Meredith/John returned the staff-editor questionnaire (70 people, 11 departments). CSV ingested to reports/; p2-staff-candidates.md updated with real persona breakdown. Wrote full AD/M365 user rollout plan (8 personas, license mapping, OU/group layout, CA policies, 4-wave sequence, 8 open decisions). Drafted follow-up email for remaining open items — Howard will edit and send. Britney Thompson and Polett Pinazavala confirmed still employed (were absent from the CSV return). Christine Nyanzunda confirmed as one person with two roles. Usernames locked for new accounts: Alma.Montt, Kyla.QuickTiffany. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
7.0 KiB
2026-04-22 — Cascades staff CSV ingest + AD/M365 user rollout plan
User
- User: Howard Enos (howard)
- Machine: HOWARD-HOME
- Role: tech
Session Summary
Meredith Kuhn and John Trozzi returned the staff-editor questionnaire that Howard sent 2026-04-18. CSV saved to C:\Users\Howard\Documents\cascades-staff-2026-04-22-1434.csv. This session ingested that CSV into the repo, updated the P2 license candidate doc with the real list, drafted a follow-up email for the remaining open items, and wrote the full AD + M365 user-setup rollout plan.
Howard then answered several of the open items live:
- Britney Thompson — still employed. Needs desktop access and possibly phone. Keep her AD account; treat as Office-PHI clinical for license math until Meredith specifies posture.
- Polett Pinazavala — still employed. Same treatment as Britney; she stays on the caregiver roster.
- Christine Nyanzunda — one person with two roles (MC Admin + part-time Sun/Mon MedTech), one account.
- Alma R Montt — username
Alma.Montt. Title still pending Meredith. - Kyla Quick Tiffany — username
Kyla.QuickTiffany(Kyla's own preference — last name as one word). Treated as a Shared-PC Reception user. - Naming convention: All NEW accounts follow TitleCase
First.Last. The lowercase exceptions in AD (britney.thompson,karen.rossini,lauren.hasselman) are the only known legacy cases — leave as-is, don't rename.
Howard will edit the follow-up email himself and send from his desktop, then return the sent copy.
Key Decisions
- CSV placement:
clients/cascades-tucson/reports/cascades-staff-2026-04-22.csv(Howard's choice). - Persona model: Eight personas derived from CSV columns (Access / Outside / ALIS). See §2 of the rollout plan.
- License default: Business Premium tenant-wide, with F3 only for the 3 drivers and Business Standard fallback for non-PHI office roles if tenant-wide Premium isn't approved.
- Rollout waves: W0 pre-flight → W1 new office accounts (Alma, Kyla) → W2 existing office reassignment → W3 caregiver bulk creation → W4 generics cleanup.
- Britney on license list: Office-PHI tier by default given clinical role, until Meredith provides a different posture call. Bumps office P2 count 19 → 20.
Problems Encountered / Deltas Found
- Britney Thompson — active in AD but absent from the CSV return. Resolved live: still employed.
- Polett Pinazavala — on 2026-04-18 caregiver roster, absent from CSV. Resolved live: still employed.
- 37 caregivers have no individual AD accounts today (verified against
docs/servers/active-directory.md). Wave 3 creates all 37. - Agency placeholders (2 rows) need a decision on whether they become real accounts or ALIS-web-only logins. Deferred to Meredith.
Credentials / Secrets
None handled or discovered this session. No vault reads. No credentials in any of the created docs.
Infrastructure / Servers Referenced
- CS-SERVER (
192.168.2.254) — primary DC forcascades.local, only DC, all FSMO roles. Source of truth for current AD state. - M365 tenant:
cascadestucson.com, tenant ID207fa277-e9d8-4eb7-ada1-1064d2221498. - GuruRMM: Cascades client
42e1b0e3-f8b7-4fc5-86bd-06bdbb073b7f, sitec157c399-82d3-4581-979a-b9fad70f4fef(unchanged). - Entra group
Cascades - Shared Phones(existing, dynamic — drives Intune phone rollout; possibly overlaps with the proposedSG-CaregiversAD-sync group).
No infrastructure changes made. Plan-level only.
Files Created
| Path | Purpose |
|---|---|
clients/cascades-tucson/reports/cascades-staff-2026-04-22.csv |
Meredith/John's returned staff-editor CSV, 70 rows. Source of truth for who should exist and with what access posture. |
clients/cascades-tucson/docs/cloud/cascades-staff-followup-2026-04-22.md |
Draft email to Meredith/John with 6 open questions (Kyla, Ederick, Christine, Alma, Britney, Polett) plus the pending "restrict everyone or selective" decision. Howard will edit and send. |
clients/cascades-tucson/docs/cloud/user-account-rollout-plan.md |
Full AD/M365 rollout plan: 8 personas, license mapping, OU/group layout, CA policy set, pre-flight reconciliation, 4-wave rollout sequence, 8 open decisions. |
Files Modified
| Path | Change |
|---|---|
clients/cascades-tucson/docs/cloud/p2-staff-candidates.md |
Replaced "Awaiting from John Trozzi" section with real persona tables from CSV. Added Britney + Polett notes (still employed, confirmed live). Updated license math: 19 office P2 → 20 with Britney. Closed "follow up with John" action item. |
Commands Run
cp "/c/Users/Howard/Documents/cascades-staff-2026-04-22-1434.csv" "clients/cascades-tucson/reports/cascades-staff-2026-04-22.csv"— CSV ingest.- Various
git status,git log,git showfor context. - Read operations across
clients/cascades-tucson/docs/cloud/anddocs/servers/active-directory.mdfor cross-reference.
No destructive commands. No database, no credential, no network changes.
Pending / Next Steps
Blocked on Meredith / John (in the follow-up email)
- "Restrict everyone to building" vs. selective — outstanding since 2026-04-16.
- Business Premium tenant-wide vs. mixed SKUs — tied to upgrade proposal.
- Ederick Yuzon spelling.
- Alma R Montt title.
- Britney Thompson access posture (phone? Outside?).
- Polett Pinazavala access posture (phone? Outside?).
- Agency placeholders — real accounts or ALIS-only?
- Drivers — F3 or Business Standard?
Waiting for Howard
- Edit and send the follow-up email from
cascades-staff-followup-2026-04-22.md. Return the final version so it's in the repo as the actual sent copy.
Ready to execute once answers come back
- Wave 1 account creation:
Alma.Montt,Kyla.QuickTiffany - Britney Thompson: confirm and apply persona tags
- Wave 3 caregiver bulk creation: 37 accounts (includes Polett)
Reference
- Rollout plan:
clients/cascades-tucson/docs/cloud/user-account-rollout-plan.md - P2 candidates (updated):
clients/cascades-tucson/docs/cloud/p2-staff-candidates.md - Caregiver-side plan (cross-reference):
clients/cascades-tucson/docs/cloud/caregiver-m365-p2-rollout.md - AD state:
clients/cascades-tucson/docs/servers/active-directory.md - Source CSV:
clients/cascades-tucson/reports/cascades-staff-2026-04-22.csv - Follow-up email draft:
clients/cascades-tucson/docs/cloud/cascades-staff-followup-2026-04-22.md
Note for Mike
Cascades user rollout design is done at the plan level — 8 personas, license math, OU/group layout, CA policy set, 4-wave sequence. Blocked on 7 decisions from Meredith (see §10 of the plan). No license spend or account creation yet. Your call at any point to change the tenant-wide Business Premium default if budget says otherwise.
Also flagging: Britney Thompson was absent from Meredith's returned CSV but is still employed per Howard — worth you confirming with Meredith next time you see her, since the omission is a signal she may not be top-of-mind for the access-policy work. Same for Polett Pinazavala on the caregiver side.