{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "OFC",
  "title": "Offboarding Checklist",
  "definitionRef": {
    "artifactId": "OFC",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "OFC.artifactDefinition.v2",
    "title": "Offboarding Checklist"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Document Title": "Offboarding Checklist",
        "Document ID": "OFC-CHK-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "HR Manager",
        "Approver": "ISMS Manager",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Document Title: Offboarding Checklist",
        "Document ID: OFC-CHK-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: HR Manager",
        "Approver: ISMS Manager",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example documents offboarding for a Product Operations employee, including leaver data, role context, access revocation, asset return, knowledge transfer, execution evidence, open items, lifecycle linkage and final completion decision. This checklist tests whether the 11 September 2026 freeze is complete for the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table"
    },
    {
      "id": "change_log",
      "title": "Revision history",
      "groups": [
        {
          "text": "A published change is a new row. Do not edit an approved version in place."
        },
        {
          "rows": [
            {
              "Version": "1.0",
              "Date": "2026-08-29",
              "Change": "Initial Arcfield Platform publication.",
              "Approved by": "ISMS Manager"
            },
            {
              "Version": "1.1",
              "Date": "2026-09-11",
              "Change": "Approved Arcfield worked example after the 11 September 2026 internal audit.",
              "Approved by": "ISMS Manager"
            }
          ]
        }
      ],
      "contentType": "revision_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "groups": [
        {
          "text": "Copy this file as the controlled Word master for your ISMS. The Arcfield identity fields on the cover are the approved worked example. Complete the steps below when you adopt the file for your organization."
        },
        {
          "items": [
            "Fill the cover identity fields (Organization, Version, Classification, Owner, Approver, Effective Date and Next Review Date) when you adopt this file. The Arcfield values shown here are the approved worked example.",
            "Issue your own version and a new Revision history row. Do not edit an approved version in place.",
            "Cite this approved version from related records. Do not copy this file into those records."
          ]
        }
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "leaver_data",
      "title": "Leaver data",
      "values": {
        "Employee name": "Alex Morgan",
        "Employee ID": "EMP-2026-047",
        "End date": "2026-09-30",
        "Employment type": "Permanent",
        "Department": "Product Operations",
        "Line manager": "Head of Product Operations",
        "HR owner": "HR Manager",
        "Offboarding case reference": "HR-OFF-2026-018",
        "Last working day": "2026-09-27",
        "Termination reason category": "Voluntary resignation"
      },
      "text": "Record the minimum leaver and case information needed to connect HR, access, asset, knowledge transfer, and evidence records.",
      "groups": [
        {
          "id": "introduction",
          "heading": "What this checklist is",
          "level": 1,
          "text": "This document is Arcfield's Offboarding Checklist. Provide auditable evidence for Offboarding Checklist. It is not a methodology essay or the governing policy. This checklist applies to the Arcfield Platform (B2B SaaS for regulated fintech and health customers): production, customer data, CI/CD, privileged access and critical suppliers. Neighbouring records (AOAVC, AI, ISO) cite this Document Control version. Do not copy these paragraphs into them."
        },
        {
          "id": "scope",
          "heading": "Scope",
          "level": 1,
          "text": "Use this table before you copy a rule into another record or exclude a duty from this file.",
          "rows": [
            {
              "In this file": "The rules, roles, worked Arcfield example and the records this file owns.",
              "Not in this file": "The ISMS boundary (ISS), Annex A selection (SoA) or live rows in AOAVC, AI, ISO."
            },
            {
              "In this file": "Interfaces that must cite this Document Control version, including CI/CD, identity and suppliers where they affect CIA.",
              "Not in this file": "Live ISS scope rows, SoA applicability decisions, or neighbouring live registers. Those files keep their own approved versions; this file does not duplicate them."
            }
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "level": 1,
          "text": "These terms are local to this file. Expand every acronym on first use in the body.",
          "rows": [
            {
              "Term": "Check ID",
              "Meaning": "The stable identifier for one check or question. Do not reuse an ID for a different question."
            },
            {
              "Term": "Exception",
              "Meaning": "A time-bound, approved departure with expiry and a compensating control."
            },
            {
              "Term": "CIA",
              "Meaning": "Confidentiality, Integrity and Availability of in-scope information and services."
            },
            {
              "Term": "Document Control version",
              "Meaning": "The approved version cited from neighbouring records. Do not copy this body into those records."
            }
          ]
        },
        {
          "id": "leaver_data",
          "heading": "Leaver data",
          "level": 1,
          "text": "Use this table for leaver data in the Arcfield Platform ISMS. Record the minimum leaver and case information needed to connect HR, access, asset, knowledge transfer, and evidence records. Field Value Employee name Alex Morgan Employee ID EMP-2026-047 End date 2026-09-30 Employment type Permanent Department Product Operations Line manager Head of Product Operations HR owner HR Manager Offboarding case reference HR-OFF-2026-018 Last working day 2026-09-27 Termination reason category Voluntary resignation Cite this Document Control version from neighbouring records.",
          "rows": [
            {
              "Field": "Employee name",
              "Value": "Alex Morgan"
            },
            {
              "Field": "Employee ID",
              "Value": "EMP-2026-047"
            },
            {
              "Field": "End date",
              "Value": "2026-09-30"
            },
            {
              "Field": "Employment type",
              "Value": "Permanent"
            },
            {
              "Field": "Department",
              "Value": "Product Operations"
            },
            {
              "Field": "Line manager",
              "Value": "Head of Product Operations"
            },
            {
              "Field": "HR owner",
              "Value": "HR Manager"
            },
            {
              "Field": "Offboarding case reference",
              "Value": "HR-OFF-2026-018"
            },
            {
              "Field": "Last working day",
              "Value": "2026-09-27"
            },
            {
              "Field": "Termination reason category",
              "Value": "Voluntary resignation"
            }
          ]
        },
        {
          "id": "validation_checklist",
          "heading": "Validation checklist",
          "level": 1,
          "text": "Use this table for validation checklist in the Arcfield Platform ISMS. Use this table as the main validation audit trail with one row per performed asset-owner check. Check ID Area What was validated Required? Performed by Approved by Date Result Evidence reference Notes AOAVC-001 Asset identity Asset ID AST-001, asset name Production platform, owner, custodian and lifecycle status Yes Asset Manager Service Owner 2026-08-29 Successful AI-AST-001-2026-Q3 Matches Asset Inventory. AOAVC-002 Classification Confidential classification and CIA needs for Production platform Yes Asset Owner ISMS Manager 2026-08-29 Successful CLASS-AST-001-2026-Q3 Confidentiality high, availability high. AOAVC-003 Dependencies Cloud hosting, identity provider and backup dependency links Yes IT Operations Service Owner 2026-08-29 Pending DEP-AST-001-2026-Q3 Supplier contact update pending. Cite this Document Control version from neighbouring records.",
          "rows": [
            {
              "Check ID": "AOAVC-001",
              "Area": "Asset identity",
              "What was validated": "Asset ID AST-001, asset name Production platform, owner, custodian and lifecycle status",
              "Required?": "Yes",
              "Performed by": "Asset Manager",
              "Approved by": "Service Owner",
              "Date": "2026-08-29",
              "Result": "Successful",
              "Evidence reference": "AI-AST-001-2026-Q3",
              "Notes": "Matches Asset Inventory."
            },
            {
              "Check ID": "AOAVC-002",
              "Area": "Classification",
              "What was validated": "Confidential classification and CIA needs for Production platform",
              "Required?": "Yes",
              "Performed by": "Asset Owner",
              "Approved by": "ISMS Manager",
              "Date": "2026-08-29",
              "Result": "Successful",
              "Evidence reference": "CLASS-AST-001-2026-Q3",
              "Notes": "Confidentiality high, availability high."
            },
            {
              "Check ID": "AOAVC-003",
              "Area": "Dependencies",
              "What was validated": "Cloud hosting, identity provider and backup dependency links",
              "Required?": "Yes",
              "Performed by": "IT Operations",
              "Approved by": "Service Owner",
              "Date": "2026-08-29",
              "Result": "Pending",
              "Evidence reference": "DEP-AST-001-2026-Q3",
              "Notes": "Supplier contact update pending."
            }
          ]
        },
        {
          "id": "evidence_reviewed",
          "heading": "Evidence reviewed",
          "level": 1,
          "text": "Use this table for evidence reviewed in the Arcfield Platform ISMS. Record the evidence reviewed to support the validation conclusion. Evidence item Source system / document Owner Date reviewed Quality result Gap identified? Evidence reference Notes Asset Inventory extract for AST-001 Asset Inventory Asset Manager 2026-08-29 Complete No AI-AST-001-2026-Q3 Owner and classification present. Access Control Matrix for Production platform Access Control Matrix IT Operations 2026-08-29 Partial Yes ACM-APP-CRM-2026-Q3 Supplier contact needs update. Cite this Document Control version from neighbouring records.",
          "rows": [
            {
              "Evidence item": "Asset Inventory extract for AST-001",
              "Source system / document": "Asset Inventory",
              "Owner": "Asset Manager",
              "Date reviewed": "2026-08-29",
              "Quality result": "Complete",
              "Gap identified?": "No",
              "Evidence reference": "AI-AST-001-2026-Q3",
              "Notes": "Owner and classification present."
            },
            {
              "Evidence item": "Access Control Matrix for Production platform",
              "Source system / document": "Access Control Matrix",
              "Owner": "IT Operations",
              "Date reviewed": "2026-08-29",
              "Quality result": "Partial",
              "Gap identified?": "Yes",
              "Evidence reference": "ACM-APP-CRM-2026-Q3",
              "Notes": "Supplier contact needs update."
            }
          ]
        },
        {
          "id": "validation_decision",
          "heading": "Validation decision",
          "level": 1,
          "text": "Use this table for validation decision in the Arcfield Platform ISMS. State the final validation decision. Field Value Validation result Conditionally accepted Accepted by owner Service Owner Reviewer ISMS Manager Open blocker decision No access blocker; supplier contact update remains open Final status Conditionally complete Decision date 2026-08-29 Evidence reference AOAVC-DEC-2026-Q3 Cite this Document Control version from neighbouring records.",
          "rows": [
            {
              "Field": "Validation result",
              "Value": "Conditionally accepted"
            },
            {
              "Field": "Accepted by owner",
              "Value": "Service Owner"
            },
            {
              "Field": "Reviewer",
              "Value": "ISMS Manager"
            },
            {
              "Field": "Open blocker decision",
              "Value": "No access blocker; supplier contact update remains open"
            },
            {
              "Field": "Final status",
              "Value": "Conditionally complete"
            },
            {
              "Field": "Decision date",
              "Value": "2026-08-29"
            },
            {
              "Field": "Evidence reference",
              "Value": "AOAVC-DEC-2026-Q3"
            }
          ]
        }
      ],
      "contentType": "field_table"
    },
    {
      "id": "termination_context",
      "title": "Termination and role context",
      "values": {
        "Role": "Product Operations Specialist",
        "Team": "Product Operations",
        "Business unit": "SaaS Platform",
        "Reports to": "Head of Product Operations",
        "Critical responsibilities": "Customer onboarding workflow administration",
        "Sensitive duties": "Customer operational data handling",
        "Customer or supplier contacts": "CloudDesk support contact list",
        "Privileged access held?": "No",
        "Security context": "Standard user with customer data access"
      },
      "contentType": "field_table"
    },
    {
      "id": "access_revocation",
      "title": "Access revocation",
      "groups": [
        {
          "text": "Use this table or list as the working record. Name owners, systems and evidence so a second person can apply the same rule."
        },
        {
          "rows": [
            {
              "System / application": "Customer Portal",
              "Account / identity": "EMP-2026-047",
              "Access type": "Standard user",
              "Revocation action": "Disable user and transfer owned workflows",
              "Performed by": "IT Operations",
              "Approved by": "Line Manager",
              "Revocation date": "2026-09-30",
              "Result": "Successful",
              "Evidence reference": "IAM-OFF-2026-018-01",
              "Notes": "Completed after last working day."
            },
            {
              "System / application": "Ticketing Platform",
              "Account / identity": "alex.morgan",
              "Access type": "Operations agent",
              "Revocation action": "Remove role and reassign queue ownership",
              "Performed by": "IT Operations",
              "Approved by": "Support Operations Manager",
              "Revocation date": "2026-09-30",
              "Result": "Successful",
              "Evidence reference": "IAM-OFF-2026-018-02",
              "Notes": "Queue ownership transferred."
            }
          ]
        }
      ],
      "contentType": "access_table"
    },
    {
      "id": "asset_return",
      "title": "Asset return and media handling",
      "groups": [
        {
          "text": "Use this table or list as the working record. Name owners, systems and evidence so a second person can apply the same rule."
        },
        {
          "rows": [
            {
              "Asset / equipment": "Managed laptop",
              "Asset ID": "LAP-047",
              "Custodian": "Alex Morgan",
              "Return required?": "Yes",
              "Return date": "2026-09-27",
              "Condition": "Good",
              "Wipe / reset performed": "Yes",
              "Performed by": "IT Operations",
              "Result": "Successful",
              "Evidence reference": "ASSET-RETURN-2026-047",
              "Notes": "MDM wipe completed."
            },
            {
              "Asset / equipment": "Office badge",
              "Asset ID": "BADGE-047",
              "Custodian": "Alex Morgan",
              "Return required?": "Yes",
              "Return date": "2026-09-27",
              "Condition": "Returned",
              "Wipe / reset performed": "Not applicable",
              "Performed by": "Office Manager",
              "Result": "Successful",
              "Evidence reference": "BADGE-OFF-2026-047",
              "Notes": "Badge disabled."
            }
          ]
        }
      ],
      "contentType": "asset_table"
    },
    {
      "id": "knowledge_transfer",
      "title": "Knowledge and ownership transfer",
      "groups": [
        {
          "text": "Use this table or list as the working record. Name owners, systems and evidence so a second person can apply the same rule."
        },
        {
          "rows": [
            {
              "Responsibility / record": "Customer onboarding workflow queue",
              "Transfer action": "Reassigned active cases",
              "New owner": "Product Operations Lead",
              "Due date": "2026-09-25",
              "Completed by": "Line Manager",
              "Completion date": "2026-09-25",
              "Result": "Successful",
              "Evidence reference": "KT-OFF-2026-018",
              "Notes": "No orphaned cases."
            }
          ]
        }
      ],
      "contentType": "evidence_table"
    },
    {
      "id": "checklist_execution_log",
      "title": "Checklist execution log",
      "groups": [
        {
          "text": "Use this table or list as the working record. Name owners, systems and evidence so a second person can apply the same rule."
        },
        {
          "rows": [
            {
              "Check ID": "OFC-001",
              "Control area": "HR closure",
              "What was done": "Confirmed final working day and offboarding trigger.",
              "Required?": "Yes",
              "Performed by": "HR Manager",
              "Approved by": "Line Manager",
              "Date": "2026-09-20",
              "Result": "Successful",
              "Evidence reference": "HR-OFF-2026-018",
              "Notes": "Case opened."
            },
            {
              "Check ID": "OFC-002",
              "Control area": "Access revocation",
              "What was done": "Removed application access and disabled identity.",
              "Required?": "Yes",
              "Performed by": "IT Operations",
              "Approved by": "ISMS Manager",
              "Date": "2026-09-30",
              "Result": "Successful",
              "Evidence reference": "IAM-OFF-2026-018",
              "Notes": "No privileged access remained."
            }
          ]
        }
      ],
      "contentType": "evidence_log_table"
    },
    {
      "id": "open_items_and_exceptions",
      "title": "Open items and exceptions",
      "groups": [
        {
          "text": "Use this table or list as the working record. Name owners, systems and evidence so a second person can apply the same rule."
        },
        {
          "rows": [
            {
              "Item ID": "OFC-OPEN-001",
              "Description": "Confirm retention owner for two archived onboarding workflow records.",
              "Owner": "Product Operations Lead",
              "Due date": "2026-10-05",
              "Blocker?": "No",
              "Exception required?": "No",
              "Exception approver": "",
              "Expiry date": "",
              "Compensating control": "Records are read-only and access revoked.",
              "Status": "Open follow-up",
              "Notes": "Track through document register update."
            }
          ]
        }
      ],
      "contentType": "exception_table"
    },
    {
      "id": "lifecycle_linkage",
      "title": "Lifecycle linkage",
      "groups": [
        {
          "text": "Use this table or list as the working record. Name owners, systems and evidence so a second person can apply the same rule."
        },
        {
          "rows": [
            {
              "Record": "HR case",
              "Reference": "HR-OFF-2026-018",
              "Owner": "HR Manager",
              "Status": "Closed"
            },
            {
              "Record": "IAM change log",
              "Reference": "IAM-OFF-2026-018",
              "Owner": "IT Operations",
              "Status": "Complete"
            },
            {
              "Record": "Asset Inventory",
              "Reference": "ASSET-RETURN-2026-047",
              "Owner": "Asset Manager",
              "Status": "Updated"
            }
          ]
        }
      ],
      "contentType": "linkage_table"
    },
    {
      "id": "offboarding_completion_decision",
      "title": "Offboarding completion decision",
      "values": {
        "HR completion": "Complete",
        "Line-manager confirmation": "Confirmed",
        "IT confirmation": "Access removed and assets returned",
        "Security review": "No blocker identified",
        "Open blocker decision": "No blockers; one retention follow-up remains non-blocking.",
        "Final status": "Conditionally complete",
        "Completion date": "2026-09-30",
        "Evidence reference": "OFC-COMPLETE-2026-018"
      },
      "contentType": "decision_table"
    },
    {
      "id": "validation_checklist",
      "title": "Validation checklist",
      "rows": [
        {
          "Check ID": "AOAVC-001",
          "Area": "Asset identity",
          "What was validated": "Asset ID AST-001, asset name Production platform, owner, custodian and lifecycle status",
          "Required?": "Yes",
          "Performed by": "Asset Manager",
          "Approved by": "Service Owner",
          "Date": "2026-08-29",
          "Result": "Successful",
          "Evidence reference": "AI-AST-001-2026-Q3",
          "Notes": "Matches Asset Inventory."
        },
        {
          "Check ID": "AOAVC-002",
          "Area": "Classification",
          "What was validated": "Confidential classification and CIA needs for Production platform",
          "Required?": "Yes",
          "Performed by": "Asset Owner",
          "Approved by": "ISMS Manager",
          "Date": "2026-08-29",
          "Result": "Successful",
          "Evidence reference": "CLASS-AST-001-2026-Q3",
          "Notes": "Confidentiality high, availability high."
        },
        {
          "Check ID": "AOAVC-003",
          "Area": "Dependencies",
          "What was validated": "Cloud hosting, identity provider and backup dependency links",
          "Required?": "Yes",
          "Performed by": "IT Operations",
          "Approved by": "Service Owner",
          "Date": "2026-08-29",
          "Result": "Pending",
          "Evidence reference": "DEP-AST-001-2026-Q3",
          "Notes": "Supplier contact update pending."
        }
      ],
      "text": "Use this table as the main validation audit trail with one row per performed asset-owner check.",
      "contentType": "section"
    },
    {
      "id": "evidence_reviewed",
      "title": "Evidence reviewed",
      "rows": [
        {
          "Evidence item": "Asset Inventory extract for AST-001",
          "Source system / document": "Asset Inventory",
          "Owner": "Asset Manager",
          "Date reviewed": "2026-08-29",
          "Quality result": "Complete",
          "Gap identified?": "No",
          "Evidence reference": "AI-AST-001-2026-Q3",
          "Notes": "Owner and classification present."
        },
        {
          "Evidence item": "Access Control Matrix for Production platform",
          "Source system / document": "Access Control Matrix",
          "Owner": "IT Operations",
          "Date reviewed": "2026-08-29",
          "Quality result": "Partial",
          "Gap identified?": "Yes",
          "Evidence reference": "ACM-APP-CRM-2026-Q3",
          "Notes": "Supplier contact needs update."
        }
      ],
      "text": "Record the evidence reviewed to support the validation conclusion.",
      "contentType": "section"
    },
    {
      "id": "validation_decision",
      "title": "Validation decision",
      "rows": [
        {
          "Field": "Validation result",
          "Value": "Conditionally accepted"
        },
        {
          "Field": "Accepted by owner",
          "Value": "Service Owner"
        },
        {
          "Field": "Reviewer",
          "Value": "ISMS Manager"
        },
        {
          "Field": "Open blocker decision",
          "Value": "No access blocker; supplier contact update remains open"
        },
        {
          "Field": "Final status",
          "Value": "Conditionally complete"
        },
        {
          "Field": "Decision date",
          "Value": "2026-08-29"
        },
        {
          "Field": "Evidence reference",
          "Value": "AOAVC-DEC-2026-Q3"
        }
      ],
      "text": "State the final validation decision.",
      "contentType": "section"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative ISMS requirements this companion artifact supports.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, Context of the Organization (Clause 4)",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "AOAVC Asset Owner Asset Validation Checklist (Implementation & Certification, Asset Management & Information Classification)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "AI Asset Inventory (Implementation & Certification, Asset Management & Information Classification)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "ACM Access Control Matrix (Secure Engineering, Access Control & Identity Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983455"
            }
          ],
          "text": "Use this table or list as the working record. Name owners, systems and evidence so a second person can apply the same rule."
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Checklist",
    "role": "Completeness check against the freeze"
  }
}
