SPIRE × CUSTODY BOARD
0% · 0/21
CONNECTING
Prepared forSPIRE DELEGATED TEAM
Companion toRUNBOOK PHASE A · B
WindowWEEK ONE
DocSPR–PROV–01

Accounts,
and who holds
the keys.

Layered glass curtain wall, overlapping reflections making the depth of the facade ambiguous.

Access is not ownership, and only one of the two survives the agency exit.

A login someone shared with you is revocable by whoever shared it. Every line here carries a test that reads the ownership record, not whether the password works. Where those answers differ, the account is not provisioned.

11To create
03Verify ownership
01Already held
01Unowned · unnamed
(01)

Critical path

THREE LANES · ONE DATE
CONVERGENCE ON 1 NOVEMBER
(01) PROVISIONING — OWNED Shared mailbox0.1 → 0.2 VAULT Nine accountsC1 – C9 Project migratedDEV HANDS OVER (02) REGISTRAR — UNOWNED Registrar ?V5 · NO OWNER NAMED DNS cutoverA RECORD · TTL (03) SEO CONTINUITY — UNOWNED Redirect map ?806 OLD URLS GSC exportSPIRE HOLDS THIS 1 November PROGRAMS GO PUBLIC
Lane 01 has an owner and a written runbook. Lanes 02 and 03 have neither, and either one stops the launch on its own. The Search Console export that unblocks lane 03 is the single asset SPIRE already holds.
(02)

Create

11 ITEMS · IN ORDER
Exposed structural steel truss lattice, repeating diagonal members receding in order.

Every account registers to systems@spireacademy.com, never an individual. Anything created on a personal address and moved later is the migration that never happens. Order binds once: GitHub must exist before Vercel connects to the repo.

0.1
Shared system mailboxFIRSTRUNBOOK A1

Create systems@spireacademy.com in Google Workspace, forwarding to Nathan and the contractor. Every verification email and billing notice below lands here. TEST  a message reaches both forwarding addresses.

0.2
Password vaultFIRST1PASSWORD / BITWARDENRUNBOOK A2

One shared business vault named SPIRE Systems. Every credential below goes in it, nothing in a spreadsheet or a message. TEST  both parties can read the vault.

C1
Supabase organisationPRORUNBOOK A3

Create the org, invite the developer, ask him to migrate the existing project in. Never accept a transfer of his own org. TEST  project sits under SPIRE's org and SPIRE holds Owner.

C2
GitHub organisationFREE / TEAMRUNBOOK A5

Developer transfers the repository in, then gets added back as a write collaborator. TEST  the repo URL shows the SPIRE org in its path.

C3
Vercel teamPRORUNBOOK A4

Developer gets a deploying seat. Connect to the repo only after C2. The build targets Vercel, not Cloudflare, and already compiles clean with no code changes. TEST  a deploy runs from the SPIRE-owned repo.

C4
Google Tag ManagerFREERUNBOOK A8

A new container, never the outgoing agency's. The developer needs the container ID for the site-wide install ticket. TEST  container ID vaulted and sent to the developer.

C5
Claude Team2 SEATS · ANNUALRUNBOOK A6

Two seats, annual billing is cheaper, every seat includes Claude Code. TEST  both seats active, shared mailbox as billing owner.

C6
n8n CloudSTARTERRUNBOOK A7

Starter now, Pro when volume requires it around the camp launch. TEST  both parties can sign in to the workspace.

C7
TailscaleFREERUNBOOK B3

Private network between the office machine and both laptops. No ports opened, no router changes. TEST  two devices on different networks reach each other.

C8
Google Analytics 4ONLY IF V2 FAILSRUNBOOK A9

If SPIRE lacks account-level admin on the existing property, build fresh under SPIRE. Historical data is worth less than clean ownership before launch. TEST  Administrator at account level, not property level.

C9
Meta Business ManagerONLY IF V4 FAILSRUNBOOK A10

Assets get transferred into it, never shared into it. Shared assets vanish when the agency's business removes them. TEST  pixel, page and catalog list SPIRE as owner.

(03)

Verify

5 ITEMS

These exist already. The question is never whether someone can log in. It is whose name sits on the ownership record once the agency's access is removed.

V1
Google Search ConsoleHELDRUNBOOK A9

SPIRE has this. Confirm it is a domain property, not URL-prefix, and that SPIRE is Owner rather than Full User. ALSO  export the full URL list this week. Nothing else unblocks the redirect map.

V2
Google Analytics 4VERIFYRUNBOOK A9

Shared credentials are not the same as holding the account. Admin → Account Access Management → confirm Administrator at account level. The runbook flags this as the known unresolved item from the agency exit. IF IT FAILS  C8 applies, new property before launch.

V3
Google AdsVERIFYRUNBOOK A10

SPIRE's own billing entity, and the agency's manager account removed, not downgraded. A manager link left in place keeps their claim. TEST  SPIRE is the payments profile, no external manager linked.

V4
Meta Business ManagerVERIFYRUNBOOK A10

Read the owner column on the pixel, page and catalog. Anything owned by the agency's business with SPIRE as partner is borrowed, and it stops working the day they leave. TEST  every asset lists SPIRE's business as owner.

V5
Domain registrarUNOWNEDNOT IN RUNBOOK

Who is registrant of record for spireacademy.com, and which account changes the A record on launch day? The runbook covers ten systems and skips the registrar. The developer's launch list assumes the record can simply be updated. TEST  SPIRE holds the registrar login, lock on, TTL lowered before cutover.

Single point of failure

V5 is the one item that can stop a launch outright.

Everything else here has a workaround that costs hours. A registrar you cannot reach on cutover day costs the launch date, and those credentials sit with the agency being removed. Resolve it before their access is cut.

(04)

Connect & equip

5 ITEMS · 4 TOKENS

After the accounts exist. A token is the third form of access, and it fails differently from a password: a token issued to a person dies when that person changes role, and a token that leaks cannot be un-leaked.

TOKEN RULE
  1. Every token is issued to systems@spireacademy.com or to a system user, never to a named person's login.
  2. Minimum scopes only. If a workflow does not write to a system, the token does not get write access to it.
  3. Straight into the vault on creation. Never pasted into email, chat or a ticket, including to us.
  4. Every token is listed in the custody matrix with its scope, its owner and its issue date.
  5. Rotated when any contractor leaves, us included. The same doctrine that ends the agency dependency applies to the next vendor, or it was never a doctrine.
T1
HubSpot private appNEEDS HUBSPOT ADMINRUNBOOK C1 C2

Scoped to contacts, deals, forms, lists, timeline and automation. TEST  a read call returns one contact.

T2
Supabase service role keyNEEDS C1RUNBOOK C3

Vault it, then add to n8n as a credential. TEST  n8n writes one test row and deletes it again.

T3
Google OAuthNEEDS V2 V3RUNBOOK C4

Analytics and Ads, authorised as the shared mailbox so it survives a person changing role. TEST  the consent screen shows systems@.

T4
Meta system user tokenNEEDS V4RUNBOOK C5

A system user, never a personal token. Personal tokens die when the person changes role. TEST  issued to a system user, not a profile.

H1
Mac mini$799–899 · 16GB / 256GBRUNBOOK B1

A refurbished or sale M4 at $480–600 is adequate. Runs Claude Desktop, Claude Code and local tooling, not a rendering machine. Company card, SPIRE's address, serial into the asset register. Not a blocker for section 02. ONE ADDITION  disk encryption stays on since the vault lives here, so an unattended reboot needs a typed password. Run every service as a background daemon, not a desktop app, and put it on a UPS.

(05)

The handover

3 BUCKETS

What the outgoing agency and the developer hold today. All three buckets must move before VividFront's access is cut, not after.

BUCKET 01

Credentials

  • Registrar loginHOLDER UNKNOWN · ASK KYLE / VF
  • DNS, ability to change the A recordVF SHARED WITH MYLAN MURPHY
  • GA4 + Search Console adminMYLAN MURPHY
  • Ads + Meta business ownershipKYLE / VIVIDFRONT
  • HubSpot super adminJEFF ANGUS
BUCKET 02

API access

  • HubSpot private app tokenSIX SCOPES
  • HubSpot form IDs for the embedsJEFF ANGUS, FROM KYLE / VF
  • Supabase service role keyAFTER C1 EXISTS
  • Google OAuth, Analytics and AdsAUTHORISE AS SYSTEMS@
  • Meta system user tokenNEVER A PERSONAL TOKEN
BUCKET 03

Codebase

  • GitHub repo into the SPIRE orgSAMUEL BENISTY
  • Supabase project migrated inNOT A TRANSFER OF HIS ORG
  • Vercel linked to the SPIRE repoONLY AFTER THE GITHUB MOVE
  • Environment variables read out and vaultedBEFORE CUTOVER
  • CMS training materialSAMUEL COMMITTED TO THIS
(06)

Action items

42 DAYS TO 1 NOV
5 of 17 actions gate the 1 November launch dateMarked in red

SPIRE delivers

OWNER · ACTION · BY
Mylan MurphyExport the full URL list from Search Console. Unblocks the redirect map, and nothing else does.23 SEP
Nathan HarrisName the registrant of record and confirm who can change the A record.23 SEP
Nathan HarrisCreate systems@spireacademy.com and the shared vault.26 SEP
Chuck / SPIRE ITSupabase org, GitHub org and Vercel team, all on the shared mailbox.26 SEP
Jeff AngusSend the HubSpot form IDs, grant admin for the private app.26 SEP
Kyle / VividFrontTransfer Ads and Meta ownership to SPIRE's entity. Removed, not downgraded.BEFORE EXIT
Mylan MurphyConfirm account-level GA4 admin, not property access.3 OCT
Samuel BenistyMigrate the Supabase project, transfer the repo into the SPIRE orgs.3 OCT
Jeff Angus + SPIRE ITIssue the four API tokens once the accounts exist: HubSpot private app, Supabase service role, Google OAuth, Meta system user. Into the vault on creation, under the token rule.10 OCT
Chuck / SPIRE ITOrder the Mac mini, enrol it, rack it, escrow the encryption key.10 OCT

We deliver

FIXED-SCOPE TICKETS THROUGH LAUNCH
Ticket 01The 806 redirect map. Every old URL clustered into wildcard patterns and exact rules, ranked by traffic and inbound links. Delivered as a CSV the developer loads straight into the redirect manager.WK 1–2
Ticket 02Tag Manager container specced, created, handed over as one site-wide install ticket. Takes every future tag off the developer's queue.WK 1
Ticket 03Account custody matrix. Every system, who holds it, at what level, granted when. Becomes the asset register.WK 1
Ticket 04DNS cutover runbook with a rollback path and TTL lowered 48 hours ahead. Neither the runbook nor the developer's list covers this.WK 2
Ticket 05Token wiring and the custody matrix. Each of the four tokens connected, scope-tested with a read call before any write call, and recorded with scope, owner and issue date.WK 2
Ticket 06n8n connected to HubSpot, Supabase, Google and Meta. Read test before any write test, every time.WK 2–3
Ticket 07End-to-end test. A real form submission followed into HubSpot, Supabase, GA4 and Meta. It arrives in all four or it is not done.WK 3
The next move

Two answers on Tuesday unblock the whole board.

Who is the registrant of record for the domain, and can someone send the Search Console URL export. Everything else here has a workaround. Those two do not, and both are free to answer.