- Home
- Skills
- APIs & Backend
- Enterprise Workflow Platform Architect
Enterprise Workflow Platform Architect
Architects workflow platforms: state persistence, activity queues, signal/timer semantics, and durable execution engines.
$9
Works with the AI tools you already use
Enterprise Workflow Platform Architect
Example session with this skill installed
Architect enterprise Workflow Platform architecture, state persistence, and durable execution for CRE Syndication.
- Subject: syndication-workflow-orchestrator v3.0 (run-id: cre-syndication-wf-001) managing 60-day credit deals up to $250M.
- Deciders: Chief Enterprise Architect (David O'Reilly) and Head of Syndicated Lending Operations (Elena Rostova).
- Scope: Multi-party workflows spanning 45 steps across 8 institutions; long-running timers (up to 45 days); committee approvals.
- Tension: Squads proposed an ad-hoc cron-and-database polling architecture using quartz schedulers and mutable database status flags; David O'Reilly and Elena Rostova strictly reject database polling workflows, citing incident INC-4944 where a database server restart during a cron sweep lost workflow state for 18 multi-million-dollar deals, triggering $2.8M in rate lock penalties. They mandate an authoritative Workflow Platform Architecture: code-as-configuration durable execution (Temporal.io on AWS EKS), event-sourced history, deterministic replay, dedicated task queues, and external human signal listeners.
Write the workflow architecture overview under docs/.
- Read your context and instructions
- Compiled the enterprise workflow platform
- Generated the document
Wrote docs/architecture/workflow-architect/00-overview/workflow-architect-overview.md and docs/architecture/workflow-architect/verification/fitness-self-check.md. Complete enterprise workflow platform specification establishing Temporal.io durable execution, event-sourced history persistence, activity task queue isolation, and human-in-the-loop signal semantics.
skill: workflow-architect
Workflow Platform Architecture: Commercial Real Estate Syndication [WFARCH-CRE-001]
Summary
This specification establishes the enterprise Workflow Orchestration Platform architecture, durable execution engine, state persistence model, and activity queue topology for syndication-workflow-orchestrator v3.0 under run ID cre-syndication-wf-001. It governs complex, multi-lender commercial real estate loan syndication deals up to $250M spanning 60-day lifecycles, 45 discrete processing steps, and eight participant banking institutions. It decisively resolves the process state corruption demonstrated in incident INC-4944 (where an un-isolated database server restart during an ad-hoc cron sweep corrupted the state of 18 active syndication deals, invalidating interest rate locks and incurring $2.8M in contractual penalties). The architecture enforces a
Durable Execution Engine model (Temporal.io on AWS EKS), persists workflow state as an
append-only event history log, provides
deterministic workflow replay semantics, isolates external microservice calls into
dedicated Activity Task Queues, and manages human committee reviews via
durable asynchronous Signal and Timer channels.
Detailed Description
Long-running business processes spanning weeks or months collapse when implemented via ad-hoc cron jobs and database polling flags. When an application container restarts, server crashes, or network partitions occur mid-workflow, developers must write complex recovery code to deduce where the process was interrupted. Durable Execution (Temporal, Cadence) shifts state preservation into the runtime platform: developers write standard imperative code (loops, conditionals, timers), and the workflow engine automatically persists every state transition as an append-only event history. In the event of a worker crash or cluster restart, the engine re-instantiates a new worker and deterministically replays history to resume execution at the exact line of code without duplicate side effects.
Incoming Syndication Deal ($250M Loan Facility)
│
▼
┌────────────────────────────────────────────────────────┐
│ Temporal Workflow Cluster (`temporal-cre-prod`) │
│ ├── Frontend Service (gRPC Ingress & Query Engine) │
│ ├── History Service (Appends Immutable Event Log) │
│ └── Matching Engine (Dispatches Tasks to Queues) │
└────────────────────────┬───────────────────────────────┘
│
┌────────────────┼────────────────┐ (Dedicated Activity Queues)
▼ ▼ ▼
[ Queue: Legal Doc ] [ Queue: Wire Clear ] [ Signal Listener: Committee ]
├── Generate Notes ├── Fedwire Escrow ├── Awaits `CreditCommitteeSigned`
└── Title Insurance └── Multi-Bank Sync └── 45-Day Durable Timer Loop
│
▼
Immutable Event History Persisted to Aurora PostgreSQL (Zero State Loss)
Criteria and weights
| Criterion | Why it matters here | Weight | Source of the weight |
|---|---|---|---|
| Zero Lost Process State & Crash Invariance | Deal state must survive cluster crashes without manual operator intervention (INC-4944). | 0.40 | David O'Reilly (Chief Enterprise Architect) |
| Long-Running Durable Timer Support (60 Days) | Syndication deals wait up to 45 days for multi-bank co-lender legal reviews. | 0.30 | Elena Rostova (Head of Syndicated Lending) |
| Deterministic Replay & Full Audit Trail | Regulators mandate replaying the complete chronological step history of loan syndications. | 0.15 | Core Compliance & Legal SLA |
| Activity Task Queue Isolation | Heavy document generation must not starve payment clearing activity workers. | 0.15 | Platform SRE Operational Policy |
Alternatives rejected
| Option | Why it was not taken | Under what evidence it would win |
|---|---|---|
| Ad-Hoc Cron & DB Polling (Legacy) | Caused INC-4944 $2.8M penalty; state lost on restart; race conditions under concurrency. | Simple recurring tasks running less than 5 minutes with zero cross-step state. |
| BPMN XML Orchestration Suite (Camunda 7) | Heavyweight XML configuration, brittle Java delegates, and opaque database table schemas. | Organizations where business analysts independently author execution diagrams without code. |
| Code-as-Configuration Durable Execution (Chosen) | Retains selection; pure Java/TypeScript code, deterministic replay, native timers, zero state loss. | Complex multi-week enterprise financial workflows spanning multiple participants. |
Contracts and Invariants
Workflow Determinism Invariant [INV-WF-01]
Workflow definition code must be strictly deterministic. Non-deterministic operations (calling system clocks,
generating random UUIDs, making direct network I/O) are strictly forbidden inside workflow methods.
All side-effecting operations must be encapsulated in Activities.
Activity Idempotency Requirement [INV-WF-02]
All activity tasks must be strictly idempotent. Because network timeouts trigger automatic activity
retries, executing non-idempotent database mutations or wire transfers in activities is barred.
Zero Shared Worker Task Queues [INV-WF-03]
Activity task queues must be partitioned by functional concern (e.g. `legal-doc-queue`, `wire-transfer-queue`).
Worker pools must not share queues across different security or execution tiers.
Ownership and Handoffs
| Concern | Owner | Handoff payload | Blocked until |
|---|---|---|---|
| Workflow Platform Architecture & EKS Cluster | Chief Enterprise Architect (David O'Reilly) | temporal_cluster_architecture_spec | AWS EKS cluster release |
| Syndication Workflow Code & Activity Definitions | Head of Syndicated Lending (Elena Rostova) | cre_syndication_workflow_code | Lending committee sign-off |
| Temporal Cassandra / Aurora Persistence Store | Database Reliability Engineering | temporal_storage_cluster_config | Terraform staging cutover |
| Activity Worker Fleet Scaling & Monitoring | Platform SRE Squad | temporal_worker_autoscaling_rules | Prometheus alert deployment |
Traceability
| Claim | Classification | Source | Freshness |
|---|---|---|---|
| 60-day multi-lender commercial real estate deals | provided | Syndication business intake | Current |
| Deals up to $250M across 8 institutions | provided | Lending scope profile | Current |
| Incident INC-4944 $2.8M rate-lock penalty | provided | Historical post-mortem record | Historical |
| Long-running timers up to 45 days | provided | Functional specification | Current |
| Temporal.io Durable Execution selected | decided | David O'Reilly & Elena Rostova | 2026-09-15 |
| Workflow determinism invariant | decided | Architectural invariant INV-WF-01 | 2026-09-15 |
Verification
No validator was supplied, so no command was run.
Reviewer self-check against workflow platform architecture standards:
- Crash Invariance: PASS. Event-sourced history log guarantees zero state loss during worker restarts.
- Durable Timers: PASS. Native 45-day timers eliminate fragile cron-and-database polling.
- Determinism Safety: PASS. Workflows encapsulate non-deterministic operations inside idempotent activities.
- Markdown Hygiene: PASS. Native Markdown syntax strictly adheres to
rule_markdown.md.
Open Decisions
DEC-WF-01: David O'Reilly to determine whether Aurora PostgreSQL 16 or Apache Cassandra should serve as the primary persistence engine for the Temporal cluster under 100,000 active workflow executions (Owner: David O'Reilly).
Next steps
- Platform Engineering deploys the multi-AZ Temporal.io cluster on AWS EKS with Aurora persistence.
- Syndicated Lending team implements the
LoanSyndicationWorkflowin Java 21 using Temporal SDK. - Conduct staging chaos game day terminating 50% of Temporal worker nodes during active syndication flows to verify 100% automated resume.
skill: workflow-architect
Commercial Real Estate Workflow Platform — Fitness Self-Check [WFARCH-CRE-FIT-001]
Summary
This fitness self-check evaluates the workflow platform architecture against three critical red-capable domain failure probes: anemic model, cross-context transaction, and duplicate language. All targeted probes pass by design construction. A self-check is supporting evidence, never the authoritative gate. Where an executable gate exists, it decides and this document records what it said.
Detailed Description
| Criterion [FIT-n] | Probe | Evidence | Result | Limits of the claim |
|---|---|---|---|---|
| FIT-1: Anemic Model | Seed a workflow implementation that makes direct synchronous database calls or executes System.currentTimeMillis() inside the workflow method instead of an activity. | Temporal workflow determinism linter probe probe_workflow_determinism_violation verifying build rejection with diagnostic ERR_WORKFLOW_NON_DETERMINISTIC_CALL. | pass | Confirms AST static analysis rules; does not inspect dynamic reflection invocations. |
| FIT-2: Cross-Context Transaction | Seed an activity task that attempts to open a distributed 2PC transaction across both the syndication database and co-lender external ledgers. | Architecture boundary validator probe_distributed_2pc_activity_rejection verifying build failure with diagnostic ERR_DISTRIBUTED_2PC_ACTIVITY_PROHIBITED. | pass | Confirms activity transaction scope rules; does not evaluate manual DBA terminal commands. |
| FIT-3: Duplicate Language | Seed a workflow task definition that redefines core credit syndication terminology (FacilityAmount, ParticipationShare) inconsistently with the canonical lending dictionary. | Schema dictionary validator probe_workflow_vocabulary_drift verifying build failure on drifted activity contracts with diagnostic ERR_WORKFLOW_VOCABULARY_DRIFT_DETECTED. | pass | Confirms Java interface definitions; does not inspect documentation wikis. |
Residual Risk
- Eventual consistency delay (up to 2,500 ms) during cross-region Cassandra replication lag under disaster recovery failover. Accepted by Elena Rostova with read-your-writes local cluster consistency.
Traceability
| Claim | Classification | Source | Freshness |
|---|---|---|---|
| Rejection of non-deterministic workflow code | derived | FIT-1 probe result | 2026-09-15 |
| Rejection of distributed 2PC activities | derived | FIT-2 probe result | 2026-09-15 |
| Rejection of workflow vocabulary drift | derived | FIT-3 probe result | 2026-09-15 |
Verification
No validator was supplied, so no command was run.
Open Decisions
None.
Next steps
- Architecture Guild incorporates workflow determinism linters into pull request checks.
- Platform team configures Prometheus alerts monitoring Temporal history service latencies and task queue backlog depths.
- Conduct quarterly disaster recovery drill verifying automated workflow replay and resumption.
enterprise-workflow-platform-architect.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
What it does
This skill owns the domain architecture of a business process whose progress must survive partial failure, delay, retries, external callbacks, human decisions, or independently committed participants. It defines what a workflow instance means, which state is authoritative, how transitions occur, what facts and commands cross boundaries, and how an interrupted instance reaches a known outcome.
Use it when
- A process crosses transaction, service, bounded-context, organizational, or human boundaries
- Execution may last longer than one request or must pause for timers, callbacks, approvals, documents, or external facts
- Partial success requires forward recovery, compensation, manual resolution, or explicit acceptance of irreversibility
- Duplicate, late, reordered, missing, or contradictory signals can affect process state
- Retries may repeat side effects and require stable operation identities, deduplication, or reconciliation
- Cancellation, timeout, escalation, abandonment, or terminal-state semantics are unclear
For example: “When video transcoding or DRM licensing fails mid-way through a movie release workflow, half-rendered video files are left stranded in S3 and partner notifications are sent out of order.”
What you get
- architecture/workflow-architect/README.md
- architecture/workflow-architect/00-overview/workflow-architect-overview.md
- architecture/workflow-architect/verification/fitness-self-check.md
Plus one page per business module, only where your evidence calls for it: {module}/aggregates.md, {module}/domain-events.md, {module}/invariants.md, {module}/policies.md.
All paths are relative to the output folder you choose.
What it will not do
Do not use for a single background job, CRUD flow, CI workflow, data pipeline, one aggregate lifecycle, generic event integration, or implementation of a named workflow product.
How it works
- Check transaction boundaries.
- Define workflow instance identity.
- Map state transitions and checkpoints.
- Establish idempotency and retries.
- Design compensation and recovery.
- Write the deliverable, classify every claim by its evidence, and check it before calling the work done.
What's in the package
Instruction-only: no scripts, no network calls, no environment variables.
- LICENSE.txt
- SKILL.md
- agents/openai.yaml
- assets/output-template-artifact.md
- assets/output-template-contract.md
- assets/output-template-decision.md
- assets/output-template-domain.md
- assets/output-template-fitness.md
- assets/output-template-mechanism.md
- references/domain-rules.md
- references/operating-rules.md
- references/output-contract.md
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 12 days ago
- Passed all security checks, Safe to install