New County Onboarding: Backend Access Provisioning Process
This article outlines the process for provisioning backend access when a new county's SmartCare environment is onboarded, covering SQL (non-prod and prod), SFTP, Report Server, and OpenVPN.
Important Notes
Streamline must use Tom Remisoski's tool to provision these accounts. When Streamline sets up backend access for a new county environment, they need to use Tom Remisoski's permissions tool to grant access — not a manual/ad hoc process. Permissions must match what's configured for the other CalMHSA county environments. This is called out again in both Zendesk ticket templates below.
Alert IT/CalHelp when new environments are stood up. Oasis will need to be updated to allow access to the server for both non-prod and prod environments. Notify IT/CalHelp as soon as each environment is stood up so this update isn't missed.
Scope
This process covers backend access provisioning for a new county's SmartCare environment across:
- SQL (non-prod and prod)
- SFTP
- Report Server
- OpenVPN
Key Timing Note
Not all environments are available at the same time:
- Available immediately at environment setup: Test, Train, Setup, QA (non-prod)
- Available later: Production — access must be requested as a follow-up once prod is stood up
Because of this, onboarding access happens in two phases. Don't wait on prod to request non-prod access, and don't let the prod request get lost — track it as an open follow-up item tied to the county's go-live timeline.
Standard Access Baseline (apply to every new county)
The following accounts get provisioned by default any time a new county environment is set up. Permission levels below must be replicated exactly — matching the baseline already in place for other counties.
| Account | Non-Prod (Test/Train/Setup/QA) | Prod | |
|---|---|---|---|
| will.bunin.admin | william.bunin@calmhsa.org | Full Read/Write | Full Read/Write |
| andrew.wagner.admin | andrew.wagner@calmhsa.org | Full Read/Write | Full Read/Write |
| awagner | andrew.wagner@calmhsa.org | Read/Write | Read Only |
| calmhsa.wbunin | william.bunin@calmhsa.org | Read/Write | Read Only |
| bdominik | bethany.dominik@calmhsa.org | Read/Write | Read Only |
| calmhsa.ecardoza | eric.cardoza@calmhsa.org | Read/Write | Read Only |
| calmhsa.jdechenne | jessica.dechenne@calmhsa.org | Read/Write | Read Only |
| calmhsa.lkirlin | lisa.kirlin@calmhsa.org | Read/Write | Read Only |
| calmhsa.lngo | lam.ngo@calmhsa.org | Read/Write | Read Only |
| chakusui | christopher.hakusui@calmhsa.org | Read/Write | Read Only |
| pmerna | peter.merna@calmhsa.org | Read/Write | Read Only |
| kstephan | khristy.stephan@calmhsa.org | Read/Write | Read Only |
| calmhsa.schema.recorder | william.bunin@calmhsa.org | Read Only | Read Only |
| calmhsa.hhannah | haylea.hanna@calmhsa.org | Read Only | Read Only |
| calmhsa.tdavis | taylor.davis@calmhsa.org | Read Only | Read Only |
| vanessa.pan | vanessa.pan@calmhsa.org | Read Only | Read Only |
Only will.bunin.admin and andrew.wagner.admin get full read/write in production. Everyone else is read-only in prod, read/write in non-prod (Haylea Hannah, Taylor Davis, and Vanessa Pan are read-only in both).
Reason for Access
| Account | Reason for Access |
|---|---|
| will.bunin.admin | Admin developer account |
| andrew.wagner.admin | Admin developer account |
| awagner | Non-admin developer account |
| calmhsa.wbunin | Non-admin developer account |
| bdominik | Reporting/data analytics |
| calmhsa.ecardoza | Migration/state reporting |
| calmhsa.jdechenne | Migration |
| calmhsa.lkirlin | Billing |
| calmhsa.lngo | Reporting |
| chakusui | Non-admin developer account |
| pmerna | Reporting/implementation |
| kstephan | Billing |
| calmhsa.schema.recorder | Developer data — requires View State access to view SQL jobs |
| calmhsa.hhannah | Reporting/analytics |
| calmhsa.tdavis | Reporting/analytics |
| vanessa.pan (Vanessa Pan) | Reporting/analytics |
Process Steps
Phase 1 — At Environment Setup (Non-Prod)
- Confirm environment names for the new county (test, train, setup, QA) once Streamline has stood them up.
- Alert IT/CalHelp that the non-prod environment is stood up so Oasis can be updated to allow server access.
- Fill out the SCARF (SmartCare Access Request Form) using the account/permission table below and attach it to the Zendesk ticket.
- Submit Zendesk ticket (Template 1) requesting SQL non-prod, SFTP, Report Server, and OpenVPN access for the full account list.
- Explicitly note in the ticket that Streamline must use Tom Remisoski's tool to provision, and that permissions should mirror the existing county baseline.
- Verify access once Streamline confirms provisioning — spot-check at least one full-access account (will.bunin.admin or andrew.wagner.admin) and one read/write non-prod account.
- Log the prod request as a follow-up — don't close this out as done, since prod access is still pending.
Phase 2 — Once Production Is Available
- Confirm with Streamline/internal team that the prod environment is live and ready for access provisioning.
- Alert IT/CalHelp that the prod environment is stood up so Oasis can be updated to allow server access.
- Fill out the SCARF for production using the account/permission table below and attach it to the Zendesk ticket.
- Submit Zendesk ticket (Template 2) requesting SQL prod, SFTP, Report Server, and OpenVPN production access, again referencing Tom Remisoski's tool and the same permission levels.
- Verify prod access — confirm the two admin accounts have full read/write, and spot-check that the read-only accounts are correctly restricted (not accidentally granted write).
- Close out onboarding once both phases are confirmed complete.
Zendesk Ticket Templates
Template 1 — Non-Prod Access Request (Test/Train/Setup/QA)
Subject: New County Backend Access Setup — [County Name] — Non-Prod
Note to Streamline: Please use Tom Remisoski's tool to provision this access. Permissions must match the existing baseline used for other CalMHSA county environments.
Requesting backend access provisioning for the new [County Name] environment across the following systems: SQL (non-prod), SFTP, Report Server, and OpenVPN.
This covers the Test, Train, Setup, and QA environments only — production is not yet available and will be requested separately once it's stood up.
Accounts and permission levels:
| Account | Access Level | |
|---|---|---|
| will.bunin.admin | william.bunin@calmhsa.org | Full Read/Write |
| andrew.wagner.admin | andrew.wagner@calmhsa.org | Full Read/Write |
| awagner | andrew.wagner@calmhsa.org | Read/Write |
| calmhsa.wbunin | william.bunin@calmhsa.org | Read/Write |
| bdominik | bethany.dominik@calmhsa.org | Read/Write |
| calmhsa.ecardoza | eric.cardoza@calmhsa.org | Read/Write |
| calmhsa.jdechenne | jessica.dechenne@calmhsa.org | Read/Write |
| calmhsa.lkirlin | lisa.kirlin@calmhsa.org | Read/Write |
| calmhsa.lngo | lam.ngo@calmhsa.org | Read/Write |
| chakusui | christopher.hakusui@calmhsa.org | Read/Write |
| pmerna | peter.merna@calmhsa.org | Read/Write |
| kstephan | khristy.stephan@calmhsa.org | Read/Write |
| calmhsa.schema.recorder | william.bunin@calmhsa.org | Read Only |
| calmhsa.hhannah | haylea.hanna@calmhsa.org | Read Only |
| calmhsa.tdavis | taylor.davis@calmhsa.org | Read Only |
| vanessa.pan | vanessa.pan@calmhsa.org | Read Only |
SCARF (SmartCare Access Request Form) is attached with the full name/permission detail — see table below. Reason for access for each account is listed in the Reason for Access section above.
Please confirm once provisioning is complete. Let us know if anything is needed from our end.
SCARF — Non-Prod
| Full Name (Username) | Permission Level | |
|---|---|---|
| William Bunin (will.bunin.admin) | william.bunin@calmhsa.org | Full Read/Write |
| Andrew Wagner (andrew.wagner.admin) | andrew.wagner@calmhsa.org | Full Read/Write |
| Andrew Wagner (awagner) | andrew.wagner@calmhsa.org | Read/Write |
| William Bunin (calmhsa.wbunin) | william.bunin@calmhsa.org | Read/Write |
| Bethany Dominik (bdominik) | bethany.dominik@calmhsa.org | Read/Write |
| Eric Cardoza (calmhsa.ecardoza) | eric.cardoza@calmhsa.org | Read/Write |
| Jessica Dechenne (calmhsa.jdechenne) | jessica.dechenne@calmhsa.org | Read/Write |
| Lisa Kirlin (calmhsa.lkirlin) | lisa.kirlin@calmhsa.org | Read/Write |
| Lam Ngo (calmhsa.lngo) | lam.ngo@calmhsa.org | Read/Write |
| Christopher Hakusui (chakusui) | christopher.hakusui@calmhsa.org | Read/Write |
| Peter Merna (pmerna) | peter.merna@calmhsa.org | Read/Write |
| Khristy Stephan (kstephan) | khristy.stephan@calmhsa.org | Read/Write |
| William Bunin (calmhsa.schema.recorder) | william.bunin@calmhsa.org | Read Only |
| Haylea Hannah (calmhsa.hhannah) | haylea.hanna@calmhsa.org | Read Only |
| Taylor Davis (calmhsa.tdavis) | taylor.davis@calmhsa.org | Read Only |
| Vanessa Pan (vanessa.pan) | vanessa.pan@calmhsa.org | Read Only |
Template 2 — Production Access Request (Follow-Up)
Subject: New County Backend Access Setup — [County Name] — Production
Note to Streamline: Please use Tom Remisoski's tool to provision this access. Permissions must match the existing baseline used for other CalMHSA county production environments.
Following up on the earlier non-prod access request for [County Name] (ticket #[___]). Production is now available — requesting backend access provisioning for SQL (prod), SFTP, Report Server, and OpenVPN.
Accounts and permission levels:
| Account | Access Level | |
|---|---|---|
| will.bunin.admin | william.bunin@calmhsa.org | Full Read/Write |
| andrew.wagner.admin | andrew.wagner@calmhsa.org | Full Read/Write |
| awagner | andrew.wagner@calmhsa.org | Read Only |
| calmhsa.wbunin | william.bunin@calmhsa.org | Read Only |
| bdominik | bethany.dominik@calmhsa.org | Read Only |
| calmhsa.ecardoza | eric.cardoza@calmhsa.org | Read Only |
| calmhsa.jdechenne | jessica.dechenne@calmhsa.org | Read Only |
| calmhsa.lkirlin | lisa.kirlin@calmhsa.org | Read Only |
| calmhsa.lngo | lam.ngo@calmhsa.org | Read Only |
| chakusui | christopher.hakusui@calmhsa.org | Read Only |
| pmerna | peter.merna@calmhsa.org | Read Only |
| kstephan | khristy.stephan@calmhsa.org | Read Only |
| calmhsa.schema.recorder | william.bunin@calmhsa.org | Read Only |
| calmhsa.hhannah | haylea.hanna@calmhsa.org | Read Only |
| calmhsa.tdavis | taylor.davis@calmhsa.org | Read Only |
| vanessa.pan | vanessa.pan@calmhsa.org | Read Only |
SCARF (SmartCare Access Request Form) is attached with the full name/permission detail — see table below. Reason for access for each account is listed in the Reason for Access section above.
Please confirm once provisioning is complete.
SCARF — Production
| Full Name (Username) | Permission Level | |
|---|---|---|
| William Bunin (will.bunin.admin) | william.bunin@calmhsa.org | Full Read/Write |
| Andrew Wagner (andrew.wagner.admin) | andrew.wagner@calmhsa.org | Full Read/Write |
| Andrew Wagner (awagner) | andrew.wagner@calmhsa.org | Read Only |
| William Bunin (calmhsa.wbunin) | william.bunin@calmhsa.org | Read Only |
| Bethany Dominik (bdominik) | bethany.dominik@calmhsa.org | Read Only |
| Eric Cardoza (calmhsa.ecardoza) | eric.cardoza@calmhsa.org | Read Only |
| Jessica Dechenne (calmhsa.jdechenne) | jessica.dechenne@calmhsa.org | Read Only |
| Lisa Kirlin (calmhsa.lkirlin) | lisa.kirlin@calmhsa.org | Read Only |
| Lam Ngo (calmhsa.lngo) | lam.ngo@calmhsa.org | Read Only |
| Christopher Hakusui (chakusui) | christopher.hakusui@calmhsa.org | Read Only |
| Peter Merna (pmerna) | peter.merna@calmhsa.org | Read Only |
| Khristy Stephan (kstephan) | khristy.stephan@calmhsa.org | Read Only |
| William Bunin (calmhsa.schema.recorder) | william.bunin@calmhsa.org | Read Only |
| Haylea Hannah (calmhsa.hhannah) | haylea.hanna@calmhsa.org | Read Only |
| Taylor Davis (calmhsa.tdavis) | taylor.davis@calmhsa.org | Read Only |
| Vanessa Pan (vanessa.pan) | vanessa.pan@calmhsa.org | Read Only |
Quick Checklist
- Non-prod environments confirmed live (Test/Train/Setup/QA)
- IT/CalHelp alerted to update Oasis for non-prod server access
- SCARF filled out and attached (non-prod)
- Zendesk ticket #1 submitted (non-prod) with Tom Remisoski's tool noted
- Non-prod access verified
- Prod go-live confirmed
- IT/CalHelp alerted to update Oasis for prod server access
- SCARF filled out and attached (prod)
- Zendesk ticket #2 submitted (prod) with Tom Remisoski's tool noted
- Prod access verified (admin accounts R/W, others read-only)
- Onboarding closed out