skip to content

In a BPMN 2.0 hiring collaboration, when should the background-check agency be a black-box pool rather than a white-box pool?

level: middleimportance: should knowfreq 30%

answer

  1. whose process is it to model
  2. messages attach to the edge
  3. the touch-points in between
  4. no sequence flow inside

basics

~20 s

In BPMN 2.0 a black-box pool references no process and message flows attach to its boundary; use it when the agency's internals are unknown or not yours to model. Use a white-box pool when its activities matter.

solid answer

~40 s

A **black-box pool** is a participant whose pool contains **no process** (its `processRef` is empty). No sequence flows are associated with it, and **message flows attach to its boundary**. It fits the background-check agency when all you know, or may assert, is the contract: a check request goes in, a report comes out. A **white-box pool** exposes the agency's process, so message flows attach to the specific activities or events that send and receive. That is justified when the agency's steps are yours to design or agree, for example a jointly specified procedure. Between the two sits a **public process** (`processType` Public), which shows only the activities that communicate with other participants. Modelling a partner's private process you do not control produces a diagram that claims knowledge you do not have.

go deeper

for a junior

Recall that a black-box pool has no process inside and messages attach to its edge, while a white-box pool shows the process.

for a middle

Apply the decision: model a partner's internals only when they are yours, known and needed, and name the public process as the middle ground.

for a senior

Challenge models that invent partner processes, and switch to a public process when cross-party ordering must be visible.

for a principal

Set a modelling policy on partner detail, balancing contractual visibility against the maintenance cost of diagrams nobody owns.

## Two ways to draw a participant BPMN 2.0.2, clause 9.3, says a pool **may or may not** reference a process, and that a pool can be shown as a **white box**, with all details (a process) exposed, or as a **black box**, with all details hidden. | | **Black-box pool** | **White-box pool** | |---|---|---| | Process referenced | none | one, drawn inside | | Sequence flows inside | none | organise the activities | | Where message flows attach | the pool **boundary** | the activities or events that send and receive | | Label | may sit anywhere, without a separator line | separated from contents by a single line | | What it asserts | the party exists and exchanges these messages | this is how the party works internally | ## Deciding for the background-check agency In the hiring collaboration the employer sends a check request and later receives a report. Ask three questions: 1. **Is the agency's procedure yours to model?** Usually not. It is another organisation's private process, and you neither design nor control it. 2. **Do you know it reliably?** A service agreement tells you inputs, outputs and perhaps turnaround, not the agency's internal steps. 3. **Does the diagram's purpose need it?** If the goal is to improve the employer's hiring process, the agency's internals add clutter without adding decisions the employer can make. If the answers are no, a **black box** is the honest choice: the agency pool shows the request message arriving at its boundary and the report message leaving it. A **white box** is justified when: - the agency's steps are **jointly specified**, for example a contract that fixes consent collection before the check starts; - you must show **which** of their activities receives or sends each message, to reason about ordering between the two sides; - you are the agency, and this is **your** internal process. ## The middle ground: a public process Clause 7 describes **public processes**: they show only the activities used to communicate with other participants, hiding all internal activities. A process's `processType` attribute can be `None` (the default), `Private` or `Public`; BPMN 1.2 called the public type "abstract". A public process for the agency would show only its touch-points: receive request, request candidate consent, send report. It documents the interaction order without claiming the internal steps. ## The employer's own pool The employer's pool is usually a white box with its private process. The standard allows **one** pool in a diagram to be drawn **without a boundary**, typically the modeller's own internal process; every other pool must have a boundary. ## Pitfalls - **Inventing a partner's process.** A white-box agency pool filled with guessed steps looks authoritative and is wrong in ways no one owns. - **Black box where ordering matters.** If the employer must know that consent is requested before the check starts, a boundary-only pool cannot show it; a public process can. - **Black-boxing yourself.** Hiding the employer's own process removes what the model is for. - **Confusing black box with a lane.** A lane, even an empty one, is still part of the employer's process; a black-box pool is a separate participant. ## What the model records In the XML, a black-box pool is simply a `participant` in the `collaboration` with **no** `processRef`. A message flow's `sourceRef` and `targetRef` may name the participant itself, because the standard lets pools or participants, activities and events be the ends of a message flow. Turning the agency into a white box later means adding a process, pointing the participant's `processRef` at it, and moving each message flow's end from the participant to the specific activity or event inside. Nothing else in the employer's model has to change, which is why starting with a black box is cheap. ## Interview summary State the rule (a black-box pool has no process, and message flows attach to its boundary), then give the decision test: model a participant's internals only when they are yours to model, known, and needed for the diagram's purpose. Mention the public process as the option that shows touch-points without internals.

  • In BPMN 2.0, can a black-box pool contain sequence flows?
    No. A black-box pool references no process, so no sequence flows are associated with it. Message flows can still attach to its boundary, which is how the interaction with it is shown.
  • In BPMN 2.0, what is a public process and how does it differ from a private one?
    A public process shows only the activities that communicate with other participants and the order of those message exchanges; internal activities are hidden. A private process is internal to one organisation. The processType attribute records None, Private or Public.
  • In BPMN 2.0, how would you draw the candidate in the employer's hiring model?
    Usually as a black-box pool: the candidate is an independent participant whose private steps the employer neither controls nor needs. Messages such as the application, interview invitation and offer attach to the candidate pool's boundary.

A black-box pool is a supplier's mailing address: you know what you post and what comes back. A white-box pool is their internal procedures manual, which you should draw only if you actually have it.

saying these in an interview costs you the question

  • Filling a partner's pool with guessed internal steps
  • Believing every pool must contain a process
  • Drawing sequence flows inside a black-box pool
  • Assuming a black-box pool cannot exchange any messages
  • Treating an empty lane as equivalent to a black-box pool