Floh is an enterprise orchestration platform that brings visual form authoring, multi-step workflows, runtime task management, and identity-aware provisioning together — with a tamper-evident audit trail across every action.
Workflow Engine — Why Floh
Enterprise work falls into a predictable shape: collect information, route it for review, take action across connected systems, and prove it happened. Most teams glue that shape together from spreadsheets, ticket queues, ad-hoc scripts, and inboxes. Floh replaces that stack with a single platform — one where forms, approvals, tasks, provisioning, and audit are first-class citizens of the same model.
A drag-and-drop workflow graph editor and an embedded JSON-Forms-based form designer let business owners model end-to-end processes without writing code — with Markdown content, context tokens, and live preview.
Single, sequential, and parallel approvals with mandatory reasons. Runtime tasks support claim / assign / hold / unhold with threaded comments and admin + portal inboxes — so work is never stuck on a single owner.
Business-role definitions linked to entitlements push grants and revocations across Active Directory, SCIM, Google Workspace, S3, Postgres / MySQL, and any HTTP API. Reach users by templated email or SMS, with OTP-backed verification.
Every action lands in an append-only audit log enforced by database triggers and a SHA-256 hash chain. HMAC-signed checkpoints export to S3 or SIEM; integrity can be verified end-to-end on demand. Compliance is not a follow-up — it ships in the box.
Workflow Engine — Platform Capabilities
Drag-and-drop graph editor with 24 step types — approvals, conditions, forks/joins, connectors, user lifecycle, and sub-workflows.
JSON-Forms-based form designer embedded in the Workflow Designer. Markdown content, context tokens, output-variable mapping, and live preview ship in the box.
Claim, assign, hold, and unhold with threaded comments. Admin and public-portal task inboxes show the same workload from inside or outside the firewall.
Single, sequential, parallel, and AND-of-list patterns with escalation timeouts, group-based routing, and mandatory rejection reasons.
Collect, review, approve, and track documents with expiration policies. Expired documents automatically trigger role revocation.
Native steps for user creation, profile updates, manager linkage, email rotation, OTP-backed verification, and first-password invitations.
Define business roles with linked entitlements. Auto-provision and deprovision access; a Privileged Access category covers privileged-session checkouts.
Handlebars-templated email and SMS via Twilio or Vonage. STOP/UNSTOP opt-out, delivery webhooks, and OTP verification all built in.
Pluggable architecture with built-ins for HTTP, LDAP / AD, S3, Postgres, MySQL, SCIM, Google Workspace. Secrets encrypted at rest with AES-256-GCM.
Real-time metrics, run-status charts, SLA tracking, approver performance, and an Assigned Roles & Entitlements report — filterable by project.
A standalone Model Context Protocol server lets AI agents author and inspect workflows, schemas, and connectors via typed, audited tool calls.
Workflow Engine — Workflows & Compliance
{{var}},
{{submitter.*}}, {{date.*}}, {{org.*}},
{{env.*}}
Step authors get inline help icons in connector config, named approval policies, and shared-store resend cooldowns for OTP-backed verification.
Workflow Engine — Integrations & Architecture
Keycloak, Entra ID, Okta, Auth0, Authifi
User lookup, group mgmt, password set
SMS, OTP Verify, opt-out webhooks
list, head, get, put, delete
Typed query + DDL via Kysely + drivers
Generic connector with SSRF guards
Handlebars templates with attachments
User + group sync to upstream IdPs
OAuth-backed directory + groups
Full Swagger UI with live introspection
Standalone MCP for AI-authored workflows
Compose stack with separate SPA workers
Floh brings workflow orchestration, form authoring, runtime task management, and identity-aware provisioning together in a single, modern platform — with audit baked in from day one.