{"description":"Runs on the existing personnel item. Modify a mover access for a new role, remove entitlements the prior role no longer justifies, and approve the modification record. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","edges":[{"id":"e-modification-approval-modification-closure","source":"modification-approval","target":"modification-closure"}],"isPublic":true,"itemTypeSlug":"personnel","metadata":{"capabilities":["transfer-access-modification"],"controlVerbs":{"UC-ACCESS-01":"operates","UC-ACCESS-03":"operates"},"controls":["UC-ACCESS-01","UC-ACCESS-03"],"department":"it","domains":["controls"],"kind":"transfer-access-modification","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:transfer-access-modification"}],"canonicalUrl":"https://workflow-library.com/all/?w=controls-personnel-transfer-access","contentDigest":"sha256:dc992c20b421860c0a318eb76700110f4fc752b38e83243bcc216325ced3047c","prerequisites":{"anchorItemType":{"slug":"personnel"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"fields":[{"itemTypeSlug":"personnel","key":"position_title"},{"itemTypeSlug":"personnel","key":"department"},{"itemTypeSlug":"personnel","key":"role_effective_date"},{"itemTypeSlug":"personnel","key":"manager_name"},{"itemTypeSlug":"personnel","key":"manager_personnel_key"}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:controls-joiner-mover-leaver"}],"roles":[{"contribution":"approval","description":"Manager and entitlement authority. Approve additions and removals.","id":"reviewer-1","nodeIds":["modification-approval"]},{"contribution":"approval","description":"Independent access reviewer. Approve modification record.","id":"reviewer-2","nodeIds":["modification-closure"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:transfer-access-modification"}],"releaseId":"sha256:dc992c20b421860c0a318eb76700110f4fc752b38e83243bcc216325ced3047c","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-personnel-transfer-access"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-personnel-transfer-access","source":"coworkcanvas-gallery","standards":[],"teams":["it"]},"name":"Transfer & Access Modification","nodes":[{"data":{"instructions":"**Objective**\nApprove additions and removals. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Personnel record, the HR transfer record, prior and new position descriptions, current entitlement extracts from each in-scope system, and the role profiles for both positions.\n2. Use the prior entitlement inventory, the new role profile, the entitlement catalogue, the conflict matrix, system owner approval routes, and policy on retaining prior access during transition.\n\n**Procedure**\n1. Extract current entitlements from source systems rather than from memory or prior tickets, compare against the prior role profile, identify accumulated entitlements outside any profile, and confirm the effective date against the HR record.\n2. Default to REMOVING prior-role entitlements and justify each retention explicitly, route additions and removals to their authorized approvers, test the resulting combined set against the conflict matrix, and refuse to advance a blocked conflict.\n\n**Record in AssureSwarm**\n1. Capture the transfer effective date, prior and new position, the complete prior entitlement inventory per system with extract dates, entitlements held outside profile, and extraction gaps.\n2. Document additions and removals with approver and date, retentions with justification and expiry, conflicts and their disposition, privileged entitlements flagged separately, and declined requests. Also record segregation-of-duties conflict.\n\n**Exit criteria**\nManager and entitlement authority provides approval: The prior entitlement inventory is extracted from source systems and dated, accumulated access is visible, and extraction gaps are declared rather than assumed empty. An approver accepts that removals were considered by default rather than by exception, retentions carry justification and an expiry, and conflicts are dispositioned before provisioning.","kind":"task","label":"Approve additions and removals","requiredApprovals":1},"id":"modification-approval"},{"data":{"controls":["UC-ACCESS-01","UC-ACCESS-03"],"instructions":"**Objective**\nApprove modification record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved delta, system administration consoles, post-change entitlement extracts, evidence of each addition and removal, and the timing expectations for transfer changes in policy.\n2. Review all stage records, the prior and post-change extracts, approvals for additions and removals, retention justifications and expiries, conflict dispositions, deviations, and outstanding items.\n\n**Procedure**\n1. Apply removals as well as additions, RE-EXTRACT entitlements after the change, reconcile the post-change state against the approved target line by line, and record residual prior-role access as a deviation rather than an oversight.\n2. Trace the post-change state to approved decisions, verify every retention carries an expiry, confirm removals actually took effect in the extract, and return unreconciled residual access with precise comments.\n\n**Record in AssureSwarm**\n1. Document applied changes per system with evidence references and dates, the post-change entitlement extract, reconciliation result, deviations with cause, and outstanding items with owners. Also record modification outcome.\n2. Capture the authorized reviewer, the modification summary, HR-backed Personnel updates specified below, retentions and their expiries, deviations accepted, outstanding items with owners, and linked issues raised.\n\nUpdate Personnel.position_title, Personnel.department and Personnel.role_effective_date only from the authoritative approved HR transfer record. Update Personnel.manager_name and Personnel.manager_personnel_key when the source establishes a changed reporting line. A transfer must not reset Personnel.engagement_start_date or Personnel.engagement_end_date; change Personnel.engagement_status only when a separate authoritative HR status event supports it. Put access execution dates, before/after entitlement inventories, approved additions/removals, retention expiries and exceptions in the markdown step result; attach approval and re-extraction evidence as step documents.\n\n**Exit criteria**\nIndependent access reviewer provides approval: The post-change state reconciles to the approved target, residual prior-role access is named as a deviation, and outstanding removals carry owners and dates. The authorized reviewer accepts the modification record as evidence an access control operated for this transfer, and closure implies no assurance over entitlements in systems outside the stated scope.","kind":"task","label":"Approve modification record","requiredApprovals":1},"id":"modification-closure"}],"sourceTemplateId":"workflow-library:controls-personnel-transfer-access"}
