{"catalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","download":{"releaseId":"sha256:0e0021998364a42f1cde3c12c246bee5c4f006e4c9c3f7215c619cbb4cba2e6b","slug":"grc-vendor-offboarding-secure-termination","url":"/assets/agent_workflow-grc-vendor-offboarding-secure-termination-015e96d2.71d0fe0fc7c2feba.json"},"kind":"record","record":{"attributes":{"department":"procurement","domain":"grc","lineOfDefense":"operate"},"canonicalUrl":"https://evidenceflows.com/workflows/all/?w=grc-vendor-offboarding-secure-termination","description":"Vendor Offboarding & Secure Termination as a decision-aware workflow triggered on a relationship termination. It runs on the vendor's existing Vendor register item - the offboarding enriches that record, it never creates a duplicate: the run marks the Vendor `monitoring_status: exited` and stamps `contract_end_date`, and where the vendor's risk is registered it links to the existing third-party Risk item (`category: third_party`). In scope: executing one vendor's contractual exit end to end - inventorying the vendor's access, data, and dedicated components; containing access immediately on for-cause exits; transitioning each service to its successor; revoking every credential; verifying data return or destruction; disposing of internal-side components using defined techniques; and retaining the post-relationship evidence. Out of scope: the underlying contract-termination or renewal business decision and any separately-governed affiliate contracts. Initial inputs are the termination trigger and effective date, the vendor's contractual exit provisions (master agreement, data processing addendum, exit plan) - which also carry the data-disposition and evidence-retention clauses consumed downstream - and the existing Vendor register item with its risk tier; there is no upstream workflow. The named deliverable is the retained, audit-standing termination evidence package assembled at compile-termination-evidence-and-retain; the workflow is terminal - close-and-archive exports the run and hands off nothing downstream.","details":{"canonicalUrl":"https://evidenceflows.com/workflows/all/?w=grc-vendor-offboarding-secure-termination","capabilities":[],"controls":["UC-TPRM-06"],"domains":["grc"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:0e0021998364a42f1cde3c12c246bee5c4f006e4c9c3f7215c619cbb4cba2e6b","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:grc-vendor-offboarding-secure-termination","standards":["nist-800-53","nist-csf-2"],"teams":["procurement","it"]},"download":{"releaseId":"sha256:0e0021998364a42f1cde3c12c246bee5c4f006e4c9c3f7215c619cbb4cba2e6b"},"history":{"digest":"1ae721fee61167a0f57846200158e5fb0ce2cd59c5a44bad9f54317a4741f0df","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-10-04T21:48:26Z","updatedRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4"},"id":"wf:G30","mapUrl":"https://evidenceflows.com/?v=1&node=wf%3AG30","slug":"grc-vendor-offboarding-secure-termination","sourceIds":["nist-800-53","nist-csf-2"],"sourceUrl":null,"title":"Vendor Offboarding & Secure Termination","type":"workflow"},"relationships":[{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:e551307721f1b290d8a4ef02e0f7113f58963d184d26519bcec63fbc88e7e009","properties":{},"sourceDetailPath":"/data/v1/records/wf-g30-ab069982.json","sourceId":"wf:G30","targetDetailPath":"/data/v1/records/uc-uc-tprm-06-0d2c1b90.json","targetId":"uc:UC-TPRM-06","type":"operates"}],"schemaVersion":1}
