Skip to content
ControlVerdict
PS.L2-3.9.2addresses
PS.L2-3.9.2Personnel Actions
Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.
  • [a]

    a policy and/or process for terminating system access and any credentials coincident with personnel actions is established;
  • [b]

    system access and credentials are terminated consistent with personnel actions such as termination or transfer; and
  • [c]

    the system is protected during and after personnel transfer actions.

View full control

Same-day deprovisioning on exit; transfers re-baseline access instead of adding to it

ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
Community is just starting — add yours. No verdicts yet.

Implementation

AO coverage. Addresses all Personnel Actions objectives: an established policy and process for terminating access and credentials with personnel actions, termination of access consistent with those actions, and protection of the system during and after transfers.

The policy and process. A written procedure covers voluntary resignation, involuntary termination, transfer, extended leave, and subcontractor rolloff. Each has a defined trigger, a timeline, and a named accountable role. HR owns the trigger, IT owns execution, and the manager owns physical property and knowledge transfer. The timeline is explicit: enclave access and credentials revoked on the effective date for a routine departure, and immediately — before notification where the process calls for it — for an involuntary termination.

Automated execution. A status change in the HRIS drives a workflow that disables the account, revokes active sessions and refresh tokens, removes all group memberships including the enclave groups, deactivates the badge, revokes registered authentication methods, disables remote access, and converts the mailbox to a delegated state for the manager. Session and token revocation is called out because disabling an account alone can leave an authenticated session alive for hours, which is exactly the window that matters.

What automation does not reach. A checklist covers what the workflow cannot: recovery of the laptop, phone, keys, and any issued media; removal from local accounts on lab systems that are not federated; rotation of any shared credential the person knew, including the two vendor appliance passwords; removal from vendor and customer portals where we hold a named seat; and removal from distribution lists that receive program information. The ticket cannot close with an outstanding item, and outstanding media specifically escalates to the ISSO.

Transfers re-baseline. A transfer does not add the new role's access to the old; it triggers a full recalculation. Access is provisioned from the new role's profile and everything not in that profile is removed, with a five-business-day overlap permitted only where the manager documents a handover need and names an end date. This one change eliminated most of our standing over-entitlement, and it is the part of the practice assessors probe hardest.

Protection during the action. For a resignation with notice in a sensitive role, or any involuntary action, the manager and HR notify security in advance so monitoring can be elevated: alerting on bulk download from enclave libraries, large outbound mail, and mass copy to removable media for that account during the notice period. This is a defined, time-bounded measure with a documented approval, not open-ended surveillance of departing employees.

After the action. Accounts stay disabled rather than deleted for the retention period so audit history remains attributable, then are removed. A monthly reconciliation compares active accounts, enclave group membership, and active badges against the current HRIS roster; anything present in identity but absent from HR is investigated the same week.

Maintenance. Quarterly test of the full leaver workflow on a test identity, measuring time from HRIS trigger to last entitlement removed. Annual review of the checklist against new systems and vendor portals added during the year.

Accepted gap. Two lab instruments carry local accounts that cannot federate. They are covered by the manual checklist rather than automation, and the quarterly reconciliation includes a direct check of their local account lists because a manual step is a step that gets missed.

What the evidence looks like

  • Personnel action procedure with triggers, timelines, and accountable roles
  • Workflow configuration showing account disable, session and token revocation, group removal, and badge deactivation
  • Completed leaver ticket with timestamps from HRIS trigger to final entitlement removal
  • Transfer example showing prior-role entitlements removed, with any overlap documented and dated
  • Monthly identity-to-HRIS reconciliation output and the quarterly workflow test result

Environment

Joiner-mover-leaver automation from Workday into a cloud identity provider, roughly 15 personnel actions a month. Transfers were the weak point: people accumulated entitlements from every role they had ever held.

Tools

Was this example useful?

Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.

Discussion(0)

No discussion on this example yet

Verdicts capture a conclusion. Use a thread when the interesting part is the argument.

Sign in to start a thread.