Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

2.2 KiB

API Reference: Implementing Google Workspace Admin Security

Libraries

google-api-python-client + google-auth

Admin SDK Directory API

Method Description
users().list(domain, projection="full") List users with full profile
users().get(userKey) Get specific user details
users().update(userKey, body) Update user settings
users().list(query="isAdmin=true") List admin users
orgunits().list(customerId) List organizational units
roles().list(customer) List admin roles
roleAssignments().list(customer) List role assignments

Reports API (Audit Logs)

Method Description
activities().list(userKey, applicationName) Get audit events
Application names: login, admin, drive, token, mobile

Key User Fields for Security

Field Description
isEnrolledIn2Sv User enrolled in 2-Step Verification
isEnforcedIn2Sv 2SV enforcement applied
isAdmin Super admin status
isDelegatedAdmin Delegated admin status
lastLoginTime Last login timestamp
recoveryEmail Recovery email (risk if external)
recoveryPhone Recovery phone number
isSuspended Account suspended

OAuth Scopes Required

  • admin.directory.user -- User management
  • admin.directory.domain -- Domain settings
  • admin.reports.audit.readonly -- Audit log access
  • admin.directory.orgunit -- Org unit management

Login Event Names

  • login_success -- Successful login
  • login_failure -- Failed login attempt
  • login_challenge -- 2FA challenge issued
  • suspicious_login -- Flagged by Google
  • account_disabled_password_leak -- Compromised password

External References