# questions-v1.md โ€” TSGCOO โ†’ Charles > Git-tracked questions/answers/decisions. Please edit inline. > Per prompt.md: gathering questions in a git-tracked way is imperative. ## Blocking questions (need answers before provisioning can run) ### Q1: Docker group membership TSGCOO is not in the docker group โ€” `docker info` fails with "permission denied on socket". The provisioning runs entirely in Docker (Playwright container). **Action needed:** `sudo usermod -aG docker TSGCOO` then re-login, or add TSGCOO to the docker group another way. **CNW:** ### Q2: Bitwarden account and credentials The `~/.config/bw/env` file does not exist. The bootstrap prompt says it should contain BW_CLIENTID, BW_CLIENTSECRET, BW_PASSWORD for a dedicated COO BW account. **Questions:** - Has the dedicated "COO" Bitwarden account been created? - Can you populate `~/.config/bw/env` with the API credentials? **CNW:** ### Q3: Cloudron invite links The provisioning manifest (`agents.yaml`) needs real Cloudron invite URLs. Only the `agents.yaml.example` template exists, with `REPLACE_WITH_TOKEN` placeholders. **Questions:** - Have Cloudron user invites been generated for vp-techops, vp-secops, vp-techcompliance (Q3 agents)? - Can you paste the invite URLs so I can populate agents.yaml? **CNW:** ### Q4: Gitea push access I can clone public repos from Gitea but cannot push (no credentials). The TSYSGroupAIOS framework + 4 new scripts need to be pushed to Gitea. **Questions:** - Should I wait for BW-based git credentials (bw-git-credential.sh)? - Or can you provide a Gitea token for the TSGCOO identity to push with? **CNW:** ## Non-blocking questions (can proceed without, but need answers for correctness) ### Q5: Cloudron SSO architecture (from transition-map ยง5, open decision #1) Are Gitea/Discourse/Redmine Cloudron-managed (auto-SSO on first login)? Or standalone? The provisioning code assumes Cloudron SSO auto-provisions accounts. If SSO is NOT auto-provisioning, the provisioning flow needs adjustment. **CNW:** ### Q6: Provisioning selectors (from agent-identity-provisioning/questions-v1.md Q1) The Playwright automation uses generic CSS selectors for Cloudron's invite acceptance, 2FA enrollment, and per-system API key pages. These need verification against the live UI. **Options:** 1. I run the provisioning with `--headed` (needs display) and iterate live 2. You provide screenshots of the Cloudron invite/2FA flow 3. We do a dry-run first and fix selectors as they fail **Which approach do you prefer?** **CNW:** ### Q7: BASELINE-PROMPT.md The TSYSGroupAIOS template (from /tmp/template-test) does not contain `BASELINE-PROMPT.md` (the 14 canonical principles). It's referenced by tsgcoo-bootstrap-prompt.md and the provisioning repo's AGENTS.md. **Question:** Where does BASELINE-PROMPT.md live? Should I create it based on the principles documented in prompt.md, or does it exist somewhere I haven't looked? **CNW:**