---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Workflow configuration

# Workflow configuration {#ariaid-title1}

* Release version: Yokohama
* 
* Updated December 3, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Define workflow, framework, regulation, and its associated versions, impacts, and view rules. CAM ships National Institute of Standards and Technology (NIST) workflow configuration by default, but you can create additional workflows for other frameworks such as Protective Security
Policy Framework (PSPF) or custom internal frameworks.

## Before you begin

* The Enable CAM workflow configuration property must be turned on. For more information, see [Enable CAM workflow configuration](https://www.servicenow.com/docs/MWP91B5HT~q2YNg0s_c7Sw "Enable the CAM workflow configuration to use custom workflows and frameworks in CAM. This feature enables you to configure workflows beyond the default National Institute of Standards and Technology (NIST) framework and adapt CAM to your organization's specific requirements.").
* You must run the migration scheduled jobs to associate existing authorization packages and boundaries with the workflow after enabling the CAM workflow configuration property. For more information, see [Run migration scheduled job](https://www.servicenow.com/docs/8__8SiFX84gaFAP8Sx2b_A "Run the migration scheduled job to associate existing authorization packages and boundaries with the workflow after enabling the CAM workflow configuration property. The migration confirms that existing data is compatible with the workflow configuration.").
* With CAM advanced plugin (app-grc-cont-auth-monitor-advanced): You can create unlimited workflow configurations. If you don't have CAM advanced plugin, you can create a maximum of two workflow configurations (including the NIST workflow).

{#work-configuration__ul_u14_42x_mhc}

Role required: sn_irm_cont_auth.admin

## Procedure

1. Navigate to AllContinuous Authorization and MonitoringAdministrationWorkflow Configurations.
2. To create a workflow configuration, select New.
3. On the Workflow Configuration New record form, fill in the fields.  
   {#work-configuration__table_ofh_sqz_thc__entry__2}

   | Fields | Descriptions |
   |-|-|
   | Name | Enter a name for the workflow. |
   | State Model | Select the state model to which you want to associate this workflow. Note: You must create the state model before you can map it to the workflow configuration. For more information, see [GRC state model configuration](https://www.servicenow.com/docs/NF4u95L8l_YwfUODLUIquw "Create a Governance, Risk, and Compliance state model to define the steps, transitions, and validations for a custom workflow in CAM. State models control how authorization packages move through workflow life cycles and determine which actions are available at each step."). |
   | Description | Enter details about the workflow and its purpose. |
   [Table 1. Workflow configuration new record form]

   {#work-configuration__table_ofh_sqz_thc}
4. Select Submit to create the workflow.

## What to do next

To add versions, impact, and view rules to the workflow, see:

* [Add version to workflow](https://www.servicenow.com/docs/dFM96WMhVM_gEy8wevOG0A "Add workflow versions to a workflow configuration to support different revisions or iterations of your workflow. Workflow versions filter control objectives based on the version requirements.")
* [Add impact to version](https://www.servicenow.com/docs/rwNPuE2GUQiZB_Za9H2Q3A "Add impact levels to a version to categorize authorization packages by risk level. Impacts filter control objectives based on the impact requirements and work with versions.")
* [Add view rules to workflow](https://www.servicenow.com/docs/vOXC~vrD2F~0AuCHS~rkig "Configure custom view rules to display specific fields, sections, or layouts for authorization packages using a particular workflow configuration. View rules enable workflow-specific user interfaces without modifying the base package form.")
{#work-configuration__ul_fvy_4wp_nhc}

*[\>]: and then


