Workflow Intelligence
An AI-powered redesign of Workflow Builder that helps enterprise administrators discover, build, test and repair automations while keeping decisions visible and under human control.
- Role
- Product Designer
- Year
- 2026
- Team
- Independent concept extension
- Tools
- Figma, Figma e, Claude Code
- Project type
- AI product concept
Overview
Workflow Intelligence is a concept extension of the Workflow Builder I designed for HCL BigFix.
The original product helped IT administrators turn repetitive endpoint-management tasks into reusable no-code workflows. It introduced a visual canvas, configurable nodes, branching, failure handling, deployments and a JSON editor for power users.
After completing that project, I wanted to explore the next problem. A visual builder reduces manual execution, but creating a dependable workflow still requires considerable product and technical knowledge.
Administrators must know what should be automated, which actions to use, how to configure them, where a workflow could fail and what should happen when it does.
Workflow Intelligence explores how AI could support that complete journey without hiding the workflow logic or taking control away from the administrator.
See the original Workflow Builder projectRelationship to the original project
The original canvas remains. The extension adds support before, during and after workflow creation.
Original Workflow Builder
- 01User already knows what to automate
- 02User selects and configures nodes
- 03System validates workflow structure
- 04User deploys and monitors the workflow
Workflow Intelligence
- 01System identifies possible automation opportunities
- 02User describes the operational goal
- 03AI creates and configures a draft
- 04User reviews assumptions and risks
- 05System tests the workflow
- 06Human approves activation
- 07AI helps diagnose and improve future runs
The redesign keeps the original canvas and adds help across the workflow lifecycle.
My objective
Explore how AI could help administrators discover, create, validate and maintain workflows while preserving the reliability, accessibility and control expected from an enterprise product.
The remaining problem
The first version made repeated workflows easier to execute, but creating them still required administrators to translate an operational goal into system logic, know the available actions and conditions, configure technical fields, define branches and failure behaviour, identify missing permissions and invalid combinations, understand failures, review execution data and decide what should improve over time.
An empty canvas is flexible, but it assumes that the user already knows what the final workflow should look like.
The challenge
AI can reduce setup effort, but endpoint-management workflows may affect hundreds or thousands of devices. A wrong suggestion can create more than a usability problem.
The redesign therefore had to help users move faster, keep the system’s decisions understandable and increase human control as the consequence of an action increases. The manual Workflow Builder also needed to remain fully usable when AI was unavailable or when an administrator preferred to build without it.
Goals
Product goal
Extend Workflow Builder from a visual automation tool into a system that supports the complete workflow lifecycle.
User goal
Help administrators move from an operational problem to a tested workflow without requiring every technical detail to be configured from scratch.
Design goal
Make AI suggestions visible, editable, testable and reversible.
Project status
This is an independent concept extension based on the constraints and learnings from the original Workflow Builder project. It was not shipped or tested as part of the HCL BigFix product.
The outcomes shown later in the case study are measurement goals, not production results.
Looking at the automation market
I reviewed how established automation products were adding AI to their workflow experiences.
Zapier
Natural-language generation · Conversational editing · Field mapping · Recovery
n8n
AI Agent nodes · Approval · Test data · Execution traces · Evaluations
Power Automate
Natural-language creation · Repair · Activity analysis · Process mining
Workato
Guided creation · Configuration suggestions · Logic review · Realistic test data
Established products show that AI support can reach beyond first-draft generation.
What I took from the benchmark
The benchmark changed the scope of the redesign. AI could support more than the first draft of a workflow. It could help across four connected areas: build, run, repair and improve.
Build
Turn an operational goal into editable workflow logic.
Run
Make bounded recommendations inside a workflow.
Repair
Explain failures and propose changes.
Improve
Find repeated work and recommend better workflows.
The opportunity
How might we help administrators discover, build, validate and improve automations with AI while keeping the workflow understandable and the administrator in control?
Design principles
AI starts the work. People finish it.
AI can create a first draft, but the administrator remains responsible for reviewing and activating it.
Explain decisions, not internal reasoning.
Show the evidence, assumptions and rules behind a suggestion. Do not expose raw model reasoning or present generated text as proof.
Control should increase with risk.
A notification can run with less supervision than a device wipe. Approval should depend on consequence and reversibility.
The manual path always remains.
Users can continue with the action library, keyboard controls or JSON editor. AI is an additional path, not a replacement.
From Workflow Builder to Workflow Intelligence
I added AI support around the original workflow canvas rather than replacing it.
Workflow dashboard
Existing workflows · Deployments · Workflow health · Automation opportunities
Create workflow
Build with AI · Guide me · Start blank · Template · Import JSON
Workflow canvas
Action library · AI Copilot · Node configuration · Review · JSON editor
AI Agent node
Objective · Model · Tools · Knowledge · Output · Human control · Fallback
Reliability centre
Test cases · Evaluations · Version comparison · Approval readiness
Operations
Run history · Diagnosis · Suggested repair · Insights · Audit history
The original canvas remains at the centre. AI support is added around creation, execution, reliability and maintenance.
Core journey
The journey does not end when AI generates a canvas. A dependable enterprise experience must help users understand, validate and maintain what was created.
Discover an opportunity
Describe the outcome
Clarify missing information
Generate an editable draft
Review assumptions and risk
Test with sample data
Approve and activate
Monitor executions
Diagnose failures
Improve the workflow
The journey does not end when AI generates a canvas.
Hero journey 01
Discover and build with AI
The first journey starts with evidence, then moves into a structured creation experience.
Automation opportunity
Repeated activity found
You completed the same endpoint follow-up sequence 46 times this month.
Check endpoint status Notify primary user Wait for response Create remediation ticket
About 12 hours of repeated work each month.
Sample data used to demonstrate the concept. Recommendations begin with visible evidence.
Choosing how to start
I kept more than one creation path because speed and control are not the same for every user or workflow. Build with AI suits a clear, low-risk task. Guide me is more appropriate when the workflow is unfamiliar or sensitive. Experienced users can continue with the blank canvas or JSON editor.
Build with AI
Describe the outcome and let AI create the first draft.
Guide me
Review and confirm each suggestion as the workflow is built.
Start blank
Use the existing action library and canvas.
Use template
Begin with an approved workflow pattern.
Import JSON
Create a workflow from an existing configuration.
Describing the outcome
The AI entry point is a way to start building, not a generic chatbot dashboard.
Create workflow
What should this workflow do?
Build with AIClarifying missing information
An incomplete prompt should not quietly become an automation. When information affects the result, the system asks before it builds.
Before I build
Three details affect the result. Please confirm them.
Who should receive the notification?
◉ Assigned primary user
○ Device owner
○ IT administrator
○ Select another recipient
Which ticket queue should receive the incident?
◉ Endpoint Security
○ IT Operations
○ Service Desk
What should happen if the endpoint starts reporting again?
◉ End the workflow
○ Notify the administrator
○ Continue monitoring
When information changes the result, the system asks before it builds.
Generated workflow
AI generates normal Workflow Builder nodes. The result is not trapped inside a conversation. Every node can be inspected, moved, edited or replaced using the existing canvas.
Action library
Triggers
Conditions
Notifications
Wait
Tickets
AI Agent
Endpoint follow-up
AI Copilot
Explain workflow
Add failure handling
Simplify
Test workflow
Regenerate selected step
Review assumptions
AI generates normal Workflow Builder nodes. Each can be inspected, moved, edited or replaced.
Selective editing
A user should not need to regenerate the entire workflow to correct one decision. AI changes should remain local, visible and reversible.
Selective edit
“Use Microsoft Teams instead of email and keep the same recipient.”
Proposed change
Replace Email Notification with Microsoft Teams Notification.
Preserved
Primary user recipient · Endpoint name · Risk level · Incident link
Checkpoints
AI makes experimentation faster, which also makes recovery more important. Checkpoints let users explore a different structure without losing a dependable version.
Checkpoints
v01
Original AI draft
AI draft
v02
User edited version
Teams change
v03
AI option
Adds retry
v04
Approved version
Ready to activate
More useful than one confidence score
I initially considered showing one confidence percentage for the generated workflow. I dropped that direction because a single number combines several different questions.
A workflow can be technically valid while relying on weak evidence. AI can be confident about a recommendation that still carries a high business consequence. I separated confidence into four visible states.
The structure, fields and permissions can technically execute.
Relevant and current information supports the recommendation.
AI has proposed an action from available evidence.
An authorised administrator accepted the decision.
High AI confidence does not automatically mean safe to execute.
Explaining a decision
The explanation focuses on information the administrator can verify. It does not expose raw chain of thought or use generated reasoning as evidence.
Create remediation ticket · Explanation
Decision
Create a high-priority remediation ticket.
Why this step was added
The administrator requested ticket creation when the endpoint remains offline after the second check.
Supporting information
• Endpoint risk level is high
• Second status check remains offline
• No open remediation ticket exists
Assumption
“Remediation ticket” is mapped to Endpoint Security.
What needs review
Confirm the queue is correct.
Hero journey 02
Adding an AI Agent
Some endpoint events cannot be handled through fixed conditions alone. An alert may contain unstructured logs, incomplete signals and patterns from previous incidents.
For these cases, I introduced an AI Agent node that can interpret information and produce a bounded, structured recommendation. The administrator defines its objective, inputs, tools, output and authority.
AI Agent node
Analyse the security alert, compare it with previous incidents and recommend whether the endpoint should be monitored, isolated or escalated.
Inputs
Current security alert · Endpoint health · Recent activity · Previous incidents
Approved knowledge
Endpoint securitybook · Severity guidelines · Resolved incidents
Approved tools
Search history · Retrieve health · Create recommendation · Request review
Structured output
Recommendation · Risk · Signals · Missing information · Requires approval
Human-control rule
Always require approval before isolation.
Fallback
Send to Security Operations if no valid recommendation.
Autonomy levels
Autonomy belongs to an individual action, not the entire workflow. A workflow may automatically collect evidence while still requiring approval before isolating a device.
Suggest only
Provides a recommendation but cannot take action.
Execute and notify
Performs a reversible action and informs the administrator.
Execute within limits
Acts only when evidence, confidence and risk conditions are met.
Always require approval
Cannot continue until an authorised person reviews the decision.
Human approval
High-consequence actions remain behind explicit approval, with the expected effect, evidence, missing information and audit context visible together.
Approval required
Recommendation: Isolate endpoint
Reviewer: Priya Shah · Due in 15 min
Malware signature detected
Three remediation attempts failed
Similar incidents required isolation
Device-owner record was last updated 90 days ago.
Endpoint loses corporate access until restored.
Hero journey 03
Test before activation
Traditional validation checks whether the workflow can run. AI evaluation also checks whether output remains useful and consistent across different inputs.
Test cases
✓ Normal endpoint recovery
✓ Endpoint remains offline
✓ Missing device owner
✓ Ticket queue unavailable
○ Critical security alert
○ Conflicting endpoint signals
○ AI Agent returns invalid output
Evaluation summary · Sample data
Valid output rate · Correct routing · Human override rate · Tool-call failure rate · Average runtime · Approval escalation rate
0 destructive actions executed
Illustrative data. AI evaluation checks whether output remains useful and consistent across inputs.
Previewing impact
The preview helps administrators understand the likely effect before the workflow reaches real devices.
Sample preview
14 endpoints match the trigger.
Sample dataprimary users notified
would recover
tickets created
isolated automatically
requires review
Hero journey 04
Diagnose and repair
The assistant diagnoses the failure, shows the evidence and proposes a repair. It does not silently modify a live workflow.
Failed execution
Workflow failed at Create remediation ticket
The selected Project ID is no longer available.
Ticketing configuration still refers to the archived Endpoint Operations project.
EvidenceProject returned “not found”. It succeeded before archival. Two active projects support this ticket type.
Replace Endpoint Operations with Endpoint Security and preserve field mappings.
Needs confirmationBoth projects are available. I cannot determine which queue owns this incident.
Repair comparison
Repairs are compared in context, tested and saved as a draft before they reach a live workflow.
Before
Project: Endpoint Operations
Status: ArchivedAfter
Project: Endpoint Security
Status: ActivePreserved
Priority · Endpoint ID · Incident description · Assigned team · Existing branches
Learning from workflow history
The system should help administrators recognise patterns, but it should not convert every correlation into an automatic change. Insights remain recommendations until someone reviews the underlying cases.
Workflow insights · Illustrative concept data
Repeated human override
Reviewers changed Isolate to Monitor in 38% of low-risk cases.
Possible improvement
Increase evidence required before recommending isolation for low-risk endpoints.
Slowest step
Ticket creation adds an average of 18 seconds.
Repeated failure
Seven runs failed because an endpoint owner was missing.
Designing the way back
The manual builder is the fallback for every AI state. An unavailable model should never prevent an administrator from accessing or editing the workflow.
Ambiguous goal
What should qualify as an inactive endpoint?
Recovery: Answer a clarification question or build manually.
Unsupported action
This environment cannot automatically create Jira tickets.
Recovery: Choose an available ticketing action.
Missing permission
You can edit this workflow but cannot activate it.
Recovery: Request approval from a workflow administrator.
Partial generation
Six steps were created. The remediation action still needs configuration.
Recovery: Configure manually or ask AI for another option.
Conflicting logic
This branch both ends the workflow and continues to ticket creation.
Recovery: Select the intended behaviour.
Unsafe loop
This workflow can trigger itself repeatedly.
Recovery: Add an exit condition before activation.
High-consequence action
This workflow may isolate endpoints automatically.
Recovery: Add human approval or restrict the action.
AI unavailable
AI assistance is temporarily unavailable. Your current workflow has been preserved.
Recovery: Continue with the action library or JSON editor.
Stale configuration
The referenced policy changed after generation.
Recovery: Review the new policy before activation.
AI cannot become the only interface
The original Workflow Builder treated keyboard interaction as a primary path rather than a fallback. The AI redesign continues that approach.
A conversational input can make creation faster, but it cannot replace structured controls, predictable focus and an accessible representation of the workflow.
AI status is never communicated through colour alone. Generated content is announced without stealing focus. Users can skip to the first issue, cancel generation or testing, and use structured controls alongside natural-language input.
Linear workflow view
- 1Trigger: endpoint stops reportingOpen config · Move ↑ · Move ↓ · Duplicate · Delete · Explain · Review
- 2Condition: endpoint risk is highOpen config · Move ↑ · Move ↓ · Duplicate · Delete · Explain · Review
- 3Action: notify primary userOpen config · Move ↑ · Move ↓ · Duplicate · Delete · Explain · Review
- 4Wait: 30 minutesOpen config · Move ↑ · Move ↓ · Duplicate · Delete · Explain · Review
- 5Action: check endpoint statusOpen config · Move ↑ · Move ↓ · Duplicate · Delete · Explain · Review
- 6Condition: endpoint remains offlineOpen config · Move ↑ · Move ↓ · Duplicate · Delete · Explain · Review
- 7Action: create remediation ticketOpen config · Move ↑ · Move ↓ · Duplicate · Delete · Explain · Review
- 8End workflowOpen config · Move ↑ · Move ↓ · Duplicate · Delete · Explain · Review
Canvas and linear view remain in sync. Every workflow action has a keyboard-operable alternative.
What I would test next
Because this is a concept extension, I would validate the riskiest assumptions before increasing its scope.
The first question is not whether users like the AI interface. It is whether they can understand, correct and safely approve what it creates.
Participants
Administrators new to Workflow Builder · Experienced endpoint administrators · Keyboard-only and screen-reader users · Product architects · Security and compliance stakeholders
Tasks
Create from an ambiguous goal · Correct a generated node · Configure an AI Agent · Test sample data · Repair a failed run · Continue when AI is unavailable
What I would measure
Time to first valid workflow · Corrections before approval · Missed assumptions · Invalid workflow rate · Keyboard and screen-reader completion · Recovery from failed generation
Expected product impact
The concept would be successful if it reduced the effort required to create and maintain workflows without increasing unsafe or misunderstood automation.
I would expect it to improve time to first valid workflow, discoverability of automation opportunities, completion of technical configurations, recovery from failed executions, understanding of AI-generated decisions, reuse of approved workflow patterns and accessibility for users who find a visual canvas difficult to operate.
These are hypotheses for future validation, not measured production outcomes.
From building workflows to understanding them
The original Workflow Builder focused on making repeated endpoint operations easier to automate.
This redesign pushed the problem further. It explored how administrators could discover what to automate, describe the outcome they want, test the resulting workflow and understand what happens when AI becomes part of the execution.
The most important design decision was not adding a prompt to the canvas. It was defining the boundary between an AI suggestion, a system-verified configuration and a human-approved action.
I kept the original action library, canvas, keyboard interaction and JSON editor because dependable manual control still matters. AI adds another way into the product, but it should never become the only way through it.
The first release made workflow automation usable. This concept explores how it could become easier to discover, build and maintain without making its decisions harder to understand.
This project is an independent design exploration and was not shipped as part of HCL BigFix.