{"description":"Run one instance per HR-triggered joiner, mover, or leaver event as a decision-routed access-lifecycle control that enriches the EXISTING Control item for JML / user-access provisioning-deprovisioning (control library, domains=access_control_identity, framework nist-800-53 + iso-27001) - attach the instance to that control, never create a duplicate. Consume the authoritative HR event record from the external HR system of record (the trigger): classify the event, then provision role-based access, adjust with SoD checks on transfer, or evidence timely removal on exit, and file the named audit-ready access-lifecycle evidence package before closing. In scope: identity-provider, directory, HR-system, ERP, and connected-SaaS entitlements for the affected worker. Out of scope: HR record creation itself, physical-security badge policy, and system-owner entitlement design. The run is terminal - no upstream or downstream AssureSwarm workflow: it starts from the external HR event and ends at the archived evidence package attached to the Control item. The anchor Control links (item relationship) to the access Risk it mitigates.","edges":[{"id":"e-classify-lifecycle-event-provision-joiner-access","label":"Joiner","source":"classify-lifecycle-event","target":"provision-joiner-access","whenValue":"joiner"},{"id":"e-classify-lifecycle-event-adjust-mover-access","label":"Mover","source":"classify-lifecycle-event","target":"adjust-mover-access","whenValue":"mover"},{"id":"e-classify-lifecycle-event-deprovision-leaver","label":"Leaver","source":"classify-lifecycle-event","target":"deprovision-leaver","whenValue":"leaver"},{"id":"e-provision-joiner-access-verify-timeliness-and-evidence","source":"provision-joiner-access","target":"verify-timeliness-and-evidence"},{"id":"e-adjust-mover-access-verify-timeliness-and-evidence","source":"adjust-mover-access","target":"verify-timeliness-and-evidence"},{"id":"e-deprovision-leaver-verify-timeliness-and-evidence","source":"deprovision-leaver","target":"verify-timeliness-and-evidence"},{"id":"e-verify-timeliness-and-evidence-periodic-sample-audit","source":"verify-timeliness-and-evidence","target":"periodic-sample-audit"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-ACCESS-01","UC-HR-03","UC-ACCESS-03","UC-HR-06","UC-ASSET-07","UC-GOV-08"],"department":"it","domains":["controls"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=controls-joiner-mover-leaver","contentDigest":"sha256:16938047ff0802214480433fbaa4f58aa66b270ca388b9d30d02736ad190c4c1","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:16938047ff0802214480433fbaa4f58aa66b270ca388b9d30d02736ad190c4c1","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-joiner-mover-leaver"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-joiner-mover-leaver","source":"coworkcanvas-gallery","standards":["nist-800-53","iso-27001"],"teams":["it","hr"]},"name":"Joiner-Mover-Leaver Access Lifecycle","nodes":[{"data":{"decisionField":"lifecycle_event","description":"Agent pre-classifies the validated event with evidence; the reviewer confirms joiner, mover, or leaver routing","formData":{"fields":[{"key":"lifecycle_event","label":"Classify lifecycle event","options":[{"label":"Joiner - new hire or rehire","value":"joiner"},{"label":"Mover - transfer or role change","value":"mover"},{"label":"Leaver - termination or contract end","value":"leaver"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Route the authoritative HR event down exactly one lifecycle path (joiner, mover, or leaver) so downstream provisioning, adjustment, or removal acts on a single confirmed classification. This instance runs on (enriches) the existing JML / user-access Control item in the control library; do not create a new control. Owned by the access/identity control owner, with HR confirming the event facts.\n\n**Inputs** — The authoritative HR event record lives in the external HR system of record (the trigger); upload its extract as a step document (PBC) here and cite its reference in the step result. The in-scope-systems inventory (identity provider, directory, HR system, ERP, connected SaaS) plus documented exclusions has no native Asset/System item type — attach it as a scope-list document on this step. The anchor Control item (framework nist-800-53 + iso-27001, domains access_control_identity) already exists and carries the control mapping this run enriches.\n\n**Decision criteria**\n\nFirst confirm the triggering record is complete and authoritative before choosing a branch: worker identifier, event type code, effective date and time, manager, department, and worker type all present and matching the source HR system — never act on email or verbal notice. Reconcile the worker against the directory by unique identifier, flagging same-name collisions, duplicate or already-processed events, rehires with legacy accounts, contractor conversions, and future-dated events that must not be actioned early. Then pick the branch:\n\n- **joiner** — new hires and rehires (hire / rehire / onboard event codes). Choose joiner when a worker gains an initial access baseline. Rehires still take this path but require legacy-account reconciliation. Maps to NIST 800-53 AC-2 / PS-3 and ISO 27001 A.5.16.\n- **mover** — transfers, promotions, department or role changes (transfer / reorg / role-change codes). Choose mover when the worker stays employed but their role-and-entitlement baseline changes. Maps to NIST 800-53 PS-5 / AC-5 and ISO 27001 A.6.5.\n- **leaver** — terminations, resignations, retirements, and contract end (termination / offboard codes). Choose leaver whenever the employment or engagement ends, voluntary or involuntary. Maps to NIST 800-53 AC-2 / PS-4 and ISO 27001 A.5.18.\n\nResolve edge cases by written policy, not judgment: extended leave and suspension follow the leave/suspension policy (usually not a leaver); a contractor-to-employee or employee-to-contractor conversion is a paired leaver+joiner only where policy requires a new identity. Flag any event whose code and access history disagree back to HR for reconfirmation rather than guessing.\n\n**Record in AssureSwarm** — Submit the `lifecycle_event` SELECT (joiner | mover | leaver). Write the rationale into the step result, citing the HR event code, the HR record reference, and the directory evidence; name the accountable approver in the step's approver record.\n\n**Exit criteria** — The `lifecycle_event` routing selector is submitted and the step result contains a rationale and owner; the HR event facts are confirmed authoritative; the two unused branches are prunable because each branch edge value matches the submitted field value.","kind":"decision","label":"Classify lifecycle event","performedBy":{"primitives":["coach-query-data","coach-form-fill"]}},"id":"classify-lifecycle-event"},{"data":{"description":"Agent computes the birthright and role-based entitlement set and raises provisioning tickets; the manager approves before grant","instructions":"**Objective** — Grant the joiner exactly the approved birthright plus role-based entitlement set, on time and SoD-screened before any grant, so a new worker has correct least-privilege access with no toxic combination.\n\n**Inputs**\n- The submitted `classify-lifecycle-event` decision (value = joiner) and its rationale.\n- The authoritative HR event record: worker id, worker type, department, job code, manager, and effective date/time.\n- The role-to-entitlement matrix (current version): birthright groups by worker type/department, role-based entitlements by job code.\n- The segregation-of-duties (SoD) ruleset (current version).\n- The joiner SLA clock rule (which timestamp starts the clock — HR effective date vs. notification timestamp).\n- In-scope systems (identity provider, directory, HR system, ERP, connected SaaS) and any documented system exclusions.\n\n**Procedure**\n1. Compute the entitlement set from the role matrix — birthright groups from worker type and department plus role-based entitlements from the job code. Never clone a peer profile (that propagates privilege creep). List every requested item outside the matrix as an explicit exception needing system-owner approval.\n2. Run the full proposed combination through the SoD ruleset before anything is granted; attach the SoD result with each conflict itemized. A pre-grant conflict must be removed from the request or explicitly risk-accepted before proceeding.\n3. For rehires, reconcile legacy accounts first: identify dormant or disabled accounts for this identity and decide retire-versus-reactivate per policy — never silently revive old access.\n4. After approvals, raise provisioning tickets per system: create or reactivate directory/IdP accounts per the naming standard with an identifier unique to the person (ISO 27001 A.5.16); initiate MFA enrollment; deliver initial credentials out-of-band with a forced first-use reset; apply the approved groups and entitlements.\n5. Track ticket execution and re-query each target system to confirm access is actually effective — do not treat a closed ticket as working access. Capture per-system grant timestamps against the joiner SLA clock.\n\n**Record in AssureSwarm** — Attach a per-system provisioning register (document upload, structured XLSX/CSV) with one row per system: entitlement, ticket reference, and grant timestamp — there is no native ticket/entitlement item type, so this register on the step is the honest home. Attach the computed entitlement set and the SoD output as step documents. Record the approvals on the workflow instance — hiring manager for the entitlement set, system owner for out-of-matrix exceptions, security for pre-grant SoD.\n\n**Exit criteria** — Every approved entitlement is confirmed effective by system re-query; no unresolved SoD conflict remains; all approvals are recorded; grant timestamps are captured against the SLA clock.","label":"Provision joiner access","performedBy":{"primitives":["coach-query-data","coach-item-create","coach-document-upload"]}},"id":"provision-joiner-access"},{"data":{"description":"Agent diffs current versus target-role entitlements with an SoD conflict check; the manager and security approve the change","instructions":"**Objective** — Transition the mover to the new role's entitlements with no silent accumulation, and prove the resulting combined access is SoD-clean (NIST 800-53 PS-5, ISO 27001 A.6.5).\n\n**Inputs**\n- The submitted `classify-lifecycle-event` decision (value = mover) and its rationale.\n- The HR event: prior role/department, target role/job code, effective date, and new manager.\n- The role-to-entitlement matrix (target-role set) and the SoD ruleset (current versions).\n- The mover SLA clock rule.\n- In-scope systems and any documented exclusions.\n\n**Procedure**\n1. Export the mover's current entitlements across all in-scope systems as a timestamped before-state baseline — group memberships, privileged access, and shared credentials used.\n2. Diff current access against the target-role set into an explicit disposition for every entitlement: keep, add, or remove. Flag old-role privileged and sensitive-data access for priority removal. Mark any requested retention as transition access with a named owner and a hard expiry date (default 30 days unless policy differs).\n3. Run the proposed post-change combined access through the SoD conflict check; attach the output with every conflict itemized, and for each name the compensating control and the risk acceptor.\n4. After approvals, raise add and remove tickets sequenced so revocations land with or before the new grants — never leave the union of old and new access live. Set enforcement dates on transition-access expiries.\n5. Track execution, re-query systems to confirm the end state matches the approved disposition, and capture revocation/grant timestamps against the mover SLA clock.\n\n**Record in AssureSwarm** — Attach a per-disposition adjustment register (document upload, structured XLSX/CSV) with one row per entitlement: keep/add/remove, ticket reference, and timestamp — there is no native ticket/entitlement item type, so this register on the step is the honest home. Attach the before-state baseline and the SoD output as step documents. Record the new manager's approval of the full diff and security's approval of each SoD exception with its compensating control and risk acceptor on the workflow instance.\n\n**Exit criteria** — The keep-add-remove disposition is fully executed and re-query-confirmed; no unresolved SoD conflict remains; transition-access retentions have enforcement dates; revocation and grant timestamps are captured against the SLA clock.","label":"Adjust mover access","performedBy":{"primitives":["coach-query-data","coach-item-create","coach-document-upload"]}},"id":"adjust-mover-access"},{"data":{"description":"Agent schedules disablement of accounts, tokens, and sessions plus asset recovery; the human confirms final disablement authority","instructions":"**Objective** — Cut off the leaver's access at or before the effective time and recover assets, leaving no residual authentication path (NIST 800-53 AC-2 / PS-4).\n\n**Inputs**\n- The submitted `classify-lifecycle-event` decision (value = leaver) and rationale, with the voluntary-versus-involuntary flag.\n- The HR event: effective termination date/time, manager, and any retention or legal-hold flags.\n- Access sources: directory/IdP, session stores, OAuth grant lists, token and certificate inventories, shared-credential and service-account registers, VPN/remote-access lists, and the asset register.\n- The leaver SLA clock rule and the mailbox-handling policy.\n\n**Procedure**\n1. Build the leaver's complete access inventory: directory/IdP accounts, active sessions, OAuth grants, API tokens and certificates, shared credentials and service-account secrets the leaver held or knew, remote-access/VPN entries, and mailbox handling per policy.\n2. Schedule disable-at-termination actions per system — immediate for involuntary exits where policy requires — covering account disablement, session and token revocation, shared-credential rotation, and remote-access blocking. Preserve accounts under a retention or legal hold (disable, do not delete).\n3. Raise asset-recovery tasks for laptops, phones, hardware MFA tokens, badges, and keys; update the asset register; open escalations with owners and due dates for unreturned items.\n4. Track completion, capture per-system disable timestamps against the leaver SLA clock, and record the reminder of surviving confidentiality obligations issued to the worker.\n\n**Record in AssureSwarm** — Attach a per-system deprovisioning register (document upload, structured XLSX/CSV) with one row per system: action, disable timestamp, and status — there is no native ticket/entitlement item type, so this register on the step is the honest home. Track asset recovery on a recovery-tracker document (owner and due date per item); any unreturned-asset escalation that outlives the run becomes an Issue (item-create — `issue_type: exception`, `source: self_assessment`, `issue_owner`, `target_remediation_date`), linked (item relationship) to the anchor Control. Record HR/manager confirmation of the effective termination time and the security owner's exercise of final disablement authority on the workflow instance (the scheduled cutoff executes only on that confirmation).\n\n**Exit criteria** — Every access path is disabled, revoked, or rotated (or preserved under a recorded retention hold) and confirmed; disable timestamps are captured against the SLA clock; asset recovery is complete or escalated with a named owner and due date.","label":"Deprovision leaver","performedBy":{"primitives":["coach-query-data","coach-item-create","coach-document-upload","coach-items-link"]}},"id":"deprovision-leaver"},{"data":{"description":"Agent re-queries systems to verify execution and SLA timeliness and assembles the evidence record; an independent reviewer spot-checks","instructions":"**Objective** — Independently prove the lifecycle actions completed correctly and on time from system evidence (not fulfiller attestation), and assemble the audit-ready evidence record for the event.\n\n**Inputs**\n- The executed branch node's output — provision, adjust, or deprovision items, tickets, and timestamps. This node joins all three branches and runs on whichever one executed.\n- The intended end state per class: joiner = birthright plus approved role set; mover = approved keep-add-remove disposition; leaver = fully disabled with assets recovered or escalated.\n- The SLA clock table with per-event clock starts.\n- The approvals, SoD outputs, decision form values, and the HR event record for this event.\n\n**Procedure**\n1. Re-query every in-scope system for the current access state and compare it to the intended end state for the event's class. List every residual access item, missed system, or unexplained delta.\n2. Compute elapsed time from each SLA clock start to per-system completion; flag every miss against the SLA table regardless of size.\n3. Assemble the evidence record keyed to the event reference: the validated HR event, decision form values and rationale, approvals, SoD outputs, tickets, action and verification timestamps, and fresh system reports. Redact credentials. Apply the control mapping to NIST 800-53 AC-2 / PS-4 / PS-5 and ISO 27001 A.5.16 / A.5.18 / A.6.5.\n\n**Record in AssureSwarm** — Upload the assembled audit-ready access-lifecycle evidence package (document upload, PDF/ZIP) keyed to the event reference, and a timeliness worksheet (document upload, XLSX) carrying the end-state comparison result and the per-system SLA hit/miss result — these have no native item field, so they live on the step documents. Any residual access or SLA miss requiring corrective action becomes an Issue (item-create — `issue_type: deficiency` or `exception`, `source: self_assessment`, `issue_owner`, `target_remediation_date`), linked (item relationship) to the anchor Control. Log the independent reviewer's sign-off on the workflow instance, with the disposition of each miss — immediate removal, incident evaluation for lingering leaver access, and a corrective action with a named owner and due date.\n\n**Exit criteria** — The end-state comparison and the timeliness math are complete with every delta and miss dispositioned; the evidence package is uploaded and keyed to the event reference; a reviewer independent of the fulfiller has signed it audit-ready.","label":"Verify timeliness and evidence","performedBy":{"primitives":["coach-query-data","coach-document-upload","coach-item-create","coach-items-link"]}},"id":"verify-timeliness-and-evidence"},{"data":{"description":"Agent samples recent lifecycle events, retests end-to-end, drafts the sample memo, and archives the evidence under retention; the control owner dispositions the exceptions and formally closes the event","instructions":"**Objective** — Surface systemic JML weaknesses across events rather than one at a time — by registering this event in the period population and, when a sample is due, retesting a defensible selection end-to-end — then close the event with a complete, retrievable audit trail; the control owner's disposition of the proposed findings and the formal closure recorded here are the human moment.\n\n**Inputs**\n- The signed evidence record from `verify-timeliness-and-evidence` for this event.\n- The rolling period population of prior lifecycle events with their evidence.\n- The documented sampling method and the KPI/threshold definitions (SLA hit rate, residual-access rate).\n- Open-item sources: remediation and escalation items, transition-access expiries, and unreturned-asset items.\n- The retention policy and the linked records (asset register, access-review population, headcount reconciliation).\n\n**Procedure**\n_Items 5–7 close the workflow (folded from the former \"Close and archive\" step); the closure recorded on this step is the event's sign-off, so there is no separate confirmation._\n\n1. Add this event to the period population. When the periodic sample is due, select events by the documented sampling method — covering all three classes (joiner/mover/leaver) and both automated and manual fulfillment; never convenience picks.\n2. Retest each sampled event end-to-end: re-pull system evidence, reperform the completeness and timeliness checks, and recompute SLA metrics from the original clock starts.\n3. Trend breach root causes (late HR feed, broken integration, manual queue backlog, unclear ownership) and KPIs across the period.\n4. Draft the sample memo with proposed findings, corrective actions, and any SLA or automation-tuning recommendations, and put them to the control owner, who dispositions each proposed finding with a named owner and due date.\n5. Sweep for open items — remediation, escalations, transition-access expiries, unreturned assets, and the corrective actions just dispositioned — and verify each is closed or carries a named owner and due date.\n6. Archive the signed evidence package under the retention policy, keyed to the event reference; update the linked records.\n7. Send completion notifications to HR, the manager, and system owners; schedule the follow-up checks (transition-access expiry, unreturned-asset review, the next sample date); export the completed workflow record into the archive. The process owner's formal closure recorded here ends the event.\n\n**Record in AssureSwarm** — Register this event in the population by updating the population-register document; when a sample is due, upload the periodic JML sample-audit memo and retest evidence (document upload, DOCX/PDF + XLSX) carrying per-sample pass/fail and the trended KPIs — these have no native item field, so they live on the memo document. Each control-owner-confirmed finding becomes an Issue (item-create — `issue_type: finding`, `source: self_assessment`, `issue_owner`, `target_remediation_date`), linked (item relationship) to the anchor Control. Log the control owner's confirmation or rejection of each proposed finding and the assigned corrective-action owners and due dates on the workflow instance. Link the archived evidence package and the updated records (document-link); export the completed workflow record (workflow-export); record the process owner's formal closure and the confirmation that the archive is retrievable by the event reference.\n\n**Exit criteria** — This event is registered in the period population; when a sample was due, it is drawn, retested, and the memo drafted; the control owner has dispositioned every proposed finding with a named owner and due date; no open item remains without a named owner and due date; the evidence package is archived and retrievable by event reference; the process owner has formally closed the event.","label":"Periodic sample audit","performedBy":{"primitives":["coach-workflow-scan","coach-document-upload","coach-item-create","coach-items-link","coach-workflow-export"]}},"id":"periodic-sample-audit"}],"sourceTemplateId":"workflow-library:controls-joiner-mover-leaver"}
