This task is being (re)purposed to assign additional LDAP (Wikimedia IDM ("Bitu")) group memberships above and beyond those from T420688: Create new Wikimedia IDM ("Bitu") LDAP groups for GrowthBook.
Actions
- Verify Sheet is correct (CONFIRMED on IM thread 14-May-2026)
- Data Platform SRE uses LDAP tool (under DP SRE ops permission) to add each set of users, per-role, to the role identified in the sheet for the set (TODO)
@JVanderhoop-WMF has confirmed that the following looks right. I ( @dr0ptp4kt ) looked at recent logins to GrowthBook as well as the email addresses associated with records in Test Kitchen prod, and I think this about captures the folks who have had a longer term interest or nearer term interest around the facilities and have active IDs that meet criteria and their probable best matching level of access. I (@JVanderhoop-WMF
) added some PMs, analysts and engineers I know are in late stages of planning upcoming experiments.
Julie has noted through Task Description update (which Mikhail carried into the Sheet) the okay of the user list and added additional users. The updated access approval approach doesn't require additional access approvals beyond the validation of appropriate POSIX and LDAP group membership plus email address domain matches. Consequently, a blanket approval is no longer required as initially conceived at the earlier stage of this task. The Google Sheet for access will need dropdowns updated to reflect the correct level of access pertinent for the newly specified users (see this task's diffs to see who was added to the list; this requires lining up things in the data.yaml file and checking the LDAP tool, and so forth); the dropdowns should be updated by a member of Experiment Platform Team. Subsequently, LDAP group membership can be added by a DP SRE team member at a privileged shell with access to LDAP tools.
growthbook-customelevatedaccess: see https://docs.google.com/spreadsheets/d/1a_RQk8R8MZNjRM_8AHmamho3xh3eV-Pgd88PDtHr1hA/edit?gid=0#gid=0 (WMF internal only)
growthbook-readonly: see https://docs.google.com/spreadsheets/d/1a_RQk8R8MZNjRM_8AHmamho3xh3eV-Pgd88PDtHr1hA/edit?gid=0#gid=0 (WMF internal only)
This is now part of Sprint 22.
CC @KReid-WMF