{"description":"Runs on the existing \"Personnel Security Administration\" Process item (process_type: security_process; process_owner: the HR Personnel Security Partner): each cycle is one workflow instance attached to that Process - enriching the standing process, never creating a duplicate - and on the disciplinary track the violation-case Issue it opens becomes the cycle's second anchor, linked back to that Process. A modular, decision-aware workflow: it designates position risk, runs proportional background verification for new hires, role changes, and the annual high-risk rescreen sweep, produces and retains the signed employment security and confidentiality agreements required before access, and - when a policy violation is reported - runs the graduated disciplinary process through sanction determination, PS-8 notification, and retention. It originates on its own HR triggers (no upstream workflow feeds it) and hands access provisioning and revocation to the downstream Joiner-Mover-Leaver Access Lifecycle workflow rather than performing them here. Named deliverables per cycle: the position-risk designation memo and derived screening set, the background-verification packet, the signed employment security and confidentiality agreements plus security-bearing position description, the violation-case Issue, the sanction documentation and PS-8 notification record, the awareness and control-improvement feedback Issues, and the archived cycle record. In scope: one personnel-security trigger per cycle - a single new hire, role change, annual high-risk rescreen, or material agreement re-signature on the screening-and-agreements track, or one reported policy violation on the disciplinary track; a role change that also surfaces a violation is run as two separate cycles.","edges":[{"id":"e-classify-personnel-event-track-assign-position-risk-designation","label":"Screening & agreements","source":"classify-personnel-event-track","target":"assign-position-risk-designation","whenValue":"screening_and_agreements"},{"id":"e-classify-personnel-event-track-determine-and-document-sanction","label":"Conduct violation","source":"classify-personnel-event-track","target":"determine-and-document-sanction","whenValue":"conduct_violation"},{"id":"e-assign-position-risk-designation-decide-screening-clearance","source":"assign-position-risk-designation","target":"decide-screening-clearance"},{"id":"e-decide-screening-clearance-execute-employment-security-agreements","label":"Cleared","source":"decide-screening-clearance","target":"execute-employment-security-agreements","whenValue":"cleared_for_access"},{"id":"e-decide-screening-clearance-resolve-screening-exception","label":"Hold for review","source":"decide-screening-clearance","target":"resolve-screening-exception","whenValue":"hold_pending_further_review"},{"id":"e-resolve-screening-exception-execute-employment-security-agreements","source":"resolve-screening-exception","target":"execute-employment-security-agreements"},{"id":"e-execute-employment-security-agreements-close-and-archive","source":"execute-employment-security-agreements","target":"close-and-archive"},{"id":"e-determine-and-document-sanction-document-sanction-and-notify","label":"Sanction imposed","source":"determine-and-document-sanction","target":"document-sanction-and-notify","whenValue":"sanction_imposed"},{"id":"e-determine-and-document-sanction-close-and-archive","label":"Closed, no sanction","source":"determine-and-document-sanction","target":"close-and-archive","whenValue":"closed_no_sanction"},{"id":"e-document-sanction-and-notify-close-and-archive","source":"document-sanction-and-notify","target":"close-and-archive"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-HR-01","UC-HR-02","UC-HR-04"],"department":"hr","domains":["grc"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=grc-personnel-screening-agreements-sanctions-administration","contentDigest":"sha256:d2e485a453e0634692cb0eeb10d2b2baf6047d54c4c8148e28914b9b78f59cd9","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:d2e485a453e0634692cb0eeb10d2b2baf6047d54c4c8148e28914b9b78f59cd9","schemaVersion":1,"sourceTemplateId":"workflow-library:grc-personnel-screening-agreements-sanctions-administration"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"grc-personnel-screening-agreements-sanctions-administration","source":"coworkcanvas-gallery","standards":["nist-800-53","iso-27001","hipaa"],"teams":["hr"]},"name":"Personnel Screening, Agreements & Sanctions Administration","nodes":[{"data":{"decisionField":"event_track","description":"Agent summarizes the trigger evidence against policy; human decides whether this cycle runs the screening-and-agreements track or the conduct-violation track.","formData":{"fields":[{"key":"event_track","label":"Personnel event track","options":[{"label":"Screening & agreements (new hire, role change, or annual high-risk rescreen)","value":"screening_and_agreements"},{"label":"Reported policy violation (disciplinary track)","value":"conduct_violation"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Resolve which track this cycle runs — proportional screening-and-agreements or the formal disciplinary process — so the correct downstream chain executes and neither track's obligations are skipped. Owned by the HR Personnel Security Partner.\n\n**Decision criteria**\n\nIdentify the event that opened this cycle - a new hire, a role change or transfer, a scheduled high-risk rescreen, a material agreement re-signature, or a reported policy violation - from the trigger sources (the onboarding queue, role-change requests, the rescreen due list, agreements flagged for re-signature, and violation reports). These feeds are external HR systems (HRIS / HR ticketing); the specific triggering report or request is uploaded to this step as PBC/external evidence, and this workflow instance attaches to the existing \"Personnel Security Administration\" Process item (process_type: security_process). Do not co-mingle two triggers in one cycle. Summarize that event against the personnel-security policy's definitions, then pick the branch the evidence supports.\n\n- **Screening & agreements (`screening_and_agreements`)** — the trigger is a new hire, a role change or transfer with an access or data-sensitivity change, an annual high-risk rescreen, or a material agreement re-signature. These all require (re)designating position risk (PS-2), running proportional background verification (PS-3, ISO A.6.1), and executing and retaining the employment security and confidentiality agreements (PS-6, ISO A.6.2 and A.6.6) before access is granted. Before selecting, confirm whether an existing agreement is also flagged for material re-signature, so the agreement step later in the track is not silently skipped.\n- **Reported policy violation (`conduct_violation`)** — a workforce member is alleged to have breached an information-security or privacy policy (mishandled PHI, shared or misused credentials, deliberately bypassed a control). This routes to the formal, communicated disciplinary process (PS-8, ISO A.6.4, HIPAA sanction policy at 164.308(a)(1)(ii)(C)). Before selecting, confirm the report carries who, what, when, and source specificity; if it is too vague to open a case, flag it back for more information rather than route a hollow case into intake.\n\n**Record in AssureSwarm**\n- Submit the decision form: `event_track` (the branch), the step result citing the policy definitions and the specific trigger evidence that determines the track — plus whether a concurrent material re-signature is pending — and the step's approver record (step form).\n- Link the uploaded triggering report to this step and to the anchor \"Personnel Security Administration\" Process item (document link).\n\n**Exit criteria** — Form submitted with a rationale grounded in the policy definitions; the branch not selected is prunable.","kind":"decision","label":"Classify personnel event track","performedBy":{"primitives":["coach-query-data","coach-document-upload"]}},"id":"classify-personnel-event-track"},{"data":{"description":"Agent proposes or refreshes the position's risk designation from role duties, access, and data sensitivity, and identifies the annual rescreen population if this is the sweep; human confirms the designation and its screening implications.","instructions":"**Objective** — Set or refresh the position's risk designation from its actual duties, access, and data sensitivity — and, for the sweep, confirm the full rescreen population — so screening is proportional to real risk (PS-2) and no high-risk role is under-screened.\n\n**Inputs**\n- Position data — duties and responsibilities, the systems and datasets the role can reach, the classification of that data (PHI, PII, financial, Confidential or above), privileged or administrative reach, and any financial or fiduciary authority — from the external HRIS, extracted and uploaded to this step (PBC/external upload).\n- The current designation and prior screening for a role change, and the prior sweep list and the policy rescreen interval for the annual sweep — read from the personnel-security register document maintained on the anchor \"Personnel Security Administration\" Process item.\n- The designation scheme and the screening-tier matrix (which checks each tier requires) — policy reference documents attached to the anchor Process item — plus the legal constraints on checks in the individual's jurisdiction. The governing controls are the existing Control items UC-HR-01/UC-HR-02/UC-HR-04 (framework: nist-800-53 | iso-27001 | hipaa; domains: human_resources_personnel_security).\n\n**Procedure**\n1. Derive the designation from risk, not title. Weigh the sensitivity and volume of data reachable (a role that can read or exfiltrate many PHI records is high risk regardless of grade), privileged or administrative access, the ability to alter security configuration or financial records, the degree of autonomy versus supervision, and public-trust exposure. Map to the org scheme — commonly low, moderate, or high risk (federal equivalents: Low, Moderate, and High Risk public trust, or the national-security sensitivity tiers).\n2. For a role change, re-review from scratch and flag whether the new role raises or lowers the designation; never carry the prior one over by default. A lateral move into privileged access is an upgrade even at the same pay grade.\n3. For the annual sweep, enumerate every person currently in a high-risk-designated role due for rescreen at the policy interval (PS-3), queue each as a designation to confirm rather than re-derive, and reconcile the list to the HRIS so recent movers and newly high-risk incumbents are not missed.\n4. Translate the designation into the required screening set — which of identity, right-to-work, employment history, education or credential, criminal (at the appropriate county, state, and federal scope), credit (fiduciary or finance-sensitive roles only, where lawful), exclusion and sanctions screening against OIG-LEIE, SAM.gov, and OFAC (mandatory for PHI-touching and payment roles), professional-license verification, and drug screening apply — each proportional to risk and permissible in the jurisdiction under FCRA, ban-the-box and fair-chance rules, and GDPR or local data-protection limits.\n5. Confirmation: the HR Personnel Security Partner confirms the designation is proportional to the position's real risk and data sensitivity, that a role change was re-reviewed rather than carried over, and that the sweep population is complete before verification begins.\n\n**Record in AssureSwarm**\n- The catalog has no Person or Position item type, so record the designation as a position-risk designation memo — the level, its basis, and the derived proportional screening set — as a document on this step (step document), linked to the anchor Process item (document link).\n- Write the confirmed designation level and, for a high-risk role, the next-rescreen due date into the personnel-security register document maintained on the anchor \"Personnel Security Administration\" Process item (step document — the register has no native Person field).\n- For the annual sweep, record the confirmed rescreen population as a list document on this step (step document).\n\n**Exit criteria** — Designation set with a documented basis; the required screening set derived, proportional, and lawful for the jurisdiction; a role-change re-review evidenced; and, for a sweep, the population complete and reconciled to HRIS before verification.","label":"Assign position risk designation","performedBy":{"primitives":["coach-query-data","coach-item-create","coach-document-upload"]}},"id":"assign-position-risk-designation"},{"data":{"decisionField":"screening_clearance","description":"HR Personnel Security Partner with legal/security input: Inspect completed lawful checks and decide clearance only when every required result is in, otherwise hold for individualized adverse-finding review.","formData":{"fields":[{"key":"screening_clearance","label":"Screening clearance decision","options":[{"label":"Cleared - proportional screening complete, no disqualifying findings","value":"cleared_for_access"},{"label":"Hold - adverse finding requires further review before proceeding","value":"hold_pending_further_review"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Perform the authorized checks, retain the per-person evidence and decide complete clearance or a held adverse-finding review before employment or access.\n\n**Decision criteria**\nInputs for preparation: - The confirmed designation and its required screening set from the preceding authorized stage.\n- The individual (or each queued sweep individual), the jurisdiction, and the target start and access-grant date.\n- The screening vendor or consumer-reporting-agency (CRA) channel — an external system, not a Vendor item — plus the org's adjudication standards and the standalone FCRA disclosure and authorization on file where a CRA is used; capture the disclosure/authorization and the adjudication standard as evidence uploaded to this step.\n\n*Autonomous preparation incorporates Complete background verification; HR Personnel Security Partner with legal/security input reviews the combined evidence.*\n1. Before ordering, confirm the legal prerequisites: a standalone FCRA disclosure and written authorization captured for US CRA checks; ban-the-box timing respected so criminal history is not sought earlier than the jurisdiction allows; a lawful data-protection basis for EU and other jurisdictions; and scope limited to what the designation justifies — do not over-collect.\n2. Order or execute each check in the required set: identity and right-to-work (I-9 and E-Verify where applicable), employment history (dates and title with prior employers), education or credential verification, criminal at the appropriate scope, and — where the tier and law allow — credit, exclusion and sanctions screening against OIG-LEIE, SAM.gov, and OFAC, professional-license status, and drug screening. For PHI-touching roles, exclusion screening is not optional and typically re-runs monthly against the LEIE.\n3. For the annual sweep, run the same proportional set for each queued high-risk individual at the policy interval, noting the prior screening date so any coverage gap is visible.\n4. Hold the timing gate: verification completes before the start date and before access is provisioned. If a start date looms with checks outstanding, that is an exception to route to the clearance decision — not a reason to grant provisional access to sensitive systems.\n5. Compile one packet per individual recording each check's result, source, and date, and flag any adverse, incomplete, or discrepant finding (an employment-gap discrepancy, an undisclosed relevant conviction, a name on an exclusion list, a falsified credential) without adjudicating it here. Retain the raw records alongside the compiled packet.\n6. Confirmation: the HR Personnel Security Partner reviews each packet for completeness against the required set, confirms the checks stayed proportional and lawful for the role, and confirms the packet is ready for a clearance decision before employment or access begins.\n\nCompare the packet's findings against the position's risk designation and the org's adjudication standard, then pick the branch.\n\n- **Cleared for access (`cleared_for_access`)** — every required check for the designation completed, and no finding is disqualifying under the adjudication standard. Immaterial or since-explained discrepancies (a minor date mismatch already reconciled) do not block clearance but are noted. Clearance means all checks are in: a \"mostly complete\" packet with an open exclusion-list hit, a pending criminal result, or an unresolved discrepancy is not cleared.\n- **Hold pending further review (`hold_pending_further_review`)** — a potentially disqualifying or material adverse finding exists: a relevant criminal record, an OIG-LEIE, SAM, or OFAC exclusion or sanctions hit, a falsified credential, an unexplained employment gap, a failed drug screen where lawful, or a check that could not complete. Holding does not pre-decide the outcome — it routes to structured resolution. For a CRA-sourced adverse finding, this is where FCRA pre-adverse-action obligations attach (notice, a copy of the report, the Summary of Rights, and a reasonable waiting period), and EEOC individualized-assessment factors — the nature and gravity of the offense, time elapsed, and its relevance to this role — govern any use of criminal history.\n\n**Record in AssureSwarm**\n- Upload each check's raw record and the compiled background-verification packet as documents on this step (step document / document upload).\n- There is no Person or designation item to attach to, so link the packet document to the anchor \"Personnel Security Administration\" Process item and reference the position-risk designation memo from the preceding authorized stage (document link).\nSubmit the decision form: `screening_clearance` (the branch), the step result citing which checks cleared, the specific adverse finding and its adjudication basis (or none), and any legal constraints noted, and the step's approver record. Link the packet and any adverse-finding summary to the decision (document link).\n\n**Exit criteria**\nInspect completed lawful checks and decide clearance only when every required result is in, otherwise hold for individualized adverse-finding review.\nEvery required check completed or explicitly exception-flagged; a packet compiled per individual with each finding's source and date and any adverse finding flagged; raw records retained; verification precedes start and access; the packet is ready for the clearance decision.\nForm submitted with a rationale; any adverse finding is routed to resolution rather than adjudicated on this form; the branch not selected is prunable.","kind":"decision","label":"Decide screening clearance","performedBy":{"primitives":["coach-document-upload","coach-items-link","coach-query-data"]}},"id":"decide-screening-clearance"},{"data":{"description":"Agent compiles the adverse-finding detail and mitigation options; human determines whether the individual proceeds with mitigations, is reassigned, or the offer or role change is withdrawn.","instructions":"**Objective** — Adjudicate a held adverse finding to a defensible, consistent outcome — proceed with mitigations, reassign, or withdraw — so the individual's status is fixed before agreements or provisioning, with the legal record intact.\n\n**Inputs**\n- The full adverse-finding detail and the packet carried from the clearance decision.\n- The legal constraints on using the finding: the FCRA adverse-action sequence, EEOC individualized-assessment factors, ban-the-box and fair-chance rules, and any jurisdiction-specific limits.\n- Precedent: how the organization resolved comparable findings before, for consistency.\n- The role's designation and whether a lower-risk reassignment whose screening the packet already satisfies exists.\n\n**Procedure**\n1. Run the individualized assessment rather than a blanket rule: weigh the nature and gravity of the finding, the time elapsed, and its relevance to this specific role's duties and access. A decade-old unrelated misdemeanor rarely justifies withdrawal for a moderate-risk role; a recent fraud conviction is material for a finance-privileged one.\n2. Where a CRA report drove it and you are leaning adverse, complete the FCRA adverse-action sequence: a pre-adverse-action notice with a copy of the report and the Summary of Rights, a reasonable waiting period (commonly five business days) for the individual to dispute, then the adverse-action notice. Skipping these steps creates real legal exposure.\n3. Draft the resolution options and tie each to the finding's materiality: proceed with mitigations (a restricted least-privilege access profile, added supervision, or privileged access deferred pending a probationary period), reassign to a lower-risk role the packet already clears, or withdraw the offer or role change.\n4. Capture the input of the stakeholders the finding requires — HR, legal, security, and the hiring manager as relevant — and test the proposed outcome against precedent so comparable findings resolve comparably; disparate treatment is its own liability.\n5. Confirmation: the HR Personnel Security Partner, with the relevant stakeholders, determines the resolution — proceed with mitigations, reassign, or withdraw — documents the rationale and the legal sequence followed, and confirms the individual's status before agreement execution or closure.\n\n**Record in AssureSwarm**\n- Record the outcome, individualized-assessment factors, mitigation conditions and consulted stakeholders in the native result, with the decision in native approvals. This adverse-finding adjudication is a review result, not a `policy_exception` Issue — it resolves a screening finding rather than granting a policy waiver.\n- Upload the pre-adverse- and adverse-action correspondence and any precedent reference as documents on this step, and link them to the anchor \"Personnel Security Administration\" Process item (step document / document link).\n\n**Exit criteria** — Resolution decided and documented with individualized-assessment rationale; the FCRA and legal sequence evidenced where applicable; any mitigation conditions specified so they carry into provisioning; the individual's status fixed for the agreements step or recorded as a withdrawal.","label":"Resolve screening exception","performedBy":{"primitives":["coach-document-upload","coach-form-fill"]}},"id":"resolve-screening-exception"},{"data":{"description":"Agent assembles the employment terms, confidentiality and access agreements, and position description carrying role-specific security duties, and routes them for signature - initial or re-signature - before access is granted; human confirms execution.","instructions":"**Objective** — Assemble and obtain signature on the employment security, confidentiality, and access agreements plus the security-bearing position description — initial signature or material re-signature — with every required document signed and dated before any access is provisioned (PS-6 and PS-9; ISO A.6.2, A.6.5, and A.6.6).\n\n**Inputs**\n- The cleared (or mitigation-conditioned) individual from the clearance or exception path, or a withdrawal outcome if the exception step withdrew the case.\n- The current approved agreement set: employment terms stating the individual's information-security responsibilities and the obligations that survive employment, the confidentiality or non-disclosure agreement, the acceptable-use agreement or rules of behavior, and any role-specific addenda (for example a HIPAA PHI confidentiality attestation).\n- The position description carrying the role's security duties (PS-9), and the version and date the individual last signed, for re-signature checks.\n- Any mitigation conditions from a resolved exception to fold into the terms.\n\n**Procedure**\n1. Determine the case: an initial signature (new hire, role change, or an individual proceeding out of a resolved exception) versus a required re-signature because the standard agreement text has materially changed since the individual last signed, or a periodic re-attestation is due under PS-6. Select the correct document set — do not re-paper an unchanged agreement, and do not skip a re-signature after a material change.\n2. Assemble the set proportional to the designation: everyone signs the confidentiality or non-disclosure agreement and the acceptable-use rules of behavior; PHI-touching roles add the HIPAA confidentiality attestation; privileged roles add the elevated-access rules-of-behavior addendum; and any exception mitigation condition (such as a restricted-profile acknowledgment) is folded in.\n3. Confirm the agreements actually state the surviving post-employment obligations (ISO A.6.5) and the individual's specific information-security responsibilities (A.6.2). A generic signature block with no stated duties is weak evidence.\n4. Route the set for signature (wet or e-signature with an auditable signing trail) and confirm every required document is signed and dated. Signature completion is the gate: no system or sensitive-information access is provisioned before it.\n5. If the exception step resolved the case as a withdrawal, skip signature entirely and record the withdrawal outcome here instead of routing documents, closing the loop without a hollow agreement.\n6. Confirmation: the HR Personnel Security Partner confirms the correct set — initial or re-signature — was routed, that signature is complete and dated before access, and that a withdrawn case was recorded rather than routed for signature.\n\n**Record in AssureSwarm**\n- Obtain the individual’s auditable wet or electronic signature on the actual approved confidentiality/IP, acceptable-use and other applicable agreements. Retain each signed, dated agreement and the security-bearing position description as documents and record execution in the native result/approval record. Use the start date from the HR request; verify the standalone screening authorization was retained before checks were ordered, without requesting a late duplicate consent. The catalog has no Agreement or Person item type, so the signed set lives as step documents rather than items.\n- Link the signed agreement set to the anchor \"Personnel Security Administration\" Process item, and note the case (initial signature, re-signature, or withdrawal) and the signature dates on this step (document link / step document).\n\n**Exit criteria** — The correct agreement set signed and dated before access, or a withdrawal recorded; surviving-obligation and information-security-responsibility clauses present; documents attached and linked; the record ready for retention and the access gate.\n\n","label":"Execute employment security agreements","performedBy":{"primitives":["coach-form-create","coach-document-upload"]}},"id":"execute-employment-security-agreements"},{"data":{"decisionField":"sanction_decision","description":"HR Personnel Security Partner with manager/legal as required: Assess preserved case evidence, severity, intent and comparable precedent and decide a proportionate sanction or unsubstantiated closure.","formData":{"fields":[{"key":"sanction_decision","label":"Sanction decision","options":[{"label":"Sanction imposed - graduated per severity and intent","value":"sanction_imposed"},{"label":"Closed - violation not substantiated, no sanction warranted","value":"closed_no_sanction"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Preserve and assess the reported violation, compare precedent and determine the justified sanction or unsubstantiated outcome.\n\n**Decision criteria**\nInputs for preparation: - The violation report: the individual involved, the policy or control breached, the source and date of the report, and the evidence supplied.\n- The formal, communicated disciplinary process and the security or privacy policies alleged to be breached.\n- The individual's disciplinary history and comparable prior cases, for consistency and precedent — held as prior violation-case Issue items (source: management_identified), queried and linked to this new case.\n- Any legal or HR constraints: investigatory-interview representation rights (for example Weingarten rights in a unionized setting) and data-handling limits on the investigation record.\n\n*Autonomous preparation incorporates Intake and classify violation; HR Personnel Security Partner with manager/legal as required reviews the combined evidence.*\n1. Log the case with the concrete facts: who, which policy or control, when, the reporting source, and the evidence attached. Preserve the primary evidence so it survives scrutiny — system and access logs, the offending artifact — with dates and provenance; do not paraphrase away the primary evidence.\n2. Gather corroborating evidence and, where the process calls for it, a statement from the individual and any witnesses. Observe representation rights where they apply, and keep the investigation proportionate and documented.\n3. Classify severity and apparent intent against the framework: distinguish willful or malicious conduct (intentional data exfiltration, deliberate control bypass) from negligent conduct (careless handling) from accidental or first-time lapses, and gauge harm — was PHI or PII actually exposed, how many records, is it potentially reportable. Severity and intent together set where the graduated scale starts.\n4. Retrieve the individual's history and comparable prior cases so the eventual sanction can be tested for consistency; treating like cases alike is the defense against disparate-treatment claims.\n5. Confirm the case has enough specificity and evidence to proceed to a sanction decision; if not, flag it back for more information rather than advancing a thin case.\n6. Confirmation: the HR Personnel Security Partner or the investigator confirms the intake is complete, the classification is reasonable, and the case — including comparable precedent — is ready for a sanction decision.\n\nCompile the classified case, the applicable disciplinary-policy provisions, and the comparable prior cases into one decision packet, then pick the branch.\n\n- **Sanction imposed (`sanction_imposed`)** — the evidence substantiates the violation and a sanction proportional to severity and intent is warranted. Graduate it: for a negligent or first-time lapse, a documented warning or required retraining; for repeated or serious conduct, suspension or a final written warning; for willful or high-harm conduct (intentional PHI theft, deliberate control circumvention), up to termination. The chosen level must be consistent with how comparable prior cases resolved — an outlier sanction needs an articulated reason. Note the roles that must be notified of the outcome, since PS-8 requires notifying defined roles within a defined period.\n- **Closed, no sanction (`closed_no_sanction`)** — the evidence does not substantiate the violation, or the investigation shows no policy breach occurred (a false report, or an authorized action misread as a breach). This is not exoneration by default: the rationale must state what the evidence showed, and any process or awareness gap the report surfaced still routes to feedback even without a sanction.\n\n**Record in AssureSwarm**\n- Create the violation case as an Issue — `issue_type: exception`, `source: management_identified`, `severity` per the classification, `description` = who / which policy or control / when, `identified_date`, `issue_owner` = the investigator (item create).\n- Relate the case Issue to the breached Control item (UC-HR-01/UC-HR-02/UC-HR-04 as applicable), to the prior violation-case Issues used as precedent, and to the anchor \"Personnel Security Administration\" Process item (item relationship).\n- Upload the preserved primary evidence and any statements as documents on the case Issue (step document / document upload).\n- Submit the decision form: `sanction_decision` (the branch), the step result citing the substantiating or exculpating evidence, the severity-and-intent basis, the precedent comparison, and — if imposed — the sanction level and the notification roles, and the step's approver record (step form).\n- Link the decision packet to this step (document link), and mirror the outcome onto the case Issue: set `Issue.management_response` to the sanction level and rationale, and set the Issue status to closed if the case is unsubstantiated (item field update).\n\n**Exit criteria**\nAssess preserved case evidence, severity, intent and comparable precedent and decide a proportionate sanction or unsubstantiated closure.\nThe case logged with preserved primary evidence; severity, intent, and harm classified against the framework; comparable precedent retrieved; specificity sufficient to decide (or the case flagged back); the case ready for sanction determination.\nForm submitted with a rationale grounded in evidence and precedent; notification roles identified if a sanction is imposed; the branch not selected is prunable.","kind":"decision","label":"Determine and document sanction","performedBy":{"primitives":["coach-item-create","coach-document-upload","coach-items-link","coach-query-data","coach-item-update"]}},"id":"determine-and-document-sanction"},{"data":{"description":"Automatically document the already-decided sanction, deliver the authorized role notifications and route feedback and access-change handoffs.","instructions":"**Objective** — Document the imposed sanction with its rationale, deliver the required notifications to the defined roles within the policy timeframe, and route the case's feedback into awareness and control improvement, so the sanction is enforceable, the PS-8 notification requirement is met, and the violation improves the control environment.\n\n**Inputs**\n- The sanction decision, its rationale, and the notification role list from the preceding authorized stage.\n- The PS-8 notification requirement: which roles must be notified, and within what time period.\n- The awareness or training owner and the control or process owner, for feedback routing.\n- Any downstream obligation the violation triggers (for example a HIPAA breach-assessment path if PHI was exposed — related but handled separately).\n\n**Procedure**\n1. Document the sanction in the case record: its type and level, the rationale tying it to severity, intent, and precedent, the effective date, and any conditions (a retraining deadline, access changes, a probationary period). This is the enforceable record — vague documentation undermines the sanction if it is later challenged.\n2. Deliver the required notifications to the defined roles — the individual's manager, security, privacy or compliance, and legal as applicable — within the policy timeframe, recording who was notified, when, and how. Where the sanction changes access (suspension or termination), notify the provisioning owner so access is adjusted or revoked promptly, handing execution to the joiner-mover-leaver access lifecycle process.\n3. Draft the feedback items the case surfaces and route each to its owner: an awareness or targeted-training communication where the violation reflects a knowledge gap, and a control or process improvement where it reflects a control weakness that let the violation happen. Even a case closed as not substantiated can surface a process improvement.\n4. Retain the complete case record — intake, evidence, decision, sanction documentation, notifications, and feedback items — on the case.\n5. Reconcile the documentation to the prior authorized sanction and retain delivery evidence showing the defined roles received notice within the timeframe; keep failed delivery and unowned feedback open for the responsible owner. No additional confirmation is required.\n\n**Record in AssureSwarm**\n- Upload the sanction documentation and the PS-8 notification record (recipients, timestamps, method) as documents on the case Issue (step document / document upload).\n- Create each feedback item as an Issue — `issue_type: observation` for an awareness/training gap or `opportunity` for a control/process improvement, `source: management_identified`, `issue_owner` = the awareness or control owner — and relate each feedback Issue to the affected Control item and to the case Issue (item create / item relationship).\n- Update the case Issue with the sanction conditions: `Issue.remediation_plan` = the conditions (e.g. retraining deadline, access changes) and `Issue.target_remediation_date` (item field update).\n- Where the sanction changes access (suspension or termination), the notification to the provisioning owner is the Handoff package to the downstream Joiner-Mover-Leaver Access Lifecycle workflow (handoff package).\n\n**Exit criteria** — The sanction documented with enforceable detail; the required notifications delivered within the policy timeframe and logged; an access-change handoff made where the sanction requires it; feedback items routed to named owners.\n\n> **⚡ Audit Artist accelerator:** `/coach-notify` — sends the PS-8 sanction notifications to the defined roles and logs recipients, timestamps, and delivery so the notification requirement is evidenced.","label":"Document sanction and notify","performedBy":{"primitives":["coach-document-upload","coach-items-link","coach-notify","coach-item-create","coach-item-update"]},"requiredApprovals":0},"id":"document-sanction-and-notify"},{"data":{"description":"Automatically retain the selected track’s authorized record, verify clearance-plus-signature evidence before access handoff, update rescreen/mitigation dates and archive closure.","instructions":"**Objective** — Retain this cycle's artifacts under the retention schedule, confirm access was gated on screening clearance plus signed agreements, assemble and archive the complete record for whichever track ran, and update the personnel-security register — so the prior decisions and actual signed agreements authorize the retained cycle record.\n\n**Inputs**\n- For the screening-and-agreements track: the position-risk-designation item, the background-verification packet, the signed agreement set with the security-bearing position description (or the withdrawal record), the role's rescreen interval if it is high risk, and the IT or security provisioning owner with the access-grant request for this individual.\n- For the disciplinary track: the case intake and evidence, the sanction decision, and the notification and feedback record — including a case closed as not substantiated.\n- The records-retention schedule (the retention period per record type) and the designated retention location.\n- The personnel-security register on the anchor \"Personnel Security Administration\" Process item (rescreen due dates, open exception mitigations, case statuses).\n- The accountable owner and any stakeholder named earlier in the cycle.\n\n**Procedure**\n_The screening-only retention and access stages apply only to that track; the final stages retain either selected track under its prior authorization._\n1. Archive each artifact to the retention location, tagged with its retention period and linked to the personnel record: the designation, the verification packet, the signed employment terms, the confidentiality or non-disclosure agreement, the access agreement, and the position description. Personnel-security and HIPAA workforce records carry multi-year retention (HIPAA documentation is retained six years from creation or last effective date under 164.316(b)(2)); apply the org schedule.\n2. Confirm the two-part gate to IT or security: provisioning proceeds only now that both screening clearance and signed agreements are on file. Record the access-grant date against both gating records so the causal order — prerequisites, then grant — is evidenced. Where a resolved exception set a restricted profile, confirm the provisioning matches that profile, not full access.\n3. Set or update the individual's next rescreen due date if the position is high risk, so the annual sweep's trigger scan picks it up at the defined interval (PS-3).\n4. If this cycle was a scheduled rescreen, close out this individual's line in the sweep list.\n5. For a withdrawn case, retain the designation, the verification packet, and the withdrawal record, and confirm no provisioning occurred, instead of archiving a signed agreement set.\n6. Assemble the complete cycle record for the track that ran — the artifacts retained above on the screening track, or the case intake, evidence, sanction decision, notifications, and feedback items on the disciplinary track — indexed so it reads without oral explanation: a reviewer holding only this package can see the trigger, the decisions, and the outcome. Pull in any externally referenced artifact rather than pointing at it.\n7. Archive the assembled record to the retention location with its retention period, linked to the personnel or case record. Verify retrievability by opening the archived copy, not by trusting the upload confirmation. The archive confirmation is recorded; any post-archive correction is a new dated addendum, not an edit to the sealed record.\n8. Update the personnel-security register so the next trigger scan is accurate: the next rescreen due date for a high-risk role, any open exception mitigation with its review date, or the case status. A silently un-updated register is how a due rescreen or an expiring mitigation gets missed.\n9. Confirm no open thread survives: an outstanding mitigation condition, a pending notification, or an unrouted feedback item each needs an owner and a due date before close.\n10. Verify that the archived record is complete evidence on its own — designation, screening, and signed agreements with access gated on both (or no provisioning confirmed for a withdrawal) on the screening track; the case record with its sanction and notifications on the disciplinary track — that the next rescreen date is set and the register is updated for the next cycle, and record automatic closure after communicating the prior authorized outcome to the accountable owner and named stakeholders.\n\n**Record in AssureSwarm**\n- Link each archived artifact — the designation memo, the background-verification packet, the signed agreement set, and the position description — to the anchor \"Personnel Security Administration\" Process item (document link), and export the assembled record set and the workflow instance record to the retention location as this cycle's audit trail (workflow export / record export). There is no Person item, so the archive index itself is a document on this step.\n- Record the access-grant date and the two-part gate confirmation (screening clearance plus signed agreements on file) as a document on this step; this gate/grant confirmation is the Handoff package handed to the downstream Joiner-Mover-Leaver Access Lifecycle workflow (handoff package).\n- Record the archive location and reference on this step, and write the register updates — next rescreen due date for a high-risk role, open-mitigation review dates, case status — into the personnel-security register document maintained on the anchor Process item.\n- For a disciplinary cycle, close out the case Issue: set `Issue.actual_remediation_date` / `Issue.verified_date` and the Issue status to closed (item field update).\n\n**Exit criteria** — All artifacts archived with retention tags and linked, and the assembled cycle record verified retrievable with its reference recorded; access gated on clearance plus signed agreements with the grant date recorded (or no-provisioning confirmed for a withdrawal); the next rescreen date set for a high-risk role and the sweep line closed if this was a scheduled rescreen; the register updated for the next cycle; every open thread carried forward with an owner and a due date; closure records the prior authorized decisions and completed record checks.","label":"Close and archive","performedBy":{"primitives":["coach-workflow-export","coach-document-upload","coach-item-update","coach-export-package"]},"requiredApprovals":0},"id":"close-and-archive"}],"sourceTemplateId":"workflow-library:grc-personnel-screening-agreements-sanctions-administration"}
