user-engine/workplans/USER-WP-0035-onboarding-handoff-findings.md
tegwick fd11e1a1c0
Some checks are pending
CI Smoke / container-smoke (push) Waiting to run
CI Smoke / host-smoke (push) Waiting to run
Record State Hub IDs for USER-WP-0035
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 58902@bnt-lap001
Assistant-Session: 7ac7f865-2dc5-4aa7-8eb7-27a342109c2f
2026-09-23 22:11:14 +02:00

2.4 KiB

id type title domain repo status flavor owner topic_slug created updated related state_hub_workstream_id
USER-WP-0035 workplan Onboarding handoff findings from the 2026-09-23 operator run communication user-engine active implementation claude-code user-engine 2026-09-23 2026-09-23
USER-WP-0027
USER-WP-0028
NK-WP-0036
NK-WP-0041
35aa6adf-255a-5705-9294-a50d98e45f00

Intake for the net-kingdom findings from the human onboarding run on 2026-09-23 (NK-WP-0036-T05, net-kingdom@6c4fcaf; hub message 21b0b7e4). Provider sign-in, Create login, single-use setup link, password set and portal sign-in all worked. Three findings touch journeys U04 and T03 in docs/account-journeys.md. This records them against user-engine; the provider-side items stay with net-kingdom.

Name the login and the sign-in address at every handoff point

id: USER-WP-0035-T01
status: done
priority: high
state_hub_task_id: "a26b22ae-05fd-52f4-accc-068ccba7bbda"

Findings 2 and 3. The derived login name (bernd.worsch-99 from a plus-addressed mail) is not obvious to the recipient, users try the email address first, and the tenant-admin user entry offered no sign-in address to pass on. Plus-addressed email sign-in additionally fails at Authelia, which net-kingdom tracks as NK-WP-0041-T02; user-engine must therefore not imply that the email address works.

2026-09-23: the tenant-admin user entry now shows the sign-in address next to the login name and states that the email address is not the login name. The password-setup handoff page repeats the sign-in address for after the password is set and says plainly that this portal does not deliver the link. Regression coverage is in test_journey_roles.UserJourneys.test_password_handoff_names_actual_login_and_failure_can_retry. No claim about password or factor state is added, and no delivery is claimed.

id: USER-WP-0035-T02
status: wait
priority: high
state_hub_task_id: "fae614ba-ffc0-511d-9d22-2d91fbab057f"

Finding 1: the setup link reaches the provider's screen only. A real handoff depends on the operator passing it on out of band. Closing this needs the governed transactional mail lane (email-connect plus the OpenBao delivery token) that SCOPE records as operator-owned; U04 and T02 in tests/journey-coverage.json stay external-blocked until then. Do not substitute a portal-rendered link for delivery evidence.