See where your AI acts, and where people decide.
Stepflow maps agentic workflows as runbooks your whole team can read. Each step shows who acts, what it can access and which person signs off. Every run lands in a hash-chained audit trail, so a later edit shows.
How it works
Stepflow does not run your workflows. Your AI and your tools do the work. Stepflow holds the map they work from and the record of what happened.
- 01
Map it
Your AI drafts the runbook over MCP. You place each step in its lane, Human, AI or Systems, and set what it can touch.
- 02
Check and publish
Checks flag any AI that writes or sends with no human gate before it. A named approver publishes a numbered version.
- 03
Run and record
As your AI works it posts events to the step it is on. Each event is labeled by source and chained to the one before it.
One picture of where AI, people and systems meet.
Each runbook is a swimlane map. Lenses restyle the same map for the question in front of you, so a finance lead, an IT manager and an auditor can each find their answer without reading the whole thing.
Example runbook, Vendor invoices. An invoice email arrives in the invoices mailbox (Systems lane). Claude extracts the invoice fields with read access and no review (AI lane). The Controller approves the bill at a gate (Human lane). On approval, Claude posts the bill to QuickBooks Online with write access, and a Drive automation archives the invoice PDF to Google Drive. On rejection, Claude sends a rejection notice to the vendor with no approval before it, which is an error. An escalation review has no one assigned, which is a warning.
Every system, every permission, and the gate before it.
The access register lists each step that touches data: the system, its access level, how much the AI does on its own and the human gate guarding it. Export it as a PDF or CSV for the people who sign off.
| Lane | Step | Actor | Owner | Resource | Access | Autonomy | Human gate before it |
|---|---|---|---|---|---|---|---|
| Example access register for Vendor invoices. Claude reads the invoices mailbox with no review. Claude writes to QuickBooks Online after the Approve bill gate. Claude sends rejection notices to vendors with no human gate before it, an error overridden at v3 with a recorded reason. A Drive automation writes to Google Drive after the Approve bill gate. | |||||||
A run log that says who reported what, and shows any edit.
Every event names its source. Self-reported means your AI posted it. System-reported means another system sent it. Each row is hashed with SHA-256 together with the row before it. Check the chain below, then alter a row and check it again.
| # | Time | Step and event | Source | Row hash | Check |
|---|---|---|---|---|---|
| Example run 1042 of Vendor invoices v3: seven events from 09:14 to 09:31. Each is labeled self-reported (posted by Claude via MCP) or system-reported (sent by a webhook), and each is hashed with SHA-256 together with the row before it. | |||||
Errors block publish. Overrides need a reason.
- Checks run on every change. An AI that acts without review and writes or sends with no human gate before it is an error. A step with no one assigned is a warning.
- Errors block publish unless the approver records a reason. The override is stored on the version and shown in the register.
- Instruction changes are shown at publish. The approver sees every edit to the instructions your AI follows at each step since the last version, and who wrote it.
- Separation of duties is one setting. Turn it on and the last editor cannot publish without a recorded exception.
Acts without review and sends outside the business with no approval before it.
No one is assigned, and nothing happens after it. Warnings do not block publish.
- Published by
- You (Controller)
- Time
- Override
- The error on Send rejection notice, with your reason, identity and time in the hashed history
- Shown on
- The version, the step and the access register
No credentials held
Stepflow never logs in to your systems or calls them. It records which systems each step touches and at what access level.
AI can draft. People publish.
Your AI connects with a draft-only token. It can read runbooks, edit drafts and post run events. It cannot publish, delete or share.
Sign-in only, views logged
There are no public links. Viewers sign in, and views and exports are logged.
- Read runbooksAllowed
- Edit draftsAllowed
- Post run eventsAllowed
Each member can revoke their own AI connections in settings, and removing a member or changing their role narrows theirs. It takes effect on the AI's next request. Claude's access to your other systems, such as your mailbox or QuickBooks, is set in those systems, not in Stepflow.
From one person's agents to a register for every team runbook.
The same runbook works at every size. What changes is who needs to read it.
Know what your agents can touch.
You run agents across your inbox, files and accounts. Stepflow puts each one on a page: what it reads, what it can change, and where it waits for you.
Show the owner where people decide.
Your team uses AI in finance, sales and operations. Map each workflow once, put a named approver on every step that writes or sends, and keep one record of who approved each version.
Give risk and audit a register for every runbook.
List every place AI acts, the systems it touches, the access it holds and the gate before it. Evidence is labeled by source and hash-chained, and views and exports are logged.
Build it for your client, then hand it over.
Build the runbooks in your own workspace, then transfer them to your client's workspace. The client owns them, and you stay on as a free guest editor until they remove you. Your AI loses access to the runbooks you transferred.