# Cascades of Tucson — Remaining Work Plan (to completion) > Consolidated execution plan tying the open Syncro tickets to the broader migration > workstreams (workstations -> domain, users/departments, HIPAA caregiver lockdown). > Built 2026-06-24 (Howard) from a live AD+RMM diff. Companion to `PROJECT_STATE.md` > and `wiki/clients/cascades-tucson.md` (current truth). > Goal: finish the migration quickly by working it as one sequenced plan. > > **REFRESHED 2026-07-13** (reconcile pass vs wiki + live state): caregiver CA posture > updated to the 7/1 interim cutover, roster 35, Home->Pro completions folded in, > CS-SERVER EDR installed, ticket table reconciled against Syncro (0 open as of 7/10). > The "Live snapshot" below is still the 6/24 AD-vs-RMM diff -- domain-join states are > per-machine current in the wiki's "Migration phase status" table. > > **REFRESHED 2026-07-15 — FINISH-LINE PASS** (full live verification sweep: Graph/M365, > Datto EDR, UniFi, MSP360, DNS — all evidence in the 7/15 session log + wiki recompile): > - **CARF Technology Plan FINALIZED** (`docs/proposals/cascades-technology-plan-2026-07-15.md`) > — this roadmap is the execution engine behind it; plan targets (30/60/90 day) map to the > workstreams below. > - **jodi.ramstack DECOMMISSIONED 7/15** (disabled + sessions revoked + suspended-Standard > license reclaimed; mailbox was already deprovisioned by the suspended sub — no data in-tenant). > Suspended Standard now 29 consumed. > - **EDR verified 35/35** incl. CS-SERVER; email auth (SPF/DKIM/DMARC) verified; ALIS SSO > verified (secret good to 2028); 77 APs confirmed; voice VLAN exactly 37 devices. > - **Synology -> CS-SERVER share sync IS live and working** (wiki was stale; corrected). > - **New workstreams added**: WS8 (SharePoint/Teams HIPAA migration), WS9 (ALIS online > payments), WS3 step 3b (nurse-station phone-parity shared login). > - Prepaid block: **21.5 hrs** (live 7/15). > - Goal restated: **close every workstream out** — the sequence at the bottom is the > finish order. --- ## Live snapshot — domain-join inventory (2026-06-24, AD vs RMM diff) **Domain (`cascades.local`) — joined staff workstations (12):** ACCT2-PC, CRYSTAL-PC, DESKTOP-DLTAGOI (Sharon/LE), DESKTOP-F94M8UT, DESKTOP-H6QHRR7, DESKTOP-N5G1ROO (Chris Knight), DESKTOP-ROK7VNM, DESKTOP-U2DHAP0 (Ashley), ASSISTNURSE-PC, NURSESTATION-PC, RECEPTIONIST-PC, MEGAN. (Plus infra: CS-SERVER = DC, CS-QB = QB VM. Stale AD objects to clean: DESKTOP-1ISF081 (last logon 2025-03), AZUREADSSOACC is the Seamless-SSO object — leave.) **In RMM but NOT domain-joined — still to migrate (~17):** | Machine | User / role | Plan | |---|---|---| | ASSISTMAN-PC | Meredith Kuhn (on LOCAL acct `meredithk`) | Domain-join + migrate her to `cascades\Meredith.Kuhn` | | ANN-PC | (verify user) | Join + OU + drives | | DESKTOP-LPOPV30 | (verify) | Join + OU + drives | | DESKTOP-MD6UQI3 | (verify, offline) | Join + OU + drives | | MAINTENANCE-PC | Maintenance | Join -> OU=Maintenance | | MDIRECTOR-PC | Shelby Trozzi (MC Director) | Join -> OU=Care-Memorycare | | MEMRECEPT-PC | MC reception (shared) | Join -> OU=Shared PCs | | NurseAssist | (distinct from ASSISTNURSE-PC) | Join or retire-as-dupe — verify | | SALES4-PC | Sales | Join -> OU=Marketing | | LAPTOP-8P7HDSEI | (verify) | Join or caregiver path | | Health-Services-Director | vs AD `HEALTH-SERVICES` | Verify dup/rename before acting | | **CHEF-PC** | Culinary (Chef JD) | **Ticket #32254** — reinstall Windows, THEN join -> OU=Culinary | | DESKTOP-TRCIEJA | Lupe Sanchez | EOL — **replace machine** (decision 2026-06-18), join the replacement | | DESKTOP-KQSL232 | Lois Lane | **DECOMMISSIONED 6/26** (her HEALTH-SERVICES box is already domain-joined) | | CascadesProxess | Proxess access-control appliance | Likely leave un-joined — verify it's an appliance | | Laptop2, LAPTOP-DRQ5L558, LAPTOP-E0STJJE8, Laptop4 | Caregiver shared laptops | Join via the **Caregiver Devices** path (Workstream 3), not the staff path | **OU structure (built):** `OU=Departments` -> Administrative, Marketing, Care-Assisted Living (+ Nurses), Care-Memorycare, Culinary, Housekeeping, Life Enrichment, Maintenance, Resident Services, Transportation, Caregivers. `OU=Workstations` -> Staff PCs, Shared PCs, `OU=Caregiver Devices` (under Staff PCs). Groups in `OU=Groups`. --- ## Workstream 1 — Workstation domain migration **Goal:** every staff PC on `cascades.local` + GuruRMM + correct dept OU + mapped dept drives; retire per-PC Synology Drive Client. **Per-machine runbook** (scripts in `docs/migration/scripts/`): 1. `phase3-pre-join-verify.ps1` (OneDrive KFM unlinked, no poisoned shell folders, name OK) 2. `phase3-join-domain.ps1` -> join `cascades.local` 3. `phase3-post-join-verify.ps1` 4. Move computer object into the correct **department OU** 5. Confirm GuruRMM agent still checks in; migrate the user profile/data 6. Map department drives (Workstream 2); uninstall Synology Drive Client; delete local cache once clean 7. Log the change **Tickets in this workstream:** #32194 (deploy spare machine for new hire — join + enroll + AD acct), #32254 (Chef-PC reinstall then join). ### Device readiness audit (2026-06-24, live probe of 15 un-joined online machines) | Machine | User | Edition | Readiness | |---|---|---|---| | DESKTOP-LPOPV30 | Karen Rossini | Win11 Pro | READY | | MAINTENANCE-PC | Bruce Miller | Win11 Pro WS | READY | | LAPTOP-E0STJJE8 | caregiver | Win11 Pro WS | READY (caregiver path) | | ASSISTMAN-PC | Meredith Kuhn | Win11 Pro | pending reboot | | ANN-PC | christina | Win11 Enterprise | pending reboot | | Laptop2 | caregiver | Win11 Pro | pending reboot | | CHEF-PC | Ramon Castaneda | Win11 Pro | do #32254 reinstall first | | LAPTOP-8P7HDSEI | User | **Win10 Home** | BLOCKED: Home->Pro + OneDrive KFM ON | | MDIRECTOR-PC | Shelby Trozzi | **Win11 Home** | BLOCKED: Home->Pro + reboot | | MEMRECEPT-PC | memfrtdesk | **Win10 Home** | BLOCKED: Home->Pro + reboot | | NurseAssist | Veronica | ~~Win11 Home~~ **Pro WS (upgraded 6/26)** | READY-ish: KFM ON (unlink) + reboot; confirmed distinct from ASSISTNURSE-PC | | SALES4-PC | Tamra (OFFBOARDED 6/30) | ~~Win11 Home~~ **Pro (supplier upgrade)** | Repurpose TBD; join when reassigned | | LAPTOP-DRQ5L558 | caregiver | Win11 Pro WS | BLOCKED: off-network (public DNS, no DC reach) | | DESKTOP-TRCIEJA | Lupe Sanchez | Win11 Pro | SKIP — EOL, being replaced | | Health-Services-Director | Lois Lane | Win11 Pro WS | already domain-joined (= AD `HEALTH-SERVICES`) | **Prep blockers / decisions (2026-06-24):** - **5 machines on Windows Home cannot domain-join** until upgraded to Pro (need license keys): LAPTOP-8P7HDSEI, MDIRECTOR-PC, MEMRECEPT-PC, NurseAssist, SALES4-PC. **Howard handling the Home->Pro upgrades himself, ONSITE** (decision 2026-06-25). - *2026-06-25 live re-check: the 6PM cron `ad0a56a9` never completed — all 5 still `EditionID=Core` (Home), Licensed on Home keys, none half-upgraded. ProductName reads "Windows 10 Home" even on the Win11 boxes (stale registry string) — trust EditionID, not ProductName.* - **DONE 2026-06-25 (~8:45 PM, remotely via RMM, no users logged in):** the 3 online Home boxes upgraded Home->Pro. Process: `changepk.exe /productkey ` flips Core->Professional (as SYSTEM it does NOT auto-reboot; registry vs licensing go out of sync — **reboot once to finalize**), then activate. Results: - **MDIRECTOR-PC** -> Professional, **self-activated FREE via a built-in Pro digital entitlement** (no MAK used, no charge). READY to domain-join. - **MEMRECEPT-PC** + **LAPTOP-8P7HDSEI** -> activated with the ACG MAK (`infrastructure/windows-pro-mak`). NOTE: the MAK is a **Pro for Workstations** MAK — `/ipk` retargets the edition to `ProfessionalWorkstation` (higher SKU, fine for domain join), `/dli` = Licensed, VOLUME_MAK channel. **2 MAK counts consumed -> bill 2x $99 = $198 to Cascades** (line items name each machine). MEMRECEPT needed an `/ato` retry (first attempt hit transient `0x8004FE92`). - **[RESOLVED 6/26-6/30]** NurseAssist + DESKTOP-MD6UQI3 upgraded to Pro for Workstations 6/26 (2 x $99 to bill — Syncro product 23571919, not yet invoiced as of 7/10); NurseAssist confirmed a distinct machine from ASSISTNURSE-PC. SALES4-PC upgraded to Pro by its supplier (no ACG charge); Tamra offboarded 6/30, machine repurpose TBD. - Next step for the 3 upgraded boxes = **domain-join** (they now read `EditionID=Professional`/PfW). - **OneDrive KFM ON** (unlink before folder-redirect GPO): LAPTOP-8P7HDSEI, NurseAssist. - **Pending reboots + KFM unlinks: held for onsite** (Howard) — disruptive to clear remotely. - **LAPTOP-DRQ5L558** is off the Cascades network (8.8.8.8/1.1.1.1 DNS, no DC reachability) — must be on-site/on-LAN before any join. - Note: the legacy `phase3-pre-join-verify.ps1` hardcodes the DC at `192.168.2.254`; clients actually reach it at `192.168.2.248` (the `.254` NIC is the Hyper-V vEthernet and does not cleanly serve domain SMB) — update the script's target before reuse. - Pro/Enterprise + internal machines are READY to join once reboots are cleared onsite: DESKTOP-LPOPV30, MAINTENANCE-PC, ASSISTMAN-PC, ANN-PC, LAPTOP-E0STJJE8, Laptop2 (+ CHEF-PC after #32254). --- ## Workstream 2 — Users, departments & file-share access **Goal:** every user in the right OU + `SG-*-RW` group; department drives mapped per the access matrix; Synology retired as primary. - Shares already created on CS-SERVER (`D:\Shares\...`): Management, Sales/SalesDept, Server, Accounting, Culinary, Activities, directoryshare, IT, Receptionist, **Executive (NEW — Ashley+Meredith)**. Confirm ALdocs/WebDocs/LifeEnrichment exist + NTFS per the matrix. - Populate `SG-*-RW` groups per `docs/migration/share-access-matrix-2026-04-23.md`. - Map dept drives per user via GPP/logon script (Receptionist drive = machine+user scoped, Tower desk only). - **Close out the matrix open questions** (per-user interviews): Lois Lane, Karen Rossini, Susan Hicks, John Trozzi, Lupe Sanchez, Shelby Trozzi, Matt Brooks, Christine Nyanzunda; `pacs`/Clinical-PHI create-or-retire; `web` retire. **Tickets:** #32193 (Executive restricted share — **DONE 2026-06-24**, E: mapped both machines), #32230 (Karen Rossini -> ALDOCS on Synology — **recheck when she's in**, she was out 2026-06-24). --- ## Workstream 3 — HIPAA caregiver lockdown — GO-LIVE (highest value, mostly built) **[UPDATED 2026-07-15]** The 7/1 cutover put caregivers in an **interim posture**: all 35 `SG-Caregivers` may sign in on desktops AND phones, **on-network only** (`e35614e1` off-network block — policy itself enabled since 2026-04-29 per live CA read 7/15, trusted IPs 72.211.21.217/32 + 184.191.143.62/32 — + `7d491c7a` 8h sign-in frequency enforced; `SG-Caregivers` excluded from MFA-for-all). The compliance-block policy `ede985e2` was **DISABLED 2026-07-01 — do not re-enable** (superseded by the allow-list). Temp passwords are live for phone sign-in (must-change cleared fleet-wide 7/2; `PSO-Caregivers` never-expire FGPP in place). Roster = **35** after the 7/1 reconcile. **Juan Andrade offboards 2026-07-16 afternoon** (coord todo `80716a98`). Final lockdown = flip from test scope to real caregivers, one device at a time (detail: wiki "Entra Access Architecture"): 1. Swap GPO `CSC - Caregiver Workstation` security filter `SG-Caregivers-Test` -> `SG-Caregivers`. 2. CA allow-list policy `1b7fd025`: **two changes** — retarget test group `SG-Caregivers-DeviceTest` -> `SG-Caregivers` AND flip from report-only (`enabledForReportingButNotEnforced`) to enforced. Prereqs: `SG-Break-Glass` + GDAP/service-provider exclusions in place (break-glass accounts still NOT created — do this first). 3. Move each caregiver machine into `OU=Caregiver Devices` + `SG-PC-MainTower`/`SG-PC-MemoryCare` one at a time: Laptop2, LAPTOP-DRQ5L558, LAPTOP-E0STJJE8, ASSISTNURSE-PC (needs re-join + re-tag after Win11 reinstall), NURSESTATION-PC (+ verify NurseAssist/Laptop4). NOTE: the device-lockdown (auto-logoff) GPO only applies once machines are in `OU=Caregiver Devices` — until then desktops caregivers use under the interim posture have NO auto-logoff enforcement. 3b. **[ADDED 2026-07-15, Howard] Nurse-station desktops = phone-parity shared login.** The TWO nurse-station desktops — **NURSESTATION-PC + ASSISTNURSE-PC** (explicitly NOT the medtech laptops) — get the same model as the caregiver phones: ANY caregiver signs in with their own `cascades\` username, lands on ALIS via SSO, and sees the SAME standardized desktop shortcuts to the SAME sites as the phones. Implementation: allow `SG-Caregivers` interactive logon on those two machines; deploy the shortcut set via the `CSC - Caregiver Workstation` GPO (per-machine, all-users desktop) so every profile is identical; no per-user profile customization; auto-lock/sign-out from the device-lockdown GPO applies (step 6). Define the canonical shortcut list from the phone home-screen set (ALIS + the same sites — capture the list from a phone before building). 4. ALIS email-match the 35 caregivers + medtechs (ALIS staff Email = Entra UPN); ALIS records still to create for Munezero/Cota/Robinson; Vallejo email-match; 7 discharged-record decisions; turn off ALIS-native 2FA per user, then move to SSO-only (native login is a CA bypass path). 5. Lower ALIS app session timeout 20 -> 15 min (Howard, ALIS admin). 6. **Reboot NURSESTATION-PC** to activate + verify the device-lockdown GPO (lock @3min, 90s warn, sign-out @15min). 7. Phones-only lockdown cohort: deferred to end of rollout — `docs/cloud/caretaker-phones-only-list.md`. 8. Pilot cleanup: delete `pilot.test`, remove stale `SG-Caregivers-Pilot` exclude from the MFA policy, delete the pilot/test groups. --- ## Workstream 4 — M365 - **Relicense remaining suspended Business Standard users -> Business Premium** (Standard SKU is SUSPENDED — time-sensitive). Live 7/15: SPB 45 enabled / 41 consumed (4 free); suspended Standard **29 consumed** after the jodi.ramstack reclaim — 29 users to move needs ~25 more SPB seats OR a per-user needs pass (lighter licenses where full Office isn't needed — the CARF plan Area 2 budgets ~$375–575/mo for the mix). Count seats + decide mix before touching licenses. - ~~Decommission jodi.ramstack~~ — **DONE 2026-07-15** (disabled, sessions revoked, license reclaimed; mailbox already gone via the suspended sub — nothing recoverable in-tenant). - **Create break-glass accounts (`breakglass1/2-csc@`) + enroll FIDO2 YubiKeys** — still not created (confirmed 5/27); now a **prerequisite for the WS3 allow-list enforcement flip**. - **Remove the standing Privileged Authentication Administrator role from the `ComputerGuru - Tenant Admin` SP** (stranded by Alma's 6/25 offboarding; needs a Global Admin; keep its Conditional Access Administrator role). Pending Mike. - Build audit retention (Log Analytics 90d + Storage 6yr) in `rg-audit-cascadestucson` — approved 2026-04-29, still unbuilt (HIPAA SS164.312(b) gap, includes D:\Homes object-access auditing). - Zeke Huerta: register Authenticator MFA (under MFA-for-all with no method since 7/1). - Megan Hiatt: re-verify the April credential-stuffing remediation held (flagged 6/30). --- ## Workstream 5 — Server / infrastructure - **Cloud backup (MSP360 -> ACG-backup): re-verified 2026-07-15** — daily file-level backup running clean (incrementals current). **[WARN] The image/system-state side was ~10 days stale at the 7/15 check** — confirm/repair the image plan + set retention BEFORE the SSD swap. [GATE for any drive work] - **CS-SERVER RAID -- CORRECTED 2026-06-24: HEALTHY, not degraded** (live OMSA: both mirrors Ok, all 5 disks Online, all LEDs green; the 6/15 degraded self-recovered). **NO emergency drive swap.** 1:0:4 = global hot spare (do not remove). **Planned** reliability upgrade: replace the 2 consumer 320 GB drives (esp. flaky WD 0:0:3) with the 2x enterprise SSD **already purchased**, on a scheduled window w/ confirmed image/system-state backup. **[WARN] PSU redundancy lost** -- one PSU not delivering, check onsite. Service Tag 9MQFTK1. Real fix = DC migration off the 16-yr-old R610. - ~~Clean up old-MSP agent sprawl (Datto RMM/CentraStage + Datto EDR/Infocyte) thrashing the spindle~~ — **DONE on CS-SERVER 2026-06-26** (full legacy Datto stack removed). **Current Datto EDR installed on CS-SERVER 2026-07-13** (HUNTAgent=Running, cmd `0a60cac7`) — the DC is back under managed endpoint protection. Fleet stragglers tracked in the wiki (DESKTOP-TRCIEJA BD_ACTIVE, laptop3/laptop1/ cascades-laptop reconcile, Syncro BD-deployment removal, GravityZone portal cleanup). - Synology -> backup-only: **the share syncs Synology -> CS-SERVER ARE set up and working** (confirmed by Howard 7/15; wiki corrected). Remaining: finish the role flip (server is primary, Synology becomes the onsite backup target per CARF plan Area 5) + close the workgroup/Kerberos quirk. - Rotate the Synology signin-portal credential (was committed plaintext historically). - pfSense: **AutoConfigBackup not enabled** (found 7/15) — enable it (config IS backed up via our repo copy, but ACB gives point-in-time restore). --- ## Workstream 6 — Network (mostly complete) - **CSC ENT device-island consolidation (phones + Helpany on 5 GHz)** — repurpose CSC ENT as a **5 GHz-only WPA2 PPSK** SSID and consolidate BOTH the Poly voice handsets (-> VLAN 30) and the Helpany "Paul" radar sensors (-> new VLAN 40) onto it, separated at the VLAN layer. Gets both off congested 2.4 GHz; keeps WPA2-only gear isolated so CSCNet can later move to WPA3/WiFi7/6GHz. Supersedes the standalone "Voice 5 GHz lock" item below and the earlier "delete CSC ENT" idea (deleting it would orphan the Pauls). Both vendors can move their devices remotely once we provide the network. **Onsite gate: verify per-room 5 GHz coverage before the band flip** (steel walls; weak-5GHz devices stay on 2.4). Full design + sequence: `docs/network/csc-ent-device-island-plan.md`. - Build VLAN 40 (Helpany, egress-only to `*.sedimentum.com` + snapcraft/ubuntu) on pfSense. - Enable PPSK on CSC ENT: key `Ftfd85710#` -> VLAN 40 (Pauls keep SSID+key, not reprogrammed); new voice key -> VLAN 30 (phones re-pointed by Howard/Richard). - Flip CSC ENT to 5 GHz-only (`apply-wlan.sh ... bands 5g`) in a coordinated window; pilot a few phones + Pauls, then full rollout. - Helpany = Sandro Cilurzo / Eugenie Nicoud; Poly = Richard Turner (Vertical). - **PREREQUISITE (live 2026-06-24): CSC ENT has 149 clients, only 68 are Helpany.** ~79 non-Helpany devices must be evacuated first — 14 staff PCs (domain mig), 11 printers, **11 DIRECTV + 11 resident IoT/TV + 15 personal phones + 17 unknown (resident-facing — need help reconnecting)**. ~51 are on 2.4 GHz and would drop on a 5 GHz-only flip. Per-device inventory + resident help-list: `docs/network/csc-ent-client-inventory-2026-06-24.md`. TODO: pull `stat/alluser` for offline resident TVs; identify the 17 unknowns + generic phones with John Trozzi. - **#32319** WiFi Room 343 — relocate a floor-2/4 AP for coverage (unifi-wifi skill, site `va6iba3v`). - **#32342** Copy Room switch — install + adopt into UniFi. - Sub-gigabit sweep (live 7/15): **34 switch ports at 100 Mbps + 5 AP uplinks below gig** — cabling/NIC sweep, prioritize the AP uplinks. (Live UniFi count 7/15: **11 switches**, 77 APs, voice VLAN exactly 37 devices.) - *(Superseded)* Voice 5 GHz lock — now folded into the CSC ENT consolidation above (single dedicated 5 GHz network for phones + sensors, not just a phone-side band lock). --- ## Workstream 7 — Onsite peripheral - **#32370** eFax setup (Karen & Christin) + portable scanner on both machines. --- ## Workstream 8 — M365 collaboration migration (SharePoint / Teams) — HIPAA lockdown > Added 2026-07-15 (Howard): move Cascades onto SharePoint, Teams, and the wider Microsoft 365 > platform to lock down data access and advance HIPAA compliance. Pairs with the network upgrade > work (WS6) and the domain migration (WS1/2) — the dept OU/group structure built there becomes > the SharePoint/Teams permission model. - **Scope/plan the migration**: department file shares (CS-SERVER `D:\Shares` + Synology) -> SharePoint document libraries with role-based permissions mapped from the existing AD dept groups; Teams for internal comms/collab (replaces ad-hoc channels); OneDrive for per-user files. - **HIPAA guardrails first-class**: role-scoped access (same SG model as caregiver lockdown), audit logging (ties into the WS4 audit-retention build), retention policies, DLP evaluation, sensitivity labels for PHI, external-sharing OFF by default. - **Licensing already supports it** — Business Premium (45 seats) includes SharePoint/Teams/ OneDrive/Intune/Purview basics; the WS4 relicensing moves the office staff onto it. - Sequencing: after (or alongside tail of) the domain migration — don't build SharePoint permissions on the pre-migration flat-share model. Candidate first movers: the newer role-based shares (Executive restricted, Company Web Docs, ALDOCS). - Synology then finishes its transition to backup-only (WS5) once shares live in SharePoint. - Also on the plan doc: Copilot evaluation under HIPAA guardrails + the KPI dashboard's SharePoint/Power BI Phase 1 (scheduled exports) land on this same platform. --- ## Workstream 9 — ALIS online payment system > Added 2026-07-15 (Howard): get Cascades onto ALIS's online payment system (resident/family > billing payments through the clinical-record platform, Medtelligent). - **Scope with Medtelligent** — **scoping questions DRAFTED 2026-07-15** (`docs/proposals/alis-online-payments-scoping-2026-07-15.md`, 18 questions: availability/ pricing/processor/PCI/BAA/ledger-posting/API/rollout). Next action: send to the Medtelligent rep, loop in Jeff Bristol (accounting@) on replies. Q9 doubles as the BAA chase (Medtelligent BAA unverified — feeds the area-4 BAA inventory regardless). - Coordinate with the business office (Jeff Bristol / accounting@) on the AR workflow change and family communication. - IT-side items: SSO already live for ALIS (staff side); verify family-facing payment portal access needs nothing on our network/identity side; add Medtelligent's payment processing to the BAA/vendor tracker (plan area 4). - Ties into the KPI dashboard (ALIS billing data is a Phase 1 export source). --- ## Finish sequence — re-cut 2026-07-15 (order of completion) Everything below is scoped, built, or blocked on exactly one prerequisite — this is the close-out order, not a wish list. 1. **2026-07-16 afternoon: offboard Juan Andrade** (disable + SG-Caregivers removal + license reclaim) — coord todo `80716a98`. Do NOT disable before then. 2. **Break-glass accounts (`breakglass1/2-csc@`) + FIDO2 keys + strip the stranded PAA role** (WS4) — THE blocking prerequisite for the allow-list enforcement flip; the tenant runs live block policies with no break-glass today. Also the CARF plan's 30-day security item. 3. **Caregiver lockdown go-live** (WS3 steps 1–8, incl. 3b nurse-station phone-parity build) — highest HIPAA value; the real control (`1b7fd025` allow-list) is still report-only/test-scoped. Capture the phone shortcut list for 3b while onsite for the OU moves. 4. **M365 relicense the 29 suspended-Standard users** (WS4) — time-sensitive; decide seat mix first (4 SPB free vs 29 to move). 5. **Repair/confirm the image/system-state backup -> scheduled SSD swap** (WS5) — image side was ~10 days stale on 7/15; single-DC risk until done. 6. **Remaining staff domain joins + dept drives** (WS1+2: ~10 machines left after readiness blockers cleared) + printer-share repoints / Point-and-Print GPO fleet-wide (wiki VLAN 20). Onsite batch: reboots, KFM unlinks, LAPTOP-DRQ5L558 on-LAN. 7. **Network tail** (WS6: CSC ENT device island incl. the ~79-client evacuation, 34-port + 5-AP-uplink gig sweep) + **audit-retention build** (WS4 — HIPAA 164.312(b) gap, approved since 4/29). 8. **M365 collaboration migration (WS8)** — SharePoint/Teams scoping once the domain-migration tail is done; permission model rides the dept OU/SG structure from WS1/2. Synology finishes its backup-only role flip (WS5) behind it. 9. **ALIS online payments (WS9)** — vendor-driven, runs in parallel with everything above: scoping questions are DRAFTED (`docs/proposals/alis-online-payments-scoping-2026-07-15.md`) — send to Medtelligent when ready; business-office coordination (Jeff Bristol) is the long pole. 10. **Ticket-verify pass with Howard** (table below) — confirm the 6 closed-in-Syncro tickets were actually completed; any that weren't fold back into WS1/2/6/7 and get done in step 6–7 onsite trips. --- ## Open Syncro tickets -> workstream map **[RECONCILE 2026-07-13] Syncro showed 0 open tickets as of 7/10**, but the 6 tickets below were "Open — onsite" in the 6/24 plan and no completion is recorded in the wiki/session logs. **VERIFY with Howard: completed-and-closed, or closed-without-work?** Any not actually done go back on the board as workstream items (the underlying work — Chef-PC reinstall+join, Room 343 AP, Copy Room switch, eFax/scanner, spare machine, Karen ALDOCS — is still required by WS1/2/6/7). | Ticket | Workstream | Status | |---|---|---| | #32193 Executive restricted share | 2 | **DONE 2026-06-24** (E: both machines, billed 0.5h block) | | #32194 spare machine for new hire | 1 | Closed in Syncro — **verify work done** | | #32230 Karen -> ALDOCS | 2 | Closed in Syncro — Karen's ALDocs shortcut WAS set 6/26 (drive-map); likely done | | #32254 Chef-PC reinstall | 1 | Closed in Syncro — **verify reinstall + domain-join happened** | | #32319 WiFi Room 343 | 6 | Closed in Syncro — **verify AP relocation done** | | #32342 Copy Room switch | 6 | Closed in Syncro — **verify switch installed/adopted** | | #32370 eFax + scanner | 7 | Closed in Syncro — **verify eFax + scanner delivered** |