Supported provisioning path for corporate and non-HR-feed accounts

Applies to Coach Pulse identity services and the sync-employees job, with an authoring surface in coach-pulse-admin-ui. Repository attribution to be confirmed before QA. **Problem.** Coach Pulse runs a two layer identity architecture. SSO through Cognito and AD handles authentication, but the application only trusts the profiles table, which is populated by the sync-employees job reading the Tapestry HR feed. Corporate and test accounts provisioned directly in AD but absent from the HR feed authenticate successfully and then resolve to nothing: blank name, default role display, no store assignment, no C360 data. Corporate, non store manager users have been the group most affected. **What already exists.** The July 29 identity and access rebuild shipped backfill migrations setting federated aliases for 38 corporate records and keying 50 unkeyed employee IDs, written against dev and QA, so production requires its own backfill pass. The rebuild also made the system fail closed: identities outside approved corporate domains or the HR roster now receive an "account not provisioned" denial rather than a wrong but working session. A break glass provisioning path exists behind QA_IDENTITY_BREAKGLASS and is auditable. **The gap.** Backfill migrations and break glass are both exception handling. Neither is a supported path. The provisioning gap recurs every time Tapestry stands up a new tester or corporate user outside the roster, and the July diagnosis carried a recommendation that FutureProof build a manual seeding path for non HR accounts. That path has been identified and not yet built. **Recommended action.** Build a supported, audited admin path to seed and maintain profile rows for corporate and non HR-feed identities, so the fail closed behavior stays intact while legitimate corporate users can be provisioned without a migration or a feature flag. **Acceptance criteria.** 1. An authorized admin can create a profile row for an identity that authenticates through SSO but does not appear in the HR feed. 2. A seeded profile carries name, role, region and store assignment, and renders identically to an HR sourced profile across Coach Pulse surfaces. 3. Seeded profiles are marked with their provenance so they are distinguishable from HR sourced records in audit. 4. A subsequent sync-employees run does not overwrite or orphan a seeded profile. 5. Every seed, edit and revoke is written to the audit log with actor, timestamp and before and after state. 6. Fail closed behavior is unchanged for identities that are neither seeded nor on the roster. 7. Break glass remains available but is no longer the routine path for corporate provisioning. **Dependencies and out of scope.** Production backfill pass is a prerequisite and is tracked separately. The open SSO token issue affecting corporate accounts is a separate defect and is not resolved by this work. The compliance question around approximately 4,500 indirect market users accessing outside SSO, with Sarah looping in Michael Pearson, is related but distinct and is out of scope here.

Please authenticate to join the conversation.

Upvoters
Status

Approved Through QA/Ready for UAT

Board

New Functionality

ETA
Aug 17, 2026
Date

7 days ago

Author

Harrison

Subscribe to post

Get notified by email when there are changes.