Workflows & Personnel

Workflows. Engineered.

Personnel actions are where compliance quietly fails: a new hire gets access before screening, or a departing employee keeps it for weeks. The Compliance Workflows module turns onboarding, offboarding, and access changes into configurable approval sequences with role-based sign-off tied to NIST SP 800-171 — so the right people authorize each step and the evidence is generated as the work happens.

PS · AC · IA Domains supported
Role-based Sign-off by responsibility
Automatic Evidence as a byproduct
Capability

Onboarding and Offboarding as Controlled Processes

An onboarding workflow steps through what has to happen before a new person touches CUI: personnel screening completed (PS.L2-3.9.1), required training assigned, the right access provisioned, and acknowledgement of policies recorded. Each step has an owner and a sign-off, and the access-granting step cannot complete until the prerequisites are checked off. Offboarding runs the mirror image — access revoked, equipment returned, accounts disabled — so that CUI and the systems that hold it stay protected when someone leaves or changes roles (PS.L2-3.9.2).

Because the workflow enforces order, the failure modes assessors look for simply cannot occur quietly: access is not granted before screening, and it is not left active after departure. The sequence is configurable, so the steps match how your organization actually operates rather than a generic template.

Dashboard Requirements Evidence POA&M Reports
1TEN Compliance Workflows interface showing onboarding and offboarding approval steps with role-based sign-off
Capability

Role-Based Sign-Off Tied to Access

Provisioning and de-provisioning are governed by the access control practices: AC.L2-3.1.1 limits system access to authorized users, and AC.L2-3.1.2 limits that access to the transactions and functions users are permitted to perform. The workflow ties each access change to a role-based approval, so the person who can authorize access to the CUI enclave is the person whose sign-off the workflow requires — not whoever happens to be available. Approvals are recorded with identity and timestamp, supporting the accountability that the IA domain expects.

Every completed workflow leaves behind exactly the documentation an assessor asks for: who was screened and when, what access was granted, who approved it, and confirmation that offboarding closed it out. That evidence is produced automatically as the process runs, instead of being reconstructed from email months later.

Inside the Module

What You See Inside

Configurable workflows
Define the steps for onboarding, offboarding, and access changes to match your operations.
Enforced sequence
Access cannot be granted until prerequisites like screening and training are complete.
Role-based sign-off
Each step routes to the responsible approver, recorded with identity and timestamp.
Offboarding closure
Mirror workflow revokes access and disables accounts so nothing is left active.
Requirement linkage
Workflow steps map to the PS, AC, and IA practices they satisfy.
Automatic evidence
Each completed workflow produces a documented, assessment-ready record.
The problem this solves

The most common personnel-security finding is not a missing policy — it is a policy nobody follows consistently. Someone starts on Monday and gets a laptop and a login before HR finishes screening; someone resigns and their VPN account lives on for a month. PS.L2-3.9.1 and PS.L2-3.9.2 are about making personnel actions reliable, and reliability comes from an enforced workflow, not good intentions. When onboarding and offboarding run as controlled sequences, the evidence writes itself and the gaps an assessor probes for never open.

Practices

Practices Supported

Practice IDDescription
PS.L2-3.9.1 Screen individuals prior to authorizing access to organizational systems containing CUI.
PS.L2-3.9.2 Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.
AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices.
AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute.
Connected Modules

Related Modules

All 110. Tracked.

1TEN is an air-gapped, on-premises GRC platform engineered for defense contractors handling CUI.

Request a Demo