{"description":"Runs on the existing personnel item. Provision a joiner access from an approved role profile, evidence each grant, and approve the provisioning record that ITGC access testing samples. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","edges":[{"id":"e-access-approval-onboarding-closure","source":"access-approval","target":"onboarding-closure"}],"isPublic":true,"itemTypeSlug":"personnel","metadata":{"capabilities":["onboarding-access-provisioning"],"controlVerbs":{"UC-ACCESS-01":"operates","UC-ACCESS-03":"operates"},"controls":["UC-ACCESS-01","UC-ACCESS-03"],"department":"it","domains":["controls"],"kind":"onboarding-access-provisioning","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:onboarding-access-provisioning"}],"canonicalUrl":"https://workflow-library.com/all/?w=controls-personnel-onboarding-access","contentDigest":"sha256:1262db80aa606cf208fe178068d49691732d4cc91a175ece393ef3af9293f373","prerequisites":{"anchorItemType":{"slug":"personnel"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"fields":[{"itemTypeSlug":"personnel","key":"engagement_status"},{"itemTypeSlug":"personnel","key":"engagement_start_date"},{"itemTypeSlug":"personnel","key":"role_effective_date"},{"itemTypeSlug":"personnel","key":"position_title"},{"itemTypeSlug":"personnel","key":"department"}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:controls-joiner-mover-leaver"}],"roles":[{"contribution":"approval","description":"Manager and entitlement authority. Obtain entitlement approval.","id":"reviewer-1","nodeIds":["access-approval"]},{"contribution":"approval","description":"Independent access reviewer. Approve provisioning record.","id":"reviewer-2","nodeIds":["onboarding-closure"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:onboarding-access-provisioning"}],"releaseId":"sha256:1262db80aa606cf208fe178068d49691732d4cc91a175ece393ef3af9293f373","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-personnel-onboarding-access"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-personnel-onboarding-access","source":"coworkcanvas-gallery","standards":[],"teams":["it"]},"name":"Onboarding & Access Provisioning","nodes":[{"data":{"instructions":"**Objective**\nObtain entitlement approval. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Personnel record, the signed offer or engagement record, the position description, the approved role-to-entitlement profile, the systems in scope, and pre-start conditions such as background screening.\n2. Use the confirmed profile, the entitlement catalogue, segregation-of-duties rules and the conflict matrix, system owner approval routes, privileged-access policy, and prior exceptions for comparable roles.\n\n**Procedure**\n1. Verify the joiner record against the authoritative HR source, confirm the role profile is current, identify entitlements requested outside the profile, check pre-start conditions are satisfied, and hold provisioning where authorization is incomplete.\n2. Route each entitlement to its authorized approver, test the COMBINED set against the conflict matrix rather than entitlement by entitlement, evaluate compensating measures where a conflict is accepted, and refuse to advance a blocked conflict.\n\n**Record in AssureSwarm**\n1. Capture the start date, requested access profile, systems in scope, out-of-profile requests with justification, pre-start condition status, requesting manager, and authorization references.\n2. Document approved entitlements with approver and date, conflicts identified, disposition and compensating measures, privileged entitlements flagged separately, and requests declined with reasons. Also record segregation-of-duties conflict.\n\n**Exit criteria**\nManager and entitlement authority provides approval: The joiner and role profile are confirmed against an authoritative source, out-of-profile requests are justified, and provisioning does not begin on incomplete authorization. An approver accepts that every entitlement carries authorized approval and that conflicts are dispositioned rather than ignored; blocked conflicts stop provisioning instead of proceeding.","kind":"task","label":"Obtain entitlement approval","requiredApprovals":1},"id":"access-approval"},{"data":{"controls":["UC-ACCESS-01","UC-ACCESS-03"],"instructions":"**Objective**\nApprove provisioning record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved entitlement list, system administration consoles and provisioning tooling, identity directory records, screenshots or extracts evidencing each grant, and the timing expectations in policy.\n2. Review all stage records, authorization references, entitlement approvals, conflict dispositions, provisioning evidence and reconciliation, deviations, and outstanding items with owners.\n\n**Procedure**\n1. Provision only what was approved, capture dated evidence per system, reconcile granted against approved line by line, record any grant made outside approval as a deviation, and confirm inherited or default entitlements were reviewed rather than assumed.\n2. Trace each granted entitlement to an approval, verify accepted conflicts carry compensating measures, confirm evidence covers every in-scope system, and return unreconciled deviations with precise comments.\n\n**Record in AssureSwarm**\n1. Document provisioned accounts and entitlements per system with evidence references and dates, the provisioning outcome, deviations with cause, inherited entitlements reviewed, and outstanding items with owners.\n2. Capture the authorized reviewer, the provisioning summary, HR-backed Personnel updates specified below, deviations accepted, outstanding items with owners and dates, and linked issues raised.\n\nUpdate Personnel.engagement_status and Personnel.engagement_start_date only from the authoritative HR or engagement record and its effective date. Provisioned access alone does not establish that the person is active; retain planned or unconfirmed status when that is the supported position. Record the approved role using Personnel.position_title, Personnel.department and Personnel.role_effective_date only when the source establishes those facts. Put access execution dates, requested/approved/granted entitlements, system evidence, accepted deviations and open exceptions in the markdown step result; attach extracts and grant evidence as step documents.\n\n**Exit criteria**\nIndependent access reviewer provides approval: Granted access reconciles to approved access with deviations named, evidence is dated and system-specific, and outstanding items carry owners rather than being closed optimistically. The authorized reviewer accepts the provisioning record as evidence an access control operated for this joiner, and closure implies no assurance over entitlements granted outside this action.","kind":"task","label":"Approve provisioning record","requiredApprovals":1},"id":"onboarding-closure"}],"sourceTemplateId":"workflow-library:controls-personnel-onboarding-access"}
