{
  "$comment": "Contract A4 PRACTICE items for the ashr-partner-l2 track, domain slack-sso-and-handover. Published, for lesson quizzes and lab preparation. The secured theory exam is NOT drawn from this file. Every item cites the ASHR.work pages it is grounded in (`cites`) and the repo files the facts were read from (`sources`). No item quotes a price and no item carries customer data.",
  "track": "ashr-partner-l2",
  "domain": "slack-sso-and-handover",
  "items": [
    {
      "id": "ashr-partner-l2.slack-sso-and-handover.01",
      "kind": "mcq",
      "domain": "slack-sso-and-handover",
      "stem": "How is the ASHR.work Slack app set up for a customer?",
      "options": [
        {
          "key": "a",
          "text": "Each employee installs the app separately"
        },
        {
          "key": "b",
          "text": "A Slack workspace admin installs the app once per company through Slack's authorisation screen, then each person types /ashr connect once to tie their Slack user to their ASHR.work profile"
        },
        {
          "key": "c",
          "text": "The partner installs it from their own Slack"
        },
        {
          "key": "d",
          "text": "It connects automatically by matching email addresses"
        }
      ],
      "answer_key": {
        "correct": [
          "b"
        ]
      },
      "max_points": 1,
      "rationale": "Connecting is a one-time step per person.",
      "cites": [
        "https://ashr.work/help/slack/using-ashr-in-slack"
      ],
      "sources": [
        "content/help/slack/using-ashr-in-slack.mdx"
      ]
    },
    {
      "id": "ashr-partner-l2.slack-sso-and-handover.02",
      "kind": "mcq",
      "domain": "slack-sso-and-handover",
      "stem": "A manager approves a leave request from a Slack DM. What is true?",
      "options": [
        {
          "key": "a",
          "text": "The Slack button bypasses the web rules"
        },
        {
          "key": "b",
          "text": "Each button runs the same rule as the web button and every decision is recorded in the audit log; admin work such as payroll, settings, reports and org changes still happens on the web"
        },
        {
          "key": "c",
          "text": "Slack approvals are not recorded"
        },
        {
          "key": "d",
          "text": "Payroll runs can be locked from Slack"
        }
      ],
      "answer_key": {
        "correct": [
          "b"
        ]
      },
      "max_points": 1,
      "rationale": "Slack is for everyday tasks; configuration is on the web.",
      "cites": [
        "https://ashr.work/help/slack/using-ashr-in-slack"
      ],
      "sources": [
        "content/help/slack/using-ashr-in-slack.mdx"
      ]
    },
    {
      "id": "ashr-partner-l2.slack-sso-and-handover.03",
      "kind": "mcq",
      "domain": "slack-sso-and-handover",
      "stem": "An employee runs /ashr payslip. What do they get?",
      "options": [
        {
          "key": "a",
          "text": "The PDF attached in the channel"
        },
        {
          "key": "b",
          "text": "A private link that works for 15 minutes and only for them; the PDF is never attached to a Slack message"
        },
        {
          "key": "c",
          "text": "Their payslip posted to their manager"
        },
        {
          "key": "d",
          "text": "Nothing; payslips are not available from Slack"
        }
      ],
      "answer_key": {
        "correct": [
          "b"
        ]
      },
      "max_points": 1,
      "rationale": "Worth showing at handover, because it answers the most common privacy question about Slack.",
      "cites": [
        "https://ashr.work/help/slack/using-ashr-in-slack"
      ],
      "sources": [
        "content/help/slack/using-ashr-in-slack.mdx"
      ]
    },
    {
      "id": "ashr-partner-l2.slack-sso-and-handover.04",
      "kind": "mcq",
      "domain": "slack-sso-and-handover",
      "stem": "The customer asks you to switch on single sign-on for their workspace. What is accurate?",
      "options": [
        {
          "key": "a",
          "text": "Any admin switches it on per workspace from Settings"
        },
        {
          "key": "b",
          "text": "Demystify ID single sign-on is a deployment-level flag, shown on Admin → Integrations; when it is off, email and password and the configured providers are the ways in, and an implementer cannot turn it on for one workspace"
        },
        {
          "key": "c",
          "text": "SSO is turned on by the partner from the partner portal"
        },
        {
          "key": "d",
          "text": "SSO is always on"
        }
      ],
      "answer_key": {
        "correct": [
          "b"
        ]
      },
      "max_points": 1,
      "rationale": "'Connect SSO where enabled': check the Integrations card, and record its state at handover.",
      "cites": [
        "https://ashr.work/help/integrations/what-each-integration-status-means"
      ],
      "sources": [
        "content/help/integrations/what-each-integration-status-means.mdx",
        "lib/server/demystify/flag.ts"
      ]
    },
    {
      "id": "ashr-partner-l2.slack-sso-and-handover.05",
      "kind": "mcq",
      "domain": "slack-sso-and-handover",
      "stem": "Before handover, where do you confirm which integrations are actually connected?",
      "options": [
        {
          "key": "a",
          "text": "In the customer's Slack settings only"
        },
        {
          "key": "b",
          "text": "On Admin → Integrations, where each card shows its real state — for Slack, an active installation record with its name and install date"
        },
        {
          "key": "c",
          "text": "By asking the customer"
        },
        {
          "key": "d",
          "text": "In the partner portal"
        }
      ],
      "answer_key": {
        "correct": [
          "b"
        ]
      },
      "max_points": 1,
      "rationale": "A handover note should say what is connected, from the product, not from memory.",
      "cites": [
        "https://ashr.work/help/integrations/what-each-integration-status-means",
        "https://ashr.work/help/integrations/how-to-check-what-is-connected"
      ],
      "sources": [
        "content/help/integrations/what-each-integration-status-means.mdx",
        "content/help/integrations/how-to-check-what-is-connected.mdx"
      ]
    },
    {
      "id": "ashr-partner-l2.slack-sso-and-handover.06",
      "kind": "scenario",
      "domain": "slack-sso-and-handover",
      "stem": "Your implementation is complete and you are handing the workspace over to the customer's HR admin. What do you cover, and what do you leave in writing?",
      "rubric": {
        "criteria": [
          "confirms roles follow least privilege: base roles plus grants, and who holds the finance grant",
          "confirms the Slack app is installed and tells people to run /ashr connect",
          "reports single sign-on state as shown on Admin → Integrations, without promising a change",
          "lists open items in writing, such as data the importers did not cover, a second PT state or settings awaiting the customer's decision",
          "lists every login created during implementation so the customer's admin can keep or remove each one",
          "states what the partner can see afterwards as partner-of-record: nothing inside the workspace"
        ],
        "max_points": 6
      },
      "max_points": 6,
      "cites": [
        "https://ashr.work/docs/explanation/tenancy-and-roles",
        "https://ashr.work/help/slack/using-ashr-in-slack",
        "https://ashr.work/help/integrations/what-each-integration-status-means",
        "https://ashr.work/help/admin/referred-by-a-partner"
      ],
      "sources": [
        "content/docs/explanation/tenancy-and-roles.mdx",
        "content/help/slack/using-ashr-in-slack.mdx",
        "content/help/integrations/what-each-integration-status-means.mdx",
        "content/help/admin/referred-by-a-partner.mdx"
      ]
    }
  ]
}
