This article explains a common reporting confusion: out-of-scope personnel may still appear with task-related statuses or in filters, depending on how the page and reports are designed.
This complements Understanding personnel statuses and scoping.
Why this can happen
Status fields can reflect historical state: a user might have had incomplete tasks before being marked out of scope.
Some filters are not scoped: depending on the view, filters can include out-of-scope users for visibility and auditability.
What to validate
Confirm the user is marked out of scope in Personnel.
Confirm what report or export you are using and whether it is intended to include out-of-scope users.
If you are preparing for an audit, verify scoping expectations with your auditor and use the Audits Module where appropriate.
What to send Support if results look incorrect
Example user(s)
What you expected to see vs what you see
Which page, filter, or export you used
Marking personnel out of scope
Can out-of-scope users still complete compliance training and policy acknowledgments?
Yes. Out-of-scope status affects compliance test populations, not whether personnel can be assigned training or policies.
Can I mark an intern as out of scope to bypass policy acknowledgment if their access is disabled?
Out-of-scope is a compliance scoping decision, not a substitute for access removal. Confirm with your auditor whether the intern warrants out-of-scope treatment.
What criteria determine whether an employee can be marked out of scope?
Personnel are out of scope when they do not access in-scope data, systems, or processes for your audit boundary.
What is the process to mark an employee as out of scope in Secureframe?
Open Personnel, select the employee, and update scoping status from the personnel profile. Use personnel groups for consistent team scoping.
