{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:d2e485a453e0634692cb0eeb10d2b2baf6047d54c4c8148e28914b9b78f59cd9","slug":"grc-personnel-screening-agreements-sanctions-administration","url":"/assets/agent_workflow-grc-personnel-screening-agreements-sanctions-administration-57db5b14.08bf108da150a17f.json"},"kind":"record","record":{"attributes":{"department":"hr","domain":"grc","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=grc-personnel-screening-agreements-sanctions-administration","description":"Runs on the existing \"Personnel Security Administration\" Process item (process_type: security_process; process_owner: the HR Personnel Security Partner): each cycle is one workflow instance attached to that Process - enriching the standing process, never creating a duplicate - and on the disciplinary track the violation-case Issue it opens becomes the cycle's second anchor, linked back to that Process. A modular, decision-aware workflow: it designates position risk, runs proportional background verification for new hires, role changes, and the annual high-risk rescreen sweep, produces and retains the signed employment security and confidentiality agreements required before access, and - when a policy violation is reported - runs the graduated disciplinary process through sanction determination, PS-8 notification, and retention. It originates on its own HR triggers (no upstream workflow feeds it) and hands access provisioning and revocation to the downstream Joiner-Mover-Leaver Access Lifecycle workflow rather than performing them here. Named deliverables per cycle: the position-risk designation memo and derived screening set, the background-verification packet, the signed employment security and confidentiality agreements plus security-bearing position description, the violation-case Issue, the sanction documentation and PS-8 notification record, the awareness and control-improvement feedback Issues, and the archived cycle record. In scope: one personnel-security trigger per cycle - a single new hire, role change, annual high-risk rescreen, or material agreement re-signature on the screening-and-agreements track, or one reported policy violation on the disciplinary track; a role change that also surfaces a violation is run as two separate cycles.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=grc-personnel-screening-agreements-sanctions-administration","capabilities":[],"controls":["UC-HR-01","UC-HR-02","UC-HR-04"],"domains":["grc"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:d2e485a453e0634692cb0eeb10d2b2baf6047d54c4c8148e28914b9b78f59cd9","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:grc-personnel-screening-agreements-sanctions-administration","standards":["nist-800-53","iso-27001","hipaa"],"teams":["hr"]},"id":"wf:G25","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AG25","slug":"grc-personnel-screening-agreements-sanctions-administration","sourceIds":["hipaa","iso-27001","nist-800-53"],"sourceUrl":null,"title":"Personnel Screening, Agreements & Sanctions Administration","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:38805ad4453a6a209d92fc85fb3c05e329471ee52082ee2d100823409d2cebda","properties":{},"sourceDetailPath":"/data/v1/records/wf-g25-fdd65bfd.json","sourceId":"wf:G25","targetDetailPath":"/data/v1/records/uc-uc-hr-02-a54c8912.json","targetId":"uc:UC-HR-02","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e3b0736dbbee585a3efb5354435c34dbb8d89994a4fdfa7ee62bb70b1bfacb9d","properties":{},"sourceDetailPath":"/data/v1/records/wf-g25-fdd65bfd.json","sourceId":"wf:G25","targetDetailPath":"/data/v1/records/uc-uc-hr-04-a71cf995.json","targetId":"uc:UC-HR-04","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fdc9f7db49a3601597ca5792f50302eddf6ed6246561f19243008acaf093bcc9","properties":{},"sourceDetailPath":"/data/v1/records/wf-g25-fdd65bfd.json","sourceId":"wf:G25","targetDetailPath":"/data/v1/records/uc-uc-hr-01-c7e14dc5.json","targetId":"uc:UC-HR-01","type":"operates"}],"schemaVersion":1}
