Feat v0.3.7 package audit (#20)
All checks were successful
CI/CD / detect-changes (push) Successful in 4s
CI/CD / test-frontend (push) Successful in 6s
CI/CD / test-go-pg (push) Successful in 2m36s
CI/CD / test-sqlite (push) Successful in 2m41s
CI/CD / build-and-deploy (push) Successful in 1m13s

Co-authored-by: Jeffrey Smith <jasafpro@gmail.com>
Co-committed-by: Jeffrey Smith <jasafpro@gmail.com>
This commit was merged in pull request #20.
This commit is contained in:
2026-03-28 21:22:39 +00:00
committed by xcaliber
parent d68451fe8e
commit d91ec02dd7
47 changed files with 2067 additions and 53 deletions

View File

@@ -0,0 +1,36 @@
# Employee Onboarding
Automated employee provisioning with manager signoff and welcome notification.
## Features
- **Starlark automated stages** — `db.insert` for provisioning records, `notifications.send` for alerts
- **Signoff gate** — manager approval required (role-based), rejection reroutes to start
- **Progressive fieldsets** — Personal Info + Access Requirements
- **ext_data tables** — `provisions` and `onboarding_log`
## Stage Flow
```
[new-hire-info] → [provision-accounts] → [manager-signoff] → [it-setup] → [welcome]
team automated (Starlark) review + signoff team automated
auto-advances reject → stage 0 auto-advances
```
## Prerequisites
- Team must have a custom **"manager"** role (via Team Admin > Members > Team Roles)
- At least one team member with the "manager" role assigned
## Starlark Hooks
- **`on_provision(ctx)`** — Inserts provisioning record into `provisions` table, notifies workflow starter
- **`on_welcome(ctx)`** — Logs completion to `onboarding_log`, sends welcome notification
## Installation
```bash
curl -X POST $BASE/api/v1/admin/packages/install \
-H "Authorization: Bearer $TOKEN" \
-F "file=@packages/employee-onboarding"
```

View File

@@ -0,0 +1,122 @@
{
"id": "employee-onboarding",
"title": "Employee Onboarding",
"type": "workflow",
"version": "0.1.0",
"tier": "starlark",
"icon": "🏢",
"author": "Switchboard Core",
"description": "Employee onboarding with automated provisioning, manager signoff, and welcome notification.",
"permissions": ["db.write", "notifications.send"],
"db_tables": {
"provisions": {
"columns": {
"employee_name": "text",
"department": "text",
"needs_vpn": "text",
"needs_admin": "text",
"equipment": "text",
"status": "text"
}
},
"onboarding_log": {
"columns": {
"employee_name": "text",
"department": "text",
"completed_by": "text",
"status": "text"
}
}
},
"workflow_definition": {
"name": "Employee Onboarding",
"slug": "employee-onboarding",
"entry_mode": "team_only",
"stages": [
{
"name": "new-hire-info",
"ordinal": 0,
"stage_mode": "form",
"audience": "team",
"stage_type": "simple",
"auto_transition": false,
"form_template": {
"fieldsets": [
{
"label": "Personal Info",
"fields": [
{ "key": "full_name", "label": "Full Name", "type": "text", "required": true },
{ "key": "email", "label": "Email", "type": "text", "required": true },
{ "key": "department", "label": "Department", "type": "select", "options": ["engineering", "sales", "marketing", "hr", "ops", "finance"], "required": true },
{ "key": "start_date", "label": "Start Date", "type": "text", "required": true }
]
},
{
"label": "Access Requirements",
"fields": [
{ "key": "needs_vpn", "label": "VPN Access", "type": "select", "options": ["true", "false"], "required": true },
{ "key": "needs_admin", "label": "Admin Access", "type": "select", "options": ["true", "false"], "required": true },
{ "key": "equipment", "label": "Equipment", "type": "select", "options": ["standard laptop", "developer workstation", "macbook pro"], "required": true }
]
}
]
}
},
{
"name": "provision-accounts",
"ordinal": 1,
"stage_mode": "automated",
"audience": "system",
"stage_type": "automated",
"auto_transition": true,
"starlark_hook": "employee-onboarding:on_provision"
},
{
"name": "manager-signoff",
"ordinal": 2,
"stage_mode": "review",
"audience": "team",
"stage_type": "simple",
"auto_transition": false,
"stage_config": {
"validation": {
"required_approvals": 1,
"required_role": "manager",
"reject_action": "new-hire-info"
}
}
},
{
"name": "it-setup",
"ordinal": 3,
"stage_mode": "form",
"audience": "team",
"stage_type": "simple",
"auto_transition": false,
"form_template": {
"fieldsets": [
{
"label": "IT Setup Confirmation",
"fields": [
{ "key": "hardware_ready", "label": "Hardware Ready?", "type": "select", "options": ["yes", "no"], "required": true },
{ "key": "accounts_created", "label": "Accounts Created?", "type": "select", "options": ["yes", "no"], "required": true },
{ "key": "it_notes", "label": "Notes", "type": "textarea" }
]
}
]
}
},
{
"name": "welcome",
"ordinal": 4,
"stage_mode": "automated",
"audience": "system",
"stage_type": "automated",
"auto_transition": true,
"starlark_hook": "employee-onboarding:on_welcome"
}
]
}
}

View File

@@ -0,0 +1,49 @@
def on_provision(ctx):
"""Automated provisioning: record in ext_data, notify HR."""
data = ctx["stage_data"]
name = data.get("full_name", "unknown")
dept = data.get("department", "general")
# Record provision in ext_data table
db.insert("provisions", {
"employee_name": name,
"department": dept,
"needs_vpn": str(data.get("needs_vpn", "false")),
"needs_admin": str(data.get("needs_admin", "false")),
"equipment": data.get("equipment", "standard laptop"),
"status": "provisioned",
})
# Notify the HR user who started this workflow
notifications.send(
ctx["started_by"],
"Accounts provisioned for " + name,
"Department: " + dept + ". Ready for manager review.",
)
return {"advance": True, "data": {
"provision_status": "complete",
"provisioned_for": name,
}}
def on_welcome(ctx):
"""Completion logging: record onboarding and send welcome."""
data = ctx["stage_data"]
name = data.get("full_name", "")
dept = data.get("department", "")
db.insert("onboarding_log", {
"employee_name": name,
"department": dept,
"completed_by": ctx["started_by"],
"status": "complete",
})
notifications.send(
ctx["started_by"],
"Onboarding complete: " + name,
"All stages finished. Welcome aboard!",
)
return {"advance": True, "data": {"onboarding_complete": True}}