{"description":"Runs on the existing system item. Record an emergency change that bypassed normal change control, evidence the elevated access used, and retrospectively test whether the bypass was justified. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","edges":[{"id":"e-emergency-intake-emergency-closure","source":"emergency-intake","target":"emergency-closure"}],"isPublic":true,"itemTypeSlug":"system","metadata":{"capabilities":["emergency-change"],"controlVerbs":{"UC-SDLC-07":"operates"},"controls":["UC-SDLC-07"],"department":"it","domains":["controls"],"kind":"emergency-change","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:emergency-change"}],"canonicalUrl":"https://workflow-library.com/all/?w=controls-system-emergency-change","contentDigest":"sha256:1e33df05e7ecbc3cc43cd5aca7ad1e022ffb1238e7f44143982f46a51eea4a33","prerequisites":{"anchorItemType":{"slug":"system"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"handoffs":[{"direction":"output","name":"Accepted retrospective, access-closure evidence and remediation actions for the change authority and the tenant's approved emergency-change procedure"}],"roles":[{"contribution":"approval","description":"Emergency change authority. Record the emergency and authorization.","id":"reviewer-1","nodeIds":["emergency-intake"]},{"contribution":"approval","description":"Independent retrospective reviewer. Approve emergency change record.","id":"reviewer-2","nodeIds":["emergency-closure"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:emergency-change"}],"releaseId":"sha256:1e33df05e7ecbc3cc43cd5aca7ad1e022ffb1238e7f44143982f46a51eea4a33","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-system-emergency-change"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-system-emergency-change","source":"coworkcanvas-gallery","standards":[],"teams":["it"]},"name":"Emergency Change","nodes":[{"data":{"instructions":"**Objective**\nRecord the emergency and authorization. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, the incident or outage record, the emergency-change policy and its authorization matrix, the authorizer identity and role, and the business impact being averted.\n\n**Procedure**\n1. Establish that the trigger genuinely met the emergency criteria rather than reflecting poor planning, confirm the authorizer held the delegated authority, capture the authorization timestamp relative to the change, and compute the retrospective review deadline.\n\n**Record in AssureSwarm**\n1. Capture the incident reference, trigger and business impact, emergency criteria met, authorizer identity and authority basis, authorization timing relative to the change, and the retrospective review deadline. Also record emergency justification and authorization.\n\n**Exit criteria**\nEmergency change authority provides approval: The emergency criteria and delegated authority are evidenced, authorization timing relative to the change is recorded honestly, and the retrospective deadline is set.","kind":"task","label":"Record the emergency and authorization","requiredApprovals":1},"id":"emergency-intake"},{"data":{"controls":["UC-SDLC-07"],"instructions":"**Objective**\nApprove emergency change record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use production change and deployment logs, session recordings, break-glass checkout records, the elevated-access grant and its expiry, and post-change system state.\n2. Use the authorization record, the reconstructed change, incident timeline, testing performed after the fact, comparable prior emergencies, and the emergency-change rate for this system.\n3. Review all stage records, authorization timing, log-reconstructed change, elevated access grant and revocation, retrospective testing, control gaps, and remediation owners.\n\n**Procedure**\n1. Reconstruct the change from system logs rather than from recollection, record every command or artifact applied, confirm elevated access carried an expiry, and verify that break-glass credentials were rotated after use.\n2. Test the change against the requirements it should have met, compare the emergency rate against normal change volume for a pattern of routine bypass, confirm the review happened inside the policy window, and classify avoidable emergencies as control gaps.\n3. Trace the applied change to the authorization and to post-hoc testing, verify elevated access was revoked and credentials rotated, confirm control gaps carry remediation, and return self-justifying retrospectives with precise comments.\n\n**Record in AssureSwarm**\n1. Document the change applied with log references and timestamps, access class used, elevated grant and expiry, credential rotation after use, session evidence, and any change made beyond the emergency scope.\n2. Record the retrospective result, review date against the deadline, post-hoc testing performed, emergency-rate observations, control gaps identified, remediation with owners and dates, and unauthorized changes escalated. Also record remediation detail.\n3. Capture the authorized reviewer, the summary, accepted retrospective result, review date, elevated-access closure evidence, control gaps and remediation with owners and dates, and linked exceptions raised. Also record emergency change summary.\n\n**Exit criteria**\nIndependent retrospective reviewer provides approval: The applied change is reconstructed from logs, elevated access is shown to be time-bound and revoked, and scope creep beyond the emergency is surfaced rather than folded in. An approver accepts that the retrospective rests on post-hoc testing rather than restated justification, late reviews are recorded as such, and routine bypass patterns are surfaced as control gaps. The authorized reviewer accepts the record as evidence the emergency-change control operated, and closure implies no assurance that the bypassed normal controls would have passed.","kind":"task","label":"Approve emergency change record","requiredApprovals":1},"id":"emergency-closure"}],"sourceTemplateId":"workflow-library:controls-system-emergency-change"}
