Project 5: Designing a Governance Layer for Citizen-Developed Automation Workflows in n8n
Project Description
Low-code and no-code platforms such as n8n let employees build automated workflows without deep programming skills, known as "citizen development." It allows fast, innovative and flexible solutions. However, research and industry practice show a more complex picture. Personal, private automations are usually built and used freely. But automations that get shared with others, or that need access to critical systems such as SAP or other ERP platforms, need approval from IT or a similar gatekeeper.
Most tools do not offer a built-in way to make this difference visible or to enforce it. As a result, workflows that touch sensitive data can go live without review. This creates risks around data protection, compliance, and system integrity. At the same time, treating every workflow the same way slows down harmless personal automations.
A tiered governance approach can solve this problem. Personal workflows should stay free to build. Shared workflows and workflows that use critical data should be reviewed before they go live. This project explores how such a permission and approval layer can be added around n8n. The result will give the PIA Lab a working example of governed, tiered automation that can be reused and extended in future research and teaching.
Project Objectives: The goal of this project is to design and implement a prototype governance layer that adds permission tiers and an approval process around n8n workflows.
Key objectives:
- Analyse typical n8n workflow patterns and classify them into three tiers: personal (private, low-risk), shared (used by others), and critical-data (connected to systems such as SAP or ERP).
- Design a permission model with clear tier rules and approval criteria for each tier, with strict review for critical-data workflows.
- Implement a working prototype with three components:
(1) a program that scans n8n for new or changed workflows and assigns each one to a tier
(2) a database that stores tier and approval status (pending / approved / rejected)
(3) a dashboard where a reviewer approves or rejects pending workflows. Approved workflows are activated in n8n through n8n's own API. - Build an audit log recording all submissions, approvals, and rejections.
- Document the governance design and architecture as a short handbook focusing on structures, processes, and relational mechanisms, so future projects can reuse or extend it.
Project Requirements:
- Project documentation (standard/mandatory)
- Creation of a project plan and task allocation among group members using project management techniques (standard/mandatory)
- Interim and final presentations of project results (standard/mandatory)
- Requirements analysis and design of a tier-based permission model for n8n workflows
- Development of a working prototype including workflow classifier, approval database, and approval dashboard
- Integration with n8n's API to enforce workflow activation and deactivation based on approval status
- Preparation of dummy workflows and dummy data to demonstrate all three tiers end-to-end
Prerequisites:
- Students of the Faculty of Computer Science in the fields of Information Systems or Software Engineering
- Basic programming skills (ideally Python)
- Interest in workflow automation, low-code platforms, and IT governance topics
- No prior knowledge of n8n required — hands-on onboarding will be provided
Literatur
- Bock, A.C., Frank, U. Low-Code Platform. Bus Inf Syst Eng 63, 733–740 (2021). https://doi.org/10.1007/s12599-021-00726-8
- Viljoen, Altus; Radić, Marija; Hein, Andreas; Nguyen, John; and Krcmar, Helmut (2024) "Governing Citizen Development to Address Low-Code Platform Challenges," MIS Quarterly Executive: Vol. 23: Iss. 3, Article 6.
- Viljoen, A. , B. Stelzl , M. Yang , et al. 2026. “ Navigating Flexibility and Standardisation in Low-Code/No-Code Development.” Information Systems Journal 36, no. 1: 95–109. https://doi.org/10.1111/isj.70001 .
- Binzer, Björn; Elshan, Edona; Fürstenau, Daniel; and Winkler, Till J. (2024) "Establishing a Low-Code/No-Code-Enabled Citizen Development Strategy," MIS Quarterly Executive: Vol. 23: Iss. 3, Article 3. Available at: https://aisel.aisnet.org/misqe/vol23/iss3/3
- S. De Haes and W. Van Grembergen, "IT Governance Structures, Processes and Relational Mechanisms: Achieving IT/Business Alignment in a Major Belgian Financial Group," Proceedings of the 38th Annual Hawaii International Conference on System Sciences, Big Island, HI, USA, 2005, pp. 237b-237b, doi: 10.1109/HICSS.2005.362 . keywords: {Companies;Financial management;Information technology;International trade;Wood industry;Board of Directors;Market research},
How to apply
If you are interested in this porject, follow the steps below to submit your application.
1. Form a project group
Projects are typically carried out in groups of 3–5 students. We recommend forming a group with fellow students before applying.
2. Prepare your application
Send a short application including:
- your transcript of records
- a short motivation letter (about one page) explaining why your group is interested in the project.
3. Submit your application
Send your application via email to:jannis.nacke (at) icb.uni-due.de
