{"description":"Standing operator workflow for the public-posting and external-sharing authorization queue plus the quarterly permitted-without-authentication register and public-content exposure sweep, run per publication request and each quarter. Each operating cycle runs as one instance that enriches the existing UC-ACCESS-14 Control item in the control library (NIST 800-53 AC-14/AC-21/AC-22, family AC, preventive, quarterly) — it never creates a new control, and the workflow instance itself is the durable audit trail attached to that Control. In scope: public-facing systems (public website, support portal, developer documentation, status page, social channels) and external data shares governed by sharing agreements. Out of scope: authenticated internal content and access provisioning. Consumes each cycle: the living public-content and external-share register, the permitted-without-authentication register, and the active-sharing-agreements register (all pre-existing, refreshed cycle over cycle); the information-classification scheme (a Policy item, policy_type: standard); and the prior cycle's open carry-forward Issues. Named deliverables: the classified intake register, the authorization-verification log, the per-request publication dispositions, the refreshed permitted-without-authentication register, the quarterly exposure-sweep dashboard and findings report, and exposure corrective-action Issues linked to the Control. This control runs standalone — no upstream workflow feeds it and no downstream workflow consumes its output; the per-request authorization path and the quarterly sweep path are independent and both close in this instance.","edges":[{"id":"e-review-and-authorize-publication-close-and-archive-approved_to_publish","label":"Approved","source":"review-and-authorize-publication","target":"close-and-archive","whenValue":"approved_to_publish"},{"id":"e-review-and-authorize-publication-redact-and-resubmit-content","label":"Redact","source":"review-and-authorize-publication","target":"redact-and-resubmit-content","whenValue":"return_for_redaction"},{"id":"e-review-and-authorize-publication-close-and-archive-denied_noncompliant","label":"Denied","source":"review-and-authorize-publication","target":"close-and-archive","whenValue":"denied_noncompliant"},{"id":"e-redact-and-resubmit-content-close-and-archive","source":"redact-and-resubmit-content","target":"close-and-archive"},{"id":"e-sweep-public-surfaces-for-exposure-remediate-exposure-and-notify","label":"Exposure","source":"sweep-public-surfaces-for-exposure","target":"remediate-exposure-and-notify","whenValue":"exposure_found"},{"id":"e-sweep-public-surfaces-for-exposure-close-and-archive","label":"Clean","source":"sweep-public-surfaces-for-exposure","target":"close-and-archive","whenValue":"clean_no_exposure"},{"id":"e-remediate-exposure-and-notify-close-and-archive","source":"remediate-exposure-and-notify","target":"close-and-archive"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-ACCESS-14"],"department":"it","domains":["controls"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=controls-public-content-external-sharing-authorization","contentDigest":"sha256:920c97d575af92eedda7f4b4e83b78d86377f2c1f6eba6645f8542651b6ba7c0","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:920c97d575af92eedda7f4b4e83b78d86377f2c1f6eba6645f8542651b6ba7c0","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-public-content-external-sharing-authorization"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-public-content-external-sharing-authorization","source":"coworkcanvas-gallery","standards":["nist-800-53"],"teams":["it","compliance-legal"]},"name":"Public Content & External Sharing Authorization","nodes":[{"data":{"decisionField":"publication_disposition","description":"Authorize release after reconciling the queue, classification, poster eligibility, owner authority and nonpublic-content scan.","formData":{"fields":[{"key":"publication_disposition","label":"Publication Disposition","options":[{"label":"Approved to publish","value":"approved_to_publish"},{"label":"Return for redaction","value":"return_for_redaction"},{"label":"Denied, noncompliant","value":"denied_noncompliant"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Authorize release after reconciling the queue, classification, poster eligibility, owner authority and nonpublic-content scan.\n\n**Inputs**\n- The anchor: the existing UC-ACCESS-14 Control item this cycle runs against (Control.framework=nist-800-53, Control.family, Control.description, Control.control_owner) — the workflow enriches it, never creates it.\n- The publication request queue and the external-sharing request queue, from the external intake systems (there is no native publication/sharing-request item type in the eight-type schema — see Record in AssureSwarm), each entry carrying requester, target channel or recipient, and the proposed content or data set.\n- The existing request queue, owner-authorization record, sharing agreement and exact content document; request only genuinely missing business purpose or audience from a requesting author outside the complete executor and approver roster. Participants supply their own facts in native results.\n- The information-classification scheme (public / internal / confidential / restricted) — a Policy item in the policy library (policy_type: standard) with the governed scheme document attached — and the register of active external data-sharing agreements (uploaded as a step document each cycle; no native agreement/contract item type).\n- The current public-content and external-share register carried forward from the prior cycle, plus any open carry-forward Issue items the prior cycle's close-and-archive linked to this Control. This control runs standalone — no upstream workflow feeds it.\n- The classified intake register from \"Intake and classify publication requests\", including the external-sharing subset and its linked sharing agreements.\n- The current designated-poster roster and the public-content training-completion register.\n- The delegation-of-authority records identifying information owners and authorized releasers, and the information-owner authorization record for each external share.\n- The information-classification rules governing what may appear on a public surface.\n\n**Procedure**\n_This checkpoint absorbs “Intake and classify publication requests”. The agent runs the preparation, evidence assembly and record updates below; the named owners retain the substantive decisions and approvals stated in the procedure._\n1. Intake and classify publication requests: Produce a complete, deduplicated register of every pending public-posting and external-sharing request, each tagged with request type, target, and information classification, so the right authorization checks can be applied.\n2. Pull all open publication and external-sharing requests from the intake queue (coach-query-data), capturing requester, target public-facing system or external recipient, and the proposed content or data set for each.\n3. Inspect the existing request and authoritative records first. Request only unresolved business purpose or intended audience through the existing requester channel and hold authorization until those facts arrive; no separate intake questionnaire is required.\n4. Scan open workflows (coach-workflow-scan) to detect any request that duplicates an already in-flight publication or sharing case; consolidate duplicates onto the existing case rather than processing twice.\n5. Create one intake record per distinct request (coach-item-create) recording: request type (public posting vs external share), target system or party, and information classification (public / internal / confidential / restricted). Where the requester's claimed classification disagrees with the classification scheme, record the scheme's classification and flag the divergence for the review step.\n6. For each external-sharing request, link the record to its governing data-sharing agreement (coach-items-link); flag any external share with no matching agreement on file as a blocker.\n7. Assemble the classified intake register and attach it (coach-document-upload).\n8. Review and authorize publication: Confirm every requester is eligible — a designated poster with current training, or a releaser holding information-owner authorization consistent with the item's classification and its sharing agreement — scan each item for nonpublic content, and decide whether each eligible item is approved to publish, returned for redaction, or denied. Owned by the Public Content Release Officer.\n9. Pull the designated-poster roster and the training-completion register (coach-query-data).\n10. For each public-posting request, match the requester to the roster and confirm their public-content training is current (not lapsed past the org's refresh interval).\n11. For each external-sharing request, confirm the requester holds information-owner or delegated-release authority per the delegation records.\n12. For any requester whose training has lapsed or who is absent from the roster, route the requester through the existing training and roster-correction process and obtain its completion evidence before the request proceeds.\n13. Compile the eligibility exceptions with the specific reason for each and attach the findings (coach-document-upload).\n14. Pull the information-owner authorization record for each external-sharing request (coach-query-data) and compare each against the item's classification level and the linked agreement's permitted-use and recipient terms; flag authorizations that are missing, expired, or broader or narrower than the classification allows.\n15. Route each authorization exception to the accountable information owner for a fresh authorization decision.\n16. Record each authorization outcome and link it to the originating request, then attach the authorization-verification log (coach-document-upload).\n17. Scan each eligible item's content against the classification rules (coach-query-data), checking for embedded PII, credentials, internal financial data, or other nonpublic information.\n18. Compile a per-item findings summary noting each flagged element, its location, and severity, cross-referenced against the eligibility and authorization results so the decision record reflects the full picture; draft the review packet and attach it (coach-document-upload).\n19. Pick each item's disposition against the criteria below and submit the SELECT.\n\n**Decision criteria**\n- `approved_to_publish` — the content scan found no nonpublic information (no PII, credentials, internal financial data, or other restricted content), and both the poster-eligibility and the external-authorization checks passed. Content is clean and authorized.\n- `return_for_redaction` — the content is authorized to publish in principle, but the scan found specific nonpublic elements that must be removed or masked first.\n- `denied_noncompliant` — the request cannot proceed: the requester was ineligible, required authorization is absent, or the content is fundamentally unsuitable for public release.\n\n**Record in AssureSwarm**\n- The authorization step result records source references for the existing request, exact content document, owner authority and agreement, plus any missing business purpose or audience supplied by the requesting content owner.\n- The classified intake register as a step document (coach-document-upload) — one row per distinct request with columns for request type (public posting vs external share), target system or recipient, and information classification. The eight-type schema has no native publication/sharing-request item, so this register document is the system of record for the queue; coach-item-create and coach-items-link maintain the register rows and their cross-references rather than standalone items.\n- Each external-sharing row cross-referenced to its governing agreement in the sharing-agreements register (coach-items-link as a register cross-reference — there is no native agreement item to link to).\n- Every external share with no matching agreement flagged in the register as a blocker.\n- Submit the `publication_disposition` SELECT field with the chosen branch value; record the decision rationale and evidence references in the step result, and name the decision owner or approver.\n- Training and roster-correction evidence for lapsed or unlisted requesters.\n- The authorization-verification log as a step document (coach-document-upload) — one row per external share recording the owner authorization, the item's classification, the linked agreement's permitted-use and recipient terms, and the pass/exception outcome, with each exception's fresh owner decision recorded against its row. There is no native authorization or request item, so outcomes live as rows here; coach-item-create and coach-items-link maintain the log rows and their cross-reference back to the intake-register row, not standalone items.\n- The eligibility-exception findings and the review packet attached to this step (coach-document-upload).\n\n**Exit criteria**\n- Every pending request has a distinct intake record with a classification and sufficient requester purpose; duplicates are consolidated; every external-sharing request is either linked to an agreement or flagged as missing one; the register is attached and the control owner has confirmed the queue is complete.\n- Every remaining request comes from a designated, trained poster or an authorized releaser, with flagged requesters held or rejected pending remediation; every external share in scope carries current, matching owner authorization and unresolved exceptions are held back from release; the `publication_disposition` routing selector is submitted and the step result contains a rationale and owner; the two unchosen branches are prunable.","kind":"decision","label":"Review and authorize publication","performedBy":{"primitives":["coach-query-data","coach-workflow-scan","coach-item-create","coach-items-link","coach-document-upload","coach-form-create"]}},"id":"review-and-authorize-publication"},{"data":{"description":"Agent removes flagged nonpublic information and prepares the corrected version; human confirms the redaction is complete before publication","instructions":"**Objective** — Remove every flagged nonpublic element from an item returned for redaction and prepare a clean version ready to publish.\n\n**Inputs**\n- The item(s) with disposition `return_for_redaction` and their review findings from \"Review and authorize publication\" (the flagged elements and their locations).\n\n**Procedure**\n1. Draft the redacted version of each returned item, removing or masking every flagged element identified in the review findings while preserving the intended public message.\n2. Re-scan the redacted version (coach-query-data) to confirm no flagged element remains.\n3. Update the intake record (coach-item-create) to reflect the redaction performed, and link the corrected version to the original request (coach-items-link).\n4. Attach the before-and-after redaction record (coach-document-upload).\n\n**Record in AssureSwarm**\n- The before/after redaction record as a step document (coach-document-upload), preserving the original flagged elements and the cleaned version side by side so a reviewer can confirm the removal.\n- The corrected version cross-referenced to its intake-register row (coach-item-create and coach-items-link update the register row to reflect the redaction performed — there is no native request item, so this is a register-row update rather than a new item).\n\n**Exit criteria** — Every flagged element is verifiably removed; the corrected content preserves its public message; the control owner has confirmed the item is ready to publish.\n\n> **⚡ Audit Artist accelerator:** `/coach-redact` masks the flagged nonpublic elements and produces the before-and-after redaction record for review.","label":"Redact and resubmit content","performedBy":{"primitives":["coach-query-data","coach-redact","coach-item-create","coach-items-link","coach-document-upload"]}},"id":"redact-and-resubmit-content"},{"data":{"decisionField":"sweep_disposition","description":"Agent reconciles the documented no-authentication actions against live system configuration and inspects live public-facing content against the classification scheme; human classifies the sweep as clean or exposure found","formData":{"fields":[{"key":"sweep_disposition","label":"Sweep Disposition","options":[{"label":"Clean, no exposure found","value":"clean_no_exposure"},{"label":"Exposure found","value":"exposure_found"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Keep the documented set of actions permitted without identification or authentication explicit, current, and limited to designated public functions, then decide whether the quarterly inspection of live public-facing content found any nonpublic exposure. Owned by the Public Content Release Officer.\n\n**Inputs**\n- The permitted-without-authentication register (each public-facing system and the functions it exposes without login) and the live configuration of each in-scope public system. This path runs on the quarterly cadence independent of the per-request queue — the register and live config are its initial inputs.\n- The public-content register's inventory of published items across the public website, portal, documentation, status page, social channels, public API responses, and object storage.\n- The information-classification scheme (a Policy item, policy_type: standard) governing what may appear on a public surface.\n\n**Procedure**\n_Items 1–8 are agent-run (items 1–4 folded from the former \"Maintain permitted-without-authentication register\" step); the human moment is the sweep classification in item 9._\n1. Pull the current permitted-without-authentication register (coach-query-data), covering each system and its no-login functions (for example public search, status pages, password-reset initiation, public API read endpoints).\n2. Query the live configuration of each in-scope system and compare it against the register to detect drift: anonymous-accessible functions not on the documented list, or documented functions no longer present.\n3. Compile the drift findings with system, function, and discrepancy type for each, and assign an owner to every drift item.\n4. Update the register to reflect confirmed, approved functions and attach the refreshed register plus drift findings (coach-document-upload).\n5. Pull the full inventory of published items from the public-content register (coach-query-data), covering the public website, portal, documentation, status page, social channels, and any public API responses or object storage.\n6. Inspect each item's live current state against the classification scheme, checking specifically for nonpublic information added after original publication (linked documents, embedded metadata, revised pages).\n7. Cross-reference the findings against the refreshed permitted-without-authentication register to confirm no undocumented anonymous-accessible function is exposing nonpublic data.\n8. Build an exposure-sweep dashboard (coach-dashboard-create) summarizing systems checked, items inspected, and findings by severity, and attach the sweep findings report (coach-document-upload).\n9. Classify the sweep against the criteria below and submit the SELECT.\n\n**Decision criteria**\n- `clean_no_exposure` — every inspected public surface matches its intended classification; no nonpublic information (PII, credentials, internal data, stale documents, revealing metadata) is exposed, and the register is limited to designated public functions with no unexplained drift.\n- `exposure_found` — at least one item exposes nonpublic information — for example content added after original publication, a linked document, embedded metadata, or an undocumented anonymous-accessible function — that must be removed or corrected.\n\n**Record in AssureSwarm**\n- Submit the `sweep_disposition` SELECT field with the chosen branch value; record the rationale and evidence references and name the decision owner.\n- The refreshed permitted-without-authentication register and its drift findings attached to this step (coach-document-upload).\n- The exposure-sweep dashboard (coach-dashboard-create) and the sweep findings report (coach-document-upload).\n\n**Exit criteria** — The register is complete, explicitly documented, and limited to designated public functions, with any drift assigned an owner; the `sweep_disposition` routing selector is submitted and the step result contains a rationale and owner; the unchosen branch is prunable.","kind":"decision","label":"Sweep public surfaces for exposure","performedBy":{"primitives":["coach-query-data","coach-dashboard-create","coach-document-upload"]}},"id":"sweep-public-surfaces-for-exposure"},{"data":{"description":"Agent removes exposed nonpublic content and opens a corrective action; human confirms the exposure is fully cleared","instructions":"**Objective** — Eliminate any nonpublic information found exposed on a public surface and track the correction to closure.\n\n**Inputs**\n- The exposure findings and dashboard from \"Sweep public surfaces for exposure\" (disposition `exposure_found`), with each exposed item and its location.\n\n**Procedure**\n1. Remove or replace the exposed content on the live system immediately, and purge it from any cache, CDN edge, or search index where feasible; confirm removal took effect (coach-query-data).\n2. Create a corrective-action item per exposure (coach-item-create) capturing root cause, owner, and due date, and link it to the sweep finding (coach-items-link).\n3. Notify the information owner and the requester who originally published the item; flag the permitted-without-authentication register or the public-content register for update if the root cause was an undocumented function or a stale posting.\n4. Attach the remediation and removal evidence (coach-document-upload).\n\n**Record in AssureSwarm**\n- One Issue per exposure (coach-item-create) — issue_type: finding, source: self_assessment, severity set to the exposure's risk, root_cause, issue_owner, identified_date, and target_remediation_date — linked to the anchor UC-ACCESS-14 Control (coach-items-link: Issue ↔ Control) and cross-referenced to the sweep finding.\n- Owner and original-publisher notifications and the removal evidence attached to this step (coach-document-upload); the permitted-without-authentication register or public-content register flagged for update where the root cause was an undocumented function or a stale posting.\n\n**Exit criteria** — The exposed information is verifiably no longer publicly retrievable; each corrective action is owned and dated; affected parties were notified; the control owner has confirmed the exposure is cleared.\n\n> **⚡ Audit Artist accelerator:** `/coach-notify` sends the exposure notice to the information owner and the original publisher.","label":"Remediate exposure and notify","performedBy":{"primitives":["coach-query-data","coach-item-create","coach-items-link","coach-notify","coach-document-upload"]}},"id":"remediate-exposure-and-notify"},{"data":{"description":"Automatically archive the authorized cycle record and carry open actions into the next cycle.","instructions":"**Objective** — Automatically preserve the authorized cycle record and its carry-forward actions after the preceding decision.\n\n**Inputs**\n- Items reaching this step either directly approved (`approved_to_publish`) at \"Review and authorize publication\" or cleared through \"Redact and resubmit content\".\n- The intake and authorization records for each item.\n- Items with disposition `denied_noncompliant` from \"Review and authorize publication\" and the specific eligibility or review finding behind each.\n- All completed release, denial, redaction, register, sweep, and remediation records from this cycle (the terminal outputs of both the per-request authorization path and the quarterly sweep path).\n\n**Procedure**\n_After the preceding authorized decision, run the packaging, linkage, archival and carry-forward procedure automatically. No additional human approval is required._\n1. Publish and record release (run this phase only for approved_to_publish or a successfully cleared redaction; skip it for denied requests and the independent sweep): Release the approved, authorized item to its target public system or external party and record it in the public-content and external-share register for lifecycle tracking.\n2. Post the approved item to its target public-facing system, or transmit it to the authorized external party through the agreed channel — using only the exact approved version.\n3. Create a release record (coach-item-create) capturing publish date, channel or recipient, classification, and the approving decision.\n4. Link the release record to the intake and authorization records (coach-items-link).\n5. Update the public-content and external-share register so the item is tracked for the quarterly sweep and any future takedown, and attach the release confirmation (coach-document-upload).\n6. Log denial and close request (run this phase only for denied_noncompliant requests; skip it for approved or redacted releases and the independent sweep): Close each denied request with a documented reason and requester guidance, confirming no content was released.\n7. Record the denial reason for each denied item (coach-item-create), referencing the specific eligibility or review finding that drove the decision.\n8. Draft a notification to the requester explaining the denial and the corrective steps needed to resubmit, and link it to the request (coach-items-link).\n9. Confirm no partial or draft version of the content remains accessible on any public system or was sent to the external party.\n10. Attach the denial log (coach-document-upload).\n11. Close and archive: Close the operating cycle, preserve the audit trail under retention, and seed the next cycle so nothing is left untracked.\n12. Export the full operating record (coach-workflow-export), covering publication decisions, external-sharing authorizations, the permitted-without-authentication register, and the quarterly sweep findings; archive it in the designated evidence repository under retention controls.\n13. Create carry-forward items (coach-item-create) for any open redactions, denials pending resubmission, or open corrective actions, and link them to their source (coach-items-link) so they arrive as explicit inputs to the next cycle.\n14. Update the control execution log with the cycle result and key metrics (requests processed, denials, redactions, exposures found and remediated), and confirm the next quarterly sweep is scheduled.\n15. Attach the closure record (coach-document-upload).\n\n**Record in AssureSwarm**\n- The public-content and external-share register updated with a release row capturing publish date, channel or recipient, classification, and the approving disposition — the schema has no native publication/release item, so this register document is the system of record; coach-item-create and coach-items-link maintain the release row and its cross-reference to the intake and authorization rows. The updated register is attached to this step (coach-document-upload).\n- The release confirmation attached to this step (coach-document-upload).\n- The denial log as a step document (coach-document-upload) — one row per denied request with the denial reason and the specific eligibility or review finding that drove it. There is no native request item, so the denial is recorded as a log/register row; coach-item-create and coach-items-link maintain the row and its cross-reference to the intake-register row, not a standalone item.\n- The requester notification copy attached to this step (coach-document-upload).\n- The full operating record exported (coach-workflow-export) and archived under retention in the designated evidence repository; the workflow instance itself, attached to the UC-ACCESS-14 Control, stands as the durable audit trail for the cycle.\n- Carry-forward Issue items (coach-item-create) for any open redactions, denials pending resubmission, or open corrective actions — issue_type: observation, issue_owner, target_remediation_date — each linked to the anchor Control (coach-items-link: Issue ↔ Control) so they arrive as existing inputs to the next cycle.\n- The closure record attached to this step (coach-document-upload).\n\n**Exit criteria**\n- The published or shared content matches exactly what was approved with no last-minute unauthorized change; the register entry is complete; the exact approved release and its register entry have been automatically verified.\n- Every denial is documented with a clear reason, the requester was notified, and no unauthorized content was released; the request is closed.\n- The archived record is immutable and retrievable; the next quarterly sweep is scheduled; nothing remains open without a tracked owner; the authorized cycle record is complete.\n\n> **⚡ Audit Artist accelerator:** `/coach-notify` drafts and sends the requester denial notice with the corrective-resubmission steps.","label":"Close and archive","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-document-upload","coach-notify","coach-workflow-export"]},"requiredApprovals":0},"id":"close-and-archive"}],"sourceTemplateId":"workflow-library:controls-public-content-external-sharing-authorization"}
