{"description":"Runs on the existing personnel item. Revoke a leaver access across every in-scope system within the policy window, evidence each revocation, and approve the revocation record. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","edges":[{"id":"e-revocation-execution-revocation-closure","source":"revocation-execution","target":"revocation-closure"}],"isPublic":true,"itemTypeSlug":"personnel","metadata":{"capabilities":["offboarding-access-revocation"],"controlVerbs":{"UC-ACCESS-01":"operates"},"controls":["UC-ACCESS-01"],"department":"it","domains":["controls"],"kind":"offboarding-access-revocation","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:offboarding-access-revocation"}],"canonicalUrl":"https://workflow-library.com/all/?w=controls-personnel-offboarding-access","contentDigest":"sha256:caafde58d223a05539df8c7f542b5c52d75a17bde58042450b390792a9c7b218","prerequisites":{"anchorItemType":{"slug":"personnel"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"fields":[{"itemTypeSlug":"personnel","key":"engagement_status"},{"itemTypeSlug":"personnel","key":"engagement_end_date"}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:controls-joiner-mover-leaver"}],"roles":[{"contribution":"expertise","description":"Manager and entitlement authority. Revoke access and capture evidence.","id":"reviewer-1","nodeIds":["revocation-execution"]},{"contribution":"approval","description":"Independent access reviewer. Approve revocation record.","id":"reviewer-2","nodeIds":["revocation-closure"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:offboarding-access-revocation"}],"releaseId":"sha256:caafde58d223a05539df8c7f542b5c52d75a17bde58042450b390792a9c7b218","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-personnel-offboarding-access"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-personnel-offboarding-access","source":"coworkcanvas-gallery","standards":[],"teams":["it"]},"name":"Offboarding & Access Revocation","nodes":[{"data":{"instructions":"**Objective**\nRevoke access and capture evidence. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Personnel record, the HR termination record, entitlement extracts from every in-scope system, asset and device registers, shared and service account membership, physical access records, and the revocation window in policy.\n2. Use the access inventory and deadline, system administration consoles, directory disablement records, asset recovery receipts, shared-credential rotation records, and physical badge deactivation logs.\n\n**Procedure**\n1. Extract entitlements from source systems, INCLUDE shared accounts, service accounts, and non-directory credentials that role-based extracts miss, confirm whether the termination type requires immediate revocation, and compute the deadline from the effective date.\n2. Revoke in dependency order so directory disablement does not hide downstream entitlements, ROTATE shared credentials the leaver knew rather than only removing membership, capture dated evidence per system, and record each revocation against the deadline rather than in aggregate.\n\n**Record in AssureSwarm**\n1. Capture the termination effective date and type, revocation deadline, the complete access inventory per system with extract dates, devices and physical credentials, shared and service account membership, and extraction gaps.\n2. Document revoked access per system with evidence references and timestamps, credential rotations performed, devices recovered, physical access deactivated, timeliness per item, and outstanding revocations with owners.\n\n**Exit criteria**\nManager and entitlement authority provides expertise: The inventory covers named, shared, and service access plus physical credentials; the deadline is computed from policy; and extraction gaps are declared rather than presumed empty. Every inventoried item is revoked, rotated, or recorded as outstanding with an owner; timeliness is measured per item against the deadline; and shared credentials are rotated rather than assumed safe.","kind":"task","label":"Revoke access and capture evidence","requiredApprovals":1},"id":"revocation-execution"},{"data":{"controls":["UC-ACCESS-01"],"instructions":"**Objective**\nApprove revocation record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use post-revocation entitlement extracts, directory status, authentication and access logs since the termination date, asset register status, and the original inventory for comparison.\n2. Review all stage records, the original and post-revocation extracts, timeliness per item, credential rotations, asset recovery, verification comparison, residual access, and unverifiable items.\n\n**Procedure**\n1. Re-extract INDEPENDENTLY rather than accepting the operator confirmation, compare against the original inventory item by item, inspect authentication activity after the termination date, and classify unverifiable items as unverifiable rather than complete.\n2. Trace every inventoried item to a revocation or an owned exception, confirm late revocations are recorded as such rather than smoothed, verify residual access has a remediation owner, and return incomplete verification with precise comments.\n\n**Record in AssureSwarm**\n1. Record the verification result, post-revocation extract references and dates, item-by-item comparison, residual access with cause and owner, post-termination authentication observed, and items that could not be verified. Also record residual access detail.\n2. Capture the authorized reviewer, the revocation summary, HR-backed Personnel updates specified below, late revocations, residual access with owners and dates, unverifiable items, and linked issues raised.\n\nUpdate Personnel.engagement_end_date and Personnel.engagement_status only from the authoritative HR termination or engagement-end record and its effective date. Completed access revocation alone does not establish that the engagement ended; do not mark ended before the supported end date. Preserve Personnel.engagement_start_date and historical role dates. Put per-system access revocation/verification dates, the original entitlement inventory, credential rotations, late removals, residual access and unverifiable items in the markdown step result; attach source extracts and verification evidence as step documents.\n\n**Exit criteria**\nIndependent access reviewer provides approval: An approver accepts that verification rests on independent re-extraction, residual access carries an owner and a date, and unverifiable items are declared rather than treated as clean. The authorized reviewer accepts the revocation record as evidence an access control operated for this leaver, late and residual items stay visible as control exceptions, and closure implies no assurance over systems outside the stated scope.","kind":"task","label":"Approve revocation record","requiredApprovals":1},"id":"revocation-closure"}],"sourceTemplateId":"workflow-library:controls-personnel-offboarding-access"}
