1 of 34

Employee Onboarding and Offboarding Task Force�Security Recommendations

College-led Process Alignment Task Force for Employee Onboarding & Offboarding (EO&O) 

�Presented to ctcLink College Collaboration Group (cCCG) �July 22, 2026

1

2 of 34

Agenda

Overview of Task Force

Benefits of Process Alignment

Progress Report

Scope of Work

Recommendations

Enhancement Request Recommendations

Questions

2

3 of 34

EO&O Task Force Membership Roles

25 + representatives from colleges & SBCTC agency

    • 15 college representatives
      • Small, medium, large, multi-campus, district 
      • Technical college representation
      • Colleges fully using the system
      • Colleges not fully using the system
      • Roles including Local Security Administrators, Human Resources, Training
    • 8 SBCTC representatives
      • Roles include Application Security, Functional Analyst-HCM, ctcLink Training 
    • 3 Supporting Roles
      • PAW Leadership
      • Notes & Logistics

3

4 of 34

EO&O Task Force Members

  • Subject Matter Experts
    • Andrea Britten, Pierce
    • Annie Vo, Seattle Colleges
    • Claire Jordan, Tacoma
    • Dawnell Schroeder, Green River
    • Ebony Jackson, Renton Technical
    • Erica Jesberger, Columbia Basin
    • Erika Bockmann, Walla Walla
    • Jack Foerster, Edmonds
    • Jane Benson, Whatcom
    • Joy Anglesey, Centralia
    • Marah Selves, Lake Washington
    • Rose Madison, Everett
    • Rosemary Darrough, Highline
    • Shayne Wong, Clover Park
    • Will Peters, South Puget Sound
  • Task Force Lead 
    • Sindie Howland, Everett
  • SBCTC Representatives
    • Sheila Sloan, Application Security
    • Laurel Anderson, Application Security
    • Agnieszka Pederson, HCM
    • Linda Mellot, HCM
    • Gretchen Fulmer, ctcLink Training
    • Jerry Lambert, ctcLink Training
    • Carmen McKenzie, Data Services 
    • Ivy Brent, Data Services  
  • cCCG/Paw Liaisons
    • Dani Rider, SBCTC
    • Wright Harrison, Green River
    • Terye Senderhauf, Peninsula

4

5 of 34

Benefits of Process Alignment 

  • Improved Process Efficiency
    • Identifies "best practice" workflows 
    • Standardizes across the consortium
  • Better College Staff Experience
    • For daily users, provides consistency and clarity
    • For infrequent users, provides guidance and documentation
  • Targeted Training Materials
    • Training can be universal and include more detail
    • The "why" and "when" are global when the process is the same for all colleges
  • More Reliable Reporting 
    • Better collection practices minimize "dirty data" and improves accuracy
    • The resulting reports and analytics are comparable across colleges

5

  • Simplified Auditing & Compliance
    • Streamlines
    • Makes regional and government compliance simpler and quicker
  • Shared Support Efficiency
    • Faster troubleshooting
    • Higher 'first-call' resolution
    • Fewer configurations to document and support
  • Better system maintenance
    • Oracle updates can be tested and implemented more rapidly
    • Simple universal knowledge base articles and scripts can apply to every college
    • Less custom coding to update
    • Single process flows can be easily validated 

6 of 34

Task Force Objectives & Responsibility 

  • Develop a "Best Practice" model for all colleges in the system
  • Establish recommendations based on ctcLink guiding principles 
  • Understand ctcLink functionality and ctcLink system requirements before considering enhancement requests 
  • Ensure each process has a tailored best practice framework to promote adoption and alignment

6

7 of 34

ctcLink Guiding Principles that apply to Process Alignment 

  • Enhancement Requests (ERs) seeking ctcLink customizations must be considered only as meets the following conditions:
    • The ER is mandated by a statutory requirement business case (approved by governance) that benefit the system as a whole, or an overriding majority of colleges.
    • The ER does not adversely delay Oracle releases and/or updates due to excessive retroactive code updates.
  • The ctcLink system is the system of record. System Enhancement Requests that seek to replicate information and processes of ctcLink are discouraged.
  • Processes and procedures may not need to be identical on each campus; however, processes and procedures must be sufficiently similar to remain within the common academic and business services framework of the community and technical college system.

7

8 of 34

Progress Report – July 2026

  • Received Task Force nominations
  • Selected Task Force members
  • October 29, 2025: Held Kickoff
  • Defined Scope of Work​
  • Sent out Bright Spots Survey
  • Gathered College SME contact list​
  • Established two meetings per week for HCM & Security
  • Started meeting one meeting per week for Training

8

Recommendation Status

  • Total Brainstormed so far (57)
  • Informational (11)
  • College/SBCTC Process Changes (30)
  • Global Configuration Changes (11)
  • Customizations (5)

Security Recommendations (16)

  • College Process Change (6)
  • Enhancement Requests (10)

9 of 34

10 of 34

Recommendations for Sustainable Success Grounded in Strategy

  • A response to systemic challenges that required a collective, peer-driven approach.
  • 15 Taskforce members from 15 colleges ensures that every recommendation carries the weight of practical, front-line user experience.
  • These are not rushed, half-baked ideas. The taskforce invested significant time in a deliberate journey of discovery and rigorous debate.

10

11 of 34

Scope of Work: Employee Onboarding  

  • Employee Onboarding Security Steps 
    1. Establishing an Employee's Security User Profile
    2. Adjustments to a User Profile for Additional Access
    3. Who Decides Elevated Access Needs?
    4. Multi-College Employees: Confirm "Other College" Access
    5. HCM Pillar Access Setup
    6. Campus Solutions Access Setup
    7. Faculty Access Setup
    8. Finance Pillar Access Setup 

11

Today we are presenting specific Security onboarding only.   

The processes on the right are covered today.  

HCM specific recommendations were presented on July 8, 2026.

Cross-pillar and Training will be presented at future meetings. 

The alphabetic letters align with recommendation numbering.

12 of 34

College Business Process �Recommendations

The following recommendation codes are not sequential as this is a partial list. More

HCM/Security joint recommendations will be presented at a future cCCG meeting. 

12

13 of 34

SEC B.3.1 Templates for Security

Process: Adjustments to a User Profile for Additional Access

Current State

  • It is a challenge to manage the numerous security configurations across the different pillars.
  • Individual roles with "confusing acronyms" and "similar-sounding names" are added manually.
  • Employees performing specific crossover functions (e.g., Grant Management or Project Costing) have different roles assigned when they should receive the exact same set of permissions. There is no standardization.
  • Potential Segregation of Duties (SOD) conflicts are only found during audits so mitigating controls are not put into place when security is assigned.

13

14 of 34

SEC B.3.1 Templates for Security �Recommendation

Recommendation – College Business Process

  • Colleges shall create ctcLink Security templates that include roles and secondary security in User Profile Definition (UPD) and SACR for job functions (not job title). Examples: Advisor, Department Manager, Query Access, Budget Authorities, General Student Support, Basic HCM job role.
  • When adding SACR to a template, use the Security User Replacement tool to copy SACR settings to templates as a shortcut for building templates.
  • When adding UPD to a template, use Launchpad to copy UPD settings to templates as a shortcut for building templates.
  • For initial build out of templates, submit a ticket to the SBCTC Security team if assistance is needed.

14

15 of 34

SEC B.3.1 Templates for Security

Future State

  • Templates simplify security management by grouping required roles and secondary security configurations by job function.
  • Templates are based on job functions rather than job titles, ensuring employees performing similar work receive consistent and appropriate access and ensures that employees performing a specific crossover function (e.g., Grant Management or Project Costing) receives the same set of permissions.
  • Employees receive the correct combination of roles and permissions needed to complete their job duties without requiring manual assignment of individual security roles.
  • Templates reduce complexity by eliminating the need to interpret individual role names and acronyms when assigning access.
  • Standardized, pre-defined templates make it easier to identify and review potential Segregation of Duties (SOD) conflicts and document mitigating controls for audit requirements.
  • Templates streamline onboarding by allowing employees to receive appropriate access more quickly.
  • Templates support employees with multiple responsibilities by allowing colleges to combine applicable job functions without unnecessary duplicate security requests.

15

16 of 34

SEC C.2.1 Data Access Approvers

Process: Who Decides Elevated Access Needs? 

Current State

  • The role responsible at each college for reviewing and approving ctcLink security access varies by college and may be called something different such as Pillar Lead, Data Steward, Data Governance.
  • Employees potentially have roles and access they do not need. Example: Bob left basic needs position, they created two positions to replace Bob. Can't just copy over security roles from Bob to new employee, Fran. Fran may have too much or too little access due to position needs changing.
  • Many colleges do not have a formal review and approval process in place, resulting in Local Security Administrators (LSAs) making all security decisions.
  • Similar positions may have different security access across the college, creating inconsistencies and increasing the risk of inappropriate access.

16

17 of 34

SEC C.2.1 Data Access Approvers Recommendation

Recommendation – College Business Process 

  • Data Access Approvers are responsible for reviewing and approving ctcLink security roles for every position that uses the system. A review is required to ensure roles remain adequate, consistent, and appropriate for the position. Careful attention should be made when reviewing PII access, starting with the lowest level needed to complete job duties.
  • Reviews are needed in the following situations:
    • When an employee’s ctcLink job duties change and require the addition or removal of security access.
    • When a vacant position is being reopened and the job duties have changed from the previous version of the position.

17

18 of 34

SEC C.2.1 Data Access Approvers Future State

Future State

  • Data Access Approvers ensure employees have the appropriate level of access to perform their job responsibilities, no more and no less.
  • Similar positions receive consistent security access across the college, reducing confusion and supporting equitable business processes.
  • Security access aligns with SBCTC security templates and follows the principle of least privilege, especially for access to sensitive and PII data.
  • Employees begin training with the access they need, reducing delays and improving the onboarding experience.
  • Consistent role assignments improve security, strengthen accountability, and provide clear visibility into who has access to what.
  • A formal approval process establishes checks and balances by separating the review and approval of security access from the assignment of security roles.
  • Security reviews become a standard part of position management, ensuring access remains current as job duties evolve.

18

19 of 34

SEC D.1.1 Coordinating O&O with other colleges  - 1 of 3

Process: Multi-College Employees: Confirm "Other College" Access

Current State

  • Some colleges not offboarding in a timely manner or not completely offboarding (leaving SACR).
  • Lack of communication between colleges causes issues with managing the timing of offboarding/onboarding.
  • Some colleges do not respond quickly and some never respond. This could be caused by using an outdated contact list or email goes to spam.
  • Often faculty have extremely different roles at different colleges and coordination between colleges is required.
  • Some employees are no longer working but still on payroll and they do not get offboarded from CS and FIN roles they should no longer have access to.

19

20 of 34

SEC D.1.1 Coordinating O&O with other colleges  - 1 of 3 Recommendation

Recommendation – College Business Process

When emailing or calling other LSAs, use the LSA contact query (QXX_SEC_LSA_EMAIL_CONTACTS), rather than static lists, to coordinate onboarding/offboarding with other colleges.

20

21 of 34

SEC D.1.1 Coordinating O&O with other colleges  - 1 of 3 Future State

Future State

  • Colleges use the LSA Contact Query as the primary source for contacting Local Security Administrators (LSAs) at other colleges, ensuring requests are sent to current contacts.
  • Onboarding and offboarding activities are coordinated more effectively between colleges, reducing delays and preventing communication gaps.
  • Employees receive the appropriate access at the appropriate time, while access is removed promptly when it is no longer needed.
  • Consistent communication between colleges improves the management of employees who work across multiple institutions or have different responsibilities at each college.
  • Timely coordination reduces the risk of employees retaining unnecessary access and strengthens overall security and compliance.
  • Using a single, current source for LSA contacts eliminates reliance on outdated distribution lists and reduces missed requests caused by incorrect contact information.

21

22 of 34

SEC D.1.2 Coordinating O&O with other colleges  - 2 of 3

Process: Multi-College Employees: Confirm "Other College" Access

Current State

  • Communication between colleges occurs through a variety of channels, resulting in inconsistent response times.
  • Email requests may be delayed, overlooked, filtered as spam, or sent to outdated contacts.
  • Time-sensitive onboarding and offboarding requests can be delayed while waiting for responses.
  • There is no standard communication channel for coordinating security requests between colleges.
  • Sensitive information may inadvertently be shared through inappropriate communication methods.

22

23 of 34

SEC D.1.2 Coordinating O&O with other colleges  - 2 of 3 Recommendation

Recommendation – College Business Process

  • Use the LSA Teams chat when coordinating onboarding/offboarding with other colleges.
  • No PII data should be shared in the LSA Teams chat.

23

24 of 34

SEC D.1.2 Coordinating O&O with other colleges  - 2 of 3 Future State

Future State 

  • The LSA Teams chat becomes the standard communication channel for coordinating onboarding and offboarding activities between colleges.
  • Real-time communication improves response times and speeds coordination for time-sensitive security requests.
  • Colleges collaborate more efficiently, reducing delays in granting or removing access.
  • A standardized communication method creates a more consistent experience across the college system.
  • PII is excluded from Teams conversations, ensuring sensitive information is shared only through approved, secure methods.

24

25 of 34

SEC D.1.3 Coordinating O&O with other colleges  - 3 of 3

Process: Multi-College Employees: Confirm "Other College" Access

Current State

  • New LSAs are not always added to the LSA Teams chat or may not be added by their colleagues in a timely manner.
  • There is no consistent process to ensure all active LSAs have access to the Teams chat.
  • Employees who are no longer serving as LSAs may remain in the Teams chat.
  • Inconsistent membership can delay communication, reduce collaboration, and create unnecessary security exposure.

25

26 of 34

SEC D.1.3 Coordinating O&O with other colleges  - 3 of 3 Recommendation

Recommendation – College Business Process 

  • When onboarding LSAs, State Board should automatically add the new LSA employees to the LSA Teams chat.
  • State Board should conduct twice a year audits to ensure appropriate employees are on the LSA Teams chat.

26

27 of 34

SEC D.1.3 Coordinating O&O with other colleges  - 3 of 3 Future State

Future State 

  • New LSAs are automatically added to the LSA Teams chat as part of the onboarding process.
  • Twice yearly audits ensure Teams chat membership remains current and limited to active LSAs.
  • All LSAs have timely access to system wide communications, collaboration, and support.
  • Consistent membership improves communication, strengthens collaboration between colleges, and reduces the risk of unauthorized access to LSA discussions.

27

28 of 34

SEC H.2.1 Process Group Mapping

Process: Finance Pillar Access Setup

Current State

  • Finance process group acronyms can be difficult to interpret, making it challenging to assign the appropriate security access.
  • Inconsistent understanding of process groups may result in users receiving too much, too little, or incorrect access.
  • Similar job roles may receive different process groups based on individual interpretation.
  • Time is spent researching or validating process group assignments, delaying onboarding and security requests.

28

29 of 34

SEC H.2.1 Process Group Mapping�Recommendation

Recommendation – College Business Process

Use the FSCM security process groups Quick Reference Guide (QRG) to clarify the 29 Finance (AP/AR) process group acronyms and ensure process groups are assigned accurately based on employee job responsibilities.

29

30 of 34

SEC H.2.1 Process Group Mapping �Future State

Future State

  • Colleges consistently use the FSCM Security Process Groups QRG when assigning Finance process groups.
  • Employees receive process groups that accurately align with their job responsibilities and required system functions.
  • Similar positions receive consistent security assignments across colleges, reducing variation and improving standardization.
  • Clear guidance reduces uncertainty, improves the accuracy of security requests, and supports the principle of least privilege.
  • Consistent process group assignments streamline onboarding, reduce rework, and improve the overall security request process.

30

31 of 34

College Business Process�Questions?

31

32 of 34

Enhancement Request Recommendations

32

33 of 34

Link to Enhancement Request Presentation

33

34 of 34

Next Steps

  • Send questions or feedback to Sindie Howland, showland@everettcc.edu
  • Vote on Security College Business Process Recommendations
  • Enhancement Request Process
    • Provide Feedback on voting form
  • HR/Security Cross-Functional Recommendations at next cCCG meeting, August 26, 2026

34