# Workflows and external data

**You'll need:** an administrative role. **Administration → Workflows.**

## Workflows

A workflow is a sequence of steps that runs the same way every time: generate, review,
approve, publish. Where a [task](/guide/automation/tasks) is one piece of work, a
workflow defines work that repeats.

**Create workflow** opens a canvas of steps. Each step has:

| | |
|---|---|
| **Name** and **Type** | What it is and what kind of step it is. |
| **Position** | Where it sits in the sequence. |
| **Properties** | Its configuration. |
| **Hidden** | Whether it shows in the instance view. |

**Transitions** connect steps and can be restricted by **role**, which is how an approval
step becomes a real gate: only someone holding the named role can move the instance from
one state to the next.

## Instances

Every run of a workflow is an **instance**, listed under **Workflow instances** with its
current state and status.

<Mermaid chart={`stateDiagram-v2
  [*] --> CREATED
  CREATED --> RUNNING
  RUNNING --> SUCCEEDED
  RUNNING --> FAILED
  RUNNING --> CANCELLED
  SUCCEEDED --> [*]
  FAILED --> [*]
  CANCELLED --> [*]
`} />

Only `RUNNING` can move; the other three are terminal. An instance stuck in `CREATED`
never started, which is a different problem from one that reached `FAILED`.

Open an instance and the **Step Timeline** shows each step with its **Input**,
**Output** and, if it failed, its **Error**. Check the timeline when a run did not do
what you expected, rather than the workflow definition, which only shows what was
supposed to happen.

**All instances** and **My instances** filter the list.

## External data

**Administration → External Data.** Connect the systems your information already lives
in so agents can query them live, instead of copying data into a knowledge base where it
goes stale.

Services such as HubSpot, Salesforce and Mailchimp connect here. For each connection:

- **Connection name**, what agents will see it as
- **Credentials**, stored securely and never displayed again
- **Allow write operations**, off by default

<Callout type="caution">
	With write access enabled, agents can create and modify data in the connected service.
	Leave it off unless you specifically need it, and turn it on for one connection at a
	time rather than as a default.
</Callout>

Each connection shows its status (**Connected**, **Pending**, **Error** or **Disabled**)
and whether it is **Read-only** or **Read & write**.

**Disconnect** revokes a connection, and agents lose access immediately.

### Give an agent access

Connections do nothing until an agent is given the **External Data** capability. You can
also restrict which connected systems that agent may reach rather than granting all of
them. See [agents](/guide/ai/agents).

## Knowledge base or external connection?

| Use a [knowledge base](/guide/ai/knowledge-bases) | Use an external connection |
|---|---|
| The content is yours to maintain here | The system of record is elsewhere |
| It changes slowly | It changes constantly |
| You want it cited and versioned | You want it live |
| Products, policies, brand, FAQs | Deal stages, ticket status, campaign metrics |

Copying a fast-changing system into a knowledge base is the most common setup mistake
here. The copy is accurate for a few days and misleading after that.
