{"catalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","download":{"releaseId":"sha256:10cf976bdde7c1dcd08884f2d5b7f6e425a93b7e5d0ed6f641b588a5d14f38ba","slug":"controls-public-content-external-sharing-authorization","url":"/assets/agent_workflow-controls-public-content-external-sharing-authorization-3233bc82.4c42d875bf9e8f93.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://evidenceflows.com/workflows/all/?w=controls-public-content-external-sharing-authorization","description":"Standing operator workflow for the public-posting and external-sharing authorization queue plus the quarterly permitted-without-authentication register and public-content exposure sweep, run per publication request and each quarter. Each operating cycle runs as one instance that enriches the existing UC-ACCESS-14 Control item in the control library (NIST 800-53 AC-14/AC-21/AC-22, family AC, preventive, quarterly) — it never creates a new control, and the workflow instance itself is the durable audit trail attached to that Control. In scope: public-facing systems (public website, support portal, developer documentation, status page, social channels) and external data shares governed by sharing agreements. Out of scope: authenticated internal content and access provisioning. Consumes each cycle: the living public-content and external-share register, the permitted-without-authentication register, and the active-sharing-agreements register (all pre-existing, refreshed cycle over cycle); the information-classification scheme (a Policy item, policy_type: standard); and the prior cycle's open carry-forward Issues. Named deliverables: the classified intake register, the authorization-verification log, the per-request publication dispositions, the refreshed permitted-without-authentication register, the quarterly exposure-sweep dashboard and findings report, and exposure corrective-action Issues linked to the Control. This control runs standalone — no upstream workflow feeds it and no downstream workflow consumes its output; the per-request authorization path and the quarterly sweep path are independent and both close in this instance.","details":{"canonicalUrl":"https://evidenceflows.com/workflows/all/?w=controls-public-content-external-sharing-authorization","capabilities":[],"controls":["UC-ACCESS-14"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:10cf976bdde7c1dcd08884f2d5b7f6e425a93b7e5d0ed6f641b588a5d14f38ba","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-public-content-external-sharing-authorization","standards":["nist-800-53"],"teams":["it","compliance-legal"]},"download":{"releaseId":"sha256:10cf976bdde7c1dcd08884f2d5b7f6e425a93b7e5d0ed6f641b588a5d14f38ba"},"history":{"digest":"269839a31b9cc0a21df58b12635fdc20baf54d142f8bf672ff0bccf50e70f357","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-10-04T21:48:26Z","updatedRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4"},"id":"wf:C32","mapUrl":"https://evidenceflows.com/?v=1&node=wf%3AC32","slug":"controls-public-content-external-sharing-authorization","sourceIds":["aiuc-1","nist-800-53"],"sourceUrl":null,"title":"Public Content & External Sharing Authorization","type":"workflow"},"relationships":[{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:cf6570a2c3cf7f1caef0ab9a761c8dd3b18bd337750b3d0018674a9f77d403a8","properties":{},"sourceDetailPath":"/data/v1/records/wf-c32-53bd0bae.json","sourceId":"wf:C32","targetDetailPath":"/data/v1/records/uc-uc-access-14-99fd72b5.json","targetId":"uc:UC-ACCESS-14","type":"operates"}],"schemaVersion":1}
