workflow

Joiner-Mover-Leaver Access Lifecycle

Run one instance per HR-triggered joiner, mover, or leaver event as a decision-routed access-lifecycle control that enriches the EXISTING Control item for JML / user-access provisioning-deprovisioning (control library, domains=access_control_identity, framework nist-800-53 + iso-27001) - attach the instance to that control, never create a duplicate. Consume the authoritative HR event record from the external HR system of record (the trigger): classify the event, then provision role-based access, adjust with SoD checks on transfer, or evidence timely removal on exit, and file the named audit-ready access-lifecycle evidence package before closing. In scope: identity-provider, directory, HR-system, ERP, and connected-SaaS entitlements for the affected worker. Out of scope: HR record creation itself, physical-security badge policy, and system-owner entitlement design. The run is terminal - no upstream or downstream AssureSwarm workflow: it starts from the external HR event and ends at the archived evidence package attached to the Control item. The anchor Control links (item relationship) to the access Risk it mitigates.

Record JSON · Open in map · Data retrieval guide

Catalog revision: f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e. A connection does not establish full coverage.

Attributes

domain
controls
department
it
lineOfDefense
operate

Details

teams
  • it
  • hr
domains
  • controls
standards
  • nist-800-53
  • iso-27001
sourceTemplateId
workflow-library:controls-joiner-mover-leaver
releaseId
sha256:0191ba4d56ea98d45cdba8e7fd21323449b18c9fba5f1dee9603d60b76345f77
canonicalUrl
https://assureswarm.com/workflows/all/?w=controls-joiner-mover-leaver
capabilities
    mappingStatus
    mapped
    lineOfDefense
    operate
    controls
    • UC-ACCESS-01
    • UC-HR-03
    • UC-ACCESS-03
    • UC-HR-06
    • UC-ASSET-07
    • UC-GOV-08
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:0191ba4d56ea98d45cdba8e7fd21323449b18c9fba5f1dee9603d60b76345f77

            Connections