Clearance onboarding, the pattern
A read on the structural difference between cleared and commercial onboarding.
May 24, 2026 · Winrove Team
The Wrong Mental Model Costs You Audits
A mid-size defense contractor recently failed a Defense Counterintelligence and Security Agency (DCSA) facility review not because their engineers lacked clearances, but because their onboarding team had treated cleared hires the same way they treated commercial hires. The I-9s were complete. The offer letters were signed. The problem was that nobody had maintained the briefing logs, the SF-86 prep documentation was scattered across email threads, and the access-list reconciliation had never been tied back to the original investigation tier. The auditor did not find a missing form. She found a missing chain.
That is the core issue. Cleared onboarding is not commercial onboarding with a background check appended. It is a structurally different workflow, with a different cast of accountable parties, a different cadence measured in years rather than days, and a set of artifacts that travel with the individual for the life of their clearance. Model it wrong and you will pass Day 1 every time while failing every audit thereafter.
The Three Structural Differences
1. The FSO Is Not HR
In a commercial onboarding, HR owns the process end to end. They collect the I-9, route the offer letter, trigger the background check vendor, and close the file when the employee badges in. Their accountability runs to the company.
In a cleared onboarding, HR still does all of that, but a second accountable party enters the picture: the Facility Security Officer (FSO). The FSO's accountability runs to the program office and, ultimately, to DCSA. Those two accountability lines are not parallel. They intersect at every clearance event, and when they conflict, the FSO's obligation to the government program wins.
Practically, this means the FSO must be in the loop before the offer is extended (to confirm the candidate's existing clearance status or the sponsor's willingness to initiate), during onboarding (to execute the visit authorization letter or VAL, brief the employee on the Standard Form 312 nondisclosure agreement, and log the initial security briefing), and continuously thereafter (to manage CE alerts, annual briefings, foreign travel reports, and access-list changes). The FSO is not a one-time checkpoint. She is a permanent co-owner of the engineer's personnel record from hire through separation and sometimes beyond.
Onboarding systems that treat the FSO as an approver in a linear workflow miss this. The FSO needs a persistent, auditable view of every clearance-relevant event, not a notification email when a task is complete.
2. The Continuous Evaluation Cycle Has No End Date
Commercial onboarding ends on Day 1. The I-9 is complete, the direct deposit is set up, and the file is closed. The only future obligation is I-9 reverification if the employee presented a document with an expiration date, and most commercial HR teams handle that with a calendar reminder.
Cleared onboarding ends never. The moment an engineer is read onto a program, a set of recurring obligations begins that will run for the entire tenure of their clearance:
- Continuous Evaluation (CE) check-ins: Under the CE program, cleared individuals are subject to automated record checks against financial, criminal, and other databases on an ongoing basis. When a CE alert fires, the FSO must document the response and, depending on severity, report to DCSA within defined windows.
- Annual and refresher briefings: Most programs require annual security refresher briefings. The log entry for each briefing, including the date, the briefer, and the employee's signature, is a required artifact. Missing a single year creates a gap that an auditor will flag.
- Foreign travel reporting: Pre-travel briefings and post-travel debriefs are required for cleared personnel traveling to certain countries. The documentation must be retained and tied to the individual's clearance record.
- Access-list reconciliation: Every classified system or space has an access list. That list must be reconciled against current clearance status and program need-to-know on a regular basis. When an engineer changes programs, transfers, or separates, the reconciliation must happen within the timeframes specified in the NISPOM (32 CFR Part 117).
- I-9 reverification: If the employee presented a List A or List C document with an expiration date, reverification is required before that date. For cleared personnel, a lapsed I-9 can trigger additional scrutiny because it suggests a gap in identity verification continuity.
Each of these obligations has a statutory or regulatory deadline. Missing them is not a paperwork inconvenience. It is a compliance finding that can affect the facility clearance (FCL) itself.
3. The Audit Posture Requires a Chain, Not a Folder
A DCSA labor floor check or a standard HR audit pulls a personnel file. The auditor wants to see that the right forms exist and that they are complete. The evidence model is a folder: a set of discrete documents that can be checked off a list.
A DCSA facility review, a program office spot check, or an adjudicator's request for supplemental information requires something different. The auditor is reconstructing a timeline. She wants to see that the SF-86 was submitted on a specific date, that the interim access determination followed within the expected window, that the initial briefing occurred before first access, that every annual briefing since then has been logged, and that every CE alert has been acknowledged and resolved. The evidence model is a chain: a sequence of dated, linked artifacts that demonstrate continuous compliance from hire to present.
A folder can have gaps. A chain cannot. If the briefing log for year three is missing, the chain is broken, and the auditor cannot confirm that the engineer was briefed before accessing classified material that year. The absence of a document is itself a finding.
This distinction has a practical implication for how you store records. A shared drive with folders organized by employee name will pass a folder audit. It will fail a chain audit because there is no mechanism to verify completeness, sequence, or integrity. You need a system that enforces the chain: that requires each artifact to be created in order, timestamps it at creation, and flags gaps before the auditor does.
The Workflow Shape in Practice
A cleared onboarding for a Secret-level hire on a DoD program typically moves through the following sequence, with the FSO and HR operating in parallel rather than in series:
- Pre-offer: FSO confirms existing clearance via DISS (Defense Information System for Security) or initiates sponsorship. HR prepares the offer letter with contingency language tied to clearance verification.
- Offer acceptance through Day 1: HR collects I-9 (Section 1 on or before Day 1, Section 2 within three business days). FSO executes the VAL if the hire is transferring from another facility, or initiates the SF-86 package for a new investigation. The SF-312 NDA is signed and logged.
- Interim access (if applicable): For T3 (Secret) investigations, interim access may be granted before the full investigation closes. The FSO documents the interim determination and the CONOP (concept of operations) for access during the interim period.
- Investigation closure: DCSA closes the investigation and adjudication is completed. The FSO logs the final determination and updates the access list.
- Continuous phase: Annual briefings, CE monitoring, foreign travel processing, and access-list reconciliation run on their respective schedules until separation.
- Separation: Debriefing is conducted and logged. The SF-312 obligations are reviewed with the employee. DISS is updated. Access lists are purged within required timeframes.
Each step generates at least one artifact. Several steps generate multiple artifacts that must be linked to each other. The total record for a five-year cleared employee on a single program can easily exceed thirty discrete documents, each with its own retention requirement under 32 CFR Part 117 and the NISPOM.
What Winrove Does in This Shape
Winrove, built by IT Custom Solution LLC and available at winrove.com, is designed around this workflow shape rather than the commercial onboarding shape. That means SF-86 prep and document collection are built in, not bolted on. Investigation tier status (T1 through T5) is tracked as a first-class field, not a note in a text box. The interim CONOP is a structured artifact, not a PDF attachment. The CE calendar generates recurring tasks with deadlines tied to the individual's record. Briefing logs are timestamped and linked to the employee's clearance history. Access reconciliation is a workflow step, not a spreadsheet exercise.
Winrove does not certify clearances, make adjudicative determinations, or replace the FSO's judgment. What it does is produce the chain: the complete, ordered, dated, gap-free evidence record that a DCSA reviewer or program office auditor needs to reconstruct compliance from hire to present.
The Practical Takeaway
If your onboarding system was built for commercial hiring and you are using it for cleared personnel, audit it against the chain model, not the folder model. Walk through a five-year cleared employee's record and ask whether you can reconstruct every briefing, every CE response, every access-list change, and every investigation milestone in sequence with timestamps. If you cannot, you have a gap that a DCSA reviewer will find before you do. Fix the model first. The forms will follow.
Preserved Field Notes article. Original path /blog/clearance-onboarding-pattern/. No unrelated help guide has been substituted.