Agent Operating Guide
/coach-bulk-user-change
Sweep every Canvas item and workflow-Step assignment for a departing or transferring person and propose the removals or reassignments as one suggest_change batch admins approve.
One-shot replacement for “click into 47 items and remove this person”. When someone leaves
the organization, transfers teams, or changes roles, the skill finds every place they’re
assigned, across the shared core item types
(audit, issue, risk, control, process, policy, authority_source), any custom USER fields,
and every workflow Step (assignee, watchers, approvers, and
form requestor/responder), then proposes the change. It never applies directly: every
removal or reassignment is a suggest_change payload, grouped
under a single batch id so an admin reviews and approves the whole batch in Canvas in one
click. Nothing changes until they do.
When to use
Section titled “When to use”When a person leaves, transfers, or changes role and you need to strip or reassign their access everywhere at once: instead of clicking into each item to catch every owner field, watchlist, and Step assignee. Missing one leaves the departed user with phantom access.
The skill needs the shared core item types in place. If pre-flight fails, run /coach-starter-pack first.
Inputs
Section titled “Inputs”| Flag | Required | Notes |
|---|---|---|
--user <user-id|email> |
Yes | The subject of the change. |
--action remove|reassign|change-role |
Yes | What to do with their assignments. |
--reassign-to <user-id|email> |
If reassigning | The successor to hand assignments to. |
--new-role <role> |
If changing role | The new role label. |
--scope portfolio|all |
No | How wide to sweep. Default all. |
--dry-run |
No | List what would change, with no suggest_change calls. |
Example
Section titled “Example”/coach-bulk-user-change --user jane.smith@company.com --action remove resolves Jane’s user
record, queries every assignment surface, item owner, lead, team, and watchlist fields,
custom USER fields, and Step assignees, watchers, approvers, and form roles, and
summarizes what it found (for example, “47 assignments across 6 surfaces”). It plans a
removal per assignment, surfaces any required field that can’t be left null as a blocker to
reassign first, then submits one suggest_change per change under a shared batch id. You open
the preview link and approve the batch in Canvas.
Good to know
Section titled “Good to know”- Never applies directly. Every change is a suggestion; the admin approves the whole batch in Canvas in one click, and nothing changes until they do.
- The Step sweep is non-negotiable. A user may own only a handful of items but be assignee on dozens of Steps across attached workflows: those are included, not just item-level fields.
- Blockers surface; they don’t silently drop. A required scalar field that removal would
empty (for example,
control.owner, which can’t be null) is flagged so you reassign it before the batch goes in. - Idempotent. Re-running for the same person after the batch is approved finds nothing left and prints “Already clean.”
change-roleonly shifts the role label: it doesn’t touch assignments. Usereassignif the role change means they shouldn’t keep their current work.- Pair terminations with HR data so the skill can confirm the person is genuinely separated, not merely on PTO.
Related
Section titled “Related”- /coach-starter-pack: install the shared core item types this sweep depends on.
- /coach-item-update: change one item’s fields; this is the batch version across many.
- suggest_change: the gated write every change in the batch routes through.
- query_data: how the skill discovers every assignment surface before planning.