Skip to main content

Google Workspace Inventory — MR People Team

Every Google account, Apps Script project, spreadsheet, and Drive folder used in the MR engagement. This is what you need access to.

Accounts

AccountTypePurpose
cmprssn@madison-reed.comMR-issued Workspace accountRuns Apps Script agents, owns the mailbox (receives Paylocity/PulpStream email exports), owns Drive export folders. Paylocity login: user cmprssn, company ID 105419, role Company-Admin-No-SSN.
mr-cmprssn@cmprssn-core-agents.iam.gserviceaccount.comGoogle service account (SA)Writer access to agent spreadsheets and the Exports folder. Used for tooling and data transformation (seeding config tabs, writing via Sheets API). Cannot create files in My Drive (no storage quota); writes land in shared drives or files created by cmprssn@ first.

Identity containment rule (decided July 9, 2026): All Google file interaction for MR work uses exactly these two identities. The general CMPRSSN service account (cmprssn-drive@...) is for CMPRSSN's own drives only and should not be granted access to MR surfaces.

Apps Script Projects

Pay Reconciliation Agent

FieldValue
Project namePeople Team - Recon
Script ID1y_bDSSiFcmmeBoumUbTfEXuqV7rlI_l3nER_tJf4PdxjduTConj80STF
Web App URL (webhook)https://script.google.com/macros/s/AKfycbwHh-RJhmC7h862axV1wXWvSuu8vEoUFXEEkz4ZUr25DXbYSBBNBLbEI55slmXOHoEeIg/exec
Deployment IDAKfycbwHh-RJhmC7h862axV1wXWvSuu8vEoUFXEEkz4ZUr25DXbYSBBNBLbEI55slmXOHoEeIg
Deployed2026-06-23
Agent spreadsheet ID1N1XKbBfT52mzPZQyKpHryRHllM4TGmmcLZKqNeJ1ehw
clasp push commandclasp push -P product/mr-people-agents/recon/apps-script --force
StatusLIVE (DRY_RUN=false, Syra reviewing weekly)

Minimum Wage Monitor

FieldValue
Script IDUnknown.clasp.json is gitignored. Ask Kyle.
Agent spreadsheet IDUnknown — may not be deployed yet.
StatusBuilt, awaiting deployment decisions

Leave Agent

FieldValue
Script IDUnknown.clasp.json is gitignored. Ask Kyle.
Agent spreadsheet IDUnknown — live components migrated to mr-people repo.
StatusPartially live (leave-feed and leave-notify in mr-people; reconciliation and pre-screen still in build repo)

Spreadsheets

SheetIDPurpose
Recon agent1N1XKbBfT52mzPZQyKpHryRHllM4TGmmcLZKqNeJ1ehwConfig, FieldRules, TimeBankRules, Maps, AccrualRules, Routing, Exception Queue, Audit Log, Dry Run snapshots
Grecia's leave trackerUnknown — the leave-notify agent reads it. Ask Kyle for the sheet ID.
Minwage agentUnknown — may not exist yet.

Google Drive Folders

FolderIDURLPurpose
MR Client Intake (root)1DdFTfu8IP-JAsZ3clwZDPjgI8FQmGxd4Drive linkTop-level client intake folder
Workflows / People1kFWOj0vmTbtofND-V8wN1rutVlvI6vdRPeople team workflow design docs and build prompts
Workflows / Supply Chain1Xu28h4kYWbZQyuGODshBCMvEaJwl9k2vSupply chain workflow docs
Exports inbox (recon)Config key INGEST_INBOX_FOLDER_ID in the recon spreadsheetWhere SFTP-bridged Paylocity CSV exports land for the recon agent to pick up

Google Docs (key deliverables)

Proposals and contracts

DocIDPurpose
People Systems embed proposal (Shlanda)12D8gikNjItHuHvAGwTK_yOvb-d5UHWkhNdwOzbi--fwThe $12K/month People Systems seat proposal
LOA/Benefits embed proposal (Lindsey)1Vv2UlKdIeN9piAnn7uil9Li6XRhuVKG1ZTdannM2nQgThe $12K/month Benefits & Leave seat proposal
Consolidated package (Brad)1IFg_RcFKbEoUXiioVJbMROcABDnHi6odZ698-CPem6oThe $30K/month combined package
SOW No. 3 (People Systems + pod)1Mikw7YP86DrAn4V0mV3lPS9aGYbNbsLMJOnpKDmWVywSignable contract for Shlanda's team
SOW No. 4 (Benefits & Leave)1HxiZ3QI8gL8KysEXPUyT7_utABlKvThtn3rxVbr5AGcSignable contract for Lindsey's team
Supply chain proposal (internal)1N5EtXnWTVb8D_3awbQM_G2zPHCGbhlbXaOKmd3GJIrEKyle's proposal for Erica
Supply chain proposal (EXT, client-facing)13761lK1bZsbSihvMZXBjDOB-XEkXG3GvNmdXG4-XTs4Promoted copy Erica can see

Workflow design docs

DocIDPurpose
Reconciliation design1toFb5uN_0fFaTryZKCIRX79jF3vyYxWDYZ5nIkjHUkoDesign doc for the pay reconciliation agent
Reconciliation build prompt1GUsGlsoPNgPUWTV0TSj2XAl9dUfz4H-0RRdyg5ExJVUBuild prompt used to create the agent
Minimum-wage design1QGT0n5zZ9eN2pXd0ujK1sJZhASy2EZrws7zFSc0dZ40Design doc for the minimum wage monitor
Minimum-wage build prompt1njADUfLcijWwTiygGeziGWp6KK0JwFDpj9gclr2GaPUBuild prompt
Leave design1sTUZMt-jCSEj0sB3ij14aOCqef4yntF0LsQ8vMRvrOMDesign doc for the leave agent
Leave build prompt11fYbAjBLx2C36eYXTWFCdN77uehMZYkovelWSfDwFqcBuild prompt

Other

DocIDPurpose
HR bot feasibility (Brad)1IZ_7Q6Fg__yvlVFVdRXDH_qOOFw9LyTvQoZDldH90RMBuild-vs-buy for the three HR agents
Elena architecture intake1GJC38Jan_6AF1oYJ3wegZfKoDpfvlrZFitPgQ5W7vxkAgentic brain architecture questions
30-60-90 roadmap1kety9bwm9fAWn4eYsPb9rK2u-qul3o1lmYhgT2l33nQEngagement roadmap

Local Secrets (~/.config/cmprssn/secrets.env)

Your machine already has Kyle's full secrets setup at ~/.config/cmprssn/secrets.env. This gives you programmatic access to most MR systems without needing additional credentials. The file is loaded by scripts in the core repo; it is never committed to git.

What you already have

ServiceEnv var(s)What it unlocks
PulpStream APIPULPSTREAM_API_KEYProgrammatic access to PulpStream leave data
PulpStream SFTPPULPSTREAM_SFTP_USERNAME, _PASSWORD, _ROUTE (files.pulpstream.com)Upload leave files to PulpStream
DocuSign APIMADISON_REED_DOCUSIGN_INTEGRATION_KEY, _USER_ID, _SECRET_KEYFull eSignature API access
DocuSign RSA keyMADISON_REED_DOCUSIGN_APP_RSA_PRIVATE (points to ~/.config/cmprssn/mr_docusign_rsa_private.pem)JWT auth for DocuSign
DocuSign inboxMADISON_REED_DOCUSIGN_INBOX_DRIVE_ID (0AG5VbV08w_L3Uk9PVA)Shared Drive for DocuSign documents
MR Slack botMADISON_REED_SLACK_BOT_TOKENPost messages as @peopleteambot in MR Slack
MR Looker APIMR_LOOKER_CLIENT_ID, MR_LOOKER_CLIENT_SECRETQuery MR's Looker BI dashboards
MR Google SAMADISON_REED_GOOGLE_SERVICE_ACCOUNT_FILE (points to ~/.config/cmprssn/cmprssn-mr-drive-sa.json)Read/write MR Drive folders and Sheets via service account
CMPRSSN Google SAGOOGLE_SERVICE_ACCOUNT_FILE (points to ~/.config/cmprssn/cmprssn-drive-sa.json)CMPRSSN's own Drive (not for MR surfaces)
MR SFTP (Paylocity)MADISON_REED_HOSTED_SFTP_PRIVATE_KEY, _PUBLIC_KEY (SSH key pair at ~/.config/cmprssn/id_ed25519_mr)SFTP into MR's hosted server for Paylocity report bridge
RAG APIRAG_API_URL, RAG_API_TOKENCMPRSSN's retrieval-augmented generation API
CMPRSSN SlackSLACK_BOT_TOKENCMPRSSN's own Slack workspace
GitHub workflowWORKFLOW_PATAutomated PR workflows for the core repo

What this means

PulpStream and DocuSign are not fully blocked as the proposals suggested. The API keys and SFTP credentials exist on your machine. What was blocked was the web login / portal access; the programmatic path is available. You can build integrations against these systems now.

What you still need

AccessWhyAsk
cmprssn@madison-reed.com Google account login (password or delegated access)The service account handles programmatic Sheets/Drive access, but you need the actual Google account login to use the Apps Script browser editor, authenticate clasp, send emails as cmprssn@, and manage triggersKyle
MadisonReed/mr-people GitHub repo collaborator accessClone, read, and push to the People team's department brain repoKyle or Mikyo

Other key files in ~/.config/cmprssn/

FilePurpose
cmprssn-mr-drive-sa.jsonMR-specific Google service account credentials (the mr-cmprssn SA)
cmprssn-drive-sa.jsonCMPRSSN's own Google service account (not for MR surfaces)
id_ed25519_mr / .pubSSH key pair for MR's SFTP server (Paylocity report bridge)
mr_docusign_rsa_private.pemRSA private key for DocuSign JWT authentication
mr-sftp-paylocity / .ppk / .pubAdditional SFTP key files (PPK format for PuTTY compatibility)
google-oauth-client.jsonGoogle OAuth client config
agropago_oauth_client.json / agropago_token.jsonAgroPago client credentials (separate engagement)

Slack App

FieldValue
App namePeople Team Notifications
Bot handle@peopleteambot
Created bycmprssn@madison-reed.com
Installed inMadison Reed Slack workspace (no IT gate needed)
Scopeschat:write (at minimum)

Script Properties (secrets, per agent)

These are stored in each Apps Script project's Script Properties (Project Settings UI), not in code or spreadsheets. Key names only; values are never committed to git.

Recon agent

KeyPurpose
AGENT_SPREADSHEET_IDPoints to the recon spreadsheet
DRY_RUNtrue or false
WEBHOOK_SECRETAuth secret for the Paylocity webhook URL
INGEST_INBOX_FOLDER_IDDrive folder where SFTP-bridged exports land
WEBAPP_EXEC_URLThe public /exec URL (so setupWebhook() prints correct URLs)
PAYLOCITY_CLIENT_IDOAuth2 client credentials (when API path is used)
PAYLOCITY_CLIENT_SECRETOAuth2 secret
PAYLOCITY_COMPANY_IDMR company ID
PAYLOCITY_ENVsandbox or production

Minwage / Leave agents

KeyPurpose
AGENT_SPREADSHEET_IDPoints to the agent's spreadsheet
DRY_RUNtrue or false
ANTHROPIC_API_KEYFor the bounded Claude calls
LLM_MODELOptional override (default: claude-sonnet-4-6)

What you need to request

Blockers (can't operate without these)

  • cmprssn@madison-reed.com Google account login — password or delegated access. Needed for: Apps Script editor, clasp auth, sending emails as cmprssn@, managing triggers. The service account in secrets.env handles programmatic Sheets/Drive, but you need the actual login for everything else.
  • MadisonReed/mr-people GitHub repo access — add lebraat as a collaborator with write access. This is the People team's department brain where the live agent code lives.

Nice to have (can work around, but should get)

  • The script IDs and spreadsheet IDs for minwage and leave agents (if deployed) — .clasp.json files are gitignored
  • Grecia's leave tracker spreadsheet ID — the leave-notify agent reads it
  • Walkthrough of how Kyle has clasp set up locally (which Google account is authenticated, any aliases)

Already have (via ~/.config/cmprssn/secrets.env)

  • MR Google service account (Drive/Sheets programmatic access)
  • PulpStream API key + SFTP credentials
  • DocuSign API credentials + RSA key
  • MR Slack bot token
  • MR Looker API credentials
  • MR SFTP keys (Paylocity report bridge)
  • RAG API token
  • GitHub workflow PAT