Ticket: Marcus Tailscale onboarding + first login walkthrough

ticket-westside-ops-marcus-onboarding Doc

active backlog westside-ops ticket

Ticket: Marcus Tailscale onboarding + first login walkthrough

Story: story-westside-ops-spreadsheet-access (this ticket fulfills the Success Metric)
Architecture: arch-deployment-westside-ops
Labels: story:spreadsheet-access,arch:deployment,type:onboarding,track:ops,scope:planned
Blocks: nothing (this is the final ticket)
Blocked by: k8s overlay (needs a live URL)

Purpose

Get Marcus's phone onto the tailnet, confirm his Keycloak account has the westside-ops-user role, walk him through the first login, and verify end-to-end that the paradigm is delivered: Marcus independently sees his data without AI, developer, or admin in the loop. This ticket is where the story's Success Metric is validated.

Scope

Phase 1: Tailscale install on Marcus's phone

  • Lucas sits with Marcus (in person or over a call) for ~10 minutes
  • Marcus opens the App Store / Play Store and installs Tailscale
  • Lucas opens the Tailscale admin console and generates an invite link for Marcus (email-based invite to the tailnet)
  • Marcus opens the invite, signs in with his email provider, joins the tailnet
  • Verify from Tailscale admin console that Marcus's phone appears as a tailnet member

Phase 2: Keycloak role assignment (may already be done by services-entry ticket)

  • Open Keycloak admin console: https://keycloak.tail5b443a.ts.net
  • Navigate to the westside realm → Users → find Marcus's account by email
  • Go to Role Mappings → assign westside-ops-user realm role
  • If the role doesn't exist yet, create it first in Realm Roles

Phase 3: First login walkthrough

  • Marcus opens Safari/Chrome on his phone and navigates to https://westside-ops.tail5b443a.ts.net
  • Verify: page loads (proves tailnet membership working), redirects to Keycloak (proves OIDC flow)
  • Marcus signs in with his existing westside credentials
  • After login: verify the sidebar shows all 9 pages
  • Marcus clicks "Players" — verify the grid loads with 66 rows
  • Walk Marcus through: (1) sorting by clicking a column header, (2) using the column filter icon, (3) selecting a cell range, (4) copying with Ctrl+C (or long-press on mobile), (5) pasting into another app
  • Show Marcus the other 8 pages so he knows what's there
  • Answer whatever questions come up — write them down if they suggest feature gaps

Phase 4: 1-week observation window (the Success Metric)

  • Marcus uses the tool for his actual weekly operational tasks without prompting from Lucas
  • Lucas tracks: did Marcus's Westside-related messages to Lucas drop? Did Marcus complete at least 5 independent operational tasks using westside-ops?
  • At end of week 1, Marcus and Lucas review: what worked, what didn't, what's missing
  • Findings become new backlog tickets (probably: specific new page columns, specific filters that Marcus wants pre-applied, maybe a first action button if copy-paste friction shows up)

Acceptance Criteria

  • [ ] Marcus's phone is on the tailnet (visible in Tailscale admin console)
  • [ ] Marcus's Keycloak account has westside-ops-user role in the westside realm
  • [ ] Marcus can load https://westside-ops.tail5b443a.ts.net on his phone without assistance
  • [ ] Marcus can log in via Keycloak and see the sidebar with 9 pages
  • [ ] Marcus can open the Players page and see 66 rows of real data
  • [ ] Marcus demonstrates sort, filter, search, and copy independently (Lucas confirms by watching him do each once)
  • [ ] After 1 week: Marcus has completed at least 5 operational tasks using the tool without asking Lucas/Ava to query data
  • [ ] Week-1 retro captured as new tickets on board-westside-ops (backlog column, per backlog-first enforcement)

Files touched

  • Tailscale admin console state (Marcus added to tailnet)
  • Keycloak realm state (role assignment)
  • No repo files

Rollback

Remove Marcus from the tailnet and/or revoke the westside-ops-user role. Marcus retains access to the existing westside-app — no disruption to his current workflows.

Out of scope

  • Training Marcus on SQL, database concepts, or internal terminology. Show him what he can do, not how it works under the hood.
  • Linking westside-ops from westside-app's existing admin — that's Phase 2 of the rollout plan, decided after Marcus has used westside-ops
  • Documentation for Marcus. Plain-language per feedback_marcus_plain_language: one short "how to use this" paragraph is enough. If he needs more, the tool is wrong.
  • Adding other Westside staff or coaches. v1 is Marcus only. Other users are a follow-up story.

Dependencies

Blocked by: everything above. This is the last ticket in the chain.