Print one set per student for the live session. This pack contains the waiver case file (the M3 centrepiece and capstone), the year-in-review file (M4), and the separation pack (M5). Trainer notes and expected-reasoning guidance are on the final sheet.
| Sheet | Content | Used in |
|---|---|---|
| 1 | Waiver case file — role brief (front page) | M3 + capstone |
| 2 | Integrity reference — six traits, seven risk areas, two safeguards, tie-breaker | M3 + capstone |
| 3 | Recommendation template | M3 + capstone |
| 4 | Year-in-review file + annual check worksheet | M4 |
| 5 | Separation pack — post card, checklist, debrief card | M5 |
| 5B | Governed response — clearance information posted online (ai.heart canon) | M5 Part 1 |
| 6 | Trainer notes — expected reasoning (trainer only) | All |
Your role: security adviser supporting the recruitment. The hiring delegate has asked for your recommendation on an eligibility-waiver question.
The role: requires ongoing access to classified material — a clearance is therefore mandatory.
The vacancy: eleven months unfilled. The program has a genuine, measurable backlog; the delegate reports real harm to delivery.
The applicant:
The delegate's proposal: approve an eligibility waiver on scarce-skills grounds — "the path exists precisely for this situation."
Your task: weigh the file against the six integrity traits and the two safeguards (Sheet 2), then write a recommendation a reviewer can check (Sheet 3). The file is deliberately incomplete — note what you need before you could decide. The waiver is an amended, escalated risk decision, not a routine fix.
1 · Which traits can you assess today, and from what evidence?
2 · Which traits cannot be assessed cleanly — and what blocks them?
3 · What do the two safeguards require you NOT to weigh?
4 · Who escalates this decision, and how does the escalation become visible?
5 · What information, if it existed, would change your recommendation?
Integrity is described in the cited requirement through six traits. Write them in your own words as you would explain them to a candidate:
1 · Maturity —
2 · Trustworthiness —
3 · Honesty —
4 · Resilience —
5 · Tolerance —
6 · Loyalty —
Why disclosure matters more than the thing disclosed: honesty is on the list, and the assessment is about how a person handles the process, not a search for reasons to refuse them.
The six traits are examined across seven risk factor areas. Tick each you can say something about from THIS file:
External loyalties Personal relationships and conduct Financial Alcohol and drug
Criminal history Security violations Emotional and mental health
Tie-breaker: where genuine doubt remains, it is resolved in favour of the national interest.
1 · Sexual orientation is not a relevant factor.
2 · No negative inference is drawn from someone seeking mental-health counselling. The mental-health area is about wellbeing and support — never about penalising a person for getting help.
Put these where staff can find them without having to ask you. The people who most need to read them are the people who never raise the topic.
Your entity's half is the sponsorship record — who approved the clearance, at what level, why. The authority's half is the grant itself. A clearance permits ongoing access at a level; it does not confer entitlement to particular material — that is still need-to-know.
Recommendation (circle one):
Proceed with waiver · Decline waiver · Split the decision · Defer — more information needed
| Assessable today (traits + evidence you can point to) | |
| Not assessable today (and what blocks it) | |
| What I need before deciding | |
| Escalation step (who decides, and how the decision is recorded) | |
| Residual-risk position (what remains uncertain after your assessment) | |
| Signed (practice) | date |
Write the paragraph a delegate could actually sign. Structure: the decision → the reasoning the reviewer can check → the conditions or information that would change it.
Last year: no flags. Annual check completed, no issues noted.
This year's file contains:
Nothing else in the file. No adverse findings, no security incidents, no changes to the holder's role.
| Step | Your entry |
|---|---|
| 1 · What has changed since last year? | |
| 2 · Which changes are suitability-relevant — and why? | |
| 3 · What do I note (record) vs escalate (act)? | |
| 4 · Who receives the escalation, if any? | |
| 5 · What stays with the entity vs the vetting authority? |
I used the same questions as every other year — no improvisation.
I described facts, not judgements ("debt mentioned by a colleague, unverified" — not "he's a gambler").
I weighed the two safeguards: nothing here is a relevant factor if it touches
orientation or mental-health support.
I treated the annual check as routine — a step, not a verdict.
Debrief: What makes a change "suitability-relevant"? Who decides what — entity or authority? How do you keep the check calm? (PSPF Req 164, Req 168; Personnel Std Req 0172)
The text (as posted): "Celebrating five years of trust — proud to hold my security clearance. Great place to work."
Your response, as the security function:
One sentence to the person who posted:
Clearance information must not be posted online (new 2026 requirement). The truth of the post is not the point — the exposure is.
The request: a departing officer hands back their pass but asks to keep system access for two weeks "in case anything comes up", and asks what they can still say about their work after they leave.
Separation checklist — complete both halves:
Debrief completed — ongoing obligations confirmed (what they can/cannot say, who their security contact remains):
Access withdrawn — systems, passes, keys, remote access, all accounts, effective immediately:
The two lines they can say after leaving:
The line they cannot:
Debrief: Why is the debrief a security control and not a formality? What does "clean separation" protect — the person, the entity, the information? (ISM-2104; PSPF Req 182, Req 186)
Input under review: the public post — "Celebrating five years of trust — proud to hold
my security clearance. Great place to work."
Classification of the event: an output that crossed the containment boundary without a release
certificate. The holder does not hold release authority for clearance information; the entity's security
function does. The response is therefore governed, not improvised.
| L | Layer | Check on this case | Verdict |
|---|---|---|---|
| L1 | Input validation | Post text captured and verified — hash · schema · source: public profile, no doctoring. | PASS |
| L2 | Context analysis | Intent celebratory, not malicious — but state fit fails: public platform, uncontrolled audience, no state in which clearance disclosure is authorised. | HOLD |
| L3 | Harm / loss | Loss cap: clearance level, agency and tenure exposed to open collection; harm floor: personal pride does not outweigh exposure. | HOLD |
| L4 | Equity weighting | Bias bound: the holder is corrected and supported, not punished — no adverse inference against integrity; Δ impact: proportionate, non-public response. | PASS |
| L5 | Coherence check | Response consistent with the 2026 requirement (ISM-2104) and entity comms policy. Self-model residual: verify the entity's own guidance tells staff what may not be posted — if not, that gap is part of the finding. | VERIFY |
| L6 | Integration gate | Cross-layer consistency: corrective (L4), bounded (L3), matched to the 2026 rule (L5). No layer contradicts another. | PASS |
| L7 | Audit generation | Proof: screenshot, timestamp, action taken, holder's acknowledgement — logged, signed, append-only. | PASS |
| L8 | Output certification | The response text is certified for release by the designated officer before it goes out — release certificate required. | VERIFY |
Overall verdict: HOLD → VERIFY → CERTIFIED RELEASE (risk index band: HOLD ≤0.45 · FAILSAFE >0.45 — the event already egressed, so the governed object is the response, which is fully controllable.)
A good governed answer starts by naming what the post is: an output that left the containment boundary without a release certificate. The clearance holder does not hold release authority for clearance information — the entity's security function does — so the first action is to treat the post as an unauthorised external disclosure to be corrected, logged and learned from, not as a personal failing to be punished. Under ISM-2104 (new in 2026), clearance information must not be posted online; the truth of the claim is not the issue — exposure to open collection is. The response has two halves: engage the holder factually and support them to remove or correct the post, and verify whether any further clearance information (level, agency, role, dates) has been shared elsewhere. The response is released only after the layers verify and certify it — a corrective conversation is itself an output that must not be improvised. Separately, if the entity's own guidance does not already tell staff what may not be posted, that gap is part of the finding.
Cited controls: ISM-2104 · PSPF Req 182 · PSPF Req 186
Assessable today: maturity and honesty from the panel process and the applicant's own disclosures; loyalty/allegiance partly (no adverse findings, but the unverifiable period blocks a clean read); financial and criminal history for the Australian period.
Not assessable: the seven-year overseas period — incomplete employer records, two countries, mixed employment types. That period sits squarely across external loyalties and personal conduct risk areas.
What a good recommendation does: treats the waiver as an amended, escalated risk decision (not routine); separates the citizenship limb from the unverifiable-period limb; names the escalation step (the vetting authority, recorded); states the residual risk; and either defers pending verifiable history or splits the decision. It does not let vacancy harm alone decide, and it does not treat "the path exists" as sufficient reason.
Common weak answers: waiver as default; deciding on the unverifiable period alone; no escalation step; "redesign the role" without reasoning (it is a legitimate capstone position — require the trade-off analysis).
Changed: relationship, travel, second-hand debt mention. Suitability-relevant: the unverified debt mention is worth recording and, because it is second-hand and unverified, worth a calm verification question through the proper channel — not a finding. The relationship and travel are facts to weigh, not triggers. Escalate: only material that touches the risk areas; note the rest. Entity vs authority: the entity manages ongoing suitability and the sponsorship record; the authority reassesses formally. The two safeguards apply throughout — no inference from orientation or counselling.
Post: response requires removal (or correction) and a factual conversation — the exposure, not the pride, is the issue (ISM-2104). Exit: debrief completed AND access withdrawn immediately — the two-week extension is the exact risk separation exists to close (Req 186). They can say general professional references; they cannot disclose specifics of classified work or ongoing obligations (Req 182).
Reveal after students have drafted their own response to the post — never before. Walk the eight layers with the room, name the overall verdict (HOLD → VERIFY → CERTIFIED RELEASE), name Node 9 (the designated security function holds release authority; the holder does not), and read the governed answer aloud. Point out the two structural habits the canon formalises: (1) the response is an output too — it must not be improvised; (2) the audit trail is append-only, so the action is recorded even when the correction succeeds. The reusable block template lives in aiheart_governed_response_TEMPLATE.html — use it to add governed responses to any scenario in any course, keeping the provenance line (AI-assisted, gated against cited sources) on every block.
Noticed — saw the issue, vague response. Applied — used the right procedure/format. Judged — weighed competing facts, proportionate choice. Owned — named accountability and their own next step. Lift responses in debrief: "that's Applied — what would Judged look like?"