{"description":"Run on an existing personnel item using signed engagement, screening references and an approved role profile. Produce an Onboarding Readiness Package with IT access evidence for HR, the manager and subsequent access reviews.","edges":[{"id":"e-initiate-provision","source":"initiate","target":"provision"},{"id":"e-provision-training","source":"provision","target":"training"}],"isPublic":true,"itemTypeSlug":"personnel","metadata":{"capabilities":["employee-onboarding","access-provisioning"],"controlVerbs":{},"controls":["UC-HR-01","UC-HR-06","UC-ACCESS-01","UC-ACCESS-09"],"department":"hr","domains":["controls"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=controls-employee-onboarding","contentDigest":"sha256:ecd83603cb9d5ba1cf47ac8c3d5a980d850a4edfec45dd1bb52098ba3cfeda98","prerequisites":{"anchorItemType":{"slug":"personnel"},"evidenceDestinations":[{"description":"Markdown findings, source references, decisions, unresolved items and owners on each Step.result.","id":"step-results"},{"description":"Restricted Onboarding Readiness Package and redacted system evidence attached to the relevant steps; raw HR documents stay in the authorized HR source.","id":"step-documents"},{"description":"Named human approvers; resolve role membership and separation before execution. The catalog cannot assign tenant users.","id":"native-approvals"}],"fields":[{"itemTypeSlug":"personnel","key":"personnel_key","type":"TEXT"},{"itemTypeSlug":"personnel","key":"full_name","type":"TEXT"},{"itemTypeSlug":"personnel","key":"work_email","type":"TEXT"},{"itemTypeSlug":"personnel","key":"department","type":"TEXT"},{"itemTypeSlug":"personnel","key":"position_title","type":"TEXT"},{"itemTypeSlug":"personnel","key":"manager_personnel_key","type":"TEXT"},{"itemTypeSlug":"personnel","key":"engagement_status","type":"SELECT"},{"itemTypeSlug":"personnel","key":"engagement_start_date","type":"DATE"},{"itemTypeSlug":"personnel","key":"systems_scope","type":"TEXTAREA"},{"itemTypeSlug":"personnel","key":"verification_gaps","type":"TEXTAREA"},{"itemTypeSlug":"personnel","key":"source_record_url","type":"TEXT"}],"handoffs":[{"direction":"input","name":"Signed engagement, approved role and screening references","roleId":"hr-lead","sourceTemplateId":"workflow-library:hr-recruiting"},{"direction":"output","name":"Approved minimum-facts access request with effective time","roleId":"it-operator"},{"direction":"output","name":"Onboarding Readiness Package","roleId":"line-manager"}],"roles":[{"contribution":"approval","description":"HR owns eligibility, restricted records and engagement-state updates.","id":"hr-lead","nodeIds":["initiate","training"]},{"contribution":"expertise","description":"Manager authorizes the role and assesses readiness.","id":"line-manager","nodeIds":["initiate","training"]},{"contribution":"approval","description":"System entitlement authority distinct from requester and operator.","id":"access-owner","nodeIds":["initiate"]},{"contribution":"expertise","description":"IT has administrative permission and evidences actual grants.","id":"it-operator","nodeIds":["provision"]}],"status":"declared","systems":[{"capabilities":["schema-read","item-read","item-update","step-result-write","step-document-attach","native-step-approval"],"id":"canvas"},{"capabilities":["restricted-personnel-read","training-assign","training-completion-read"],"id":"hr-source"},{"capabilities":["account-inventory-read","access-grant","mfa-configure","entitlement-evidence-export"],"id":"identity-and-business-systems"}]},"provenance":[{"source":"company-hiring-loop:portable-procedure"},{"source":"studio-itgc:personnel-onboarding-procedure"}],"releaseId":"sha256:ecd83603cb9d5ba1cf47ac8c3d5a980d850a4edfec45dd1bb52098ba3cfeda98","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-employee-onboarding"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-employee-onboarding","source":"coworkcanvas-gallery","standards":["iso-27001","nist-800-53","soc2"],"teams":["hr","it"]},"name":"Employee Onboarding","nodes":[{"data":{"controls":["UC-HR-01","UC-HR-06","UC-ACCESS-01"],"description":"HR lead, line manager and access owner: approval.","instructions":"**Objective** — Authorize the joiner and the minimum access needed for the approved job.\n\n**Inputs** — The existing Personnel record; restricted HR source referenced by personnel.source_record_url; signed offer or engagement agreement, screening outcome and consent references; approved role profile, entitlement catalogue and conflict matrix supplied by the manager and access owner.\n\n**Procedure**\n1. Resolve the declared fields, named approvers and restricted evidence destinations before execution. Read personnel.personnel_key, full_name, work_email, department, position_title, manager_personnel_key, engagement_start_date, engagement_status and systems_scope. Match the person to the HR source; resolve duplicate names and rehire accounts by identifier.\n2. HR reviews the signed agreement, applicable screening consent and outcome, and pre-start conditions. Keep screening reports and personal details in their restricted source. If evidence is missing, record the specific gap and owner; do not infer clearance or create a duplicate person.\n3. The line manager approves the job, reporting line, training needs, equipment and proposed entitlements. The access owner approves each system entitlement, effective date and any expiry after testing the combined set for segregation-of-duties conflicts. Block unresolved conflicts; any authorized exception must have its granting authority, expiry and compensating measures in restricted evidence.\n4. Prepare the HR-to-IT handoff with personnel key, work identity, approved systems and entitlements, effective date/time and timezone, manager, approval references and conditions. Exclude compensation, screening details and unrelated personal data. HR, manager and access owner approve this package through native approvals before IT acts.\n\n**Record in AssureSwarm** — Update verified personnel.department, position_title, manager_personnel_key, engagement_start_date, systems_scope and verification_gaps. Attach the approved minimum-facts access request and restricted source-reference index. Write the executor narrative as a markdown string in Step.result; attach supporting files as step documents. Record human sign-off through native step approvals.\n\n**Exit criteria** — Three distinct authorized approvers cover HR eligibility, the manager request and system entitlement authority; unresolved pre-start or access conditions block provisioning.","kind":"task","label":"Initiate Onboarding Request","requiredApprovals":3,"roleIntegrity":{"decisionOwner":"HR lead, line manager and access owner","ermPhase":"manage","independenceRequired":false,"lineRole":"first","serviceMode":"operational"}},"id":"initiate"},{"data":{"controls":["UC-ACCESS-01","UC-ACCESS-09"],"description":"IT access operator: expertise.","instructions":"**Objective** — Apply the approved access request and reconcile the resulting entitlements.\n\n**Inputs** — The approved initiate handoff, system-specific administrative permission, role catalogue, identity directory and account inventories.\n\n**Procedure**\n1. Confirm the operator has permission to execute each requested action and that the approved effective time has arrived. A AssureSwarm approval does not grant system administration rights. If tooling or authorization is absent, hold the affected action with an owner.\n2. Provision only approved accounts and entitlements, configure required MFA and review default and inherited access. Use named administrative accounts and never put credentials, tokens or secret values in AssureSwarm.\n3. Re-extract the granted entitlement set and reconcile it line by line to the approved request. Capture system, account reference, entitlement, actual execution time, actor and system evidence for every grant; record failures, extra privileges and missing grants.\n4. The IT operator applies specialist judgment to the reconciliation and resolves or escalates deviations. Provide the dated access-completion package to HR and the manager. HR cannot self-assert that access changed.\n\n**Record in AssureSwarm** — Attach the access-completion package and redacted extracts; record actual grants, MFA evidence, deviations and remediation owners. Do not set an access-complete field on Personnel; none is declared. Write the executor narrative as a markdown string in Step.result; attach supporting files as step documents. Record human sign-off through native step approvals.\n\n**Exit criteria** — IT evidence covers each approved system and proves actual state; incomplete or unauthorized changes remain open and cannot be described as complete.","kind":"task","label":"Provision System Access","requiredApprovals":1,"roleIntegrity":{"decisionOwner":"IT access operator","ermPhase":"manage","independenceRequired":false,"lineRole":"first","serviceMode":"operational"}},"id":"provision"},{"data":{"controls":["UC-HR-06"],"description":"HR lead and line manager: expertise.","instructions":"**Objective** — Decide whether the person is ready to perform the approved role and resolve remaining onboarding conditions.\n\n**Inputs** — Approved role and training requirements from initiate, IT completion evidence from provision, equipment receipts, learning-system completion records and restricted agreement references.\n\n**Procedure**\n1. Assign and track required security awareness and job training through the authorized HR or learning operator. Reuse existing completion evidence. Any missing acknowledgement or agreement from the employee is requested through an authorized channel and retained in the restricted source; no default questionnaire is needed.\n2. The manager assesses role readiness using completed training, equipment delivery and the evidenced access set. HR evaluates any unresolved screening, agreement, training or access conditions against the applicable onboarding policy. Hold readiness when a required condition fails; return deviations to the responsible owner and re-review changed evidence.\n3. HR records engagement_status as active only when the effective start date is reached and the approved conditions are satisfied. A future start remains planned. Record gaps with owners and due dates, attach the Onboarding Readiness Package, and retain its reference for the manager and future access review.\n\n**Record in AssureSwarm** — Update personnel.engagement_status, engagement_start_date and verification_gaps from verified evidence. Attach the Onboarding Readiness Package with training and equipment evidence references and the IT package index. Write the executor narrative as a markdown string in Step.result; attach supporting files as step documents. Record human sign-off through native step approvals.\n\n**Exit criteria** — HR and the manager approve role readiness based on source evidence; any approved temporary limitation states its authority, owner and deadline. An incomplete access action remains visible.","kind":"task","label":"Security Awareness Training","requiredApprovals":2,"roleIntegrity":{"decisionOwner":"HR lead and line manager","ermPhase":"manage","independenceRequired":false,"lineRole":"first","serviceMode":"operational"}},"id":"training"}],"sourceTemplateId":"workflow-library:controls-employee-onboarding"}
