Skip to content

Agent Operating Guide

/coach-bulk-user-change

Sweep every Canvas item and workflow-Step assignment for a departing or transferring person and propose the removals or reassignments as one suggest_change batch admins approve.

One-shot replacement for “click into 47 items and remove this person”. When someone leaves the organization, transfers teams, or changes roles, the skill finds every place they’re assigned, across the shared core item types (audit, issue, risk, control, process, policy, authority_source), any custom USER fields, and every workflow Step (assignee, watchers, approvers, and form requestor/responder), then proposes the change. It never applies directly: every removal or reassignment is a suggest_change payload, grouped under a single batch id so an admin reviews and approves the whole batch in Canvas in one click. Nothing changes until they do.

When a person leaves, transfers, or changes role and you need to strip or reassign their access everywhere at once: instead of clicking into each item to catch every owner field, watchlist, and Step assignee. Missing one leaves the departed user with phantom access.

The skill needs the shared core item types in place. If pre-flight fails, run /coach-starter-pack first.

Flag Required Notes
--user <user-id|email> Yes The subject of the change.
--action remove|reassign|change-role Yes What to do with their assignments.
--reassign-to <user-id|email> If reassigning The successor to hand assignments to.
--new-role <role> If changing role The new role label.
--scope portfolio|all No How wide to sweep. Default all.
--dry-run No List what would change, with no suggest_change calls.

/coach-bulk-user-change --user jane.smith@company.com --action remove resolves Jane’s user record, queries every assignment surface, item owner, lead, team, and watchlist fields, custom USER fields, and Step assignees, watchers, approvers, and form roles, and summarizes what it found (for example, “47 assignments across 6 surfaces”). It plans a removal per assignment, surfaces any required field that can’t be left null as a blocker to reassign first, then submits one suggest_change per change under a shared batch id. You open the preview link and approve the batch in Canvas.

  • Never applies directly. Every change is a suggestion; the admin approves the whole batch in Canvas in one click, and nothing changes until they do.
  • The Step sweep is non-negotiable. A user may own only a handful of items but be assignee on dozens of Steps across attached workflows: those are included, not just item-level fields.
  • Blockers surface; they don’t silently drop. A required scalar field that removal would empty (for example, control.owner, which can’t be null) is flagged so you reassign it before the batch goes in.
  • Idempotent. Re-running for the same person after the batch is approved finds nothing left and prints “Already clean.”
  • change-role only shifts the role label: it doesn’t touch assignments. Use reassign if the role change means they shouldn’t keep their current work.
  • Pair terminations with HR data so the skill can confirm the person is genuinely separated, not merely on PTO.
  • /coach-starter-pack: install the shared core item types this sweep depends on.
  • /coach-item-update: change one item’s fields; this is the batch version across many.
  • suggest_change: the gated write every change in the batch routes through.
  • query_data: how the skill discovers every assignment surface before planning.