This task is being (re)purposed to assign additional LDAP (Wikimedia IDM ("Bitu")) group memberships above and beyond those from {T420688}.
@JVanderhoop-WMF has confirmed that the following looks right. I ( @dr0ptp4kt ) looked at recent logins to GrowthBook as well as the email addresses associated with records in Test Kitchen prod, and I think this about captures the folks who have had a longer term interest or nearer term interest around the facilities and have active IDs that meet criteria and their probable best matching level of access. I (@JVanderhoop-WMF
) added some PMs, analysts and engineers I know are in late stages of planning upcoming experiments.
Pending Julie okay, I can look for common managerial approval to confirm further access with some blanket approval (the `data.yaml` permissions are sufficient except as noted for one user). I believe LDAP group membership can then subsequently be added by a DP SRE team member at a privileged shell with access to LDAP tools.
`growthbook-customelevatedaccess`: cjming (could be promoted to Admin if desired and interested), sfaci (could be promoted to Admin if desired and interested), jiawang, milimetric, jdrewniak, mgrosse, suecarmol, mfossati, sgimeno, emc-wmf, toyofuku, kgraessle, kcvelaga, kharlan, dlynch, akhatun, amastilovic, wmde-fisch, seanleong-wmde, snowick, mneisler, conniecc1, linafaridwmde
`growthbook-readonly`: ksarabia (ksarabia probably ought to seek membership in deployment so as to get elevation to growthbook-customelevatedaccess), gehel (also has ops membership, but probably only needs growthbook-readonly), joal, ovasileva, jseddon, sherryyang, hfanwmf, kstoller, ggalofre, sperry-wmf, jaz, ppel
Additionally, bvibber will need access to `analytics_private_data` for baseline membership in GrowthBook if seeking access to growthbook-readonly or growthbook-customelevatedaccess (BTW, already has deployment).
This is being dropped into Sprint 21 for review, may be dragged into following sprint.
CC @KReid-WMF
Related: {T419622}