{"description":"Standing operator workflow for the monthly environmental and utility systems preventive-maintenance calendar — fire/water/environmental protection, emergency power and lighting, protected cabling, and electromagnetic shielding — producing the single maintenance-and-inspection log required as evidence. Anchor: each monthly cycle runs as a new workflow instance attached to the existing umbrella physical/environmental-maintenance Control item in the control library (control_category=physical, frequency=monthly, framework nist-800-53|iso-27001|nist-csf-2), with the specific UC-PHYS-03/05/06/07 Control items linked — the run enriches that Control's execution history, never creates a duplicate control. Consumes its inputs directly with no feeder workflow: the PM calendar entry, the fire/water/power/lighting/cabling/shielding asset inventories, and the independent maintenance vendor's service tickets and test records (the vendor is a Vendor item in the third-party register; its tickets attach as step evidence). The prior cycle's archived export and its still-open deficiency Issues (linked to the anchor Control) are the only carry-forward channel. In scope: the physical environmental and utility protection systems for the in-scope facilities and rooms (fire detection and suppression, water-damage detection and shutoff valves, temperature/humidity monitoring, UPS and generators, emergency lighting and power shutoffs, protected cabling and wiring closets, and electromagnetic shielding). Out of scope: logical access, network security, and the building's base construction. There is no downstream workflow: this standing cycle drains to its own retained archive and seeds next month's cycle with the corrective-action Issues left open.","edges":[{"id":"e-verify-environmental-monitoring-and-life-safety-status-escalate-life-safety-deficiency","label":"Deficiency","source":"verify-environmental-monitoring-and-life-safety-status","target":"escalate-life-safety-deficiency","whenValue":"deficiency_found"},{"id":"e-verify-environmental-monitoring-and-life-safety-status-classify-maintenance-cycle-disposition","label":"Operational","source":"verify-environmental-monitoring-and-life-safety-status","target":"classify-maintenance-cycle-disposition","whenValue":"operational"},{"id":"e-escalate-life-safety-deficiency-classify-maintenance-cycle-disposition","source":"escalate-life-safety-deficiency","target":"classify-maintenance-cycle-disposition"},{"id":"e-classify-maintenance-cycle-disposition-log-corrective-actions-and-escalate","label":"Deficiencies","source":"classify-maintenance-cycle-disposition","target":"log-corrective-actions-and-escalate","whenValue":"deficiencies_identified"},{"id":"e-classify-maintenance-cycle-disposition-close-and-archive","label":"Normal","source":"classify-maintenance-cycle-disposition","target":"close-and-archive","whenValue":"all_systems_normal"},{"id":"e-log-corrective-actions-and-escalate-close-and-archive","source":"log-corrective-actions-and-escalate","target":"close-and-archive"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-PHYS-03","UC-PHYS-05","UC-PHYS-06","UC-PHYS-07"],"department":"facilities","domains":["controls"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=controls-environmental-utility-systems-maintenance","contentDigest":"sha256:21904d7b642920d0441d7813b4bf123b80990fcbd1dcd9f0f17bdc6b0d556fa6","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:21904d7b642920d0441d7813b4bf123b80990fcbd1dcd9f0f17bdc6b0d556fa6","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-environmental-utility-systems-maintenance"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-environmental-utility-systems-maintenance","source":"coworkcanvas-gallery","standards":["nist-800-53","iso-27001","nist-csf-2"],"teams":["facilities","it"]},"name":"Environmental & Utility Systems Maintenance","nodes":[{"data":{"decisionField":"life_safety_status","description":"Judge vendor fire and water test records, valve accessibility, environmental calibration and automatic alarm delivery to determine life-safety status.","formData":{"fields":[{"key":"life_safety_status","label":"Life-Safety Systems Status","options":[{"label":"Operational, within tolerance","value":"operational"},{"label":"Deficiency found","value":"deficiency_found"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Judge vendor fire and water test records, valve accessibility, environmental calibration and automatic alarm delivery to determine life-safety status.\n\n**Inputs**\n- The preventive-maintenance (PM) calendar entry that opened this monthly cycle, with the in-scope facilities/rooms and named system owners it lists — uploaded as a calendar extract/PDF on this step (AssureSwarm has no native schedule item type; this standing workflow reads the PM calendar directly, with no upstream workflow feeding it).\n- The asset inventory for fire detection/suppression, water-detection sensors, and shutoff valves — uploaded as a CSV/XLSX extract on this step (AssureSwarm has no native Asset item type, so the inventory lives as a step document).\n- The independent maintenance vendor's service tickets and test records for this cycle — uploaded here as ticket/test-record evidence; the vendor itself is a Vendor item in the third-party register (Vendor — category facilities or managed_services, business_owner, monitoring_status).\n- The prior-cycle maintenance-and-inspection log (the prior instance's archived export document) and any still-open carryover corrective actions (open Issue items, issue_type=deficiency, linked to the anchor Control).\n- Control references: the linked UC-PHYS-03/05/06/07 Control items in the control library (Control.control_id, Control.framework nist-800-53|iso-27001, Control.domains=physical_environmental_security), covering NIST 800-53 PE-13 (fire protection), PE-15 (water-damage protection), plus the independent-energy-source requirement for the suppression system.\n\n**Procedure**\n_This checkpoint absorbs “Inspect fire and water detection systems”. The agent runs the preparation, evidence assembly and record updates below; the named owners retain the substantive decisions and approvals stated in the procedure._\n1. Inspect fire and water detection systems: Pull this cycle's fire detection and suppression test records from the independent maintenance vendor: detector function tests, suppression-agent pressure/weight checks, and confirmation the system runs on an energy source independent of the building's primary power.\n2. Pull the water-damage detection sensor test results and the master shutoff-valve list; for each valve confirm physical location, correct labeling, and unobstructed reach.\n3. Cross-check every test record against the PM calendar so no scheduled fire/water device was skipped this cycle; flag any overdue device as a finding.\n4. Record pass/fail per device with technician and date. Worked example: a wet-pipe zone whose detector passed but whose isolation valve is blocked by stacked equipment is a FAIL on accessibility even though the detector tested good.\n\n**Decision criteria**\n- `operational` — the fire/water round results all pass, temperature/humidity readings sit within documented setpoints with no unresolved excursion, and each fire/water/environmental alarm was confirmed to auto-notify responsible personnel without manual intervention.\n- `deficiency_found` — any life-safety system failed its test, an alarm did not auto-notify, a shutoff valve was inaccessible, or an environmental reading is outside required range (NIST CSF 2.0 PR.IR-02; ISO 27001 A.7.5).\n\nAgent evidence-gathering substeps (run before the human picks):\n1. Query the temperature and humidity monitoring and control system for this cycle's readings, calibration status, and any excursions outside required range; compare against the documented setpoints.\n2. Trigger a test activation or review the last automatic-notification event for each fire-suppression, water-detection, and environmental alarm; confirm the responsible personnel (facilities on-call, security operations) received the notification automatically, with no manual step.\n3. Consolidate the fire/water round results with the environmental status into a single life-safety status summary, compared against the prior-cycle baseline.\n\n**Record in AssureSwarm**\n- Attach the fire/water round results as an XLSX inspection-results workpaper on this step (coach-document-upload) — pass/fail, technician, and date per device — together with the vendor test records, service tickets, and the shutoff-valve accessibility checklist. AssureSwarm has no native maintenance-log item type, so this per-round record lives as a step document, not an item; only failed devices are promoted to Issue items downstream.\n- Pull the source test records and asset inventory with coach-query-data. When a device fails, raise the finding as an Issue in the escalation/corrective-action step and link it to its driving test record (coach-item-create, coach-items-link).\nSubmit the SELECT field `life_safety_status` (`operational` | `deficiency_found`). Record the decision rationale with evidence references in the step result and the decision owner/approver in the step's approver record. Attach the life-safety status summary (coach-document-upload); pull readings with coach-query-data.\n\n**Exit criteria**\n- Fire detection/suppression tested and independently maintained this cycle with an independent energy source confirmed; water-damage detection functioning; every shutoff valve accessible and labeled; all results in the log with tickets linked; no PM-calendar fire/water device left untested.\n- The form is submitted with rationale and owner recorded; the chosen branch's downstream is enabled and the unused branch is prunable.","kind":"decision","label":"Verify environmental monitoring and life-safety status","performedBy":{"primitives":["coach-query-data","coach-item-create","coach-items-link","coach-document-upload"]}},"id":"verify-environmental-monitoring-and-life-safety-status"},{"data":{"description":"Agent opens an urgent corrective action and notifies the maintenance vendor; human confirms interim mitigation before rounds continue","instructions":"**Objective** — Open an urgent corrective action with interim mitigation the moment a fire, water, or environmental life-safety system fails this cycle's check, so protection is restored before the disposition is judged.\n\n**Inputs**\n- The life-safety status summary and the `deficiency_found` decision from the life-safety checkpoint, naming the failed system and the specific finding.\n- The relevant test record for the failed device, alarm, or valve.\n- The independent maintenance vendor / emergency contact roster and the available interim-mitigation options.\n\n**Procedure**\n1. Create an urgent corrective-action item capturing the failed system, the specific finding (failed detector, non-auto-notifying alarm, inaccessible shutoff valve, or out-of-range environmental reading), and the required interim mitigation.\n2. Put interim mitigation in place immediately, matched to the failure: a manual fire watch, temporary or portable suppression, manual monitoring rounds, or compensating sensors.\n3. Notify the independent maintenance vendor or emergency contact to schedule urgent repair; record the vendor response and the committed repair date.\n4. Link the corrective action to the life-safety status summary and to the driving test record.\n\n**Record in AssureSwarm**\n- Create the urgent corrective action as an Issue item (coach-item-create) — issue_type=deficiency, severity=critical (or high), source=self_assessment, root_cause naming the failed system, remediation_plan capturing the interim mitigation and the vendor-committed repair date, issue_owner, identified_date, and target_remediation_date.\n- Link the Issue to the affected UC-PHYS Control and the anchor Control (coach-items-link — Issue ↔ Control) and to the driving test record so the finding traces to its evidence.\n- Attach the life-safety status summary and the vendor confirmation as step documents (coach-document-upload).\n\n**Exit criteria** — Interim mitigation confirmed in place, vendor repair scheduled with a committed date, and the deficiency tracked to closure; the cycle may proceed to disposition.","label":"Escalate life-safety deficiency","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-document-upload"]}},"id":"escalate-life-safety-deficiency"},{"data":{"decisionField":"maintenance_cycle_disposition","description":"Judge tested emergency-power capacity, lighting and shutoffs, protected cable routes, shielding and surge protection together with resolved life-safety results.","formData":{"fields":[{"key":"maintenance_cycle_disposition","label":"Maintenance Cycle Disposition","options":[{"label":"All systems normal","value":"all_systems_normal"},{"label":"Deficiencies identified","value":"deficiencies_identified"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Judge tested emergency-power capacity, lighting and shutoffs, protected cable routes, shielding and surge protection together with resolved life-safety results.\n\n**Inputs**\n- The PM calendar entry for this cycle and the emergency-power asset inventory (UPS units, generators, transfer switches) — uploaded as CSV/XLSX extracts on this step (AssureSwarm has no native schedule or Asset item type, so both live as step documents).\n- The maintenance vendor's UPS battery-health/runtime results and generator load-test results (transfer-switch exercise, fuel level, load-bank or building-load test) — uploaded here as test-record evidence; the vendor is a Vendor item in the third-party register.\n- The documented capacity requirement — the runtime and load the utility must sustain for orderly shutdown or continued operation of the critical systems it supports — uploaded as a reference document on this step.\n- Control references: the linked UC-PHYS-03/05/06/07 Control items in the control library (Control.control_id, Control.domains=physical_environmental_security), covering NIST 800-53 PE-11 (emergency power) and supporting utilities PE-9, PE-10, PE-12.\n- The PM calendar entry and the emergency-lighting fixture inventory keyed to evacuation routes, plus the facility diagram showing the emergency power-off (EPO) shutoff location — uploaded as CSV/XLSX and reference-document extracts on this step (no native schedule or Asset item type).\n- The emergency-lighting test log with per-fixture battery-replacement intervals — uploaded here as test-record evidence.\n- Control references: the linked UC-PHYS-03/05/06/07 Control items in the control library (Control.control_id, Control.domains=physical_environmental_security), covering NIST 800-53 PE-12 (emergency lighting) and PE-10 (emergency shutoff).\n- The PM calendar entry, the facility cabling diagram, and the wiring-closet/patch-panel access log since the last cycle — uploaded as reference-document and CSV/XLSX extracts on this step (no native schedule or Asset item type).\n- Approved change and maintenance tickets to reconcile against closet access — uploaded here as the ticket list.\n- Control references: the linked UC-PHYS-03/05/06/07 Control items in the control library (Control.control_id, Control.domains=physical_environmental_security), covering NIST 800-53 PE-4 (cabling access control) and PE-9 (power equipment and cabling).\n- The PM calendar entry and the facility's electromagnetic-protection design record (which rooms, racks, or components require shielding or separation because they handle sensitive information, and their designated placement) — uploaded as reference documents on this step.\n- The surge-protection device inventory with last fault-indicator test dates — uploaded as a CSV/XLSX extract on this step (no native Asset item type).\n- Control references: the linked UC-PHYS-03/05/06/07 Control items in the control library (Control.control_id, Control.domains=physical_environmental_security), covering NIST 800-53 PE-19 (information leakage / emanations) and PE-21 (electromagnetic pulse and surge protection).\n\n**Procedure**\n_This checkpoint absorbs “Service and load-test emergency power”, “Verify emergency lighting and power shutoffs”, “Inspect cabling, conduits, and wiring closets”, “Verify electromagnetic shielding and surge protection”. The agent runs the preparation, evidence assembly and record updates below; the named owners retain the substantive decisions and approvals stated in the procedure._\n1. Service and load-test emergency power: Pull UPS battery-health and runtime-test results for each unit.\n2. Pull generator load-test results: transfer-switch exercise, fuel level, and a load-bank or building-load test.\n3. Compare tested runtime and load capacity against the documented requirement; a tested runtime below the requirement is a FAIL even if the unit started and ran.\n4. Confirm the broader utility inspection-and-maintenance schedule (power, HVAC, telecommunications) is current, flagging any overdue item.\n5. Record pass/fail, tested capacity versus required capacity, technician, and date.\n6. Verify emergency lighting and power shutoffs: Query the emergency-lighting test log for this cycle's automatic-activation test of every fixture along each evacuation route.\n7. Identify any fixture that failed to activate or is past its battery-replacement interval; a route with even one dead fixture fails the route.\n8. Inspect the EPO shutoff location, signage, and physical protection (cover, tamper alarm) against the facility diagram; confirm it remains reachable and correctly labeled.\n9. Record pass/fail per evacuation route and for the shutoff.\n10. Inspect cabling, conduits, and wiring closets: Pull the wiring-closet and patch-panel access log; identify who accessed each closet since the last cycle and cross-check against approved change/maintenance tickets — any access without a matching ticket is an exception.\n11. Walk the cable routes and closets against the cabling diagram: inspect protected conduits, the physical separation of power and communications lines, and the condition of power equipment, jacketing, and terminations for damage.\n12. Inspect every patch panel and wiring closet for unauthorized or unrecognized devices (rogue taps, unregistered switches, capture devices); photograph any anomaly found.\n13. Record findings per closet and route.\n14. Verify electromagnetic shielding and surge protection: Query the electromagnetic-protection design record and confirm which rooms, racks, or components are in scope for shielding/separation and their designated placement.\n15. Inspect shielded enclosures, cable separation, and surge-protection devices at building entry and on critical circuits against the design record; review the last test of each surge-protection device's fault indicator.\n16. Confirm sensitive components remain in their designated placement and that no unshielded cable run or relocated device has created a new emanation or pulse exposure since the last cycle.\n17. Record findings per shielded zone and device.\n\n**Decision criteria**\n- `all_systems_normal` — every round (fire/water/environmental, emergency power, lighting/shutoffs, cabling, electromagnetic protection) passed within tolerance, no PM-calendar item is overdue, and any life-safety deficiency escalated this cycle is already closed.\n- `deficiencies_identified` — any check failed or remains open, or any shutoff, alarm, lighting, cabling, or shielding gap was found.\n\nAgent evidence-gathering substeps (run before the human picks):\n1. Consolidate every round's records into the single maintenance-and-inspection log, cross-referencing test records, service tickets, and alarm-notification checks.\n2. Compute cycle metrics: passed versus failed checks per system, any overdue PM-calendar item, and the status of the life-safety escalation if one was opened.\n3. Build a cycle-readiness dashboard showing each system against its threshold and the trend against prior cycles.\n\n**Record in AssureSwarm**\n- Attach the emergency-power round results as an XLSX inspection-results workpaper on this step (coach-document-upload) — pass/fail per unit with the tested-versus-required capacity comparison, technician, and date — together with the UPS/generator load-test results and vendor service tickets. AssureSwarm has no native maintenance-log item type, so this per-round record lives as a step document, not an item.\n- Pull the load-test data and emergency-power asset inventory with coach-query-data. Promote any unit that fails capacity to an Issue in the corrective-action step and link it to its driving test record (coach-item-create, coach-items-link).\n- Attach the lighting/shutoff round results as an XLSX inspection-results workpaper on this step (coach-document-upload) — pass/fail per evacuation route and for the EPO shutoff — together with the lighting test log and the shutoff inspection checklist. AssureSwarm has no native maintenance-log item type, so this per-round record lives as a step document, not an item.\n- Pull the lighting test log and fixture inventory with coach-query-data. Promote any failed route or an inaccessible shutoff to an Issue in the corrective-action step and link it to its driving test record (coach-item-create, coach-items-link).\n- Attach the cabling round results as an XLSX inspection-results workpaper on this step (coach-document-upload) — findings per closet and route — together with the access-log reconciliation, the full inspection checklist, and any anomaly photos. AssureSwarm has no native maintenance-log item type, so this per-round record lives as a step document, not an item.\n- Pull the wiring-closet/patch-panel access log with coach-query-data. Promote any damage, unauthorized device, or unreconciled closet access to an Issue in the corrective-action step and link it to its driving evidence (coach-item-create, coach-items-link).\n- Attach the electromagnetic-protection round results as an XLSX inspection-results workpaper on this step (coach-document-upload) — findings per shielded zone and surge-protection device — together with the shielding and surge-protection inspection checklist. AssureSwarm has no native maintenance-log item type, so this per-round record lives as a step document, not an item; a genuine shielding gap or new emanation exposure is promoted to an Issue in the corrective-action step.\n- Pull the electromagnetic-protection design record and surge-protection inventory with coach-query-data.\nSubmit the SELECT field `maintenance_cycle_disposition` (`all_systems_normal` | `deficiencies_identified`). Record the rationale and evidence references in the step result and the decision owner/approver in the step's approver record. Build the dashboard (coach-dashboard-create), attach the disposition summary (coach-document-upload), and consolidate the log with coach-query-data.\n\n**Exit criteria**\n- UPS and generator capacity meet the documented requirement, servicing occurred on the defined schedule, and results are logged with tickets linked.\n- Every evacuation-route fixture activated automatically, no fixture is past its battery interval, and the emergency power shutoff is accessible, protected, and correctly labeled; results logged.\n- Cabling, conduits, and power equipment show no unrepaired damage, power and communications lines remain separated per design, no unauthorized device was found, and every closet access reconciles to an approved ticket; results logged.\n- Shielding and separation intact, surge-protection devices functional with current fault-indicator tests, and sensitive components in their protected placement; results logged.\n- The form is submitted with rationale and owner recorded; the consolidated log and dashboard back the choice; the unused branch is prunable.","kind":"decision","label":"Classify maintenance cycle disposition","performedBy":{"primitives":["coach-query-data","coach-item-create","coach-items-link","coach-document-upload","coach-dashboard-create"]}},"id":"classify-maintenance-cycle-disposition"},{"data":{"description":"Agent converts every open deficiency into an owned corrective action; human confirms each is tracked and escalated where required","instructions":"**Objective** — Convert every deficiency identified this cycle into an owned, tracked, and escalated-where-required corrective action so no fire, water, environmental, power, cabling, or shielding gap degrades unaddressed.\n\n**Inputs**\n- The cycle disposition summary and its `deficiencies_identified` decision, listing each open deficiency and the system it affects.\n- Each driving test record or log entry, and any interim mitigation already in place from a mid-cycle life-safety escalation.\n- The accountable facilities/security owner roster and the escalation thresholds.\n\n**Procedure**\n1. Parse the cycle disposition summary to list each open deficiency with its root cause and the system it affects.\n2. Create a corrective-action item for each deficiency capturing root cause, owner, due date, and interim mitigation.\n3. Link each corrective action to the driving test record or log entry.\n4. Escalate any deficiency still open past its interim-mitigation window, or that affects a life-safety system, to the accountable facilities or security owner.\n\n**Record in AssureSwarm**\n- Create one Issue item per deficiency (coach-item-create) — issue_type=deficiency, source=self_assessment, root_cause, severity, issue_owner, identified_date, and target_remediation_date — collectively forming the corrective-action register.\n- Link each Issue to the affected UC-PHYS Control and the anchor Control (coach-items-link — Issue ↔ Control) and to its driving test record or round document.\n- Attach the consolidated corrective-action register as an XLSX document on this step (coach-document-upload).\n\n**Exit criteria** — Every deficiency has a named owner and due date, required escalations were routed, and nothing remains untracked before closure.","label":"Log corrective actions and escalate","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-document-upload"]}},"id":"log-corrective-actions-and-escalate"},{"data":{"description":"Automatically archive the authorized cycle record and carry open actions into the next cycle.","instructions":"**Objective** — Automatically preserve the authorized cycle record and its carry-forward actions after the preceding decision.\n\n**Inputs**\n- The single maintenance-and-inspection log (test records, service tickets, and alarm-notification checks) from every round, plus the cycle disposition.\n- Any open corrective actions or vendor-committed repair dates from the corrective-action register.\n- The designated evidence repository, its retention controls, and the PM calendar for next month.\n\n**Procedure**\n1. Export the full maintenance-and-inspection log and archive it in the designated evidence repository under retention controls; record the archive location and reference.\n2. Create carry-forward items for any open corrective action or vendor-committed repair date and link them to their source, so they arrive as explicit inputs to next month's cycle.\n3. Update the control execution log with the cycle result and key metrics.\n4. Confirm next month's PM-calendar date is scheduled.\n\n**Record in AssureSwarm**\n- Export the full single maintenance-and-inspection log via coach-workflow-export (XLSX) and attach the retention copy as a step document; the archived workflow instance on the anchor Control is itself the durable audit trail and the control's execution-log entry for this cycle (AssureSwarm has no dedicated execution-log field on Control).\n- Leave each still-open deficiency Issue as the carry-forward channel — set actual_remediation_date/verified_date on any closed this cycle and keep the rest open (issue_type=deficiency, target_remediation_date) — and link each to the anchor Control (coach-item-create, coach-items-link) so next month's instance reads them as explicit inputs.\n- Attach the closure record as a step document (coach-document-upload).\n\n**Exit criteria** — The archived log is complete and retrievable under retention, next month's cycle is scheduled, nothing remains open without a tracked owner, and the authorized cycle record is complete.","label":"Close and archive","performedBy":{"primitives":["coach-workflow-export","coach-item-create","coach-items-link","coach-document-upload"]},"requiredApprovals":0},"id":"close-and-archive"}],"sourceTemplateId":"workflow-library:controls-environmental-utility-systems-maintenance"}
