{"schema":"https://ver.cy/schemas/card/1.0.0","id":"vr.wm-act-040","code":"wm-act-040-onboarding-offboarding","url":"https://ver.cy/models/wm-act-040-onboarding-offboarding/","name":"Onboarding / Offboarding","alternateNames":[],"kind":"world-model","status":"published","version":"0.3.0-research.1","language":"en","classifiers":{"family":"World Models","category":"Activities and processes","entryKind":"aggregate","plane":"","domain":["ACT.HR"],"industry":["Cross-industry"],"navPath":"NAV.ACT.HR","tags":["onboarding","offboarding","act.hr"],"facets":{}},"whatItIs":"Owns case identity and lineage, mandatory transition profile, trigger and authority, exact employment and role bindings, plan releases, tasks, dependencies, notices, desired account and access changes, asset and workspace coordination, data and knowledge handover, induction and training coordination, execution evidence, verification, exceptions, closure, quality, interoperability, privacy and retention. Person, Employment, Role, Organization, Account, Credential, Access Grant, Device, Asset, Licence, Workspace, Training, Competency, Agreement, Benefit, Dataset, Record, Communication and Audit masters remain external.","purpose":"Represent one governed worker transition case for joining, moving, leaving or rejoining, coordinating desired changes and independently verified execution across employment, access, asset, knowledge and support systems.","scope":{"in":["Case identity, join/move/leave/rejoin profile, trigger, authority, employment and role bindings, plans, tasks and obligations","Identity, accounts, access, credentials, workspaces, facilities, assets, licences, data custody, handover, induction, training, administration and support coordination","Execution and verification evidence, revocation, returns, exit, closure, lifecycle, metrics, exceptions, interoperability, privacy, retention and safe agents"],"out":["Independent person, employment, role, account, access, asset, training, agreement, benefit, data, communication or audit master lifecycles","Inferring employment, authority, access, task completion, revocation, return or deletion from a request, checklist or adjacent state","Implementing an HR system, identity provider, device manager, payroll, benefits, learning system, records repository or universal labour regime"],"boundaries":[{"neighbor":"Person, Employment and Role Assignment","distinction":"The case binds exact external relationships and desired changes but does not create or terminate those masters."},{"neighbor":"Account, Credential, Group and Access Grant","distinction":"The case requests and verifies changes; authoritative identity and access systems own effective state and authorization semantics."},{"neighbor":"Device, Asset, Licence, Workspace and Facility","distinction":"The case coordinates issue, transfer or return while inventory and custody masters retain identity and lifecycle."},{"neighbor":"Training, Competency, Agreement and Benefit","distinction":"The case binds requirements and completion evidence but does not own the underlying definitions, awards, agreements or benefits."},{"neighbor":"Dataset, Record, Communication and Audit","distinction":"Handover and access evidence are referenced; content, retention, disclosure and audit masters remain separately governed."}]},"distinguishingFeatures":["Models the transition case for joining or leaving, not the employment, role or accounts it coordinates.","Records desired access changes as requests; actual grants live in the access system.","Separates request, execution, verification and effective state.","Covers asset return and knowledge handover as tracked tasks."],"structure":{"bundles":[{"id":"case-identity-trigger-and-authority","name":"Case identity, trigger and authority","description":"Groups governed context for case identity, trigger and authority.","layers":[{"id":"transition-profile-identity-and-lineage","name":"Transition profile, identity and lineage","description":"Groups transition evidence for transition profile, identity and lineage.","findings":[{"id":"join-move-leave-rejoin-profile-and-neighbor-boundary","name":"Join, move, leave, rejoin profile and neighbor boundary","description":"Records join, move, leave, rejoin profile and neighbor boundary as source-qualified desired, requested, executed or verified transition context without absorbing external master records.","questions":[{"text":"What transition-scoped identities, classes, roles, versions, values and explicit unknowns establish join, move, leave, rejoin profile and neighbor boundary?","id":"join-move-leave-rejoin-profile-and-neighbor-boundary-q01","kind":"classification"},{"text":"Which authority, source, method, evidence, event time, knowledge time, confidence and limits support join, move, leave, rejoin profile and neighbor boundary?","id":"join-move-leave-rejoin-profile-and-neighbor-boundary-q02","kind":"state"},{"text":"How may join, move, leave, rejoin profile and neighbor boundary be validated, executed, challenged, corrected, related, retained or disposed without losing history?","id":"join-move-leave-rejoin-profile-and-neighbor-boundary-q03","kind":"process"}]},{"id":"case-identifier-source-version-predecessor-successor-and-lineage","name":"Case identifier, source, version, predecessor, successor and lineage","description":"Records case identifier, source, version, predecessor, successor and lineage as source-qualified desired, requested, executed or verified transition context without absorbing external master records.","questions":[{"text":"What transition-scoped identities, classes, roles, versions, values and explicit unknowns establish case identifier, source, version, predecessor, successor and lineage?","id":"case-identifier-source-version-predecessor-successor-and-lineage-q01","kind":"identity"},{"text":"Which authority, source, method, evidence, event time, knowledge time, confidence and limits support case identifier, source, version, predecessor, successor and lineage?","id":"case-identifier-source-version-predecessor-successor-and-lineage-q02","kind":"ownership"},{"text":"How may case identifier, source, version, predecessor, successor and lineage be validated, executed, challenged, corrected, related, retained or disposed without losing history?","id":"case-identifier-source-version-predecessor-successor-and-lineage-q03","kind":"interoperability"}]}]},{"id":"trigger-employment-role-and-authority","name":"Trigger, employment, role and authority","description":"Groups transition evidence for trigger, employment, role and authority.","findings":[{"id":"employment-role-organization-manager-location-and-effective-change-binding","name":"Employment, role, organization, manager, location and effective-change binding","description":"Records employment, role, organization, manager, location and effective-change binding as source-qualified desired, requested, executed or verified transition context without absorbing external master records.","questions":[{"text":"What transition-scoped identities, classes, roles, versions, values and explicit unknowns establish employment, role, organization, manager, location and effective-change binding?","id":"employment-role-organization-manager-location-and-effective-change-binding-q01","kind":"relationship"},{"text":"Which authority, source, method, evidence, event time, knowledge time, confidence and limits support employment, role, organization, manager, location and effective-change binding?","id":"employment-role-organization-manager-location-and-effective-change-binding-q02","kind":"event"},{"text":"How may employment, role, organization, manager, location and effective-change binding be validated, executed, challenged, corrected, related, retained or disposed without losing history?","id":"employment-role-organization-manager-location-and-effective-change-binding-q03","kind":"provenance"}]},{"id":"trigger-reason-request-authority-risk-urgency-and-confidentiality","name":"Trigger, reason, request, authority, risk, urgency and confidentiality","description":"Records trigger, reason, request, authority, risk, urgency and confidentiality as source-qualified desired, requested, executed or verified transition context without absorbing external master records.","questions":[{"text":"What transition-scoped identities, classes, roles, versions, values and explicit unknowns establish trigger, reason, request, authority, risk, urgency and confidentiality?","id":"trigger-reason-request-authority-risk-urgency-and-confidentiality-q01","kind":"authority"},{"text":"Which authority, source, method, evidence, event time, knowledge time, confidence and limits support trigger, reason, request, authority, risk, urgency and confidentiality?","id":"trigger-reason-request-authority-risk-urgency-and-confidentiality-q02","kind":"security"},{"text":"How may trigger, reason, request, authority, risk, urgency and confidentiality be validated, executed, challenged, corrected, related, retained or disposed without losing history?","id":"trigger-reason-request-authority-risk-urgency-and-confidentiality-q03","kind":"privacy"}]}]}]},{"id":"planning-governance-and-obligations","name":"Planning, governance and obligations","description":"Groups governed context for planning, governance and obligations.","layers":[{"id":"transition-plan-tasks-roles-and-dependencies","name":"Transition plan, tasks, roles and dependencies","description":"Groups transition evidence for transition plan, tasks, roles and dependencies.","findings":[{"id":"plan-template-profile-milestone-window-readiness-and-success-criteria","name":"Plan template, profile, milestone, window, readiness and success criteria","description":"Records plan template, profile, milestone, window, readiness and success criteria as source-qualified desired, requested, executed or verified transition context without absorbing external master records.","questions":[{"text":"What transition-scoped identities, classes, roles, versions, values and explicit unknowns establish plan template, profile, milestone, window, readiness and success criteria?","id":"plan-template-profile-milestone-window-readiness-and-success-criteria-q01","kind":"requirement"},{"text":"Which authority, source, method, evidence, event time, knowledge time, confidence and limits support plan template, profile, milestone, window, readiness and success criteria?","id":"plan-template-profile-milestone-window-readiness-and-success-criteria-q02","kind":"interoperability"},{"text":"How may plan template, profile, milestone, window, readiness and success criteria be validated, executed, challenged, corrected, related, retained or disposed without losing history?","id":"plan-template-profile-milestone-window-readiness-and-success-criteria-q03","kind":"relationship"}]},{"id":"task-owner-dependency-deadline-state-evidence-exception-and-escalation","name":"Task, owner, dependency, deadline, state, evidence, exception and escalation","description":"Records task, owner, dependency, deadline, state, evidence, exception and escalation as source-qualified desired, requested, executed or verified transition context without absorbing external master records.","questions":[{"text":"What transition-scoped identities, classes, roles, versions, values and explicit unknowns establish task, owner, dependency, deadline, state, evidence, exception and escalation?","id":"task-owner-dependency-deadline-state-evidence-exception-and-escalation-q01","kind":"process"},{"text":"Which authority, source, method, evidence, event time, knowledge time, confidence and limits support task, owner, dependency, deadline, state, evidence, exception and escalation?","id":"task-owner-dependency-deadline-state-evidence-exception-and-escalation-q02","kind":"composition"},{"text":"How may task, owner, dependency, deadline, state, evidence, exception and escalation be validated, executed, challenged, corrected, related, retained or disposed without losing history?","id":"task-owner-dependency-deadline-state-evidence-exception-and-escalation-q03","kind":"event"}]}]},{"id":"policy-notice-agreements-and-continuing-duties","name":"Policy, notice, agreements and continuing duties","description":"Groups transition evidence for policy, notice, agreements and continuing duties.","findings":[{"id":"policy-jurisdiction-notice-privacy-purpose-consent-rights-and-accessibility","name":"Policy, jurisdiction, notice, privacy purpose, consent, rights and accessibility","description":"Records policy, jurisdiction, notice, privacy purpose, consent, rights and accessibility as source-qualified desired, requested, executed or verified transition context without absorbing external master records.","questions":[{"text":"What transition-scoped identities, classes, roles, versions, values and explicit unknowns establish policy, jurisdiction, notice, privacy purpose, consent, rights and accessibility?","id":"policy-jurisdiction-notice-privacy-purpose-consent-rights-and-accessibility-q01","kind":"privacy"},{"text":"Which authority, source, method, evidence, event time, knowledge time, confidence and limits support policy, jurisdiction, notice, privacy purpose, consent, rights and accessibility?","id":"policy-jurisdiction-notice-privacy-purpose-consent-rights-and-accessibility-q02","kind":"spatial"},{"text":"How may policy, jurisdiction, notice, privacy purpose, consent, rights and accessibility be validated, executed, challenged, corrected, related, retained or disposed without losing history?","id":"policy-jurisdiction-notice-privacy-purpose-consent-rights-and-accessibility-q03","kind":"decision"}]},{"id":"employment-security-confidentiality-ip-conduct-access-and-post-exit-obligations","name":"Employment, security, confidentiality, IP, conduct, access and post-exit obligations","description":"Records employment, security, confidentiality, ip, conduct, access and post-exit obligations as source-qualified desired, requested, executed or verified transition context without absorbing external master records.","questions":[{"text":"What transition-scoped identities, classes, roles, versions, values and explicit unknowns establish employment, security, confidentiality, ip, conduct, access and post-exit obligations?","id":"employment-security-confidentiality-ip-conduct-access-and-post-exit-obligations-q01","kind":"constraint"},{"text":"Which authority, source, method, evidence, event time, knowledge time, confidence and limits support employment, security, confidentiality, ip, conduct, access and post-exit obligations?","id":"employment-security-confidentiality-ip-conduct-access-and-post-exit-obligations-q02","kind":"process"},{"text":"How may employment, security, confidentiality, ip, conduct, access and post-exit obligations be validated, executed, challenged, corrected, related, retained or disposed without losing history?","id":"employment-security-confidentiality-ip-conduct-access-and-post-exit-obligations-q03","kind":"ownership"}]}]}]},{"id":"identity-access-workplace-and-facilities","name":"Identity, access, workplace and facilities","description":"Groups governed context for identity, access, workplace and facilities.","layers":[{"id":"identity-accounts-credentials-and-access","name":"Identity, accounts, credentials and access","description":"Groups transition evidence for identity, accounts, credentials and access.","findings":[{"id":"person-identity-proofing-worker-id-directory-account-and-alias-binding","name":"Person identity proofing, worker ID, directory account and alias binding","description":"Records person identity proofing, worker id, directory account and alias binding as source-qualified desired, requested, executed or verified transition context without absorbing external master records.","questions":[{"text":"What transition-scoped identities, classes, roles, versions, values and explicit unknowns establish person identity proofing, worker id, directory account and alias binding?","id":"person-identity-proofing-worker-id-directory-account-and-alias-binding-q01","kind":"identity"},{"text":"Which authority, source, method, evidence, event time, knowledge time, confidence and limits support person identity proofing, worker id, directory account and alias binding?","id":"person-identity-proofing-worker-id-directory-account-and-alias-binding-q02","kind":"quality"},{"text":"How may person identity proofing, worker id, directory account and alias binding be validated, executed, challenged, corrected, related, retained or disposed without losing history?","id":"person-identity-proofing-worker-id-directory-account-and-alias-binding-q03","kind":"privacy"}]},{"id":"access-grant-role-group-entitlement-credential-mfa-privilege-and-separation","name":"Access grant, role, group, entitlement, credential, MFA, privilege and separation","description":"Records access grant, role, group, entitlement, credential, mfa, privilege and separation as source-qualified desired, requested, executed or verified transition context without absorbing external master records.","questions":[{"text":"What transition-scoped identities, classes, roles, versions, values and explicit unknowns establish access grant, role, group, entitlement, credential, mfa, privilege and separation?","id":"access-grant-role-group-entitlement-credential-mfa-privilege-and-separation-q01","kind":"access"},{"text":"Which authority, source, method, evidence, event time, knowledge time, confidence and limits support access grant, role, group, entitlement, credential, mfa, privilege and separation?","id":"access-grant-role-group-entitlement-credential-mfa-privilege-and-separation-q02","kind":"exception"},{"text":"How may access grant, role, group, entitlement, credential, mfa, privilege and separation be validated, executed, challenged, corrected, related, retained or disposed without losing history?","id":"access-grant-role-group-entitlement-credential-mfa-privilege-and-separation-q03","kind":"state"}]}]},{"id":"applications-workspaces-facilities-and-safety","name":"Applications, workspaces, facilities and safety","description":"Groups transition evidence for applications, workspaces, facilities and safety.","findings":[{"id":"application-service-account-owner-start-stop-provisioning-and-verification","name":"Application, service, account, owner, start, stop, provisioning and verification","description":"Records application, service, account, owner, start, stop, provisioning and verification as source-qualified desired, requested, executed or verified transition context without absorbing external master records.","questions":[{"text":"What transition-scoped identities, classes, roles, versions, values and explicit unknowns establish application, service, account, owner, start, stop, provisioning and verification?","id":"application-service-account-owner-start-stop-provisioning-and-verification-q01","kind":"validation"},{"text":"Which authority, source, method, evidence, event time, knowledge time, confidence and limits support application, service, account, owner, start, stop, provisioning and verification?","id":"application-service-account-owner-start-stop-provisioning-and-verification-q02","kind":"identity"},{"text":"How may application, service, account, owner, start, stop, provisioning and verification be validated, executed, challenged, corrected, related, retained or disposed without losing history?","id":"application-service-account-owner-start-stop-provisioning-and-verification-q03","kind":"measurement"}]},{"id":"workspace-location-badge-key-physical-access-safety-emergency-and-return","name":"Workspace, location, badge, key, physical access, safety, emergency and return","description":"Records workspace, location, badge, key, physical access, safety, emergency and return as source-qualified desired, requested, executed or verified transition context without absorbing external master records.","questions":[{"text":"What transition-scoped identities, classes, roles, versions, values and explicit unknowns establish workspace, location, badge, key, physical access, safety, emergency and return?","id":"workspace-location-badge-key-physical-access-safety-emergency-and-return-q01","kind":"spatial"},{"text":"Which authority, source, method, evidence, event time, knowledge time, confidence and limits support workspace, location, badge, key, physical access, safety, emergency and return?","id":"workspace-location-badge-key-physical-access-safety-emergency-and-return-q02","kind":"lifecycle"},{"text":"How may workspace, location, badge, key, physical access, safety, emergency and return be validated, executed, challenged, corrected, related, retained or disposed without losing history?","id":"workspace-location-badge-key-physical-access-safety-emergency-and-return-q03","kind":"definition"}]}]}]},{"id":"assets-data-knowledge-and-readiness","name":"Assets, data, knowledge and readiness","description":"Groups governed context for assets, data, knowledge and readiness.","layers":[{"id":"equipment-assets-licences-and-custody","name":"Equipment, assets, licences and custody","description":"Groups transition evidence for equipment, assets, licences and custody.","findings":[{"id":"device-equipment-card-key-token-software-licence-and-inventory-reference","name":"Device, equipment, card, key, token, software licence and inventory reference","description":"Records device, equipment, card, key, token, software licence and inventory reference as source-qualified desired, requested, executed or verified transition context without absorbing external master records.","questions":[{"text":"What transition-scoped identities, classes, roles, versions, values and explicit unknowns establish device, equipment, card, key, token, software licence and inventory reference?","id":"device-equipment-card-key-token-software-licence-and-inventory-reference-q01","kind":"composition"},{"text":"Which authority, source, method, evidence, event time, knowledge time, confidence and limits support device, equipment, card, key, token, software licence and inventory reference?","id":"device-equipment-card-key-token-software-licence-and-inventory-reference-q02","kind":"authority"},{"text":"How may device, equipment, card, key, token, software licence and inventory reference be validated, executed, challenged, corrected, related, retained or disposed without losing history?","id":"device-equipment-card-key-token-software-licence-and-inventory-reference-q03","kind":"requirement"}]},{"id":"issue-custody-condition-transfer-return-loss-damage-wipe-and-disposal-evidence","name":"Issue, custody, condition, transfer, return, loss, damage, wipe and disposal evidence","description":"Records issue, custody, condition, transfer, return, loss, damage, wipe and disposal evidence as source-qualified desired, requested, executed or verified transition context without absorbing external master records.","questions":[{"text":"What transition-scoped identities, classes, roles, versions, values and explicit unknowns establish issue, custody, condition, transfer, return, loss, damage, wipe and disposal evidence?","id":"issue-custody-condition-transfer-return-loss-damage-wipe-and-disposal-evidence-q01","kind":"evidence"},{"text":"Which authority, source, method, evidence, event time, knowledge time, confidence and limits support issue, custody, condition, transfer, return, loss, damage, wipe and disposal evidence?","id":"issue-custody-condition-transfer-return-loss-damage-wipe-and-disposal-evidence-q02","kind":"measurement"},{"text":"How may issue, custody, condition, transfer, return, loss, damage, wipe and disposal evidence be validated, executed, challenged, corrected, related, retained or disposed without losing history?","id":"issue-custody-condition-transfer-return-loss-damage-wipe-and-disposal-evidence-q03","kind":"retention"}]}]},{"id":"data-knowledge-training-and-support","name":"Data, knowledge, training and support","description":"Groups transition evidence for data, knowledge, training and support.","findings":[{"id":"data-owner-record-custody-file-mailbox-repository-transfer-retention-and-hold","name":"Data owner, record custody, file, mailbox, repository, transfer, retention and hold","description":"Records data owner, record custody, file, mailbox, repository, transfer, retention and hold as source-qualified desired, requested, executed or verified transition context without absorbing external master records.","questions":[{"text":"What transition-scoped identities, classes, roles, versions, values and explicit unknowns establish data owner, record custody, file, mailbox, repository, transfer, retention and hold?","id":"data-owner-record-custody-file-mailbox-repository-transfer-retention-and-hold-q01","kind":"ownership"},{"text":"Which authority, source, method, evidence, event time, knowledge time, confidence and limits support data owner, record custody, file, mailbox, repository, transfer, retention and hold?","id":"data-owner-record-custody-file-mailbox-repository-transfer-retention-and-hold-q02","kind":"privacy"},{"text":"How may data owner, record custody, file, mailbox, repository, transfer, retention and hold be validated, executed, challenged, corrected, related, retained or disposed without losing history?","id":"data-owner-record-custody-file-mailbox-repository-transfer-retention-and-hold-q03","kind":"lifecycle"}]},{"id":"induction-training-policy-acknowledgement-competency-mentor-handover-and-readiness","name":"Induction, training, policy acknowledgement, competency, mentor, handover and readiness","description":"Records induction, training, policy acknowledgement, competency, mentor, handover and readiness as source-qualified desired, requested, executed or verified transition context without absorbing external master records.","questions":[{"text":"What transition-scoped identities, classes, roles, versions, values and explicit unknowns establish induction, training, policy acknowledgement, competency, mentor, handover and readiness?","id":"induction-training-policy-acknowledgement-competency-mentor-handover-and-readiness-q01","kind":"quality"},{"text":"Which authority, source, method, evidence, event time, knowledge time, confidence and limits support induction, training, policy acknowledgement, competency, mentor, handover and readiness?","id":"induction-training-policy-acknowledgement-competency-mentor-handover-and-readiness-q02","kind":"decision"},{"text":"How may induction, training, policy acknowledgement, competency, mentor, handover and readiness be validated, executed, challenged, corrected, related, retained or disposed without losing history?","id":"induction-training-policy-acknowledgement-competency-mentor-handover-and-readiness-q03","kind":"evidence"}]}]}]},{"id":"execution-verification-handover-and-outcome","name":"Execution, verification, handover and outcome","description":"Groups governed context for execution, verification, handover and outcome.","layers":[{"id":"communications-administration-benefits-and-support","name":"Communications, administration, benefits and support","description":"Groups transition evidence for communications, administration, benefits and support.","findings":[{"id":"welcome-exit-notice-audience-channel-template-language-acknowledgement-and-feedback","name":"Welcome or exit notice, audience, channel, template, language, acknowledgement and feedback","description":"Records welcome or exit notice, audience, channel, template, language, acknowledgement and feedback as source-qualified desired, requested, executed or verified transition context without absorbing external master records.","questions":[{"text":"What transition-scoped identities, classes, roles, versions, values and explicit unknowns establish welcome or exit notice, audience, channel, template, language, acknowledgement and feedback?","id":"welcome-exit-notice-audience-channel-template-language-acknowledgement-and-feedback-q01","kind":"event"},{"text":"Which authority, source, method, evidence, event time, knowledge time, confidence and limits support welcome or exit notice, audience, channel, template, language, acknowledgement and feedback?","id":"welcome-exit-notice-audience-channel-template-language-acknowledgement-and-feedback-q02","kind":"relationship"},{"text":"How may welcome or exit notice, audience, channel, template, language, acknowledgement and feedback be validated, executed, challenged, corrected, related, retained or disposed without losing history?","id":"welcome-exit-notice-audience-channel-template-language-acknowledgement-and-feedback-q03","kind":"identity"}]},{"id":"payroll-benefit-tax-legal-form-contact-support-and-downstream-handoff","name":"Payroll, benefit, tax, legal form, contact, support and downstream handoff","description":"Records payroll, benefit, tax, legal form, contact, support and downstream handoff as source-qualified desired, requested, executed or verified transition context without absorbing external master records.","questions":[{"text":"What transition-scoped identities, classes, roles, versions, values and explicit unknowns establish payroll, benefit, tax, legal form, contact, support and downstream handoff?","id":"payroll-benefit-tax-legal-form-contact-support-and-downstream-handoff-q01","kind":"relationship"},{"text":"Which authority, source, method, evidence, event time, knowledge time, confidence and limits support payroll, benefit, tax, legal form, contact, support and downstream handoff?","id":"payroll-benefit-tax-legal-form-contact-support-and-downstream-handoff-q02","kind":"provenance"},{"text":"How may payroll, benefit, tax, legal form, contact, support and downstream handoff be validated, executed, challenged, corrected, related, retained or disposed without losing history?","id":"payroll-benefit-tax-legal-form-contact-support-and-downstream-handoff-q03","kind":"requirement"}]}]},{"id":"revocation-return-exit-and-certification","name":"Revocation, return, exit and certification","description":"Groups transition evidence for revocation, return, exit and certification.","findings":[{"id":"disable-revoke-terminate-session-rotate-secret-remove-group-and-verify-access-loss","name":"Disable, revoke, terminate session, rotate secret, remove group and verify access loss","description":"Records disable, revoke, terminate session, rotate secret, remove group and verify access loss as source-qualified desired, requested, executed or verified transition context without absorbing external master records.","questions":[{"text":"What transition-scoped identities, classes, roles, versions, values and explicit unknowns establish disable, revoke, terminate session, rotate secret, remove group and verify access loss?","id":"disable-revoke-terminate-session-rotate-secret-remove-group-and-verify-access-loss-q01","kind":"security"},{"text":"Which authority, source, method, evidence, event time, knowledge time, confidence and limits support disable, revoke, terminate session, rotate secret, remove group and verify access loss?","id":"disable-revoke-terminate-session-rotate-secret-remove-group-and-verify-access-loss-q02","kind":"process"},{"text":"How may disable, revoke, terminate session, rotate secret, remove group and verify access loss be validated, executed, challenged, corrected, related, retained or disposed without losing history?","id":"disable-revoke-terminate-session-rotate-secret-remove-group-and-verify-access-loss-q03","kind":"access"}]},{"id":"exit-interview-return-reconciliation-knowledge-transfer-continuing-duty-and-closure-certificate","name":"Exit interview, return reconciliation, knowledge transfer, continuing duty and closure certificate","description":"Records exit interview, return reconciliation, knowledge transfer, continuing duty and closure certificate as source-qualified desired, requested, executed or verified transition context without absorbing external master records.","questions":[{"text":"What transition-scoped identities, classes, roles, versions, values and explicit unknowns establish exit interview, return reconciliation, knowledge transfer, continuing duty and closure certificate?","id":"exit-interview-return-reconciliation-knowledge-transfer-continuing-duty-and-closure-certificate-q01","kind":"validation"},{"text":"Which authority, source, method, evidence, event time, knowledge time, confidence and limits support exit interview, return reconciliation, knowledge transfer, continuing duty and closure certificate?","id":"exit-interview-return-reconciliation-knowledge-transfer-continuing-duty-and-closure-certificate-q02","kind":"security"},{"text":"How may exit interview, return reconciliation, knowledge transfer, continuing duty and closure certificate be validated, executed, challenged, corrected, related, retained or disposed without losing history?","id":"exit-interview-return-reconciliation-knowledge-transfer-continuing-duty-and-closure-certificate-q03","kind":"temporal"}]}]}]},{"id":"lifecycle-quality-interoperability-and-agents","name":"Lifecycle, quality, interoperability and agents","description":"Groups governed context for lifecycle, quality, interoperability and agents.","layers":[{"id":"lifecycle-exceptions-quality-and-improvement","name":"Lifecycle, exceptions, quality and improvement","description":"Groups transition evidence for lifecycle, exceptions, quality and improvement.","findings":[{"id":"planned-authorized-scheduled-active-blocked-completed-cancelled-corrected-and-archived-event","name":"Planned, authorized, scheduled, active, blocked, completed, cancelled, corrected and archived event","description":"Records planned, authorized, scheduled, active, blocked, completed, cancelled, corrected and archived event as source-qualified desired, requested, executed or verified transition context without absorbing external master records.","questions":[{"text":"What transition-scoped identities, classes, roles, versions, values and explicit unknowns establish planned, authorized, scheduled, active, blocked, completed, cancelled, corrected and archived event?","id":"planned-authorized-scheduled-active-blocked-completed-cancelled-corrected-and-archived-event-q01","kind":"lifecycle"},{"text":"Which authority, source, method, evidence, event time, knowledge time, confidence and limits support planned, authorized, scheduled, active, blocked, completed, cancelled, corrected and archived event?","id":"planned-authorized-scheduled-active-blocked-completed-cancelled-corrected-and-archived-event-q02","kind":"exception"},{"text":"How may planned, authorized, scheduled, active, blocked, completed, cancelled, corrected and archived event be validated, executed, challenged, corrected, related, retained or disposed without losing history?","id":"planned-authorized-scheduled-active-blocked-completed-cancelled-corrected-and-archived-event-q03","kind":"quality"}]},{"id":"timeliness-completeness-access-drift-asset-gap-exception-incident-feedback-and-improvement","name":"Timeliness, completeness, access drift, asset gap, exception, incident, feedback and improvement","description":"Records timeliness, completeness, access drift, asset gap, exception, incident, feedback and improvement as source-qualified desired, requested, executed or verified transition context without absorbing external master records.","questions":[{"text":"What transition-scoped identities, classes, roles, versions, values and explicit unknowns establish timeliness, completeness, access drift, asset gap, exception, incident, feedback and improvement?","id":"timeliness-completeness-access-drift-asset-gap-exception-incident-feedback-and-improvement-q01","kind":"measurement"},{"text":"Which authority, source, method, evidence, event time, knowledge time, confidence and limits support timeliness, completeness, access drift, asset gap, exception, incident, feedback and improvement?","id":"timeliness-completeness-access-drift-asset-gap-exception-incident-feedback-and-improvement-q02","kind":"classification"},{"text":"How may timeliness, completeness, access drift, asset gap, exception, incident, feedback and improvement be validated, executed, challenged, corrected, related, retained or disposed without losing history?","id":"timeliness-completeness-access-drift-asset-gap-exception-incident-feedback-and-improvement-q03","kind":"composition"}]}]},{"id":"provenance-interoperability-retention-and-safe-automation","name":"Provenance, interoperability, retention and safe automation","description":"Groups transition evidence for provenance, interoperability, retention and safe automation.","findings":[{"id":"scim-security-control-hr-system-task-and-provenance-crosswalk","name":"SCIM, security-control, HR-system, task and provenance crosswalk","description":"Records scim, security-control, hr-system, task and provenance crosswalk as source-qualified desired, requested, executed or verified transition context without absorbing external master records.","questions":[{"text":"What transition-scoped identities, classes, roles, versions, values and explicit unknowns establish scim, security-control, hr-system, task and provenance crosswalk?","id":"scim-security-control-hr-system-task-and-provenance-crosswalk-q01","kind":"interoperability"},{"text":"Which authority, source, method, evidence, event time, knowledge time, confidence and limits support scim, security-control, hr-system, task and provenance crosswalk?","id":"scim-security-control-hr-system-task-and-provenance-crosswalk-q02","kind":"temporal"},{"text":"How may scim, security-control, hr-system, task and provenance crosswalk be validated, executed, challenged, corrected, related, retained or disposed without losing history?","id":"scim-security-control-hr-system-task-and-provenance-crosswalk-q03","kind":"constraint"}]},{"id":"purpose-redaction-retention-hold-agent-authority-idempotency-dry-run-and-postcheck","name":"Purpose, redaction, retention, hold, agent authority, idempotency, dry run and post-check","description":"Records purpose, redaction, retention, hold, agent authority, idempotency, dry run and post-check as source-qualified desired, requested, executed or verified transition context without absorbing external master records.","questions":[{"text":"What transition-scoped identities, classes, roles, versions, values and explicit unknowns establish purpose, redaction, retention, hold, agent authority, idempotency, dry run and post-check?","id":"purpose-redaction-retention-hold-agent-authority-idempotency-dry-run-and-postcheck-q01","kind":"access"},{"text":"Which authority, source, method, evidence, event time, knowledge time, confidence and limits support purpose, redaction, retention, hold, agent authority, idempotency, dry run and post-check?","id":"purpose-redaction-retention-hold-agent-authority-idempotency-dry-run-and-postcheck-q02","kind":"requirement"},{"text":"How may purpose, redaction, retention, hold, agent authority, idempotency, dry run and post-check be validated, executed, challenged, corrected, related, retained or disposed without losing history?","id":"purpose-redaction-retention-hold-agent-authority-idempotency-dry-run-and-postcheck-q03","kind":"exception"}]}]}]}]},"agentConduct":{"may":["Create transition tasks from an approved plan.","Request account, access and equipment changes from their owners.","Track asset return and report missing items.","Verify that revoked access is actually removed."],"mustNot":["Grant access or terminate employment without delegated authority.","Delete personal mailboxes or records before retention review.","Disclose the reasons for a departure.","Mark a transition complete while access revocation is unverified.","Leave shared credentials of a leaver unrotated."],"requiresHuman":["Authorising termination dates and access levels.","Decisions on handling a leaver's personal data and files.","Exceptions such as retaining access after departure."]},"ethics":{"considerations":["Departures can be sensitive; dignity and confidentiality must be protected.","Leavers' personal data needs lawful handling and return of personal items.","Late access removal endangers the organisation and its customers."],"affectedParties":["Joining and leaving staff","Managers and colleagues","Customers whose data the staff could access"]},"owners":{"steward":"Dimension owner and worker-transition authority","roles":[{"name":"Employment or transition authority","responsibilities":["Own trigger and effective transition."]},{"name":"Manager and HR steward","responsibilities":["Own plan, role readiness and worker communication."]},{"name":"Identity and access steward","responsibilities":["Own accounts, credentials, grants and revocation evidence."]},{"name":"Asset and workplace steward","responsibilities":["Own custody, workspace and physical access."]},{"name":"Data and knowledge steward","responsibilities":["Own record custody and handover."]},{"name":"Training and support steward","responsibilities":["Own induction, competence and support."]},{"name":"Privacy and security steward","responsibilities":["Own protected views, incidents and residual risk."]},{"name":"Records and audit steward","responsibilities":["Own retention, holds, disposition and auditability."]}],"masterSystems":[]},"relations":[{"target":"Person, Employment, Role Assignment, Organization and Unit models","type":"references","note":"Bind subject and transition authority without absorbing workforce masters."},{"target":"Account, Credential, Group, Access Grant and Facility Access models","type":"composes","note":"Coordinate desired and verified access changes while masters retain effective state."},{"target":"Device, Asset, Licence, Workspace and Facility models","type":"references","note":"Coordinate custody and readiness through authoritative inventory references."},{"target":"Training, Competency, Agreement, Benefit, Dataset, Record, Communication and Audit models","type":"references","note":"Link obligations, readiness, handover and evidence without lifecycle cascade."},{"target":"NIST SP 800-53, CIS Controls v8, SCIM RFC 7643 and RFC 7644","type":"aligned","note":"Project security-control and identity-provisioning views with pinned versions and declared loss."},{"target":"Person, Employment and Role Assignment","type":"neighbor","note":"The case binds exact external relationships and desired changes but does not create or terminate those masters."},{"target":"Account, Credential, Group and Access Grant","type":"neighbor","note":"The case requests and verifies changes; authoritative identity and access systems own effective state and authorization semantics."},{"target":"Device, Asset, Licence, Workspace and Facility","type":"neighbor","note":"The case coordinates issue, transfer or return while inventory and custody masters retain identity and lifecycle."},{"target":"Training, Competency, Agreement and Benefit","type":"neighbor","note":"The case binds requirements and completion evidence but does not own the underlying definitions, awards, agreements or benefits."},{"target":"Dataset, Record, Communication and Audit","type":"neighbor","note":"Handover and access evidence are referenced; content, retention, disclosure and audit masters remain separately governed."},{"target":"WM-ORG-005","type":"parent"}],"interaction":{"identity":{"applicability":"required","items":["Authoritative master-system transition-case identifier qualified by source and profile.","Governed global case IRI.","Dimension UUID."]},"properties":{"applicability":"not-applicable","items":[]},"recognition":{"applicability":"optional","items":["A transition case names a person, an employment or role reference, a type (join, move, leave) and an effective date.","It is confused with the employment record, an access request or a training course."]},"capabilities":{"applicability":"required","items":["Register transition case: Governed operation to register transition case with attributable evidence and no hidden master-system mutation.","Plan and authorize transition: Governed operation to plan and authorize transition with attributable evidence and no hidden master-system mutation.","Provision identity, access and workplace: Governed operation to provision identity, access and workplace with attributable evidence and no hidden master-system mutation.","Issue and reconcile assets: Governed operation to issue and reconcile assets with attributable evidence and no hidden master-system mutation.","Transfer data and knowledge: Governed operation to transfer data and knowledge with attributable evidence and no hidden master-system mutation.","Deliver induction, training and support: Governed operation to deliver induction, training and support with attributable evidence and no hidden master-system mutation.","Revoke access and recover assets: Governed operation to revoke access and recover assets with attributable evidence and no hidden master-system mutation.","Close and certify transition: Governed operation to close and certify transition with attributable evidence and no hidden master-system mutation.","Measure quality and correct drift: Governed operation to measure quality and correct drift with attributable evidence and no hidden master-system mutation.","Project, retain and audit: Governed operation to project, retain and audit with attributable evidence and no hidden master-system mutation."]},"hazards":{"applicability":"required","items":["Orphaned accounts with active access after departure.","Lost devices or data leaving with former staff.","New staff unable to work because provisioning failed."]},"interfaces":{"applicability":"required","items":["SCIM 2.0 (IETF RFC 7643 and 7644).","HR Open Standards.","ISO/IEC 27001 Annex A controls on joiners, movers and leavers."]},"context":{"applicability":"required","items":["Employee, contractor, volunteer, contingent worker, public officer and third party require different profiles.","Planned and emergency or involuntary separations require different notice, timing and access controls.","SCIM expresses exchange and administrative status but does not define authorization semantics."]}},"sources":[{"title":"SP 800-53 Rev. 5 Security and Privacy Controls","url":"https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final","note":"National Institute of Standards and Technology"},{"title":"CIS Critical Security Controls Navigator v8","url":"https://www.cisecurity.org/controls/cis-controls-navigator/v8","note":"Center for Internet Security"},{"title":"SCIM Core Schema","url":"https://www.rfc-editor.org/info/rfc7643/","note":"Internet Engineering Task Force"},{"title":"SCIM Protocol","url":"https://www.rfc-editor.org/info/rfc7644/","note":"Internet Engineering Task Force"},{"title":"Getting On Board: A Model for Integrating and Engaging New Employees","url":"https://www.opm.gov/policy-data-oversight/training-and-development/reference-materials/online-courses/maximizing-employee-engagement/content/common/cw/data/Getting_Onboard_a_Model_for_Integrating_and_Engaging_New_Employees.pdf","note":"U.S. Office of Personnel Management"},{"title":"Managing Risk of Adverse or Involuntary Employee Separations","url":"https://www.cisa.gov/sites/default/files/2024-08/ISC-Managing-Risk-of-Adverse-Involuntary-Employee-Separations_508__2024-05-30.pdf","note":"Cybersecurity and Infrastructure Security Agency"},{"title":"Identity and access management","url":"https://www.ncsc.gov.uk/collection/10-steps/identity-and-access-management","note":"UK National Cyber Security Centre"},{"title":"ISO 30414:2025 Human capital reporting and disclosure","url":"https://www.iso.org/standard/30414","note":"International Organization for Standardization"},{"title":"General Data Protection Regulation","url":"https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=celex%3A32016R0679","note":"European Union"},{"title":"PROV-O: The PROV Ontology","url":"https://www.w3.org/TR/prov-o/","note":"World Wide Web Consortium"},{"title":"Web Content Accessibility Guidelines 2.2","url":"https://www.w3.org/TR/WCAG22/","note":"World Wide Web Consortium"},{"title":"NIST Privacy Framework","url":"https://www.nist.gov/privacy-framework","note":"National Institute of Standards and Technology"},{"title":"Disposing of records","url":"https://www.nationalarchives.gov.uk/information-management/manage-information/policy-process/disposal/","note":"The National Archives, United Kingdom"},{"title":"Date and Time on the Internet: Timestamps","url":"https://www.rfc-editor.org/rfc/rfc3339","note":"Internet Engineering Task Force"}],"openQuestions":["Verify relation rows and cross-model consistency once Employment, Role, Account, Access Grant, Asset, Training, Agreement and Audit parent models are supplied with explicit foreign keys, ownership rules and lifecycle bindings to enable aggregate composition validation.","Instantiate region-specific profiles for applicable jurisdictions (US federal with OPM/CISA rules, UK public sector with NCSC rules, EU member states with GDPR rules) with local labour law counsel review of confidentiality, access control, record retention, involuntary separation notice and worker rights variations.","Obtain ISO 30414:2025 full normative standard and integrate HR capital reporting conformance requirements into findings and service layer policies; currently represented only by public abstract, limiting organizational reporting scope.","Conduct secondary-provider independent review (Claude or Grok) on final relation rows and region-specific instantiations if model scope changes materially after deferred research completion; document provider selection rationale and any further timeouts.","Claude and Grok each timed out on one bounded attempt; no independent external result was admitted.","No approved relation rows were supplied; the Employment parent and proposed master relations remain candidate holds.","ISO 30414 is represented only by its public abstract; no normative conformance is claimed.","OPM and CISA are United States profiles, NCSC is United Kingdom guidance and GDPR is European Union law; none is universal.","Payroll, benefits, labour law, collective consultation, immigration, records, safety, accessibility and involuntary-separation rules vary by jurisdiction."],"resources":{"spec":"/models/wm-act-040-onboarding-offboarding/spec.yaml","agents":"/models/wm-act-040-onboarding-offboarding/AGENTS.md","source":"https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-act-040"},"provenance":{"origin":"world-models research","builtFrom":["models/wm-act-040-onboarding-offboarding/spec.yaml","ver-cy/world-models/card-supplements/wm-act-040-onboarding-offboarding.json"],"providers":["Codex"],"researchStatus":"reviewable-draft","generatedAt":"2026-09-06T07:54:53Z","builder":"tools/build_cards.py@1.0.0"},"completeness":{"sections":{"classifiers":"filled","whatItIs":"filled","purpose":"filled","distinguishingFeatures":"filled","structure":"filled","agentConduct":"filled","ethics":"filled","owners":"filled","relations":"filled","interaction.identity":"filled","interaction.properties":"not-applicable","interaction.recognition":"filled","interaction.capabilities":"filled","interaction.hazards":"filled","interaction.interfaces":"filled","interaction.context":"filled","sources":"filled"},"notes":{"interaction.properties":"Institutional or informational subject: no invented physical properties.","_supplement":"Sections authored in card supplement 1.0.0 by Claude (Opus 5.5) (2026-10-05, unreviewed). Written from the published specification and established practice in the field; no new sources were read. Unreviewed."},"score":1.0}}