Conversation
…mbers
Authorized: remove the non-PIs from pi@ (23 of 24 audited addresses are Co-Investigators, and
PI entitlement is roster-derived per the "only people who can be pulled out of RePORTER are PIs"
rule).
New action:'remove_extra' with a required `group` — removal is scoped to ONE named group per
call, never "clean everything". Three hard rails, because this is destructive and outward-facing:
1. Only addresses belonging to a KNOWN consortium member (primary or secondary email in the
KG) can be removed — service accounts like admin@/noreply@, nested groups and external
collaborators are structurally excluded, not merely filtered in the UI.
2. Only Google role MEMBER is touched; OWNER/MANAGER are never removed (removing an owner can
break the group).
3. Anything skipped by 1 or 2 is reported separately as extra_protected, so nothing is
silently ignored.
Repair still only ADDS; removal is a separate button, per group, behind a confirm that states
exactly what will happen.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
…mbers
Authorized: remove the non-PIs from pi@ (23 of 24 audited addresses are Co-Investigators, and PI entitlement is roster-derived per the "only people who can be pulled out of RePORTER are PIs" rule).
New action:'remove_extra' with a required
group— removal is scoped to ONE named group per call, never "clean everything". Three hard rails, because this is destructive and outward-facing: