{"description":"Monthly operator cycle for the standing user-activity and external-exposure monitoring control (UC-LOG-07/UC-LOG-11) — a detective, monthly-frequency Control that already exists in the control library. Each cycle runs as one workflow instance attached to that existing Control (enrich it — never create a duplicate control); the accountable owner and cadence come from Control.control_owner and Control.frequency=monthly. The instance runs the restricted privileged/remote session and acceptable-use review alongside the external open-source and dark-web exposure sweep, then converges every confirmed finding from both halves — each recorded as an Issue item linked to the anchor Control — into one consolidated restricted case log (XLSX) for security-event evaluation. Consumes upstream: no workflow feeds it — session capture and the exposure sweep are the two parallel entry points; each cycle draws on the standing monitoring program's authorized-reviewer roster, the acceptable-use policy and employee-monitoring disclosure notice (Policy items), the external search-set markers, and the prior cycle's carry-forward Issues. Named deliverables: the personnel-activity and exposure disposition decisions, the HR/legal referral and takedown Issues, the cycle-health dashboard, and the consolidated restricted case log. Downstream handoff: confirmed findings hand into the security-event evaluation queue — an informal handoff recorded as a reference on each case-log entry and in each Issue.description, since the graph has no terminal handoff node. In scope: privileged/remote session review, personnel acceptable-use monitoring, and the external open-source/dark-web exposure sweep for one monthly cycle. Out of scope: the automated SIEM alerting pipeline and the downstream security-event evaluation itself.","edges":[{"id":"e-review-activity-and-acceptable-use-coordinate-hr-legal-handling","label":"Escalate","source":"review-activity-and-acceptable-use","target":"coordinate-hr-legal-handling","whenValue":"escalate_to_hr_legal"},{"id":"e-review-activity-and-acceptable-use-classify-monitoring-cycle-readiness","label":"No findings","source":"review-activity-and-acceptable-use","target":"classify-monitoring-cycle-readiness","whenValue":"no_findings"},{"id":"e-coordinate-hr-legal-handling-classify-monitoring-cycle-readiness","source":"coordinate-hr-legal-handling","target":"classify-monitoring-cycle-readiness"},{"id":"e-sweep-external-exposure-channels-alert-and-initiate-takedown","label":"Exposure confirmed","source":"sweep-external-exposure-channels","target":"alert-and-initiate-takedown","whenValue":"exposure_confirmed"},{"id":"e-sweep-external-exposure-channels-classify-monitoring-cycle-readiness","label":"No exposure","source":"sweep-external-exposure-channels","target":"classify-monitoring-cycle-readiness","whenValue":"no_exposure_detected"},{"id":"e-alert-and-initiate-takedown-classify-monitoring-cycle-readiness","source":"alert-and-initiate-takedown","target":"classify-monitoring-cycle-readiness"},{"id":"e-classify-monitoring-cycle-readiness-log-corrective-actions","label":"Gaps","source":"classify-monitoring-cycle-readiness","target":"log-corrective-actions","whenValue":"gaps_identified"},{"id":"e-classify-monitoring-cycle-readiness-close-and-archive","label":"Healthy","source":"classify-monitoring-cycle-readiness","target":"close-and-archive","whenValue":"healthy"},{"id":"e-log-corrective-actions-close-and-archive","source":"log-corrective-actions","target":"close-and-archive"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-LOG-07","UC-LOG-11"],"department":"it","domains":["controls"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=controls-user-activity-external-exposure-monitoring","contentDigest":"sha256:507a4a5bfc78815b47c68f319b5e08063e17570820c2df86cc5c083de3191bce","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:507a4a5bfc78815b47c68f319b5e08063e17570820c2df86cc5c083de3191bce","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-user-activity-external-exposure-monitoring"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-user-activity-external-exposure-monitoring","source":"coworkcanvas-gallery","standards":["nist-800-53","nist-csf-2"],"teams":["it","hr"]},"name":"User Activity & External Exposure Monitoring","nodes":[{"data":{"decisionField":"personnel_activity_disposition","description":"Agent captures the cycle privileged and remote sessions into an access-restricted review set and reviews them and personnel technology usage against misuse indicators and acceptable-use expectations; human decides whether findings escalate to HR and legal","formData":{"fields":[{"key":"personnel_activity_disposition","label":"Personnel Activity Disposition","options":[{"label":"No findings, within acceptable use","value":"no_findings"},{"label":"Escalate to HR and legal","value":"escalate_to_hr_legal"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Assemble the cycle's complete privileged and remote session review set under the authorized-reviewer restriction, review it with personnel technology usage against acceptable-use expectations, and resolve whether the activity stays within acceptable use or whether one or more flags must be handled by HR and legal counsel as a personnel matter. The insider-risk analyst owns this call.\n\n**Inputs**\n- Cycle scope: the monthly window (start/end dates), the accountable control owner, and whether this is routine cadence or a referral-triggered accelerated pass. This is a workflow entry — no upstream workflow feeds it; scope and roster are established here from the standing monitoring program.\n- The authorized-reviewer roster: the named individuals permitted to view captured session data this cycle, plus the current employee-monitoring disclosure notice that governs user notice.\n- Source platforms: the session-recording, privileged-access-management (PAM), and remote-access/VPN systems that record in-scope sessions, plus personnel technology-usage telemetry (web, endpoint, collaboration tools) and the acceptable-use policy.\n- Control references: NIST 800-53 AU-14 (session audit) and AU-13 (monitoring for information disclosure); NIST CSF 2.0 DE.CM-03 (personnel activity monitoring).\n\n**Procedure**\n_Items 1–8 are agent-run (folded from the former \"Capture and restrict session activity\" step, which carried no separate human touch-point); the human moment is the disposition call in item 9._\n1. Confirm scope and roster before touching content: list the systems that produce privileged and remote session records for the window, confirm the authorized-reviewer roster, and confirm the employee-monitoring disclosure is current. If the disclosure has lapsed, stop and escalate — captured content may not be reviewed under a stale notice.\n2. Query the session-recording, PAM, and remote-access platforms for every privileged or remote session inside the cycle window; compile the candidate review set with session id, actor, system, start/end time, and source platform.\n3. Create a session-review case scoped to the cycle, and link each captured session record to it so the review set has one addressable container.\n4. Apply and verify the access restriction on the review set against the authorized-reviewer roster: enumerate current grants, revoke any stale grant (departed reviewer, role change), and log the resulting grant list with timestamps.\n5. Reconcile completeness: cross-check the captured session count against the source-platform totals for the window; a shortfall means a source was missed — resolve it before review begins.\n6. Review the captured privileged and remote sessions against defined misuse indicators (unusual data movement, off-hours privileged commands, access outside job function) and flag each with its evidence.\n7. Separately query personnel technology-usage logs (web, endpoint, collaboration-tool telemetry) against the acceptable-use policy and flag usage that surfaces a potentially adverse event.\n8. Cross-reference every flag against the disclosed monitoring terms to confirm it falls within noticed monitoring scope, noting any flag requiring user disclosure before further action, and assemble the review packet.\n9. The insider-risk analyst reviews the packet and submits the disposition against the criteria below.\n\n**Decision criteria**\n- `no_findings` — Every reviewed session and every acceptable-use flag is explainable as routine, authorized activity within noticed monitoring scope; nothing rises to a personnel concern. Pick this when all misuse indicators and usage flags clear on review.\n- `escalate_to_hr_legal` — One or more flags evidences potential misuse or a potentially adverse personnel event that needs HR and legal counsel to own — e.g., confirmed exfiltration-pattern data movement, privileged access used outside job function, or an acceptable-use violation carrying employment or legal consequence. Any single such flag forces this branch.\n\n**Record in AssureSwarm**\n- Submit the `personnel_activity_disposition` SELECT (`no_findings` | `escalate_to_hr_legal`).\n- Record the decision rationale with specific evidence references in the step result, and the decision owner or approver in the step's approver record.\n- Create the session-review case item (coach-item-create) and link each session record to it (coach-items-link).\n- Attach the captured-session inventory, the access-grant log, and the review packet summarizing every flag and its evidence (coach-document-upload); query the source platforms and telemetry via coach-query-data.\n\n**Exit criteria** — The captured set covers every in-scope privileged and remote session for the period with the count reconciled to source totals; access is restricted to the named authorized reviewers with no stale grants outstanding; the case, its links, the inventory, and the grant log are in place; the form is submitted with a rationale citing the specific flags, their evidence, and the disclosure status; the unused branch is prunable.","kind":"decision","label":"Review activity and acceptable use","performedBy":{"primitives":["coach-query-data","coach-document-upload","coach-item-create","coach-items-link"]}},"id":"review-activity-and-acceptable-use"},{"data":{"description":"Agent packages the flagged findings and routes them to HR and legal counsel with any required user disclosure; human confirms findings are owned and handled per the monitoring terms","instructions":"**Objective** — Route each escalated personnel-activity finding to HR and legal counsel for ownership and complete any user disclosure the monitoring terms require, so no finding rests with the insider-risk analyst alone.\n\n**Inputs**\n- The escalated flags from the `escalate_to_hr_legal` branch of the activity/acceptable-use review: the flagged session or usage evidence, the acceptable-use provision at issue, and the disclosure status for each.\n- The disclosed employee-monitoring terms that govern whether and when the affected user must be notified.\n- HR and legal counsel intake contacts and their agreed intake path.\n\n**Procedure**\n1. For each escalated finding, package the evidence (session-recording reference or usage-log extract), the acceptable-use provision breached, and the current disclosure status as an HR/legal referral item, and link the underlying session or usage evidence to it.\n2. Route each referral to HR and legal counsel through the agreed intake path, and capture their native acknowledgment of receipt and ownership. Obtain their direction on preservation, disclosure timing and further handling before taking the affected action.\n3. Where the disclosed monitoring terms require the affected user be notified before further action, prepare the disclosure notice, deliver it, and track the delivery outcome.\n4. Record any hold instructions from counsel (e.g., preserve-in-place, do not confront the user) so downstream consolidation does not act prematurely.\n\n**Record in AssureSwarm**\n- Create each HR/legal referral item (coach-item-create) and link the underlying evidence (coach-items-link).\n- Record the approved disclosure, recipient, delivery time and actual delivery outcome in the native referral result and communication evidence. These are executor records; do not create a disclosure-tracking questionnaire.\n- Attach the referral log and disclosure record (coach-document-upload).\n\n**Exit criteria** — Every escalated finding is received and owned by HR and legal counsel (acknowledged); any required user disclosure is completed per the monitoring terms and recorded; no finding is left with the insider-risk analyst alone to decide.","label":"Coordinate HR and legal handling","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-form-create","coach-document-upload"]}},"id":"coordinate-hr-legal-handling"},{"data":{"decisionField":"exposure_disposition","description":"Agent sweeps public websites, code repositories, paste/file-sharing sites, and dark-web sources for improperly disclosed organizational information; human decides whether exposure is confirmed","formData":{"fields":[{"key":"exposure_disposition","label":"Exposure Disposition","options":[{"label":"No exposure detected","value":"no_exposure_detected"},{"label":"Exposure confirmed","value":"exposure_confirmed"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Resolve whether the monthly open-source and dark-web sweep surfaced a genuine improper disclosure of organizational information or nothing actionable. The insider-risk analyst owns this call. This sweep is an independent workflow entry: it consumes the monitoring program's identifying terms and markers, not another node's output, and runs in parallel with the session-review half.\n\n**Decision criteria**\n- Preparation the agent performs first: run the defined search set against public websites and search engines, code-repository hosts, paste and file-sharing sites, and dark-web monitoring sources, using the organization's identifying terms, credential patterns, and proprietary markers; compile every hit with its source URL or location, the information exposed, and a preliminary sensitivity classification; cross-reference each hit against the prior cycle's known and already-remediated exposures to filter duplicates and confirm genuinely new disclosures.\n- `no_exposure_detected` — Every hit is a false positive, a benign public mention, or a previously-remediated exposure already tracked; nothing found is a new genuine improper disclosure.\n- `exposure_confirmed` — One or more hits confirm organizational information has been improperly disclosed — leaked credentials, proprietary source, confidential documents, or customer data — and is newly surfaced this cycle.\n\n**Record in AssureSwarm**\n- Submit the `exposure_disposition` SELECT (`no_exposure_detected` | `exposure_confirmed`).\n- Record the rationale with the confirmed hits' locations and classification in the step result, and the decision owner in the step's approver record.\n- Attach the exposure-sweep report (coach-document-upload); run searches via coach-query-data and de-duplicate against prior cycles via coach-workflow-scan.\n\n**Exit criteria** — The form is submitted with a rationale referencing the specific hits (or their absence); duplicates are filtered; the unused branch is prunable.","kind":"decision","label":"Sweep external exposure channels","performedBy":{"primitives":["coach-query-data","coach-workflow-scan","coach-document-upload"]}},"id":"sweep-external-exposure-channels"},{"data":{"description":"Agent alerts designated personnel and files takedown or mitigation requests for each confirmed exposure; human confirms alerting and takedown were initiated without amplifying exposure","instructions":"**Objective** — For each confirmed exposure, alert the designated personnel out-of-band and file a takedown or mitigation request, without amplifying the exposure.\n\n**Inputs**\n- The confirmed exposures from the `exposure_confirmed` branch of the exposure sweep: source or host, content exposed, and sensitivity classification.\n- The pre-defined out-of-band alert channel and the designated-personnel roster (security leadership, legal, communications as applicable).\n- Takedown paths per channel: hosting-platform, repository, and paste-site abuse routes, plus the designated dark-web mitigation path.\n\n**Procedure**\n1. The designated security/legal authority approves the exact recipients, restricted alert and takedown or mitigation action in the native result before dispatch. Alert the designated personnel through the pre-defined out-of-band channel for each confirmed exposure — deliberately without forwarding, re-posting, or linking the exposed content itself, so the alert does not widen distribution.\n2. Open a takedown case for each confirmed exposure capturing source, host or platform, content exposed, and classification, and link the sweep evidence to it.\n3. File the takedown or mitigation request with the hosting platform, repository, or paste-site operator (or the designated dark-web mitigation path), and record the request reference and time.\n4. Track acknowledgment and removal status; set a follow-up for any request not confirmed removed, so it carries forward rather than silently lapsing.\n\n**Record in AssureSwarm**\n- Open the takedown case item (coach-item-create) and link the sweep evidence (coach-items-link).\n- Send the out-of-band alert (coach-notify).\n- Attach the alert log and takedown-tracking record (coach-document-upload).\n\n**Exit criteria** — Designated personnel are alerted for every confirmed exposure with no alert amplifying it; a takedown or mitigation request is filed and tracked, with a removal-status follow-up, for each case.\n\n> **⚡ Audit Artist accelerator:** `/coach-notify` — dispatches the out-of-band alert to the designated-personnel roster without embedding the exposed content.","label":"Alert and initiate takedown","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-document-upload","coach-notify"]}},"id":"alert-and-initiate-takedown"},{"data":{"decisionField":"readiness_disposition","description":"Judge the consolidated cycle evidence and capability tolerances, including access, notice, coverage and takedown aging, and select the corrective path.","formData":{"fields":[{"key":"readiness_disposition","label":"Readiness Disposition","options":[{"label":"Healthy, within tolerance","value":"healthy"},{"label":"Gaps identified","value":"gaps_identified"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Judge the consolidated cycle evidence and capability tolerances, including access, notice, coverage and takedown aging, and select the corrective path.\n\n**Inputs**\nPersonnel-activity outcome: HR/legal-confirmed findings from the HR/legal coordination step (escalate path), or the recorded `no_findings` disposition.\n- External-exposure outcome: confirmed exposures and takedown cases from the alert-and-takedown step (exposure path), or the recorded `no_exposure_detected` disposition.\n- The authorized-reviewer roster, for re-asserting the restriction.\n- Downstream consumer: the security-event evaluation queue. There is no separate downstream workflow file — the linkage is this handoff reference recorded on each entry.\n\n**Decision criteria**\n*The agent prepares the combined evidence and performs the recordkeeping below. Control owner owns the stated judgments and authorizations.*\n\n*Consolidate the restricted case log.* Merge every confirmed finding from both halves of the cycle — personnel-activity and external exposure — into the single restricted case log that feeds security-event evaluation, exactly once each and with access still restricted.\n\n1. Pull every HR/legal-confirmed personnel finding and every confirmed external-exposure or takedown case from this cycle.\n2. For each confirmed finding, create or update a consolidated restricted-case-log entry tagging its source (session/usage vs external exposure) and current status, and link each entry to its originating referral or takedown case. If both halves resolved to no findings and no exposure, record the null-result cycle entry so the log still evidences the sweep ran.\n3. De-duplicate: ensure each finding appears exactly once even if it surfaced in both halves (e.g., an insider who also leaked externally).\n4. Hand each entry into the security-event evaluation queue for downstream assessment, and record the handoff reference on the entry.\n5. Re-assert the access restriction on the consolidated log against the authorized-reviewer roster.\n\n*Classify monitoring cycle readiness.* Resolve whether the standing monitoring capability operated within tolerance this cycle or carries gaps needing tracked corrective action. The control owner owns this call.\n\n\n\nPreparation the agent performs first: compute the cycle metrics — session and usage review coverage, access-restriction compliance, disclosure completion, sweep-frequency adherence, and open-takedown aging — build a cycle-health dashboard showing each metric against its threshold and trend against prior cycles, and list every breach with its owner and evidence.\n- `healthy` — Every metric is within tolerance: full review coverage, no restriction lapse, all required disclosures completed, the sweep run at the defined monthly frequency, and no takedown aging past its SLA.\n- `gaps_identified` — Any restriction lapse (a stale grant reviewed content), missed or late disclosure, missed or late sweep, or a takedown aging past SLA exists. A single breach forces this branch.\n\n**Record in AssureSwarm**\nCreate or update consolidated entries (coach-item-create) and link them to their originating cases (coach-items-link).\n- Query the confirmed findings via coach-query-data.\n- Attach the consolidated restricted case log (coach-document-upload).\n\nSubmit the `readiness_disposition` SELECT (`healthy` | `gaps_identified`).\n- Record the rationale citing the specific metric breaches in the step result, and the decision owner in the step's approver record.\n- Build the cycle-health dashboard (coach-dashboard-create), compute metrics via coach-query-data, and attach the readiness summary (coach-document-upload).\n\n**Exit criteria**\nEvery confirmed finding from both halves appears exactly once in the restricted case log; each carries a security-event-evaluation handoff reference; the log's access remains restricted to authorized reviewers.\n\nThe form is submitted with a rationale referencing the metrics and dashboard; the unused branch is prunable.","kind":"decision","label":"Classify monitoring cycle readiness","performedBy":{"primitives":["coach-query-data","coach-item-create","coach-items-link","coach-document-upload","coach-dashboard-create"]}},"id":"classify-monitoring-cycle-readiness"},{"data":{"description":"Agent converts each identified gap into an owned corrective action; human confirms every gap is tracked before closure","instructions":"**Objective** — Convert every gap identified at the readiness review into an owned, tracked corrective action so nothing degrades the standing monitoring capability unaddressed.\n\n**Inputs**\n- The readiness summary and dashboard from the `gaps_identified` branch of the readiness decision: each breached metric or case with its owner and evidence.\n- The corrective-action register (or create one for this cycle).\n\n**Procedure**\n1. Parse the readiness summary into a list of gaps, each with its root cause and the metric or case that surfaced it.\n2. Propose a corrective-action item for each gap capturing root cause, named owner, due date, and interim mitigation. Obtain each accountable owner’s native acceptance, then register the commitment and link it to the driving metric or case.\n3. Raise capability-level improvement items for systemic gaps — a chronically incomplete reviewer roster, a stale monitoring disclosure, or an unmonitored exposure channel — distinct from one-off fixes.\n4. Escalate any regulatory or contractual breach (for example, monitoring conducted under a lapsed disclosure) to the accountable owner immediately, not just via the register.\n\n**Record in AssureSwarm**\n- Create each corrective-action item (coach-item-create) and link it to its driving metric or case (coach-items-link).\n- Attach the corrective-action register (coach-document-upload).\n\n**Exit criteria** — Every gap has a named owner and a due date; systemic gaps are raised as capability items; any regulatory or contractual breach is escalated; nothing is left untracked before closure.","label":"Log corrective actions","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-document-upload"]}},"id":"log-corrective-actions"},{"data":{"description":"Archive the authorized operating record and carry forward owned open matters without another human confirmation.","instructions":"**Objective** — Close the monthly operating cycle, preserve the audit trail for the required retention period, and seed the next cycle's inputs.\n\n**Inputs**\n- The consolidated restricted case log and all cycle artifacts.\n- Open corrective actions, open takedown cases still awaiting removal confirmation, and any pending HR/legal matters.\n- The designated evidence repository and its retention controls; the monitoring schedule.\n\n**Procedure**\n1. Export the full operating record (coach-workflow-export) and archive it in the designated evidence repository under retention controls; record the archive location and reference.\n2. Carry forward the existing open corrective actions, takedown cases still awaiting removal confirmation, and pending HR/legal matters by linking each to its source so it arrives as an explicit input to the next cycle.\n3. Update the control execution log with the cycle result and key metrics, and confirm the next monthly review is scheduled.\n4. Confirm the archived record is immutable and retrievable by spot-retrieving one artifact.\n\n**Record in AssureSwarm**\n- Export the operating record (coach-workflow-export).\n- Create carry-forward items (coach-item-create) and link them to their source (coach-items-link).\n- Attach the closure record (coach-document-upload).\n\n**Exit criteria** — The archived record is immutable and retrievable; the next cycle is scheduled; nothing remains open without a tracked owner; and the recorded control-owner disposition and any required corrective-owner commitments are present; the agent records completion without a new human sign-off.","label":"Close and archive","performedBy":{"primitives":["coach-workflow-export","coach-item-create","coach-items-link","coach-document-upload"]},"requiredApprovals":0},"id":"close-and-archive"}],"sourceTemplateId":"workflow-library:controls-user-activity-external-exposure-monitoring"}
