Semantius Logo

Learner Data Privacy

1. Overview

Learner data privacy substrate that compliance training depends on: GDPR Article 6/7 consent capture, Article 15 subject access requests, and Article 17 right-to-erasure processing for training data. Carved out from LMS-COMPLIANCE-TRAINING because privacy obligations apply across the LMS even where statutory training is out of scope.

2. Entity summary

Namedata_objectDescription
Data Deletion Requestsdata_deletion_requestsRight-to-erasure requests under GDPR Article 17, covering scope, anonymization policy, regulator deadline, and fulfillment status.
GDPR Consent Recordsgdpr_consent_recordsConsent records for learner training data under GDPR, capturing purpose, lawful basis, and grant and withdrawal timestamps.
Subject Access Requestssubject_access_requestsSubject access request tickets under GDPR Article 15, tracking requester, scope, fulfillment status, and regulator deadline.
EmployeesemployeesCanonical records of people currently or formerly employed, carrying identity, employment metadata, and links to position, manager, and org unit.
Records Retention Policiesrecords_retention_policiesLegal hold and disposition rules per document class, with regulatory retention periods and scheduled destruction dates.
UsersusersPlatform users referenced as assignees, authors, approvers, and creators across records.
flowchart TD
  classDef master fill:#d4f4dd,stroke:#27ae60,color:#0b3d20;
  classDef embedded_master fill:#fff4cc,stroke:#c79100,color:#5b4500;
  classDef consumer fill:#e8def8,stroke:#7b1fa2,color:#3a155d;
  subject_access_requests["Subject Access Requests"]
  data_deletion_requests["Data Deletion Requests"]
  employees["Employees"]
  users["Users"]
  gdpr_consent_records["GDPR Consent Records"]
  records_retention_policies["Records Retention Policies"]
  subject_access_requests -->|"discloses"| gdpr_consent_records
  data_deletion_requests -->|"voids"| gdpr_consent_records
  users -->|"grants_consent_in"| gdpr_consent_records
  users -->|"files_sar"| subject_access_requests
  users -->|"files_deletion_request"| data_deletion_requests
  employees -->|"is_linked_to"| users
  users -->|"maintains"| records_retention_policies
  class subject_access_requests master;
  class data_deletion_requests master;
  class employees embedded_master;
  class users consumer;
  class gdpr_consent_records master;
  class records_retention_policies consumer;
  style gdpr_consent_records stroke-dasharray:5 5;
  style records_retention_policies stroke-dasharray:5 5;

3. Entities catalog

#data_objectcanonical codesingularpluralrolemastered inmastered labelnecessitypersonal_contententity_typewrite tiernotes
1data_deletion_requestsdata_deletion_requestsData Deletion RequestData Deletion Requestsmaster--requiredyesoperational_workflow:manage-
2gdpr_consent_recordsgdpr_consent_recordsGDPR Consent RecordGDPR Consent Recordsmaster--optionalyesoperational_workflow:manage-
3subject_access_requestssubject_access_requestsSubject Access RequestSubject Access Requestsmaster--requiredyesoperational_workflow:manage-
4employeesemployeesEmployeeEmployeesembedded_masterhcm-core-workerCore Worker Recordrequiredyesoperational_workflow:manage-
5records_retention_policiesrecords_retention_policiesRecords Retention PolicyRecords Retention Policiesconsumerecm-records-govRecords Management and Information Governanceoptional-operational_workflow:manage-
6usersusersUserUsersconsumer(platform built-in)(platform built-in)required-operational_record:manage-

4. Aliases and industry synonyms

(none: no industry-scoped aliases for this scope)

5. Relationships

5.1 Intra-scope edges

fromverbtocardinalitykindnecessityowner_sidedelete_modefk_formatnotes
subject_access_requestsdisclosesgdpr_consent_recordsmany_to_manyassociationoptionalsourceclearreference-
data_deletion_requestsvoidsgdpr_consent_recordsmany_to_manyassociationoptionalsourceclearreference-

5.2 Built-in edges (users and other platform built-ins)

fromverbtocardinalitynecessityowner_sidedelete_modefk_formatnotes
usersgrants_consent_ingdpr_consent_recordsone_to_manyrequiredsourcerestrictreference-
usersfiles_sarsubject_access_requestsone_to_manyrequiredsourcerestrictreference-
usersfiles_deletion_requestdata_deletion_requestsone_to_manyrequiredsourcerestrictreference-
employeesis_linked_tousersone_to_oneoptionaltargetclearreference-
usersmaintainsrecords_retention_policiesone_to_manyoptionalsourceclearreference-

5.3 Cross-scope edges

5.3a Outbound from this scope’s masters and contributors

Edges this scope drives: the in-scope endpoint has role of master or contributor.

(none: no outbound cross-scope edges from this scope’s masters or contributors)

5.3b Context edges on embedded shells and consumed entities

Edges the canonical owner drives, shown for context: the in-scope endpoint has role of embedded_master, consumer, or derived.

fromverbtocardinalitynecessitydelete_modefk_formatnotes
employeestriggersiga_provisioning_eventsone_to_manyoptionalnonen/a-
employeesfinalized byonboarding_document_collectionsone_to_manyoptionalnonen/a-
audit_findingsreviewsrecords_retention_policiesmany_to_manyoptionalnonen/a-
pre_employeespromotes toemployeesone_to_onerequirednone (required-if-present)n/a-
legal_holdsidentifies_custodians_fromemployeesmany_to_manyoptionalnonen/a-
legal_advice_recordsreferencesemployeesmany_to_manyoptionalnonen/a-
employeesis host forhost_assignmentsone_to_manyrequirednone (required-if-present)n/a-
contingent_workersconverts_toemployeesone_to_oneoptionalnonen/a-
merit_recommendationsapplies toemployeesone_to_oneoptionalnonen/a-
equity_grantsgranted toemployeesone_to_oneoptionalnonen/a-
compensation_statementsissued toemployeesone_to_oneoptionalnonen/a-
employeesrequestsabsence_requestsone_to_manyoptionalnonen/a-
org_unitsgroupsemployeesone_to_manyrequirednone (required-if-present)n/a-
hcm_positionsis_filled_byemployeesone_to_oneoptionalnonen/a-
employeessignsemployment_contractsone_to_manyrequired⚠ audit: required composed child out of scopen/a-
employeesgeneratesemployment_eventsone_to_manyrequired⚠ audit: required composed child out of scopen/a-
employeestriggersasset_lifecycle_eventsone_to_manyoptionalnonen/a-
employeesholdsskill_profilesone_to_oneoptionalnonen/a-
employeestriggersservice_requestsone_to_manyoptionalnonen/a-
employeestriggerspay_runsone_to_manyoptionalnonen/a-
employeesenrolls_incourse_enrollmentsone_to_manyoptionalnonen/a-
employeesbecomescareer_aspirationsone_to_oneoptionalnonen/a-
employeesbecomeswork_shiftsone_to_manyoptionalnonen/a-
employeesbecomescompensation_statementsone_to_oneoptionalnonen/a-
employeestriggersbenefit_enrollmentsone_to_manyoptionalnonen/a-
employeestriggerscorporate_cardsone_to_manyoptionalnonen/a-
employeesspawnsonboarding_journeysone_to_oneoptionalnonen/a-
employeesspawnshr_casesone_to_manyoptionalnonen/a-
employeesfeedsheadcount_plansone_to_manyoptionalnonen/a-
employeesfeedsagency_time_entriesone_to_manyoptionalnonen/a-
employeesonboarded byonboarding_journeysone_to_manyrequirednone (required-if-present)n/a-
employeesreflectslearning_recordsone_to_manyoptionalnonen/a-
employeesreflected oncompliance_assignmentsone_to_manyoptionalnonen/a-
employeesdeclareslife_eventsone_to_manyoptionalnonen/a-
employeesupdated bylife_eventsone_to_manyoptionalnonen/a-
employeessubmitssurvey_responsesone_to_manyoptionalnonen/a-
employeesflagged onengagement_driversone_to_manyoptionalnonen/a-
employeesreflected onengagement_driversone_to_manyoptionalnonen/a-
employeesraiseshr_casesone_to_manyrequirednone (required-if-present)n/a-
employeesupdated byhr_casesone_to_manyoptionalnonen/a-
case_categoriesdrivesemployeesone_to_manyoptionalnonen/a-
contingent_workersreviewed_againstemployeesone_to_oneoptionalnonen/a-
records_retention_policiesretainscontent_documentsone_to_manyoptionalnonen/a-
records_retention_policiesretainsdocument_foldersone_to_manyoptionalnonen/a-
records_retention_policiesapplies to classificationdocument_classificationsone_to_manyoptionalnonen/a-
records_retention_policiesstreams_disposition_toaudit_engagementsone_to_manyoptionalnonen/a-
candidatesbecomesemployeesone_to_onerequirednone (required-if-present)n/a-
employeesfillshcm_positionsone_to_oneoptionalnonen/a-
employeeslearns_viacourse_enrollmentsone_to_manyrequirednone (required-if-present)n/a-
employeesenrolls_inbenefit_enrollmentsone_to_manyrequirednone (required-if-present)n/a-
survey_campaignstargetsemployeesmany_to_manyoptionalnonen/a-
employeeshasemergency_contactsone_to_manyrequired⚠ audit: required composed child out of scopen/a-
employeeshaswork_eligibility_documentsone_to_manyrequired⚠ audit: required composed child out of scopen/a-
employeeshasnational_idsone_to_manyrequired⚠ audit: required composed child out of scopen/a-
employeeshasworker_addressesone_to_manyrequired⚠ audit: required composed child out of scopen/a-
employeeshasemployee_dependentsone_to_manyrequired⚠ audit: required composed child out of scopen/a-
employeeshasworker_change_requestsone_to_manyrequirednone (required-if-present)n/a-
employeesapplies_ascandidatesone_to_manyoptionalnonen/a-
employeesis the worker behindtraveler_profilesone_to_oneoptionalnonen/a-
exit_risk_assessmentsassessesemployeesone_to_oneoptionalnonen/a-
insider_risk_casesconcernsemployeesone_to_manyoptionalnonen/a-
frontline_recognitionsrecognizesemployeesone_to_manyrequirednone (required-if-present)n/a-
advocate_profilesrepresentsemployeesone_to_onerequirednone (required-if-present)n/a-

6. Cross-domain context

6.1 Master consumers (other modules / domains that embed this scope’s masters)

(none: no other module embeds this scope’s masters; the canonical owners do.)

6.2 Outbound handoffs (events this scope publishes)

source moduletarget domaintarget moduletrigger_eventtransitionpayloadintegrationfrictiondescription
HCM-CORE-WORKERHRSDHRSD-CASE-MGMTemployee.terminatedterminated (lifecycle)employeesevent_streammediumTermination kicks off offboarding case (exit interview, knowledge transfer, paperwork). Multiple downstream HRSD tasks created.
HCM-CORE-WORKERIGAIGA-ACCESS-REQUESTemployee.createdcreated (lifecycle)employeesapi_callhighNew employee in HCM triggers directory account creation and birthright-role assignment in IGA. High friction because role-to-entitlement mappings drift per business unit, and IGA frequently needs additional context (cost center, manager, location) that arrives later in the journey. Same trigger event as the HCM → Onboarding and HCM → Payroll handoffs.
HCM-CORE-WORKERIGAIGA-ACCESS-REQUESTemployee.promoted(lifecycle)employeesevent_streamhighPromotion (mover event) requires entitlement re-evaluation: add new role access, revoke prior-role access. SoD risk window during transition.
HCM-CORE-WORKERIGAIGA-ACCESS-REQUESTemployee.terminatedterminated (lifecycle)employeesapi_callhighTermination in HCM must immediately revoke identity access in IGA: disable account, remove group memberships, terminate app-level entitlements. Failure modes: contractor terminations not flowing (different HCM table); rehires confuse the de-provisioning idempotency; access lingers after termination is the canonical audit finding.
HCM-CORE-WORKERHCMHCM-LIFECYCLE-WORKFLOWSemployee.createdcreated (lifecycle)employeeslifecycle_progressionlowNew worker record surfaces in self-service: manager dashboard, new-hire welcome surface, lifecycle task inbox. In-process state read; no message bus.
HCM-CORE-WORKERHCMHCM-LIFECYCLE-WORKFLOWSemployee.terminatedterminated (lifecycle)employeeslifecycle_progressionlowTermination drives the offboarding self-service flow: exit-interview prompt, equipment-return task, knowledge-handoff surfaces in the lifecycle workflow module.
LMS-CT-GDPRHCM(domain-level)data_deletion_request.fulfilled(lifecycle)data_deletion_requestsapi_callmedium-
LMS-CT-GDPRHCM(domain-level)gdpr_consent_record.withdrawn(state_change)gdpr_consent_recordsevent_streammedium-
HCM-CORE-WORKERPAYROLLPAYROLL-RUNemployee.createdcreated (lifecycle)employeesapi_callmediumNew employee in HCM triggers comp profile activation in Payroll: gross-to-net rules selected by jurisdiction, deductions initialised, bank account and tax setup collected via Onboarding flow. Same trigger event as the HCM → Onboarding handoff; both subscribe to the employee.created event.
HCM-CORE-WORKERPAYROLLPAYROLL-RUNemployee.promoted(lifecycle)employeesevent_streammediumPromotion typically includes salary change. Effective-dated change must flow to PAYROLL with retroactive handling.
HCM-CORE-WORKERPAYROLLPAYROLL-RUNemployee.terminatedterminated (lifecycle)employeesevent_streamhighTermination drives final pay (severance, accrued PTO payout, prorated bonus). Cross-vendor stack when HCM and PAYROLL are different vendors; retro-adjustments are common.
HCM-CORE-WORKERLMSLMS-COURSE-DELIVERYemployee.createdcreated (lifecycle)employeesevent_streamlowNew-hire creation provisions required-training assignments (compliance, role-based). Drives day-one and 30-day learning workflows.
LMS-CT-GDPRLMSLMS-COURSE-DELIVERYdata_deletion_request.fulfilled(lifecycle)data_deletion_requestslifecycle_progressionmedium-
LMS-CT-GDPRLMSLMS-COURSE-DELIVERYgdpr_consent_record.withdrawn(state_change)gdpr_consent_recordslifecycle_progressionmedium-
LMS-CT-GDPRLMSLMS-COMPLIANCE-TRAININGgdpr_consent_record.withdrawn(state_change)gdpr_consent_recordslifecycle_progressionmedium-
HCM-CORE-WORKERTALENT-MGMTTALENT-PERFORMANCE-MGMTemployee.createdcreated (lifecycle)employeesapi_calllowNew employee triggers talent-profile initialisation in Talent Management: career aspirations, mobility preferences, skills profile stubs. Same employee.created trigger as Onboarding / Payroll / IGA handoffs.
HCM-CORE-WORKERTALENT-MGMTTALENT-PERFORMANCE-MGMTemployee.promoted(lifecycle)employeesevent_streamlowPromotion updates succession-plan slots and 9-box placement context.
HCM-CORE-WORKERWFM(domain-level)employee.createdcreated (lifecycle)employeesevent_streamlowNew employee provisioned in HCM becomes a schedulable resource in WFM - identity, position, base FTE. Mid-shift onboarding and badge-binding are typical edge cases.
HCM-CORE-WORKERCOMP-MGMTCOMP-PLANNINGemployee.createdcreated (lifecycle)employeesevent_streamlowNew-hire creation provides compensation basis. Bands and grades attach via job profile.
HCM-CORE-WORKERCOMP-MGMTCOMP-PLANNINGemployee.promoted(lifecycle)employeesevent_streamlowPromotion event triggers off-cycle compensation review (eligibility, band placement, increase recommendation) in COMP-MGMT.
HCM-CORE-WORKERBEN-ADMINBEN-ENROLLMENTemployee.createdcreated (lifecycle)employeesevent_streammediumNew-hire creation seeds benefits eligibility (waiting periods, default elections). Drives carrier feed setup at end of new-hire window.
HCM-CORE-WORKERBEN-ADMINBEN-ENROLLMENTemployee.terminatedterminated (lifecycle)employeesevent_streamhighTermination triggers benefits termination, COBRA / equivalent notices, and dependent coverage decisions. Late notifications cause coverage gaps.
HCM-CORE-WORKEREXPENSE(domain-level)employee.terminatedterminated (lifecycle)employeesevent_streammediumTermination triggers EXPENSE corporate-card deactivation and outstanding-report close-out.
HCM-CORE-WORKERPSAPSA-PROJECT-DELIVERYemployee.terminatedterminated (lifecycle)employeesevent_streammediumTerminated employee may be the assignee on open project_tasks. PROJECT-DELIVERY needs to surface affected tasks for reassignment or completion handover.
HCM-CORE-WORKERPSAPSA-RESOURCE-MGMTattrition_risk.high(state_change)employeesevent_streamhighML attrition score crosses high threshold. PSA resource managers may proactively rebalance assignments away from at-risk consultants on critical engagements. High friction: probabilistic→deterministic pattern (score requires judgment call), false-positive volume can swamp the staffing queue.
HCM-CORE-WORKERPSAPSA-RESOURCE-MGMTemployee.createdcreated (lifecycle)employeesevent_streamlowNew consultant hired. PSA resource pool adds the employee as available capacity; skill inventory record is seeded for downstream certifications.
HCM-CORE-WORKERPSAPSA-RESOURCE-MGMTemployee.promoted(lifecycle)employeesevent_streamlowConsultant promoted (level / job profile change). PSA reevaluates billable rate band and skill inventory; existing project_assignments may need rate revision.
HCM-CORE-WORKERPSAPSA-RESOURCE-MGMTemployee.terminatedterminated (lifecycle)employeesevent_streammediumConsultant terminated. PSA must release any active project_assignments, return capacity to bench and re-allocate forecast. Medium friction: leaver-event timing varies (immediate vs notice period) and active assignments may need urgent rebalancing.

6.3 Inbound handoffs (events this scope reacts to)

target modulesource domainsource moduletrigger_eventtransitionpayloadintegrationfrictiondescription
HCM-CORE-WORKERATSATS-CANDIDATE-CRMcandidate.hiredhired (lifecycle)employeesevent_streammediumCandidate-to-employee conversion: hired candidate from ATS triggers employee-record creation in HCM. Field mapping (candidate → employee) is rarely perfect; missing fields (legal name spelling, work-eligibility detail, tax IDs) get collected in the Onboarding journey and back-filled into HCM.
HCM-CORE-WORKERCOMP-MGMTCOMP-PLANNINGmerit_cycle.approvedapproved (state_change)employeesevent_streamlowCycle-close pay-rate changes post to the worker record (base salary, bonus target, equity guideline).
HCM-CORE-WORKEREMP-EXPEMP-EXP-CONTINUOUS-LISTENattrition_risk.high(state_change)employeesapi_callhighAttrition-risk inference from engagement signals surfaces to managers via HCM dashboards. Probabilistic-signal → deterministic-action pattern: a risk score is not a directive; intervention is gated by manager judgment, data-privacy rules (anonymity floor), and DEI-bias concerns.
HCM-CORE-WORKERPAPA-PREDICTIVE-MODELSattrition_risk.high(state_change)employeesevent_streamhighFlight-risk score flagged on employee; HR-business-partner motion required. Probabilistic-signal-to-deterministic-action friction shape; false-positive volume drives mistrust.
HCM-CORE-WORKERMDM(domain-level)employee_golden_record.createdactive (lifecycle)employeesapi_callmediumResolved identity → HCM links operational HR record.

6.4 Master providers (modules / domains that own masters this scope embeds)

data_objectrole herenecessitycanonical owner(s)slice notes
employeesembedded_masterrequiredHCM-CORE-WORKER (HCM)-
records_retention_policiesconsumeroptionalECM-RECORDS-GOV (ECM)-
usersconsumerrequired(platform built-in)-

7. Lifecycle states

data_deletion_requests (Data Deletion Request)

orderstate_nameinitial?terminal?requires_permission?derived gatedescription
1received----
2in_progress-----
3fulfilled-lms-ct-gdpr:fulfill-
4declined-lms-ct-gdpr:decline-

employees (Employee)

This scope holds employees as embedded_master; the canonical state machine is owned by HCM-CORE-WORKER.

orderstate_nameinitial?terminal?requires_permission?derived gatedescription
1draft---Pre-hire stub created during requisition or onboarding handoff; not yet a worker of record.
2active--lms-ct-gdpr:active_employeeWorker is currently employed and appears in headcount, payroll eligibility, and directory feeds.
3on_leave--lms-ct-gdpr:on_leave_employeeEmployee is on approved leave (parental, medical, sabbatical); active record but suppressed from some downstream feeds.
4suspended--lms-ct-gdpr:suspended_employeeEmployment temporarily halted (investigation, disciplinary); pay and access may be paused.
5terminated-lms-ct-gdpr:terminated_employeeEmployment ended (voluntary or involuntary); final pay processed, access deprovisioned.
orderstate_nameinitial?terminal?requires_permission?derived gatedescription
1granted----
2withdrawn-lms-ct-gdpr:withdraw-
3expired----

records_retention_policies (Records Retention Policy)

This scope holds records_retention_policies as consumer; the canonical state machine is owned by ECM-RECORDS-GOV.

orderstate_nameinitial?terminal?requires_permission?derived gatedescription
10draft---Retention policy being authored by the records officer.
20under_review----Retention policy circulated for review before activation.
30active--ecm-records-gov:activate_retention_policyRetention policy in force and applied to in-scope records.
40superseded---Retention policy replaced by a newer active policy.
50retired---Retention policy decommissioned and no longer applied.

subject_access_requests (Subject Access Request)

orderstate_nameinitial?terminal?requires_permission?derived gatedescription
1received----
2in_progress-----
3fulfilled--lms-ct-gdpr:fulfill-
4closed-lms-ct-gdpr:close-

8. Permissions and business rules (derived)

8.1 Permissions

permissiontierdescriptionincluded in :admin?
lms-ct-gdpr:readbaseline-readRead access to every entity in the module
lms-ct-gdpr:managebaseline-manageEdit operational records
lms-ct-gdpr:adminbaseline-adminEdit reference data and inherit every workflow gate below-
lms-ct-gdpr:active_employeeworkflow-gate (lifecycle)Transition employees into state active
lms-ct-gdpr:on_leave_employeeworkflow-gate (lifecycle)Transition employees into state on_leave
lms-ct-gdpr:suspended_employeeworkflow-gate (lifecycle)Transition employees into state suspended
lms-ct-gdpr:terminated_employeeworkflow-gate (lifecycle)Transition employees into state terminated
lms-ct-gdpr:withdrawworkflow-gate (lifecycle)Transition gdpr_consent_records into state withdrawn
lms-ct-gdpr:fulfillworkflow-gate (lifecycle)Transition subject_access_requests into state fulfilled
lms-ct-gdpr:closeworkflow-gate (lifecycle)Transition subject_access_requests into state closed
lms-ct-gdpr:declineworkflow-gate (lifecycle)Transition data_deletion_requests into state declined
lms-ct-gdpr:view_all_subject_access_requestsoverride (personal_content)View all subject_access_requests rows beyond row-scope
lms-ct-gdpr:manage_all_subject_access_requestsoverride (personal_content)Manage all subject_access_requests rows beyond row-scope
lms-ct-gdpr:view_all_data_deletion_requestsoverride (personal_content)View all data_deletion_requests rows beyond row-scope
lms-ct-gdpr:manage_all_data_deletion_requestsoverride (personal_content)Manage all data_deletion_requests rows beyond row-scope
lms-ct-gdpr:view_all_employeesoverride (personal_content)View all employees rows beyond row-scope
lms-ct-gdpr:manage_all_employeesoverride (personal_content)Manage all employees rows beyond row-scope
lms-ct-gdpr:view_all_gdpr_consent_recordsoverride (personal_content)View all gdpr_consent_records rows beyond row-scope
lms-ct-gdpr:manage_all_gdpr_consent_recordsoverride (personal_content)Manage all gdpr_consent_records rows beyond row-scope

8.2 Business rules

rule_namedata_objectsource flagintent
subject_access_request_edit_scopesubject_access_requestshas_personal_contentRow-scope by default; override via lms-ct-gdpr:view_all_subject_access_requests / lms-ct-gdpr:manage_all_subject_access_requests
data_deletion_request_edit_scopedata_deletion_requestshas_personal_contentRow-scope by default; override via lms-ct-gdpr:view_all_data_deletion_requests / lms-ct-gdpr:manage_all_data_deletion_requests
employee_edit_scopeemployeeshas_personal_contentRow-scope by default; override via lms-ct-gdpr:view_all_employees / lms-ct-gdpr:manage_all_employees
gdpr_consent_record_edit_scopegdpr_consent_recordshas_personal_contentRow-scope by default; override via lms-ct-gdpr:view_all_gdpr_consent_records / lms-ct-gdpr:manage_all_gdpr_consent_records

9. Roles, RACI, and responsibilities (derived)

Baseline roles, the permission hierarchy, and RACI realization are DERIVED from this scope’s entity-type write tiers + process_raci; none of it is stored in the catalog (the deployer provisions it from this blueprint).

9.1 LMS-CT-GDPR

Baseline roles:

rolebaseline grant
lms-ct-gdpr_viewerlms-ct-gdpr:read
lms-ct-gdpr_managerlms-ct-gdpr:manage

Permission hierarchy:

permissionincludes
lms-ct-gdpr:adminlms-ct-gdpr:manage
lms-ct-gdpr:managelms-ct-gdpr:read
lms-ct-gdpr:adminlms-ct-gdpr:active_employee
lms-ct-gdpr:adminlms-ct-gdpr:on_leave_employee
lms-ct-gdpr:adminlms-ct-gdpr:suspended_employee
lms-ct-gdpr:adminlms-ct-gdpr:terminated_employee
lms-ct-gdpr:adminlms-ct-gdpr:withdraw
lms-ct-gdpr:adminlms-ct-gdpr:fulfill
lms-ct-gdpr:adminlms-ct-gdpr:close
lms-ct-gdpr:adminlms-ct-gdpr:decline
lms-ct-gdpr:adminlms-ct-gdpr:view_all_subject_access_requests
lms-ct-gdpr:adminlms-ct-gdpr:manage_all_subject_access_requests
lms-ct-gdpr:adminlms-ct-gdpr:view_all_data_deletion_requests
lms-ct-gdpr:adminlms-ct-gdpr:manage_all_data_deletion_requests
lms-ct-gdpr:adminlms-ct-gdpr:view_all_employees
lms-ct-gdpr:adminlms-ct-gdpr:manage_all_employees
lms-ct-gdpr:adminlms-ct-gdpr:view_all_gdpr_consent_records
lms-ct-gdpr:adminlms-ct-gdpr:manage_all_gdpr_consent_records

Processes wired:

process_keyprocess_namePCF codePCF IDleveldescription
manage_maintain_employee_dataManage and maintain employee data7.7.3105243Capturing and updating employee information and data and information on the employees.
manage_leave_absenceManage leave of absence7.6.2.2105154Managing the period of time that an employee must be away from their primary job, while maintaining the status of employee (i.e., paid and unpaid leave of absence but not vacations, holidays, hiatuses, sabbaticals, and work-from-home programs).
manage_separationManage separation7.6.2105133Managing the process of employee separation, including leaves of absence, resignations, discharges, and layoffs. Inform the employee of the termination. Complete paperwork for continuation of benefits. Enter employment status change into system.

RACI realization:

actorkindraciprocess_keyrealization
HR-PEOPLE-OPS-SPECIALISTpersonaresponsiblemanage_maintain_employee_datagrant gates [lms-ct-gdpr:active_employee] + the gated entities’ write tier
HR-BUSINESS-PARTNERpersonaaccountablemanage_maintain_employee_dataapproval gate
HR-HRIS-ADMINpersonaconsultedmanage_maintain_employee_dataadvisory read grant
PEOPLE-MANAGERpersonainformedmanage_maintain_employee_datanotification side effect (trigger_event / webhook_receiver)
HR-PEOPLE-OPS-SPECIALISTpersonaresponsiblemanage_leave_absencegrant gates [lms-ct-gdpr:on_leave_employee] + the gated entities’ write tier
PEOPLE-MANAGERpersonaaccountablemanage_leave_absenceapproval gate
HR-BUSINESS-PARTNERpersonaconsultedmanage_leave_absenceblocking consultation state
HR-HRIS-ADMINpersonainformedmanage_leave_absencenotification side effect (trigger_event / webhook_receiver)
HR-PEOPLE-OPS-SPECIALISTpersonaresponsiblemanage_separationgrant gates [lms-ct-gdpr:terminated_employee] + the gated entities’ write tier
HR-BUSINESS-PARTNERpersonaaccountablemanage_separationapproval gate
PEOPLE-MANAGERpersonaconsultedmanage_separationadvisory read grant
HR-HRIS-ADMINpersonainformedmanage_separationnotification side effect (trigger_event / webhook_receiver)

9.2 Functional ownership and default grants

responsibilitybusiness functiondefault roledefault tier
ownerLearning and Developmentadmin:admin
contributorGovernance, Risk and Compliancemanage:manage
contributorLegalmanage:manage
consumerManufacturing Operationsread:read
consumerSalesread:read
consumerSoftware Engineeringread:read