Onboarding / offboarding
HR signal → identity provisioning → device assignment → access request approvals → asset register update → A.6.1 (employment terms) + A.5.16 (identity) evidence.
Pillar · Workflows
Orchestrate the boring stuff: approvals, escalations, evidence collection, ticket routing, runbook execution. Trigger from anything in the platform — a control failure, an incident, a stage gate, a schedule, a webhook.
Composable steps you wire together with a visual designer or YAML. All activities support retries, timeouts, idempotency keys, structured errors, and OpenTelemetry tracing.
Write activities in the language your team actually ships in.
All SDKs share the same wire protocol, the same retry semantics, the same idempotency stores (in-memory / Redis / Postgres), and the same OpenTelemetry instrumentation. Resilience is a decorator, not a node.
HR signal → identity provisioning → device assignment → access request approvals → asset register update → A.6.1 (employment terms) + A.5.16 (identity) evidence.
New supplier → questionnaire → SOC 2 + ISO 27001 doc collection → risk score → DPA generation → quarterly review schedule. Maps to A.5.19–A.5.22.
Quarterly campaign → manager review → revoke uncertified access → exception log → A.5.18 evidence pack.
Model registered → impact assessment → bias / safety tests → human-oversight plan → release gate → ISO 42001 A.6 lifecycle evidence + EU AI Act conformity record.
Alert → triage → containment playbook → comms → post-incident review → CAPA. Maps to A.5.24–A.5.30.
Schedule → tabletop or live → outcome capture → action plan → A.5.29–A.5.30 evidence.
One engine. One log. Activities that already know about your services, your CIs, your controls, and your people.