- operator CLI flows
- routine subscription maintenance
- failure triage
- go-live checks
- rollout worksheet
Core Operator Commands
Validate the config snapshot
Inspect token health
--force-refresh when you suspect stale auth state.
Inspect subscriptions
Renew near-expiry subscriptions
Automating subscription renewal (REQUIRED for production)
Microsoft Graph subscriptions expire in at most 72 hours. If nothing renews them, meeting notifications silently stop after 3 days and the pipeline looks “broken.” This is the #1 operational failure mode for any Graph-backed integration. You MUST runmaintain-subscriptions on a schedule. Pick one of these three options:
Option 1: Mibyan cron (recommended if you already run the Mibyan gateway)
Mibyan ships a built-in cron scheduler. The--no-agent mode runs a script as the job (rather than using an LLM), and --script must point at a file under ~/.mibyan/scripts/. First create the script:
Option 2: systemd timer (recommended for Linux production deployments)
Create/etc/systemd/system/mibyan-teams-pipeline-maintain.service:
/etc/systemd/system/mibyan-teams-pipeline-maintain.timer:
Option 3: Plain crontab
MSGRAPH_* credentials. Simplest fix: source ~/.mibyan/.env at the top of a wrapper script that crontab calls.
Verifying renewal is working
After you’ve set up the schedule, check renewal activity after the first scheduled run:Inspect recent jobs
Replay a stored job
Dry-run meeting artifact fetches
--organizer-user-id (the organizer’s Microsoft Entra user ID) to resolve
through the organizer-scoped /users/{id}/onlineMeetings Graph path. This is
required for Teams /meet/ short URLs, which Graph rejects on the
/communications/onlineMeetings endpoint. Webhook-driven jobs derive the
organizer automatically from the notification’s @odata.id.
Routine Runbook
After first setup
Run these in order:Daily or periodic checks
- run
mibyan teams-pipeline maintain-subscriptions --dry-run - inspect
mibyan teams-pipeline list --status failed - verify the Teams delivery target is still the correct chat or channel
Before changing webhook URLs or delivery targets
- update the public notification URL or Teams target config
- run
mibyan teams-pipeline validate - renew or recreate affected subscriptions
- confirm new events land in the expected sink
Failure Triage
No jobs are being created
Check:msgraph_webhookis enabled- the public notification URL points to
/msgraph/webhook - the client state in the subscription matches
MSGRAPH_WEBHOOK_CLIENT_STATE - subscriptions still exist remotely and are not expired
Jobs stay in retry or fail before summarization
Check:- transcript permissions and availability
- recording permissions and artifact availability
ffmpegavailability if recording fallback is enabled- Graph token health
Summaries are produced but not delivered to Teams
Check:platforms.teams.enabled: truedelivery_modeincoming_webhook_urlfor webhook modechat_idorteam_idpluschannel_idfor Graph mode- Teams auth config if Graph posting is used
Duplicate or unexpected replays
Check:- whether you manually replayed a job with
mibyan teams-pipeline run - whether the sink record already exists for that meeting
- whether you intentionally enabled a resend path in your local config
Go-Live Checklist
- Graph credentials are present and correct
-
msgraph_webhookis enabled and reachable from the public internet -
MSGRAPH_WEBHOOK_CLIENT_STATEis set and matches subscriptions - transcript subscription is created
- recording subscription is created if STT fallback is required
-
ffmpegis installed if recording fallback is enabled - Teams outbound delivery target is configured and verified
- Notion and Linear sinks are configured only if actually needed
-
mibyan teams-pipeline validatereturns an OK snapshot -
mibyan teams-pipeline token-health --force-refreshsucceeds -
maintain-subscriptionsis scheduled (Mibyan cron, systemd timer, or crontab — see Automating subscription renewal). Without this, Graph subscriptions silently expire within 72 hours. - a real end-to-end meeting event has produced a stored job
- at least one summary has reached the intended delivery sink

