Workflow examples

Start with the result. Draw the boundary around it.

Each illustrative pattern begins with the required result, then identifies the actors, selected capability, authority to avoid, crossings, evidence, and workspace fit that deserve evaluation.

Review the directory

Direct answer

Use the workflow to select the execution shape.

Choose Secure Workspace when the task is a governed session inside an existing protected system. Choose Agentic Workspace when the task assembles selected data, models, tools, compute, applications, sandboxes, or endpoints. Use both only for an explicit crossing into a separately governed protected-system session.

  • These examples are illustrative patterns, not customer evidence or product demonstrations.
  • Focused pages are available for protected-data analysis and third-party maintenance.
  • Exact capability remains product-, protocol-, runtime-, integration-, Site-, deployment-, and release-specific.

Workflow directory

Six patterns. Two focused evaluation paths.

01 · Secure + Agentic

Incident response

Investigate an event with selected telemetry, evidence, diagnostic tools, models, compute, and approved protected-system actions; keep analysis, recovery action, crossings, and closeout explicit.

Choose the execution shape
02 · Agentic

Protected-data analysis

Answer one bounded question using a defined data view, approved models and tools, bounded compute, private work, review, and controlled publication.

Review the focused workflow
03 · Secure

Third-party maintenance

Give an approved technician the named service application, target, interaction controls, transfer paths, duration, and closeout required for one maintenance result.

Review the focused workflow
04 · Secure

Restricted or legacy systems

Let an approved worker use the required protected system through an eligible application or protocol runtime without broad admission to the surrounding environment.

Review Secure Workspace
05 · Secure

Unmanaged or personal endpoints

Enter assigned work through a supported browser while keeping native target credentials and protocol runtimes away from the endpoint where the selected implementation permits.

Review endpoint responsibilities
06 · Secure + Agentic

Restricted-environment research

Collect allowed material, analyze selected data, preserve private work, and move only reviewed outputs through approved paths, with an explicit protected-system handoff when required.

Choose the workspace boundary

Evidence evaluation

Ask four questions after every workflow.

  1. 01

    Was the intended result completed?

  2. 02

    Which unnecessary authority was avoided?

  3. 03

    Which paths crossed the task boundary?

  4. 04

    Can material decisions and actions be attributed?

Use the governed-work assessment worksheet

Start with the work

Bring the result. Name the authority it should not require.

Share non-sensitive context about the actors, protected systems or data, execution, crossings, outputs, lifecycle, and evidence needs.

Contact SautX