Seraya Psikologi — Documentation

Booking and payment MVP · Implementation baseline · 96 ADR

81. Bootstrap Two Admins for Recovery

Status

Accepted for launch planning.

Context

Staff access uses Google SSO plus explicit StaffMembership. A single Admin would create an avoidable operational dependency for invite/revoke and recovery, while a full break-glass system is unnecessary for the MVP.

Decision

Bootstrap two active Admin StaffMemberships at launch. Either Admin may:

No password fallback, shared account, credential copy, or undocumented bypass is introduced. Google account recovery remains the identity provider's responsibility; application-level staff recovery uses the other active Admin to restore/revoke membership. If both Admins lose access, the owner follows a separately maintained operational recovery runbook; its secrets are never stored in PRD artifacts.

Consequences

Positive:

Costs and constraints:

Open follow-up

Record the two Admin StaffMemberships during implementation/bootstrap, define re-authentication/session expiry, and maintain the owner recovery runbook outside source/PRD artifacts.