This task is being (re)purposed to assign additional LDAP group memberships above and beyond those from {T420688}.
@JVanderhoop-WMF would you please confirm that the following looks right? I ( @dr0ptp4kt ) looked at recent logins to GrowthBook as well as the email addresses associated with records in Test Kitchen prod, and I think this about captures the folks who have had a longer term interest or nearer term interest around the facilities and have active IDs that meet criteria and their probable best matching level of access.
Pending Julie okay, I can look for common managerial approval to confirm further access with some blanket approval (the `data.yaml` permissions are sufficient except as noted for one user). I believe LDAP group membership can then subsequently be added by a DP SRE team member at a privileged shell with access to LDAP tools.
`growthbook-customelevatedaccess`: cming (could be promoted to Admin if desired and interested), sfaci (could be promoted to Admin if desired and interested), jiawang, milimetric, jdrewniak, mgrosse, suecarmol, mfossati, sgimeno, emc-wmf, toyofuku, kgraessle, kcvelaga, kharlan, dlynch, akhatun, amastilovic, wmde-fisch, seanleong-wmde
`growthbook-readonly`: ksarabia (ksarabia probably ought to seek membership in deployment so as to get elevation to growthbook-customelevatedaccess), gehel (also has ops membership, but probably only needs growthbook-readonly), ovasileva, jseddon
Additionally, bvibber will need access to analytics_private_data for baseline membership in GrowthBook if seeking access to growthbook-readonly or growthbook-custom-elevated (BTW, already has deployment).
This is being dropped into Sprint 21 for review, may be dragged into following sprint.
CC @KReid-WMF
Related: {T419622}