1.0 Introduction
This article describes the steps to create workflows in Fortanix Confidential Computing Manager (CCM) for Advanced Micro Devices (AMD) Secure Encrypted Virtualization (SEV) - Secure Nested Paging (SNP).
There are three types of workflows: Draft, Pending Approval, and Approved.
Draft workflows: Draft workflows are in-progress workflows that are still under development. These workflows have not been submitted for approval.
Pending Approval workflows: Pending Approval workflows are workflows that have been submitted for approval but have not yet received approval from all required users.
Approved workflows: Approved workflows are finalized and versioned workflows protected by quorum approval. Once approved, the workflow can be deployed.
To convert a Draft workflow into an Approved workflow, approvals are required from the users participating in the workflow.
The Application Owner builds the workflow graph. Once the workflow graph is complete, the Administrator submits it for approval. A workflow graph must be approved by all participating users before it becomes an approved workflow.
2.0 Create a Workflow
Perform the following steps to create a workflow:
In the CCM UI left navigation panel, click the Workflows menu item.
On the Workflows page, click ADD WORKFLOW to create a new workflow.
(1).png?sv=2026-02-06&spr=https&st=2026-09-18T19%3A19%3A20Z&se=2026-09-18T19%3A31%3A20Z&sr=c&sp=r&sig=QgkJqXoS2JpBqFsJPau%2FHZa1Int%2B8tFMvPgEF9a7Vf8%3D)
Figure 1: Create workflow
On the Add Workflow form:
Name: Enter a name for the workflow.
Group: Select the group for the shared workflow. If you do not select a group, Fortanix CCM uses the default group.
Click ADD WORKFLOW to create the workflow.
Add an application to the workflow graph. Drag the Application icon from the component panel and drop it in the graph area.
Click ADD APPLICATION. In the Add Application form, select the AMD SEV-SNP application build and the corresponding application configuration.
For more information on creating an application, refer to Add AMD SEV-SNP Application.
After the workflow is completed, click SAVE AND REQUEST APPROVAL to initiate the workflow approval process.
In the Request approval for draft workflow dialog box, click REQUEST APPROVAL.
WARNING
When a draft workflow is submitted for approval, it is removed from the Drafts list. You cannot edit the workflow while it is in the Pending Approval or Approved state.
The workflow remains in the Pending Approval state until it receives approval.
Navigate to Tasks → Pending, select the required workflow approval task.
In the Approval request - Create Workflow dialog box, click ACCEPT to approve the workflow.
Navigate to the workflow in Fortanix CCM and click the application. In the Application Properties right panel, copy the Application configuration ID (Runtime configuration hash).
(3).png?sv=2026-02-06&spr=https&st=2026-09-18T19%3A19%3A20Z&se=2026-09-18T19%3A31%3A20Z&sr=c&sp=r&sig=QgkJqXoS2JpBqFsJPau%2FHZa1Int%2B8tFMvPgEF9a7Vf8%3D)
Figure 2: App Configuration ID