Skip to main content

Out-of-scope personnel: why they may still show task statuses or appear in filters

Written by Brady Price

This article explains a common reporting confusion: out-of-scope personnel may still appear with task-related statuses or in filters, depending on how the page and reports are designed.

Why this can happen

  • Status fields can reflect historical state: a user might have had incomplete tasks before being marked out of scope.

  • Some filters are not scoped: depending on the view, filters can include out-of-scope users for visibility and auditability.


What to validate

  1. Confirm the user is marked out of scope in Personnel.

  2. Confirm what report or export you are using and whether it is intended to include out-of-scope users.

  3. If you are preparing for an audit, verify scoping expectations with your auditor and use the Audits Module where appropriate.


What to send Support if results look incorrect

  • Example user(s)

  • What you expected to see vs what you see

  • Which page, filter, or export you used


Marking personnel out of scope

Can out-of-scope users still complete compliance training and policy acknowledgments?

  • Yes. Out-of-scope status affects compliance test populations, not whether personnel can be assigned training or policies.

Can I mark an intern as out of scope to bypass policy acknowledgment if their access is disabled?

  • Out-of-scope is a compliance scoping decision, not a substitute for access removal. Confirm with your auditor whether the intern warrants out-of-scope treatment.

What criteria determine whether an employee can be marked out of scope?

  • Personnel are out of scope when they do not access in-scope data, systems, or processes for your audit boundary.

What is the process to mark an employee as out of scope in Secureframe?

  • Open Personnel, select the employee, and update scoping status from the personnel profile. Use personnel groups for consistent team scoping.

Did this answer your question?