{"description":"Run on an existing personnel item using an authorized departure record, access inventory and retention instructions. Produce the Employee Departure Package and hand remaining obligations to HR after IT removal evidence and manager handover review.","edges":[{"id":"e-initiate-revoke","source":"initiate","target":"revoke"},{"id":"e-initiate-transfer","source":"initiate","target":"transfer"},{"id":"e-revoke-signoff","source":"revoke","target":"signoff"},{"id":"e-transfer-signoff","source":"transfer","target":"signoff"}],"isPublic":true,"itemTypeSlug":"personnel","metadata":{"capabilities":["employee-offboarding","access-revocation"],"controlVerbs":{},"controls":["UC-HR-03","UC-ACCESS-01"],"department":"hr","domains":["controls"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=controls-employee-offboarding","contentDigest":"sha256:68d2f74392f49dc7f6fe33168ecb26fff8f603027c0745299ef3cb2c1ba77321","prerequisites":{"anchorItemType":{"slug":"personnel"},"evidenceDestinations":[{"description":"Markdown findings, source references, decisions, unresolved items and owners on each Step.result.","id":"step-results"},{"description":"Restricted departure package, redacted access logs and asset receipts on their steps; sensitive HR details remain in their authorized source.","id":"step-documents"},{"description":"Named human approvers; resolve role membership and separation before execution. The catalog cannot assign tenant users.","id":"native-approvals"}],"fields":[{"itemTypeSlug":"personnel","key":"personnel_key","type":"TEXT"},{"itemTypeSlug":"personnel","key":"full_name","type":"TEXT"},{"itemTypeSlug":"personnel","key":"work_email","type":"TEXT"},{"itemTypeSlug":"personnel","key":"manager_personnel_key","type":"TEXT"},{"itemTypeSlug":"personnel","key":"engagement_status","type":"SELECT"},{"itemTypeSlug":"personnel","key":"engagement_end_date","type":"DATE"},{"itemTypeSlug":"personnel","key":"systems_scope","type":"TEXTAREA"},{"itemTypeSlug":"personnel","key":"verification_gaps","type":"TEXTAREA"},{"itemTypeSlug":"personnel","key":"source_record_url","type":"TEXT"}],"handoffs":[{"direction":"input","name":"Authorized departure and retention instructions","roleId":"hr-lead"},{"direction":"output","name":"Minimum-facts revocation request with effective time","roleId":"it-operator"},{"direction":"output","name":"Employee Departure Package and residual obligations","roleId":"hr-lead"}],"roles":[{"contribution":"approval","description":"HR owns departure authority and employment obligations.","id":"hr-lead","nodeIds":["initiate","signoff"]},{"contribution":"expertise","description":"IT executes timed removal using authorized administrative access.","id":"it-operator","nodeIds":["revoke"]},{"contribution":"expertise","description":"Manager accepts work continuity and accounts for equipment.","id":"line-manager","nodeIds":["transfer"]}],"status":"declared","systems":[{"capabilities":["schema-read","item-read","item-update","step-result-write","step-document-attach","native-step-approval"],"id":"canvas"},{"capabilities":["restricted-personnel-read"],"id":"hr-source"},{"capabilities":["account-inventory-read","access-revoke","session-invalidate","shared-secret-rotate","entitlement-evidence-export"],"id":"identity-and-business-systems"},{"capabilities":["asset-assignment-read","asset-return-record"],"id":"asset-records"}]},"provenance":[{"source":"company-hiring-loop:portable-procedure"},{"source":"studio-itgc:personnel-offboarding-procedure"}],"releaseId":"sha256:68d2f74392f49dc7f6fe33168ecb26fff8f603027c0745299ef3cb2c1ba77321","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-employee-offboarding"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-employee-offboarding","source":"coworkcanvas-gallery","standards":["iso-27001","nist-800-53","soc2"],"teams":["hr","it"]},"name":"Employee Offboarding","nodes":[{"data":{"controls":["UC-HR-03"],"description":"HR lead: approval.","instructions":"**Objective** — Authorize the departure facts and timed removal request.\n\n**Inputs** — Existing Personnel item, authoritative termination or engagement-end record in the restricted HR source, retention instructions, systems_scope and current access inventory.\n\n**Procedure**\n1. Read personnel.personnel_key, full_name, work_email, manager_personnel_key, engagement_status, engagement_end_date, systems_scope and source_record_url. Match the worker to the HR authorization and resolve identity collisions before action.\n2. HR approves the effective date/time, timezone and removal window from the departure decision and applicable policy. Identify immediate-removal cases and evidence-preservation requirements. Do not let knowledge transfer delay a required revocation.\n3. Give IT only the personnel key, work identity, in-scope systems, removal time, authorization reference and applicable retention instructions. Give the manager the work-transfer and equipment scope. Keep reasons, compensation and sensitive departure details in restricted HR records. Verify each operator is authorized before any external action.\n\n**Record in AssureSwarm** — Update verified personnel.engagement_end_date, systems_scope and verification_gaps. Attach the approved minimum-facts departure handoff and the restricted authorization-reference index. Write the executor narrative as a markdown string in Step.result; attach supporting files as step documents. Record human sign-off through native step approvals.\n\n**Exit criteria** — HR authorization identifies the person, exact removal time and preservation constraints; IT and manager responsibilities are named.","kind":"task","label":"Initiate Offboarding","requiredApprovals":1,"roleIntegrity":{"decisionOwner":"HR lead","ermPhase":"manage","independenceRequired":false,"lineRole":"first","serviceMode":"operational"}},"id":"initiate"},{"data":{"controls":["UC-ACCESS-01","UC-HR-03"],"description":"IT access operator: expertise.","instructions":"**Objective** — Remove access within the approved window and prove the resulting state.\n\n**Inputs** — HR-approved initiate handoff, current identity and application inventories, administrative permission and preservation instructions.\n\n**Procedure**\n1. Reconcile the inventory to HR systems_scope and discover linked local, cloud, privileged, remote-access and non-SSO accounts. Record systems that cannot be inspected. Preserve evidence as authorized before destructive account cleanup; do not postpone suspension while arranging transfer.\n2. At the authorized time, suspend or remove accounts, groups and application access, invalidate sessions and tokens, recover authenticators and rotate shared secrets when exposure requires it. The IT operator must have system permission; preparation or a queued ticket does not establish removal.\n3. Capture actor, system, account, action, timestamp and timezone, source logs and post-removal checks. Attempt a permitted access-state verification without using the former worker’s credentials. Escalate residual sessions, orphan accounts or failed revocations to the responsible system owner immediately.\n4. IT reviews completeness and sends the Access Revocation Evidence Package to HR, retaining failures and actual late-removal times. HR cannot self-assert access removal.\n\n**Record in AssureSwarm** — Attach the Access Revocation Evidence Package with redacted logs and post-change extracts. Record unresolved removals, owners, deadlines and escalation references. Write the executor narrative as a markdown string in Step.result; attach supporting files as step documents. Record human sign-off through native step approvals.\n\n**Exit criteria** — Every in-scope account has dated removal evidence or an explicit unresolved failure; privileged and residual access receive specialist review.","kind":"task","label":"Revoke System Access","requiredApprovals":1,"roleIntegrity":{"decisionOwner":"IT access operator","ermPhase":"manage","independenceRequired":false,"lineRole":"first","serviceMode":"operational"}},"id":"revoke"},{"data":{"description":"Line manager: expertise.","instructions":"**Objective** — Accept transferred work and account for assigned equipment.\n\n**Inputs** — The approved initiate handoff, work inventory, asset issue receipts and authorized records-retention requirements.\n\n**Procedure**\n1. Identify open commitments and records requiring a successor. Assign a named owner for each and verify the successor can locate the required documentation through approved access.\n2. Reconcile issued equipment, badges and authenticators to returned assets and receipts. Coordinate required collection and transfers through authorized operators. Record each unreturned asset with an owner and recovery date.\n3. Assess continuity gaps and retention constraints with HR. Preserve restricted material and evidence holds. Do not transfer personal credentials or allow continued access to make handover convenient. File the manager’s acceptance, outstanding obligations and applicable confidentiality acknowledgement reference with the handover evidence.\n\n**Record in AssureSwarm** — Attach the Work and Asset Handover schedule with successor references, receipts and unresolved obligations. Store sensitive exit-interview notes only in the restricted HR source. Write the executor narrative as a markdown string in Step.result; attach supporting files as step documents. Record human sign-off through native step approvals.\n\n**Exit criteria** — The manager accepts continuity arrangements and asset accountability; unresolved obligations have responsible owners and deadlines.","kind":"task","label":"Knowledge Transfer & Handover","requiredApprovals":1,"roleIntegrity":{"decisionOwner":"Line manager","ermPhase":"manage","independenceRequired":false,"lineRole":"first","serviceMode":"operational"}},"id":"transfer"},{"data":{"controls":["UC-HR-03"],"description":"HR lead: approval.","instructions":"**Objective** — Decide whether the departure obligations permit closure and record the employment state.\n\n**Inputs** — IT-reviewed revoke evidence, manager-reviewed transfer package and original HR departure authorization.\n\n**Procedure**\n1. Reconcile actual access-removal times to the approved deadline, and equipment and work obligations to the manager’s handover. HR returns unsupported completion claims to IT or the manager; an unresolved access failure blocks completion and requires escalation.\n2. HR decides the disposition of remaining employment obligations under its authority. Obtain the relevant authority’s documented decision for obligations HR cannot accept; record owner and follow-up date for recoveries or retention duties that continue after departure.\n3. When the authoritative engagement has ended, update personnel.engagement_status to ended and retain the actual engagement_end_date. Employment end does not prove access removal: keep verification_gaps current even if the run remains incomplete. Attach the Employee Departure Package and index the remaining obligations for HR follow-up.\n\n**Record in AssureSwarm** — Update personnel.engagement_status, engagement_end_date and verification_gaps. Attach the Employee Departure Package with references to both reviewed packages and residual obligation decisions. Write the executor narrative as a markdown string in Step.result; attach supporting files as step documents. Record human sign-off through native step approvals.\n\n**Exit criteria** — HR approves closure only with evidenced access removal and resolved or authorized residual obligations; employment status and workflow completion are distinguished.","kind":"task","label":"Offboarding Completion Sign-off","requiredApprovals":1,"roleIntegrity":{"decisionOwner":"HR lead","ermPhase":"manage","independenceRequired":false,"lineRole":"first","serviceMode":"operational"}},"id":"signoff"}],"sourceTemplateId":"workflow-library:controls-employee-offboarding"}
