Workforce Hub architecture - reference design for enterprise digital employees

Workforce Hub is an enterprise platform for building and operating digital employees using agentic AI. It is designed for regulated environments with strong governance, security controls, and deployment flexibility.

Model-agnostic BPMN-ready Tool Gateway RAG Engine Control Tower

Architecture at a glance

Workforce Hub connects four layers: Experience, Digital Employees, Execution, and Governance.

Experience Layer Web • Mobile • Teams • Viber • APIs • Widgets Digital Employee Layer Agents • Skills • Guardrails • Prompt Templates • Brain (Model Routing) Execution Layer Automation Studio • BPMN (ASEE Flow) • Tool Gateway • RAG Engine Governance & Operations Layer Control Tower (SSO, RBAC, Audit) • HQ Insights (Analytics, Sentiment)

1. Experience Layer

End-user channels: web chat apps, widgets, Teams, Viber, mobile, APIs, and backoffice handoff

2. Digital Employee Layer

Agent definitions, skills, guardrails, prompt templates, and model routing (Brain Studio)

3. Execution Layer

Workflow orchestration (Automation Studio + BPMN), Tool Gateway, and RAG Engine

4. Governance & Operations

Control Tower (SSO, RBAC, audit logs) and HQ Insights (analytics, sentiment, topics)

Core components and how they fit together

Build layer: studios for digital employees

Workforce Hub provides studios that define roles, skills, tools, models, and testing.

  • Agent Studio (role and behavior definition)
  • Skill Studio (reusable skills and task execution)
  • Brain Studio (model routing), Tools Studio, Debug Studio
Explore Build AI Agents →

Automation layer: workflow orchestration (blocks + BPMN)

Workforce Hub supports workflow orchestration through Automation Studio and ASEE Flow (BPMN).

  • Automation Studio (drag-and-drop workflow blocks)
  • ASEE Flow (Camunda-compatible BPMN engine in Enterprise Edition)
  • Predictable execution, approvals, and auditability
Explore Automate with Workflows →

Data & integration layer: Tool Gateway + RAG Engine

Connect agents to enterprise systems and knowledge with governed tool access.

  • Tool Gateway (controlled access to APIs as governed tools)
  • RAG Engine (automated knowledge ingestion and retrieval)
  • Retrieval becomes a tool agents can call (agentic RAG)
Explore Data & Integrations →

Channels layer: publish agents to enterprise channels

Deploy digital employees across web, mobile, Teams, Viber, APIs, and backoffice.

  • Web chat apps, widgets, popup assistants
  • Microsoft Teams, Viber, mobile, Query API
  • Backoffice operator console for human handoff
Explore Publish to Channels →

Governance & operations layer: Control Tower + HQ Insights

Enterprise control and observability for digital employees.

  • Control Tower: SSO, RBAC/ABAC, tenant management, audit logs
  • HQ Insights: chat history, sentiment analysis, topic analysis
  • Approvals, human-in-the-loop workflows, dashboards
Explore Govern & Operate AI →

Key architecture patterns

Tool Gateway + RAG Engine Architecture

Enterprise Systems CRM • ERP • Core Knowledge Base Docs • Portals • KB Tool Gateway Governed API Access RAG Engine Knowledge Preparation Skills Execute with Tools API Tools Retrieval Tool

Tool Gateway

Securely exposes enterprise APIs as governed tools with policies and permissions

RAG Engine

Prepares knowledge automatically and exposes retrieval as a tool agents can call

Agentic RAG

Skills use retrieval and API tools together for grounded, actionable responses

Workflow Orchestration Architecture

Agent Digital Employee Automation Studio Drag-and-drop blocks Approvals • HITL • Exceptions ASEE Flow (BPMN) Camunda-compatible Enterprise Edition Execution Tools • Skills • Audit

Automation Studio

Low-code workflow builder with drag-and-drop blocks, approvals, and exception handling

ASEE Flow (BPMN)

Enterprise Edition supports BPMN orchestration (Camunda-compatible) for existing processes

Predictable Execution

Ensures agents follow defined workflows with approvals, audit logs, and escalation

Channels + Human Handoff Architecture

Agent Digital Employee Channel Hub Omnichannel Delivery Web Chat Teams Mobile API Backoffice Console Human Handoff • Contact Center

Omnichannel Delivery

Deploy once and publish to web, mobile, Teams, Viber, APIs, and custom apps

Human Handoff

Backoffice console for operators + SDK for contact center integrations

Rich UI Output

Support for code blocks, graphics, structured responses, and interactive elements

Deployment architecture: cloud, private cloud, or on-prem

Workforce Hub supports deployment models aligned to enterprise requirements.

Public Cloud AWS • Azure • GCP Fast deployment Managed services Private Cloud Dedicated VPC Controlled networking Data residency On-Premises Customer datacenter Full data control Regulatory compliance Hybrid Mixed deployment Flexible strategy Phased migration

Public cloud

Fast deployment on AWS, Azure, or GCP with managed services

Private cloud

Dedicated VPC with controlled networking and data residency

On-premises

Customer datacenter deployment for full data control and compliance

Hybrid

Mixed deployment strategy for flexible enterprise requirements

Multi-tenant architecture and internal marketplace

Workforce Hub supports enterprise groups with multiple tenants and subsidiaries.

Multi-tenant support

Tenant isolation, delegated administration, group-level governance policies, and versioning control.

  • Tenant isolation and delegated administration
  • Group-level governance policies

Internal marketplace

Distribute digital employees across teams with controlled rollout, versioning, and marketplace discovery.

  • Internal marketplace distribution
  • Versioning and controlled rollout

Security and compliance by design

Workforce Hub supports enterprise requirements including RBAC/ABAC, audit logs, tool access control, PII redaction, approval workflows, and deployment flexibility.

Access control

RBAC/ABAC for fine-grained control, SSO integration, and delegated administration

Audit & compliance

Audit logs for actions and configuration changes, compliance traceability, approvals

Data protection

PII redaction, sensitive data policies, data residency controls, encryption at rest/transit

Download Security Brief

Procurement-ready security documentation covering governance, deployment, and certifications

Download PDF →

Request Architecture Review

Technical validation session with solution architects for your deployment

Request Review →

Reference patterns (recommended)

Common enterprise patterns supported by Workforce Hub

Build once, publish everywhere

Define skills and tools once, then deploy to all channels (web, mobile, Teams, Viber, APIs)

Agentic RAG as a governed tool

RAG Engine exposes retrieval as a tool agents can call, enabling grounded responses with audit logs

Workflow-first orchestration with approvals

Use Automation Studio or BPMN to ensure predictable execution with human-in-the-loop and escalation

Tenant governance for enterprise groups

Multi-tenant architecture with delegated administration and group-level policies

Human handoff for exceptions

Backoffice console and contact center integrations for seamless human-agent collaboration

Model-agnostic deployment

Support for multiple LLM providers (OpenAI, Claude, Gemini, LLaMA, Qwen) without lock-in

Ready for an architecture review?

Workforce Hub architecture reviews help enterprise teams validate deployment, identity, integration strategy, governance requirements, and rollout plans across tenants and channels.

Frequently asked questions

Can Workforce Hub run on-prem?

Yes. Workforce Hub supports cloud, private cloud, and on-prem deployments depending on requirements.

Can we use our existing BPMN processes?

Yes. Enterprise Edition supports BPMN-based orchestration via ASEE Flow (Camunda-compatible).

How are APIs secured for agent execution?

Tool Gateway provides controlled tool access with policies, permissions, audit logs, and governance.

How do you ensure compliance?

Through RBAC/ABAC, audit logs, approvals, human-in-the-loop patterns, and tenant isolation.