---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# GRC state model configuration

# GRC state model configuration {#ariaid-title1}

* Release version: Yokohama
* 
* Updated December 5, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Create a Governance, Risk, and Compliance state model to define the steps, transitions, and validations for a custom workflow in CAM. State models control how authorization packages move through workflow life cycles and determine which actions are available at each step.

## Before you begin

Role required: sn_irm_cont_auth.admin

## Procedure

1. Navigate to AllContinuous Authorization and MonitoringAdministrationGRC State Models.
2. Select New to create a state model record.
3. On the GRC state model New record form, fill in the fields.  
   {#cam-create-state-model__table_bgm_qsj_thc__entry__2}

   | Fields | Descriptions |
   |-|-|
   | Name | Enter a name for the state model. |
   | Active | Select the Active option to enable the state model. |
   | Table name | Select Authorization Package \[sn_irm_cont_auth_auth_pack\]. |
   | State field | Select State Model \[state_model\]. |
   | State model | Select Step \[step\]. |
   [Table 1. GRC state model new record form fields]

   {#cam-create-state-model__table_bgm_qsj_thc}
4. Select Submit.  
   You're directed to the GRC state models list page.

## Result

The state model is ready to be configured with workflow states, transitions, and attributes. After completing the configuration, you can map the state model to a workflow configuration and use it for authorization
packages.

## What to do next

[Create GRC workflow states](https://www.servicenow.com/docs/QMaFYXgemGrD6RKKDKWTGQ "Add Governance, Risk, and Compliance workflow states to a state model to define the individual steps in your workflow. Each workflow state represents a phase in the authorization package life cycle and determines what you can do at that stage.")

[Add existing attributes to a GRC workflow state](https://www.servicenow.com/docs/HWD9ORU0omICSZQOgdvN1w "Add existing Governance, Risk, and Compliance state model attributes to add special capabilities to workflow steps without custom code. Attributes control features like approval requirements, report generation, and Open Security Controls Assessment Language (OSCAL) file exports for specific workflow states.")

[Create a new state model attribute](https://www.servicenow.com/docs/qe3I6hbuGQ0Po1azLys2kA "Create custom state model attributes to add specialized capabilities to workflow steps.")

*[\>]: and then


