{"description":"Standing monthly operator desk for endpoint, media, and information-handling custody. The workflow instance is the monthly operating cycle attached to the EXISTING Control item for this custody control (control_id UC-ASSET-04/06/08 and UC-NET-12, Control.frequency monthly, Control.framework spanning nist-800-53, iso-27001, soc2, pci-dss) — each cycle enriches that standing Control rather than creating a new one. In scope: fleet endpoint safeguard and acceptable-use verification, off-premises and external-system use, port/I/O/sensor and collaboration-device restriction, removable-media authorization/custody/sanitization/destruction, and the information-transfer rulebook and agreements across electronic, physical-courier, and verbal channels. Out of scope: identity/access provisioning and network-perimeter engineering, which run under their own controls. No upstream workflow feeds this desk — the prior cycle's close-and-archive export is the carry-forward input that seeds each run (the fleet inventory, media custody register, and transfer rulebook are its own standing inputs). Named deliverables: the fleet-safeguard exception list, the endpoint-posture and custody-cycle disposition decisions, the removable-media authorization log and custody register, sanitization verification evidence and retained destruction certificates, the transfer-rule status, and two corrective-action registers backed by Issue items. Endpoint, media, and transfer streams run in parallel and reconverge at two decision checkpoints that route exceptions to tracked corrective action; terminal by design — it hands off to nothing but its own next monthly cycle.","edges":[{"id":"e-classify-endpoint-and-network-posture-log-endpoint-corrective-actions","label":"Remediation","source":"classify-endpoint-and-network-posture","target":"log-endpoint-corrective-actions","whenValue":"remediation_required"},{"id":"e-classify-endpoint-and-network-posture-classify-custody-cycle-and-log-gaps","label":"Acceptable","source":"classify-endpoint-and-network-posture","target":"classify-custody-cycle-and-log-gaps","whenValue":"posture_acceptable"},{"id":"e-log-endpoint-corrective-actions-classify-custody-cycle-and-log-gaps","source":"log-endpoint-corrective-actions","target":"classify-custody-cycle-and-log-gaps"},{"id":"e-classify-custody-cycle-and-log-gaps-log-custody-corrective-actions","label":"Gaps","source":"classify-custody-cycle-and-log-gaps","target":"log-custody-corrective-actions","whenValue":"gaps_identified"},{"id":"e-classify-custody-cycle-and-log-gaps-close-and-archive","label":"Healthy","source":"classify-custody-cycle-and-log-gaps","target":"close-and-archive","whenValue":"healthy"},{"id":"e-log-custody-corrective-actions-close-and-archive","source":"log-custody-corrective-actions","target":"close-and-archive"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-ASSET-04","UC-ASSET-06","UC-ASSET-08","UC-NET-12"],"department":"it","domains":["controls"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=controls-endpoint-media-information-handling-custody","contentDigest":"sha256:6760c558247bda73e71ef40ac389982bfefd5310b84ef599ffff4896bbdac37f","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:6760c558247bda73e71ef40ac389982bfefd5310b84ef599ffff4896bbdac37f","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-endpoint-media-information-handling-custody"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-endpoint-media-information-handling-custody","source":"coworkcanvas-gallery","standards":["nist-800-53","iso-27001","soc2","pci-dss"],"teams":["it"]},"name":"Endpoint, Media & Information Handling Custody","nodes":[{"data":{"decisionField":"endpoint_posture","description":"Judge fleet safeguards, current policy acknowledgments, remote device and connection restrictions, and port and sensor exceptions to decide endpoint posture.","formData":{"fields":[{"key":"endpoint_posture","label":"Endpoint Posture","options":[{"label":"Acceptable, within tolerance","value":"posture_acceptable"},{"label":"Remediation required","value":"remediation_required"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Judge fleet safeguards, current policy acknowledgments, remote device and connection restrictions, and port and sensor exceptions to decide endpoint posture.\n\n**Inputs**\n- Central-management / MDM console: encryption status, screen-lock / auto-lock configuration, and enrollment state, per device — an external system with no native Asset/Endpoint item type, so its per-device pull is saved as a document extract on this step.\n- The current personnel roster (external HRIS) and the acceptable-use **Policy item** (policy_type: policy, with policy_owner, version, next_review_date), plus its acknowledgment log.\n- The anchor **Control item** and its sibling controls in the library define the in-scope fleet and baseline — Control.control_id, Control.framework (NIST 800-53 AC-19 device access control, IA-5 authenticator/lock posture; ISO 27001 A.8.1 user endpoint devices; SOC 2 CC6.5), and Control.family. These are the workflow's own initial inputs — this desk has no upstream workflow; the prior cycle's archived record carries state forward.\n- The reviewed fleet-safeguard and acceptable-use exception list from the upstream endpoint-safeguards step (encryption, screen lock, central-management enrollment, outstanding acknowledgments).\n- Asset-management system: devices checked out or flagged as used off premises, with the protective controls recorded for each (encryption at rest, remote-wipe/tracking, observation guidance) — no native Asset item type, so the pull is saved as a document extract on this step.\n- The register of external-system connection requests and active connections, each with its recorded terms-and-conditions agreement and any portable-storage restriction — the agreements have no native item type, so they stay attached documents.\n- Endpoint configuration baseline and central-management policy: port, I/O device (USB, Bluetooth, external-storage interfaces), and sensor restriction settings across the in-scope fleet, plus the remote-activation configuration for cameras, microphones, and shared whiteboards.\n- The documented usage-restriction baseline and the register of authorized business justifications (attached documents).\n- Control baseline via the anchor **Control item** (Control.framework: NIST 800-53 AC-20 use of external systems, MP-7 media use, SC-41 port and I/O device access, SC-42 sensor capability, SC-15 collaborative computing devices; ISO 27001 A.7.9 security of assets off-premises, A.8.1 user endpoint devices). These are the workflow's own initial inputs — no upstream workflow feeds this desk.\n\n**Procedure**\n_This checkpoint absorbs “Verify endpoint safeguards and acceptable use”. The agent runs the preparation, evidence assembly and record updates below; the named owners retain the substantive decisions and approvals stated in the procedure._\n1. Verify endpoint safeguards and acceptable use: Query the central-management console for encryption (full-disk on), screen-lock/auto-lock (timeout at or below the org standard, typically 15 minutes), and enrollment state across the in-scope fleet. Flag any device unencrypted, without an enforced lock, or unmanaged/unenrolled.\n2. Reconcile the managed-device list against the authoritative asset inventory to surface endpoints that exist but never enrolled (shadow devices) — these are exceptions even when otherwise clean, because they are unverifiable.\n3. Pull the acceptable-use acknowledgment log and cross-reference it against the current roster; list anyone who has not acknowledged the current policy version (new hires, role changes, or a re-issued policy).\n4. Use the existing acknowledgment channel, request only missing current-policy acknowledgments from outstanding personnel, and record completions as they arrive.\n5. Compile two artifacts: the fleet-safeguard exception list (device, deviation, proposed owner) and the outstanding-acknowledgment list (person, manager).\n6. Classify endpoint and off-site posture: Query the asset system for devices currently off premises; for each, confirm the recorded protection (encryption at rest, remote-wipe/tracking, screen-privacy or observation guidance). Flag any off-premises asset lacking a recorded protection.\n7. Pull the external-system connection register; match each connection to a current terms-and-conditions agreement consistent with the trust relationship. Flag any connection with no agreement or an expired one.\n8. Confirm portable-storage restrictions on external systems are enforced (for example, no organizational data written to unmanaged removable storage) and flag deviations.\n9. Compile the off-premises and external-system status summary (asset or connection, protection or agreement status, flag).\n10. Query the configuration baseline for port, I/O, and sensor restriction across the fleet; identify any device deviating from the documented usage-restriction baseline (for example, USB mass-storage enabled where policy blocks it).\n11. Pull the remote-activation configuration for collaborative devices; confirm remote activation is disabled by default or requires explicit authorization, AND presents a visible in-use indication when enabled.\n12. Cross-reference each restriction exception against a documented, authorized business justification; flag any exception lacking one.\n13. Compile the port/IO/sensor and collaboration-device compliance summary (device, setting, deviation, justification present Y/N).\n14. Consolidate all three checks — fleet safeguards and acceptable use, off-premises and external-system use, port/IO/sensor and collaboration devices — into one exception register, each entry carrying an owner and a date so nothing rests on memory.\n15. The control owner reads the consolidated register against the criteria below and submits the branch.\n\n**Decision criteria**\n- `posture_acceptable` — every safeguard, off-premises, external-system, and port/IO/sensor finding is within tolerance or already remediated: no unencrypted or unmanaged device, no off-premises asset without a recorded protection, no undocumented external connection, no unauthorized remote-activation capability, no unjustified restriction exception, and acknowledgments complete or only trivially outstanding.\n- `remediation_required` — any open exception remains: an unmanaged or unencrypted device, an external-system connection without a current terms agreement, an unauthorized remote-activation capability, an unjustified port/IO/sensor exception, or a material block of outstanding acknowledgments.\n\n**Record in AssureSwarm**\n- Pull the console export and the roster/acknowledgment log with coach-query-data; save the per-device evidence extract as a CSV/XLSX **document on this step** — no native Asset/Endpoint item type, so the attached extract is the AssureSwarm copy of fleet posture.\n- Request only missing acceptable-use acknowledgments from outstanding personnel through the existing acknowledgment channel; record completions in the acknowledgment log.\n- Attach the fleet-safeguard exception list and the outstanding-acknowledgment list as XLSX **documents on this step** (coach-document-upload).\n- Pull the off-premises asset register, the external-system connection register, the port/I/O/sensor configuration baseline, and the collaborative-device remote-activation settings with coach-query-data; save each as a **document on this step**.\n- Attach the off-premises and external-system status summary and the port/IO/sensor and collaboration-device compliance summary as **documents on this step** (coach-document-upload).\n- Promote each flagged off-premises asset, unagreed external connection, or unjustified restriction exception to an **Issue item** (item create) — issue_type: exception, source: self_assessment, issue_owner, identified_date — linked to the anchor **Control item** (items link: Issue ↔ Control).\n- Consolidate the three checks' exception Issues into one exception register with coach-query-data and attach it as a **document on this step** — a snapshot of the Issue items already linked to the anchor Control, not a separate store; build a posture **Dashboard** (coach-dashboard-create) showing exception counts by category against the prior-cycle trend.\n- Submit the `endpoint_posture` SELECT on this **step form** — the step result carries the driving evidence and the step's approver record names the decision owner or approver.\n\n**Exit criteria**\n- Both lists attached and complete; every non-compliant device and unacknowledged person named with a remediation owner; no in-scope device left unqueried.\n- Every off-premises asset and external connection assessed, and every in-scope device assessed for port/IO/sensor restriction and collaborative-device remote activation; each flagged exception is either justified or raised as an owned Issue item; both status summaries, the consolidated exception register, and the posture dashboard are attached; the `endpoint_posture` form is submitted with rationale and owner and the unused branch is prunable.","kind":"decision","label":"Classify endpoint and off-site posture","performedBy":{"primitives":["coach-query-data","coach-form-create","coach-document-upload","coach-dashboard-create","coach-item-create","coach-items-link"]}},"id":"classify-endpoint-and-network-posture"},{"data":{"description":"Agent converts each open endpoint, off-site, external-system, or port exception into an owned corrective action; human confirms every exception is owned and dated","instructions":"**Objective** — Convert every exception carried on the `remediation_required` branch of the endpoint-posture review into an owned, dated corrective action so no unmanaged device, undocumented connection, or unauthorized activation capability is left unaddressed.\n\n**Inputs**\n- The endpoint posture summary and consolidated exception register from the posture decision (its reviewed output), each exception tagged with its category and root cause.\n\n**Procedure**\n1. Parse the posture summary and list each exception with its category (fleet safeguard, acknowledgment, off-premises protection, external-system terms, port/IO/sensor) and root cause.\n2. Create a corrective-action item for each exception capturing owner, due date, and interim mitigation, and link it to the driving finding.\n3. Escalate high-risk exceptions immediately rather than waiting for the standard due date — for example an unauthorized remote-activation capability, or an undocumented external connection carrying organizational data.\n4. Compile the corrective-action register.\n\n**Record in AssureSwarm**\n- Create one **Issue item** per corrective action (item create) — issue_type: deficiency (or exception), severity, issue_owner, identified_date, target_remediation_date, with the interim mitigation in remediation_plan.\n- Link each corrective-action Issue to the anchor **Control item** and to its driving-finding Issue (items link: Issue ↔ Control, Issue ↔ Issue).\n- Attach the corrective-action register as a **document on this step** (coach-document-upload) — a snapshot of those Issues, not a separate store.\n\n**Exit criteria** — Every endpoint exception has a named owner and due date; high-risk items are escalated; corrective-action register attached.","label":"Log endpoint corrective actions","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-document-upload"]}},"id":"log-endpoint-corrective-actions"},{"data":{"decisionField":"custody_cycle_disposition","description":"Authorize policy-compliant media use and verified disposition, then judge media custody and transfer safeguards together with endpoint findings.","formData":{"fields":[{"key":"custody_cycle_disposition","label":"Custody Cycle Disposition","options":[{"label":"Healthy, within tolerance","value":"healthy"},{"label":"Gaps identified","value":"gaps_identified"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Authorize policy-compliant media use and verified disposition, then judge media custody and transfer safeguards together with endpoint findings.\n\n**Inputs**\n- The media-request queue and the approved-personnel / approved-media-type list (external / documents on this step).\n- The data-classification scheme — a **Policy item** (policy_type: standard, policy_owner, next_review_date) — and its physical-security requirement per tier (locked storage, restricted area).\n- The current media custody register, carried forward as a **document** from the prior cycle's close-and-archive export (this desk's own artifact — no upstream workflow).\n- Control baseline via the anchor **Control item** (Control.framework: NIST 800-53 MP-2 media access, MP-4 media storage, MP-5 media transport; ISO 27001 A.7.10 storage media). These are the workflow's own initial inputs — no upstream workflow feeds this step.\n- The custody register reviewed during the authorize-and-track activities in this checkpoint (the **document** record): media reaching end-of-life, scheduled for reuse, or flagged for disposal this cycle, each with its classification.\n- Approved sanitization/destruction techniques per classification — the sanitization **Policy item** (policy_type: standard) referencing NIST 800-88 clear/purge/destroy; anchor **Control item** (Control.framework: NIST 800-53 MP-6 media sanitization; ISO 27001 A.7.14 secure disposal or re-use of equipment).\n- The information-transfer rulebook — a **Policy item** (policy_type: procedure, policy_owner, next_review_date, review_frequency) covering electronic-transfer encryption requirements, approved tracked-courier services for physical media in transit, and verbal-disclosure handling guidance — carried forward from the prior cycle's archive.\n- The log of information transfers made this cycle (electronic, physical, verbal) — an external-system extract attached as a **document on this step** — each with its classification.\n- The register of external transfer agreements — attached **documents** (no native Agreement item type; the honest fallback is a step document).\n- The resolved endpoint posture and its corrective-action register from the separate endpoint branch, plus the media sanitization/destruction verification evidence and retained certificates produced within this checkpoint.\n- Control baseline via the anchor **Control item** (Control.framework: NIST 800-53 AC-4 information flow, SC-8 transmission confidentiality/integrity; ISO 27001 A.5.14 information transfer). These are the workflow's own initial inputs — no upstream workflow feeds this desk.\n\n**Procedure**\n_This checkpoint absorbs “Authorize and track removable media”, “Execute media sanitization and destruction”. The agent runs the preparation, evidence assembly and record updates below; the named owners retain the substantive decisions and approvals stated in the procedure._\n1. Authorize and track removable media: Query the media-request queue and match each pending request against the approved-personnel and approved-media-type list; reject or hold any request from an unapproved person or for an unapproved media type.\n2. Create a media-custody record for each authorized item capturing media type, classification, assigned custodian, and storage location, and link it to the requestor.\n3. Verify recorded storage meets the physical-security requirement for the classification held (for example, encrypted plus locked cabinet for confidential media; restricted-area storage for the highest tier); flag any mismatch.\n4. Confirm movement is tracked — each custody record shows current holder and location — and refresh any stale record.\n5. Compile the authorization log, the custody register, and any storage mismatches.\n6. Execute media sanitization and destruction: Query the custody register for media at end-of-life, scheduled for reuse, or flagged for disposal; determine the approved technique per item from its classification (sanitize/purge for reuse; physical destruction for disposal of high-classification media).\n7. Create a disposition record for each item capturing technique, performing party, and scheduled date, and link it to the custody record.\n8. Capture verification evidence that data can no longer be read or recovered for each sanitized item, and a destruction certificate for each destroyed item.\n9. Update each custody record to closed ONLY once verification evidence or a destruction certificate is on file — never before — and compile the retained-records register.\n10. Classify custody cycle: Query the transfer-rule register and flag any rule past its review date across the three channels (electronic encryption, tracked-courier list, verbal-disclosure handling).\n11. Pull this cycle's transfer log and match each transfer against its classification and the required safeguard — encryption in transit for electronic, tracked courier with chain-of-custody for physical media, recipient-identity verification for verbal disclosure.\n12. Verify every external recipient of transferred information is bound by a current transfer agreement; flag any transfer lacking a matching agreement or safeguard so it is tracked, not remembered.\n13. Compile the transfer-rule status and the transfer exception list.\n14. Compute the cycle metrics across all three streams: outstanding endpoint, off-site, and port exception Issues; media disposed without verification evidence or a destruction certificate; transfers lacking a matching safeguard or agreement — each against its threshold and the prior-cycle trend.\n15. The control owner reads the cycle metrics and the remaining-breach list against the criteria below and submits the branch.\n\n**Decision criteria**\n- `healthy` — every metric is within tolerance: no outstanding endpoint, off-site, or port exception; every disposed media item has verification evidence or a destruction certificate; the transfer rulebook is current and every transfer this cycle carried a matching safeguard and agreement.\n- `gaps_identified` — any unresolved endpoint exception, any media disposition without verification evidence or a certificate, any stale transfer rule, or any transfer lacking a required safeguard or agreement remains open.\n\n**Record in AssureSwarm**\n- Pull the media-request queue and the approved-personnel/media-type lists with coach-query-data; save them as **documents on this step**.\n- Record each authorized item as a row in the **custody-register document** on this step — there is no native Media/Asset item type, so per-media custody records live in the register document rather than as trackable items (honest fallback; captures media type, classification, custodian, storage location, requestor).\n- Promote each storage mismatch to an **Issue item** (item create) — issue_type: exception, source: self_assessment, issue_owner — linked to the anchor **Control item** (items link: Issue ↔ Control).\n- Attach the authorization log and the current custody register as **documents on this step** (coach-document-upload).\n- Query the custody register (the custody-register document assembled in this checkpoint) with coach-query-data.\n- Record each disposition as a row in the **disposition / retained-records document** on this step — no native Media type, so disposition records live in the register document, not as items (technique, performing party, scheduled date, linked custody row).\n- Attach verification evidence and destruction certificates (PDF) as **documents on this step**; vendor-issued certificates arrive as an **upload (PBC/external)** on the same step (coach-document-upload). Compile the retained-records register as a **document on this step**.\n- Raise an **Issue item** (item create) — issue_type: exception, source: self_assessment, issue_owner — linked to the anchor **Control item** (items link) for any item whose data cannot be verified unrecoverable; close a custody row ONLY once its verification evidence or destruction certificate is on file — never before.\n- Pull the transfer rulebook (its **Policy item** plus the attached rulebook document) and this cycle's transfer log with coach-query-data.\n- Promote each unsafeguarded or unagreed transfer to an **Issue item** (item create) — issue_type: exception, source: self_assessment, issue_owner — linked to the anchor **Control item** (items link: Issue ↔ Control).\n- Attach the transfer-rule status and the transfer exception list as **documents on this step** (coach-document-upload).\n- Compute the cycle metrics with coach-query-data and build a custody-cycle **Dashboard** (coach-dashboard-create) showing each metric against its threshold and the trend against prior cycles; attach the cycle summary as a **document on this step** listing every remaining breach with its owner and evidence.\n- Submit the `custody_cycle_disposition` SELECT on this **step form** — the step result carries the evidence and the step's approver record names the decision owner or approver.\n\n**Exit criteria**\n- Every authorized item matches an approved person and media type; storage meets classification requirements; custody register current; every mismatch flagged with an owner.\n- Verification evidence or a destruction certificate is on file for every disposed or reused item; no media released from control before its data was verified unrecoverable; retained-records register attached.\n- Transfer rulebook confirmed current (or stale rules flagged); this cycle's transfers assessed for classification-proportionate safeguards and every external recipient checked against a current agreement, with exceptions raised as owned Issue items; the transfer-rule status, exception list, metrics dashboard, and cycle summary are attached; the `custody_cycle_disposition` form is submitted with rationale and owner and the unused branch is prunable.","kind":"decision","label":"Classify custody cycle","performedBy":{"primitives":["coach-query-data","coach-item-create","coach-items-link","coach-document-upload","coach-dashboard-create"]}},"id":"classify-custody-cycle-and-log-gaps"},{"data":{"description":"Agent converts each remaining gap into an owned corrective action; human confirms every gap is owned, dated, and escalated where required","instructions":"**Objective** — Convert every gap carried on the `gaps_identified` branch of the custody-cycle review into an owned, dated corrective action so nothing degrades endpoint, media, or transfer custody unaddressed.\n\n**Inputs**\n- The cycle summary from the custody-cycle decision (its reviewed output), each gap tagged with its root cause and the metric or item that surfaced it.\n\n**Procedure**\n1. Parse the cycle summary and list each gap with its root cause and the surfacing metric or record.\n2. Create a corrective-action item for each gap capturing root cause, owner, due date, and interim mitigation, and link it to the driving metric or record.\n3. Raise capability-level improvement items for systemic gaps — a chronically unmanaged device population, an understaffed media desk, a stale transfer-agreement template — and escalate any unresolved high-risk item to the accountable owner.\n4. Compile the corrective-action register.\n\n**Record in AssureSwarm**\n- Create one **Issue item** per gap (item create) — issue_type: deficiency (systemic capability items as issue_type: opportunity), root_cause, severity, issue_owner, target_remediation_date, with the interim mitigation in remediation_plan.\n- Link each Issue to the anchor **Control item** and to the driving metric or record (items link).\n- Attach the corrective-action register as a **document on this step** (coach-document-upload) — a snapshot of those Issues.\n\n**Exit criteria** — Every gap has a named owner and due date; escalations are routed; systemic improvement items are raised; nothing is left untracked before closure.","label":"Log custody corrective actions","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-document-upload"]}},"id":"log-custody-corrective-actions"},{"data":{"description":"Automatically archive the authorized cycle record and carry open actions into the next cycle.","instructions":"**Objective** — Automatically preserve the authorized cycle record and its carry-forward actions after the preceding decision.\n\n**Inputs**\n- The signed operating record for this cycle: the endpoint-posture and custody-cycle decisions, the corrective-action registers, the media authorization and disposition records, and the transfer-rule status.\n- The designated evidence repository and its retention controls, and the next scheduled monthly review date.\n\n**Procedure**\n1. Export the full operating record and archive it in the designated evidence repository under retention controls, recording the archive location and reference.\n2. Create carry-forward items for open corrective actions, pending media dispositions, and upcoming transfer-agreement reviews, and link each to its source so it arrives as an explicit input to the next cycle.\n3. Update the control execution log with the cycle result and key metrics, and confirm the next monthly review is scheduled.\n4. Attach the closure record.\n\n**Record in AssureSwarm**\n- Export the full operating record with coach-workflow-export — the archived **workflow instance** is the audit-trail copy — and attach the export as a **document on this step**.\n- Leave open corrective-action **Issue items** OPEN and linked to the anchor **Control item** so the next monthly instance picks them up; create carry-forward **Issue items** (item create) for pending media dispositions and upcoming transfer-agreement reviews and link each to its source (items link).\n- Attach the closure record as a **document on this step** (coach-document-upload), naming the archive location/reference and the next scheduled monthly review (Control.frequency: monthly).\n\n**Exit criteria** — The archived record is immutable and retrievable; the next review is scheduled; nothing remains open without a tracked owner; the authorized cycle record is complete.","label":"Close and archive","performedBy":{"primitives":["coach-workflow-export","coach-item-create","coach-items-link","coach-document-upload"]},"requiredApprovals":0},"id":"close-and-archive"}],"sourceTemplateId":"workflow-library:controls-endpoint-media-information-handling-custody"}
