exception intake.
- Active Directory is the managed target state for staff account objects and a source boundary for many downstream systems.
Safe handling
- Protect HR extracts, request sheets, credentials, and notification artifacts.
- Restrict staff identity logs and snapshots to approved administrators.
- Document approval and deactivation controls before expanding exception intake.
Operational notes
Reliability posture
The production lifecycle path is well established, but scheduler ownership, service-account governance, downstream inventory, and rollback expectations are still fragmented across component notes.
Observability
- Integr8r logs
- snapshot artifacts
- PowerShell post-processing logs
- SMTP notification output
Security and privacy
Confidential staff identity, employment, and account data; request sheets, snapshots, and generated notifications must remain restricted.
Dependencies
Upstream- OCDE HR 2.0
- Google Sheets request governance
- Active Directory permissions
- Integr8r scheduler
Downstream- Active Directory
- Google Workspace display and account state
- other downstream staff-account systems
Ownership
OwnersTechnology Services
UsersTechnology Services, HR, district identity stakeholders
Staff AD Account Management
Operational Notes
- The active production path lives in the Integr8r
ActiveDirectoryStaff workflow plus local PowerShell post-processing and downstream directory sync behavior. - This parent record consolidates three former standalone registry entries: non-HR onboarding and timely deactivation, preferred-name synchronization, and staff onboarding email notifications.
- The staff AD account is the practical source account for many downstream staff systems, so identity drift here propagates broadly.
Registry Alignment
- Mapped registry scope:
INT-010, INT-011, and INT-012 now document one parent staff AD integration. - Registry clarified: component workflows remain useful technical records, but the production integration boundary is the full staff AD lifecycle.
- Validation gaps: scheduler inventory, service-account governance, exception approval chain, downstream system inventory, and rollback path still need explicit documentation.