{"description":"Runs on the existing system item. Run a periodic entitlement recertification for a system, evidence reviewer decisions, and confirm that required revocations were executed. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","edges":[{"id":"e-uar-distribution-uar-closure","source":"uar-distribution","target":"uar-closure"}],"isPublic":true,"itemTypeSlug":"system","metadata":{"capabilities":["periodic-user-access-review"],"controlVerbs":{"UC-ACCESS-02":"operates"},"controls":["UC-ACCESS-02"],"department":"it","domains":["controls"],"kind":"periodic-user-access-review","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:periodic-user-access-review"}],"canonicalUrl":"https://workflow-library.com/all/?w=controls-system-access-recertification","contentDigest":"sha256:e4c82920fd5501605623b273d6814f3976845ff2c498c45f5e88bfaf47aed9ae","prerequisites":{"anchorItemType":{"slug":"system"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:controls-user-access-review"}],"roles":[{"contribution":"expertise","description":"System owner and technical specialist. Distribute entitlement listings.","id":"reviewer-1","nodeIds":["uar-distribution"]},{"contribution":"approval","description":"Independent system-risk reviewer. Approve access review record.","id":"reviewer-2","nodeIds":["uar-closure"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:periodic-user-access-review"}],"releaseId":"sha256:e4c82920fd5501605623b273d6814f3976845ff2c498c45f5e88bfaf47aed9ae","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-system-access-recertification"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-system-access-recertification","source":"coworkcanvas-gallery","standards":[],"teams":["it"]},"name":"Periodic User Access Review","nodes":[{"data":{"instructions":"**Objective**\nDistribute entitlement listings. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, the entitlement extract and how it was generated, the identity directory, the reviewer assignment map, prior review results, and the recertification cadence in policy.\n2. Use the reconciled population, reviewer assignments, distribution tooling or campaign records, the response deadline, and escalation contacts for non-responding reviewers.\n\n**Procedure**\n1. Reconcile the extract to an independent count so completeness is evidenced rather than assumed, confirm reviewers hold the authority to decide, identify accounts with no accountable reviewer, and note privileged and service accounts requiring separate handling.\n2. Dispatch listings with the decision options and deadline stated, reconcile distributed line counts back to the population, chase undelivered listings, and record accounts covered by no dispatched listing as a gap rather than an omission.\n\n**Record in AssureSwarm**\n1. Capture the review period, population basis and reconciliation, extract date and generator, reviewer assignments, orphaned accounts, service and privileged accounts, and completeness limitations.\n2. Document reviewer assignments and dispatch dates, distribution status, line-count reconciliation to the population, undelivered listings, non-responding reviewers, and accounts left uncovered.\n\n**Exit criteria**\nSystem owner and technical specialist provides expertise: The population is evidenced as complete, every account has an accountable reviewer, and orphaned or unreviewable accounts are visible rather than dropped. Distributed listings reconcile to the population, the deadline and decision options were communicated, and uncovered accounts are named rather than silently excluded.","kind":"task","label":"Distribute entitlement listings","requiredApprovals":1},"id":"uar-distribution"},{"data":{"controls":["UC-ACCESS-02"],"instructions":"**Objective**\nApprove access review record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use returned reviewer responses and their timestamps, revocation tickets and system evidence, post-revocation extracts, non-response records, and prior-period recurring exceptions.\n2. Review all stage records, the population reconciliation, distribution coverage, reviewer responses, revocation evidence, non-responses, and residual exceptions with owners.\n\n**Procedure**\n1. Test response quality for blanket approval patterns and implausible turnaround, trace each removal decision to executed revocation evidence, re-extract to confirm removal, and treat non-response as a failure rather than as implicit approval.\n2. Trace the outcome to the population basis, verify uncovered accounts and non-responses carry owners, confirm revocation evidence is dated and independent, and return blanket-approval patterns with precise comments.\n\n**Record in AssureSwarm**\n1. Record the review outcome, response rates and quality observations, removal decisions traced to revocation evidence, revocations not executed, non-responses and their treatment, and recurring exceptions. Also record revocation detail and execution evidence.\n2. Capture the authorized reviewer, the review summary, accepted outcome, effective review date, next recertification cadence, unresolved exceptions with owners and dates, and linked issues raised. Also record access review summary.\n\n**Exit criteria**\nIndependent system-risk reviewer provides approval: An approver accepts that decisions are evidenced rather than rubber-stamped, required revocations are confirmed executed by re-extraction, and non-response is treated as an exception rather than approval. The authorized reviewer accepts the record as evidence the recertification control operated for the period, and closure implies no assurance over accounts excluded from the population.","kind":"task","label":"Approve access review record","requiredApprovals":1},"id":"uar-closure"}],"sourceTemplateId":"workflow-library:controls-system-access-recertification"}
