5 MCP servers live now What’s live ›
Real Biz Digital logo Real Biz Digital

Workflow automation

Governed workflow automation: the cost of a platform is the exit

The cost of a workflow automation platform is not its subscription. It is the exit — what you can carry out on the day you have to leave, and what simply ceases to exist. Almost every comparison in this category ranks platforms on what they do while you are inside them: connector counts, builder ergonomics, whether there is an approval step. That is the wrong axis, and 2026 supplied the demonstration. Relay.app had the richest human-in-the-loop model in the mainstream market and is being switched off anyway, with an export that imports nowhere. Competence did not save it, and no feature comparison predicted it.

How Barzel applies here Start free with BarzelOps

What 2026 actually demonstrated

Relay.app closes for paid accounts at 23:59 PT on 14 September 2026, after which the workspace, the user account, and the stored app credentials and tokens are deleted. The team was acquihired by Google, and the product was shut down rather than sold — so there is no successor and no migration email coming.

What makes it instructive is that Relay was not a weak product losing on merit. It had four first-class human-in-the-loop step types — approvals, data input, task completion and manual path selection — with dynamic role assignment, interactive Slack approval and per-step escalation, more granular than most of what remains. Competence is not survival. Neither is candour: Relay's own documentation says plainly that different builders use different JSON structures, and that its export needs AI interpretation first and will not work through other tools' native importers. The vendor told the truth and the export still went nowhere.

Xero retired its own HubSpot integration on 13 March 2026 — the same shape one layer down, forcing a replacement architecture on someone else's calendar. Hence the thesis: evaluate a platform on what you can carry out of it, not on what it does while you are inside it.

What are you actually buying from an automation platform?

The pricing page and the thing you acquire are not the same object. The third column decides the exit cost.

What the demo showsWhat you actually acquireWhat settles the exit cost
Connector breadth Integrations you did not write Whether each authorisation is re-establishable elsewhere, and who revokes the old
The builder canvas A proprietary representation of your business logic Whether the export carries error branches, retry policy and timeouts, or only the primary path
An approval step Commodity. Everyone has one Whether the wait is a durable row or a process a deploy can end
Stored credentials Capability lent to a third party What is deleted at termination, and which grants you must revoke yourself
Where it runs A deployment location you may not be able to change Nothing — a wall, not a work item. Decide it before signing

How do you audit a platform for lock-in?

Run this against what you are on now, and against anything you are considering.

AssetCan you export it?Does it import anywhere?What you lose
Workflow definitions Usually, as the platform's own JSON No mainstream importer accepts another's format Nothing, if you keep it as the reference of record. Everything, if you assumed portability
Credentials and tokens No, by design Not applicable Deleted vendor-side, while the grants they created stay live wherever you connected
Execution history Often not — definitions and runs are separate exports Not applicable The evidence of what ran, when and with what result. Needed months later, gone
Approval records Rarely a distinct artefact; usually log lines Not applicable What the approver was shown. A line saying a run was approved proves a click, not a decision
Scheduled triggers and webhooks Schedules travel in the definition; webhook endpoints are platform-owned URLs No Every inbound URL registered elsewhere, re-registered by hand
Custom code steps Yes, as text Only where the destination has an equivalent runtime The runtime contract — libraries, timeouts, how the step receives and returns

Is there a standard for workflow definitions?

Stated plainly, because much writing in this category implies otherwise: there is no interchange standard for workflow definitions. Every vendor's export is a private format, and none accepts a competitor's.

Real standards exist; they are in a different market. The Open Workflow Specification, at v1.0.3 and formerly Serverless Workflow, is genuinely governed under the CNCF and the Linux Foundation — but its implementations are cloud-native developer orchestration engines, and Zapier, Make and n8n have not adopted it. BPMN 2.0 is the only broadly implemented portable notation, bounded the same way: portable across Camunda, Flowable, Appian and Pega, a heavier class of platform than most teams are shopping for.

So the procurement question is not does this support a standard — none of them do — but what does the export contain, and have I tested restoring from it?

Four failure modes

The definition survives and the exceptions do not

Proprietary JSON imports nowhere. A prose description is what an AI can rebuild from, and it flattens the happy path while dropping retry behaviour, approval timeouts and the branch that runs when a field is empty — the parts that fail three weeks later. Keep both, and write the exceptions down separately. See workflow portability.

The approval is commodity and the wait is the engineering

Human-in-the-loop is table stakes: n8n, Zapier, Power Automate, Camunda and Temporal all have it. What differs is what survives the wait. Pause-and-wait holds the run in process memory, so a deploy ends it; checkpoint-and-resume serialises state to durable storage and rehydrates on a signal — n8n's Wait node does the first under 65 seconds and the second beyond it. Nor is durability exactly-once: Temporal and Zeebe both document at-least-once execution. So the idempotency key must be assigned at checkpoint time, before the first attempt, and never regenerated — a key minted on retry presents a new value on resume, and the downstream posts a second invoice. See approval checkpoints.

The integration is documented and nobody read the documentation

HubSpot to Xero is the worked example, because every constraint is published and almost none is met before month three. Invoice sync supports six currencies. Tax rates created in HubSpot do not sync to Xero. An invoice created in HubSpot must be edited there — editing it in Xero fails days later in a log nobody owns. And matching on email address, being mutable, turns a changed contact address into a duplicate customer rather than an error.

The isolation is a folder tree

For agencies and MSPs, tenant isolation and credential handling are the constraint that turns a tool into a liability. A definition is inert; a credential is capability, so per-client folders sharing one connection pool give navigation and exactly the boundary you had before. n8n's projects scope workflows and credentials together, which is why its documentation notes that credentials must move with workflows or executions break. Two dependencies then fail for every client at once: the encryption key, whose loss makes every stored credential unrecoverable, and floating image tags, which leave clients on different versions. See multi-client workspaces.

A migration decision framework

In this order, because the early questions eliminate options rather than rank them.

  1. Does processing locality apply? If regulated data enters a workflow, this decides the shortlist before any feature.
  2. What must you prove, and for how long? Integration logs are retained for the vendor's convenience, not your obligation, and leave with the subscription.
  3. Does a paused run survive a restart? Pause, redeploy, approve. One completion and one downstream artefact means the checkpoint is real.
  4. Was the idempotency key assigned before the first attempt? Read the code, not the feature list.
  5. What does the export contain, and can you restore from it? Sample file, month one, against a working original.
  6. Can you offboard one tenant and demonstrate it? If that means picking records out of a shared structure by hand, the isolation was notional.
PlatformRuns inside your boundary?What is documented
Zapier No — cloud-only Zapier staff state on the official community that it is not available on-premises.
Workato No — cloud-only The On-Prem Agent is a connectivity bridge into Workato's cloud, where processing remains.
Make Unconfirmed Ships on-prem agent installers with no published architecture documentation.
n8n Yes Genuinely self-hostable. Air-gapped licensing is an Enterprise arrangement.
Camunda Yes Publishes an official air-gapped installation guide.

Those names are for different jobs, so ranking them against each other is a category error. Zapier and Make are hosted connector-based integration platforms; n8n a self-hostable node-based automation tool; Power Automate business process automation inside the Microsoft estate; Workato an enterprise iPaaS; Camunda BPMN process orchestration; Temporal a durable execution framework for developers, not a builder for operations teams.

The regulatory tail

An approval step records that a decision was made; an audit trail records what it was made about. Where the interface renders live data at click time, the record shows that somebody approved something without showing what they saw. The evidential artefact is a payload snapshot, hashed, stored with approver identity, timestamp and decision, and re-verified before dispatch. UK GDPR Article 22C, in force since 5 February 2026, gives a right to human intervention on a significant automated decision — which presupposes an intervention you can evidence. What such a record contains is in how to build an audit trail; the wider picture is in the AI governance guide.

Where continuous transaction controls apply, a duplicate stops being a tidying job: an invoice accepted by Poland's KSeF receives an identifier and cannot be deleted, only corrected, with penalties under art. 106ni from 1 January 2027. That clock outlives the subscription — and attribution needs the same per-operation metadata evidence does, so record it once and read it twice, as argued in FinOps for AI agents.

In this cluster

Relay.app closes on 14 September 2026: what to do with the time left

What the export gives you, what is not exported at all, and where to move.

Workflow portability: what to ask before you commit to a platform

The three levels of portability that exist, and six questions for a vendor call.

Approval checkpoints: what happens to the workflow while it waits

Pause-and-wait versus checkpoint-and-resume, and why resumes double-post.

HubSpot to Xero: what actually breaks, and what to do about it

The documented constraints, the mutable matching key behind duplicate customers, and Persistent Customer Mapping's current limits.

Running client workflows: isolation, credentials and blast radius

The isolation spectrum, why credentials are the real boundary, and offboarding as the only honest test.

Where we sit

In practice

BarzelOps addresses this shape of problem: cross-system workflow automation with durable state on PostgreSQL, crash recovery and idempotency, human approval checkpoints with resumable execution, tenant isolation with signed evidence receipts, request-scoped credential memory that is excluded from storage, and a portable Governed Workflow Manifest intended to run in cloud, VPC, on-premises or air-gapped deployments. To be explicit about that term, since this page has spent several hundred words on vendor coinages: Governed Workflow Manifest is Real Biz Digital's own name for a portable definition format. It is not an industry standard — no such standard exists, which is the point, and it applies to us exactly as to everyone else. For orientation on the rest of the range: Barzel Central Gateway federates and routes tool calls, Barzel FinOps Atlas attributes cost to outcomes, and BarzelVault applies policy and approval thresholds before execution and issues signed audit receipts across its 9 tools.

How Barzel applies here

Frequently asked questions

Can Relay.app workflows be imported elsewhere?

No. Relay's documentation states the JSON will not work through other tools' native importers. Rebuild from the exported description, before 23:59 PT on 14 September 2026.

When should an idempotency key be assigned?

At checkpoint time, before the first attempt, derived from run and step identity and never regenerated. A key created on retry gives no protection at all.

Where this leaves you

Portability is not a checkbox anyone can tick, so test for it rather than shop for it — and answer the locality question before you sign, because it is the one constraint you cannot retrofit. Everything else in a migration is work; that one is a wall. None of it appears on a comparison page, and all of it is cheaper than learning the answers on someone else's shutdown date.


This guide is for information and does not constitute legal, engineering or procurement advice. Product behaviour, deployment options and dates are as published at 2 September 2026; verify each against the vendor's own current documentation before relying on it in a contract or a design.

In practice

Automation you can leave, with the approvals and the evidence intact.

A workflow platform is only as safe as your ability to leave it. BarzelOps runs cross-system workflows with durable state, human checkpoints and signed evidence, exports them as a portable manifest, and migrates Relay workflows with a dry run before cutover.

In forceRelay.app closes at 23:59 PT on 14 September 2026

BarzelOps

Governed workflow automation across the systems that run the business.

  • Durable, idempotent execution: a timeout is retried once, never filed twice.
  • Human approval checkpoints that pause the workflow and resume it.
  • Isolation per entity or client, signed evidence receipts and a portable manifest; HubSpot, Xero, Gmail, Google Drive and Slack.

Free tier: 100 calls a dayPaid plans from $19 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

Barzel Central Gateway

The AI governance control plane: one inventory and one policy layer across every MCP server and agent.

  • Registers and synchronises every tool; enforces identity, policy, region, cost and health per tool.
  • Identity mapping through OIDC, Entra ID, Okta, SAML and SPIFFE, with credential brokerage.
  • Trace and SIEM export (W3C trace context, OTLP) for the security team and the regulator.

Free tier: 1,000 calls a monthPaid plans from $10 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

Barzel FinOps Atlas

Intelligent financial operations for AI agents and automation.

  • Cost per action, workflow and business outcome, allocated as it happens.
  • Spend limits and anomaly detection before the bill, not after.
  • Financial evidence tracing and close-readiness for SOX, SOC 2 and external audit.

Free tier: 500 calls a monthPaid plans from $29 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

Enterprise: written quote by email within two business days. No sales call.

Markets in English

In local languages

Cross-market topics