Google Workspace Inventory — MR People Team
Every Google account, Apps Script project, spreadsheet, and Drive folder used in the MR engagement. This is what you need access to.
Accounts
| Account | Type | Purpose |
|---|---|---|
cmprssn@madison-reed.com | MR-issued Workspace account | Runs Apps Script agents, owns the mailbox (receives Paylocity/PulpStream email exports), owns Drive export folders. Paylocity login: user cmprssn, company ID 105419, role Company-Admin-No-SSN. |
mr-cmprssn@cmprssn-core-agents.iam.gserviceaccount.com | Google service account (SA) | Writer access to agent spreadsheets and the Exports folder. Used for tooling and data transformation (seeding config tabs, writing via Sheets API). Cannot create files in My Drive (no storage quota); writes land in shared drives or files created by cmprssn@ first. |
Identity containment rule (decided July 9, 2026): All Google file interaction for MR work uses exactly these two identities. The general CMPRSSN service account (cmprssn-drive@...) is for CMPRSSN's own drives only and should not be granted access to MR surfaces.
Apps Script Projects
Pay Reconciliation Agent
| Field | Value |
|---|---|
| Project name | People Team - Recon |
| Script ID | 1y_bDSSiFcmmeBoumUbTfEXuqV7rlI_l3nER_tJf4PdxjduTConj80STF |
| Web App URL (webhook) | https://script.google.com/macros/s/AKfycbwHh-RJhmC7h862axV1wXWvSuu8vEoUFXEEkz4ZUr25DXbYSBBNBLbEI55slmXOHoEeIg/exec |
| Deployment ID | AKfycbwHh-RJhmC7h862axV1wXWvSuu8vEoUFXEEkz4ZUr25DXbYSBBNBLbEI55slmXOHoEeIg |
| Deployed | 2026-06-23 |
| Agent spreadsheet ID | 1N1XKbBfT52mzPZQyKpHryRHllM4TGmmcLZKqNeJ1ehw |
| clasp push command | clasp push -P product/mr-people-agents/recon/apps-script --force |
| Status | LIVE (DRY_RUN=false, Syra reviewing weekly) |
Minimum Wage Monitor
| Field | Value |
|---|---|
| Script ID | Unknown — .clasp.json is gitignored. Ask Kyle. |
| Agent spreadsheet ID | Unknown — may not be deployed yet. |
| Status | Built, awaiting deployment decisions |
Leave Agent
| Field | Value |
|---|---|
| Script ID | Unknown — .clasp.json is gitignored. Ask Kyle. |
| Agent spreadsheet ID | Unknown — live components migrated to mr-people repo. |
| Status | Partially live (leave-feed and leave-notify in mr-people; reconciliation and pre-screen still in build repo) |
Spreadsheets
| Sheet | ID | Purpose |
|---|---|---|
| Recon agent | 1N1XKbBfT52mzPZQyKpHryRHllM4TGmmcLZKqNeJ1ehw | Config, FieldRules, TimeBankRules, Maps, AccrualRules, Routing, Exception Queue, Audit Log, Dry Run snapshots |
| Grecia's leave tracker | Unknown — the leave-notify agent reads it. Ask Kyle for the sheet ID. | |
| Minwage agent | Unknown — may not exist yet. |
Google Drive Folders
| Folder | ID | URL | Purpose |
|---|---|---|---|
| MR Client Intake (root) | 1DdFTfu8IP-JAsZ3clwZDPjgI8FQmGxd4 | Drive link | Top-level client intake folder |
| Workflows / People | 1kFWOj0vmTbtofND-V8wN1rutVlvI6vdR | — | People team workflow design docs and build prompts |
| Workflows / Supply Chain | 1Xu28h4kYWbZQyuGODshBCMvEaJwl9k2v | — | Supply chain workflow docs |
| Exports inbox (recon) | Config key INGEST_INBOX_FOLDER_ID in the recon spreadsheet | — | Where SFTP-bridged Paylocity CSV exports land for the recon agent to pick up |
Google Docs (key deliverables)
Proposals and contracts
| Doc | ID | Purpose |
|---|---|---|
| People Systems embed proposal (Shlanda) | 12D8gikNjItHuHvAGwTK_yOvb-d5UHWkhNdwOzbi--fw | The $12K/month People Systems seat proposal |
| LOA/Benefits embed proposal (Lindsey) | 1Vv2UlKdIeN9piAnn7uil9Li6XRhuVKG1ZTdannM2nQg | The $12K/month Benefits & Leave seat proposal |
| Consolidated package (Brad) | 1IFg_RcFKbEoUXiioVJbMROcABDnHi6odZ698-CPem6o | The $30K/month combined package |
| SOW No. 3 (People Systems + pod) | 1Mikw7YP86DrAn4V0mV3lPS9aGYbNbsLMJOnpKDmWVyw | Signable contract for Shlanda's team |
| SOW No. 4 (Benefits & Leave) | 1HxiZ3QI8gL8KysEXPUyT7_utABlKvThtn3rxVbr5AGc | Signable contract for Lindsey's team |
| Supply chain proposal (internal) | 1N5EtXnWTVb8D_3awbQM_G2zPHCGbhlbXaOKmd3GJIrE | Kyle's proposal for Erica |
| Supply chain proposal (EXT, client-facing) | 13761lK1bZsbSihvMZXBjDOB-XEkXG3GvNmdXG4-XTs4 | Promoted copy Erica can see |
Workflow design docs
| Doc | ID | Purpose |
|---|---|---|
| Reconciliation design | 1toFb5uN_0fFaTryZKCIRX79jF3vyYxWDYZ5nIkjHUko | Design doc for the pay reconciliation agent |
| Reconciliation build prompt | 1GUsGlsoPNgPUWTV0TSj2XAl9dUfz4H-0RRdyg5ExJVU | Build prompt used to create the agent |
| Minimum-wage design | 1QGT0n5zZ9eN2pXd0ujK1sJZhASy2EZrws7zFSc0dZ40 | Design doc for the minimum wage monitor |
| Minimum-wage build prompt | 1njADUfLcijWwTiygGeziGWp6KK0JwFDpj9gclr2GaPU | Build prompt |
| Leave design | 1sTUZMt-jCSEj0sB3ij14aOCqef4yntF0LsQ8vMRvrOM | Design doc for the leave agent |
| Leave build prompt | 11fYbAjBLx2C36eYXTWFCdN77uehMZYkovelWSfDwFqc | Build prompt |
Other
| Doc | ID | Purpose |
|---|---|---|
| HR bot feasibility (Brad) | 1IZ_7Q6Fg__yvlVFVdRXDH_qOOFw9LyTvQoZDldH90RM | Build-vs-buy for the three HR agents |
| Elena architecture intake | 1GJC38Jan_6AF1oYJ3wegZfKoDpfvlrZFitPgQ5W7vxk | Agentic brain architecture questions |
| 30-60-90 roadmap | 1kety9bwm9fAWn4eYsPb9rK2u-qul3o1lmYhgT2l33nQ | Engagement roadmap |
Local Secrets (~/.config/cmprssn/secrets.env)
Your machine already has Kyle's full secrets setup at ~/.config/cmprssn/secrets.env. This gives you programmatic access to most MR systems without needing additional credentials. The file is loaded by scripts in the core repo; it is never committed to git.
What you already have
| Service | Env var(s) | What it unlocks |
|---|---|---|
| PulpStream API | PULPSTREAM_API_KEY | Programmatic access to PulpStream leave data |
| PulpStream SFTP | PULPSTREAM_SFTP_USERNAME, _PASSWORD, _ROUTE (files.pulpstream.com) | Upload leave files to PulpStream |
| DocuSign API | MADISON_REED_DOCUSIGN_INTEGRATION_KEY, _USER_ID, _SECRET_KEY | Full eSignature API access |
| DocuSign RSA key | MADISON_REED_DOCUSIGN_APP_RSA_PRIVATE (points to ~/.config/cmprssn/mr_docusign_rsa_private.pem) | JWT auth for DocuSign |
| DocuSign inbox | MADISON_REED_DOCUSIGN_INBOX_DRIVE_ID (0AG5VbV08w_L3Uk9PVA) | Shared Drive for DocuSign documents |
| MR Slack bot | MADISON_REED_SLACK_BOT_TOKEN | Post messages as @peopleteambot in MR Slack |
| MR Looker API | MR_LOOKER_CLIENT_ID, MR_LOOKER_CLIENT_SECRET | Query MR's Looker BI dashboards |
| MR Google SA | MADISON_REED_GOOGLE_SERVICE_ACCOUNT_FILE (points to ~/.config/cmprssn/cmprssn-mr-drive-sa.json) | Read/write MR Drive folders and Sheets via service account |
| CMPRSSN Google SA | GOOGLE_SERVICE_ACCOUNT_FILE (points to ~/.config/cmprssn/cmprssn-drive-sa.json) | CMPRSSN's own Drive (not for MR surfaces) |
| MR SFTP (Paylocity) | MADISON_REED_HOSTED_SFTP_PRIVATE_KEY, _PUBLIC_KEY (SSH key pair at ~/.config/cmprssn/id_ed25519_mr) | SFTP into MR's hosted server for Paylocity report bridge |
| RAG API | RAG_API_URL, RAG_API_TOKEN | CMPRSSN's retrieval-augmented generation API |
| CMPRSSN Slack | SLACK_BOT_TOKEN | CMPRSSN's own Slack workspace |
| GitHub workflow | WORKFLOW_PAT | Automated PR workflows for the core repo |
What this means
PulpStream and DocuSign are not fully blocked as the proposals suggested. The API keys and SFTP credentials exist on your machine. What was blocked was the web login / portal access; the programmatic path is available. You can build integrations against these systems now.
What you still need
| Access | Why | Ask |
|---|---|---|
cmprssn@madison-reed.com Google account login (password or delegated access) | The service account handles programmatic Sheets/Drive access, but you need the actual Google account login to use the Apps Script browser editor, authenticate clasp, send emails as cmprssn@, and manage triggers | Kyle |
MadisonReed/mr-people GitHub repo collaborator access | Clone, read, and push to the People team's department brain repo | Kyle or Mikyo |
Other key files in ~/.config/cmprssn/
| File | Purpose |
|---|---|
cmprssn-mr-drive-sa.json | MR-specific Google service account credentials (the mr-cmprssn SA) |
cmprssn-drive-sa.json | CMPRSSN's own Google service account (not for MR surfaces) |
id_ed25519_mr / .pub | SSH key pair for MR's SFTP server (Paylocity report bridge) |
mr_docusign_rsa_private.pem | RSA private key for DocuSign JWT authentication |
mr-sftp-paylocity / .ppk / .pub | Additional SFTP key files (PPK format for PuTTY compatibility) |
google-oauth-client.json | Google OAuth client config |
agropago_oauth_client.json / agropago_token.json | AgroPago client credentials (separate engagement) |
Slack App
| Field | Value |
|---|---|
| App name | People Team Notifications |
| Bot handle | @peopleteambot |
| Created by | cmprssn@madison-reed.com |
| Installed in | Madison Reed Slack workspace (no IT gate needed) |
| Scopes | chat:write (at minimum) |
Script Properties (secrets, per agent)
These are stored in each Apps Script project's Script Properties (Project Settings UI), not in code or spreadsheets. Key names only; values are never committed to git.
Recon agent
| Key | Purpose |
|---|---|
AGENT_SPREADSHEET_ID | Points to the recon spreadsheet |
DRY_RUN | true or false |
WEBHOOK_SECRET | Auth secret for the Paylocity webhook URL |
INGEST_INBOX_FOLDER_ID | Drive folder where SFTP-bridged exports land |
WEBAPP_EXEC_URL | The public /exec URL (so setupWebhook() prints correct URLs) |
PAYLOCITY_CLIENT_ID | OAuth2 client credentials (when API path is used) |
PAYLOCITY_CLIENT_SECRET | OAuth2 secret |
PAYLOCITY_COMPANY_ID | MR company ID |
PAYLOCITY_ENV | sandbox or production |
Minwage / Leave agents
| Key | Purpose |
|---|---|
AGENT_SPREADSHEET_ID | Points to the agent's spreadsheet |
DRY_RUN | true or false |
ANTHROPIC_API_KEY | For the bounded Claude calls |
LLM_MODEL | Optional override (default: claude-sonnet-4-6) |
What you need to request
Blockers (can't operate without these)
-
cmprssn@madison-reed.comGoogle account login — password or delegated access. Needed for: Apps Script editor,claspauth, sending emails ascmprssn@, managing triggers. The service account insecrets.envhandles programmatic Sheets/Drive, but you need the actual login for everything else. -
MadisonReed/mr-peopleGitHub repo access — addlebraatas a collaborator with write access. This is the People team's department brain where the live agent code lives.
Nice to have (can work around, but should get)
- The script IDs and spreadsheet IDs for minwage and leave agents (if deployed) —
.clasp.jsonfiles are gitignored - Grecia's leave tracker spreadsheet ID — the leave-notify agent reads it
- Walkthrough of how Kyle has
claspset up locally (which Google account is authenticated, any aliases)
Already have (via ~/.config/cmprssn/secrets.env)
- MR Google service account (Drive/Sheets programmatic access)
- PulpStream API key + SFTP credentials
- DocuSign API credentials + RSA key
- MR Slack bot token
- MR Looker API credentials
- MR SFTP keys (Paylocity report bridge)
- RAG API token
- GitHub workflow PAT