Skip to content
Sentinel Unity

Workflow Designer

No code, but real logic

Risks, findings, policies, assessments, vendors, strategies and initiatives each follow a lifecycle you can reshape. Draw the flow, simulate it, publish a version, and the engine runs it with every step logged.

  • A system flow template for every lifecycle-bound module, copied and changed rather than built from nothing
  • Structured conditions on record fields, relationships and dates
  • Scheduled and date-field triggers; record events as triggers
  • Escalation ladders, approval matrices, acknowledgement campaigns and access requests
Download the GRC Platform brochure (PDF)

In the application · Administer

  • Workflow manager
  • Lifecycles
  • Flow designer
  • Versions
  • Simulation
  • Escalation rules
  • Approvals
  1. Finding created · severity ≥ HighTrigger
  2. owner.department = TechnologyCondition
  3. Remediation plan → Head of TechnologyApproval
  4. No decision in 5 days → CISOEscalation
  5. Set state: In progress · notify assigneesAction

Versioned, simulated before publish, run by the engine with every step logged

Two planes

Lifecycles say what a record may become; flows say what happens on the way

A lifecycle defines states and role-gated transitions per record type. A flow reacts to a transition, a schedule or a date and does the work: set a field, create a task, request an approval, notify, escalate, link a record, or start a sub-workflow.

  • Lifecycle definitions with state categories and gated transitions
  • Node types: condition, gateway, approval, action, record and relationship operations, due-date operations, sub-workflow
  • Versioned definitions; a published version keeps running while the next is drafted
  • Simulation runs before publish, with the path shown
  1. Finding created · severity ≥ HighTrigger
  2. owner.department = TechnologyCondition
  3. Remediation plan → Head of TechnologyApproval
  4. No decision in 5 days → CISOEscalation
  5. Set state: In progress · notify assigneesAction

Versioned, simulated before publish, run by the engine with every step logged

Triggers and escalation

Time is a first-class trigger

A flow can start when a record changes state, on a schedule, or when a date field falls due — a contract renewal, a review date, a policy expiry. Timers and escalation ladders move the work to the next person when the first does not act.

  • Cron and date-field triggers evaluated by the engine
  • Escalation rules with ladders and recorded escalation events
  • Task notifications routed by person, not login
  • Step log per execution; reliability and retention controls for long-running flows

Treatment decision

  1. 1Treatment planActions with owners, priority, and due dates
  2. 2Action trackingStatus per action, SLA where defined
  3. 3ReassessmentResidual score recalculated after closure

Framework alignment

Works with your control frameworks

This module shares the platform control library. International standards, sector regulations and your own internal standard are loaded the same way and mapped to one another, wherever you operate.

See the Workflow Designer in your environment

A walkthrough scoped to your entities, your frameworks, and the way your programme is actually run.