---
title: "Collaborating Groups and Shared Workflow - AWS Nitro and ACI Apps"
slug: "users-guide-create-update-revoke-third-party-groups-1"
updated: 2026-06-26T16:26:21Z
published: 2026-06-26T16:26:21Z
canonical: "support.fortanix.com/users-guide-create-update-revoke-third-party-groups-1"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://support.fortanix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Collaborating Groups and Shared Workflow - AWS Nitro and ACI Apps

## 1.0 Introduction

This article describes the steps to create, manage, and revoke collaborating groups in Fortanix Confidential Computing Manager (CCM).

A **Collaborating Group** in Fortanix CCM represents a collaboration established between two groups that belong to different Fortanix CCM accounts. Through this collaboration, the participating groups can securely share selected resources and work together on common workflows.

This document explains the end-to-end collaboration process, including creating collaborating groups, sharing collaboration tokens, building shared workflows, approving workflows, and managing collaboration lifecycle events.

## 2.0 Collaborating Groups for AWS Nitro or ACI Applications

A Fortanix CCM collaborating group is created when groups from different Fortanix CCM accounts establish a collaboration. Through this collaboration, the groups can share resources and participate together in workflows.

In a collaborating setup:

- One group acts as the [consumer group](/v1/docs/users-guide-groups-and-collaboration-groups-concepts-1#31-consumer-group) and initiates the collaboration.
- One or more groups act as [publisher groups](/v1/docs/users-guide-groups-and-collaboration-groups-concepts-1#32-publisher-group) and participate by contributing permitted resources.

The collaboration is represented and managed through shared workflows, which enforce controlled interaction, approval sequencing, and access restrictions between participating groups.

This section describes collaboration between three Fortanix CCM groups from different Fortanix CCM accounts using a workflow that includes an ACI application and two datasets. In this example, one group acts as the consumer group and the other two groups act as publisher groups.

## 3.0 Create Consumer Group

This section describes how to create consumer groups that participate in a workflow collaboration with publisher groups.

In this example, a consumer group is created in a Fortanix CCM account and initiates collaboration with publisher groups using a shared workflow. The consumer group adds an ACI application and placeholder dataset nodes to the workflow, enabling publisher groups to contribute datasets to the shared workflow.

Perform the following steps to create a consumer group for workflow-based collaboration:

1. Log in to Fortanix CCM and create a new account, for example, **DemoA**, or log in to an existing account. *For more information on how to log in and create a new Fortanix CCM account, refer to* [*Logging In*](/v1/docs/users-guide-logging-in-1)*.*
2. From the CCM left navigation panel, click the **Groups** menu item, and on the **Groups** page, click **+ ADD GROUP** to create the consumer group.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/Add-group(1).png)

**Figure 1: Create consumer group**
3. On the **GROUP** form:

a. **Name**: Enter a name for the group. For example, **DemoA-Group1**.

b. **Description** (optional): Enter a short description for the group.

c. **Labels** (optional): Add one or more key–value labels to the group.
4. Click **SAVE** to create the consumer group.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-z85ve06f.png)

**Figure 2: Consumer group created**

The group is created successfully.

### 3.1 Create Application

Perform the following steps to create an application:

1. Click the group to open the detailed view of the consumer group.
2. Create a new ACI application in the **consumer group** to participate in the workflow collaboration. From the group’s details page, go to the **APPLICATIONS** tab.
3. On the **Applications** page, click **+ ADD APPLICATION** to add a new application.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-76gymwao.png)

**Figure 3: Consumer group details page**
4. On the **APPLICATION** dialog box, select the ACI application click **ADD** to proceed to create an application.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/Screenshot (3582)(1).png)

**Figure 4: Select application**

*For more information on how to create an Enclave OS or ACI application, refer to* [*Add and Edit an Application*](/v1/docs/users-guide-add-and-edit-an-application-1)*.*

## 4.0 Create Publisher Groups

This section describes how to create publisher groups that participate in workflow collaboration with a consumer group.

In this example, two publisher groups are created in different Fortanix CCM accounts and contribute datasets to a shared workflow initiated by the consumer group.

> [!NOTE]
> **NOTE**
> 
> To collaborate with resources in the consumer group, you must create two additional groups in different Fortanix CCM accounts as collaboration between groups within the same account is not supported.

Perform the following steps:

1. Create two new Fortanix CCM accounts, for example, **DemoB** and **DemoC**, or log in to existing accounts if they already exist. *For steps to log in and create a new Fortanix CCM account, refer to* [*Logging In*](/v1/docs/users-guide-logging-in-1)*.*
2. Repeat *Steps 2 to 4* in [*Section 3.0: Create Consumer Group*](/v1/docs/users-guide-create-update-revoke-third-party-groups-1#30-create-consumer-group), to create the two new publisher groups, for example **DemoB-Group2** and **DemoC-Group3**.

### 4.1 Create Dataset

Perform the following steps to create datasets:

1. Create a dataset in the first publisher group (**DemoB-Group2**) to participate in the workflow collaboration. From the detailed view of **DemoB-Group2**, click the **Datasets** menu item, and on the **DATASET** page, click **+ ADD DATASET** to create a new dataset.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-k10v3r69.png)

**Figure 5: Add dataset**
2. On the **DATASET** form:
  1. **Name**: Enter a name for the dataset. For example, **DatasetB**.
  2. **Description** (Optional): Enter a short description of the dataset.
  3. **Labels** (Optional): Add one or more key–value labels to the dataset.
  4. **Location**: Enter the URL where the data can be accessed.
  5. **Long Description**: Enter the dataset details in GitHub-flavored Markdown format or click **Fetch Long Description** to import the Markdown file content from an external URL. Ensure that Cross-origin resource sharing (CORS) is enabled on the external URL so that Fortanix CCM can access it. *For more information, refer to the steps for* [*AWS*](https://docs.aws.amazon.com/AmazonS3/latest/userguide/enabling-cors-examples.html) *and* [*Azure*](https://docshield.tungstenautomation.com/Printix/en_US/help/admin/Printix_admin/t_how_to_set_up_azure_blob_storage_cors.html)*.*
  6. **Credentials**: Enter the credentials required to access the data.
  7. Click **SAVE** to create the dataset.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-0c7zui2h.png)

**Figure 6: Create dataset for publisher group 1**

The dataset is created successfully.
3. Repeat *Steps 1 and 2* to create a dataset, for example, **DatasetC** for the second publisher group **DemoC-Group3**.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-qk1fa6hm.png)

**Figure 7: Create dataset for publisher group 2**

*For more information on how to create a dataset, refer to* [*Create Datasets*](/v1/docs/users-guide-create-datasets-1)*.*

## 5.0 Generate Collaboration Token

To initiate collaboration, a consumer group must authenticate itself to a publisher group. Without authentication, a publisher group could receive unsolicited or spam collaboration requests from multiple consumer groups. To prevent this, the publisher group administrator generates a “collaboration token”, which serves as proof of identity for collaboration requests.

When a consumer group requests collaboration, it includes the collaboration token provided by the publisher group in the request. The publisher group then verifies the token and authenticates the consumer group before allowing the collaboration to proceed.

Perform the following steps to generate the collaboration token:

1. Go to the detailed view of **DemoB-Group2** in the **DemoB** account.
2. Click **COLLABORATE** to generate a new collaboration token.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-v8j3ilqt.png)

**Figure 8: Collaborate**
3. On the **COLLABORATE** dialog box, click **+ GENERATE** to generate the token.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-h2jglqjd.png)

**Figure 9: Generate token**
4. Click **COPY** to copy the collaboration token.

You must share this collaboration token with the consumer group administrator to enable collaboration. The method used to share the collaboration token is outside the scope of this guide.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-rubdfb5j.png)

**Figure 10: Copy collaborating token**
5. Similarly, go to the detailed view of **DemoC-Group3** in the **DemoC** account and repeat *Steps 1 to 4* above to generate and copy the collaboration token for DemoC-Group3. Then, share this token with the consumer group.
6. Click **SHOW TOKENS** to view the previously generated tokens.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-4edxeq58.png)

**Figure 11: View token**

## 6.0 Create Collaborating Group

This section explains the collaboration process between the consumer group and the publisher group using the collaboration token shared by the publisher group.

Perform the following steps to create a collaborating group for workflow collaboration:

1. Open the detailed view of the consumer group, for example **DemoA-Group1**, in the **DemoA** account.
2. Click **ACCEPT TOKEN**.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-ygye24bf.png)

**Figure 12: Accept collaboration token**
3. In the **ACCEPT TOKEN** dialog box, paste the collaboration token shared by the publisher group in [*Section 5.0: Generate Collaboration Token*](/v1/docs/users-guide-create-update-revoke-third-party-groups-1#50-generate-collaboration-token).
4. Click **PROCEED** to initiate the collaboration request.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-pk3jo8uw.png)

**Figure 13: Enter collaborating token**
5. Navigate to **Groups** and select the **COLLABORATION GROUPS** tab.
6. On the **CONSUMER** tab and verify that the consumer group **DemoA-Group1** appears associated with the publisher group **DemoB-Group2**.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-g6rkvyno.png)

**Figure 14: Consumer group collaboration request**
7. In the **Status** column, observe that the collaboration request is in the **Pending** state.

> [!NOTE]
> NOTE
> 
> The publisher group must accept the collaboration request before collaboration can begin.
8. Go to the publisher group (**DemoB-Group2**) and select the **COLLABORATION GROUPS** tab.
9. On the **PUBLISHER** tab, verify that **DemoB-Group2** shows an association request from **DemoA-Group1**.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-r6fvup7p.png)

**Figure 15: Publisher group association**
10. Click the overflow menu ![Overflow.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/20205446543124.png) for the publisher group row and click **ACCEPT** to approve the collaboration request.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-w2c864z0.png)

**Figure 16: Approve collaboration**
11. Verify that the collaboration status updates to **Accepted** in the publisher group view.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-2ax5m9tl.png)

**Figure 17: Status accepted**
12. Return to the consumer group account (**DemoA**) and confirm that the collaboration status for the consumer group (**DemoA-Group1**) also shows **Accepted**.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-50rb7e4j.png)

**Figure 18: Status accepted**
13. Repeat *Steps 1 to 12* to create a collaborating group between **DemoA-Group1** and **DemoC-Group3** using the collaboration token generated by **DemoC-Group3**.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-lt2avmxa.png)

**Figure 19: Collaborating group created**

### 6.1 Create Shared Workflow

After creating the collaborating groups, the consumer group administrator initiates collaboration by creating a shared workflow.

In the shared workflow, the consumer group administrator creates placeholder nodes. Each [placeholder node](/v1/docs/users-guide-groups-and-collaboration-groups-concepts-1#34-placeholder-nodes) is assigned to a specific publisher group, and only administrators of that publisher group can populate the placeholder nodes assigned to them.

Perform the following steps as a consumer group administrator to create a shared workflow:

1. In the **DemoA** account, click the **Workflows** menu item in the CCM UI left navigation panel.
2. On the **Workflows** page, click **+ ADD WORKFLOW** to create a new workflow.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-uckwba7v.png)

**Figure 20: Select workflow**
3. On the **WORKFLOW** form:
  1. **Name**: Enter a name for the workflow.
  2. **Group**: Select the consumer group for the shared workflow. If you do not select a group, Fortanix CCM uses the default group.
  3. Click **SAVE** to create the shared workflow.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-gfhcj6b5.png)

**Figure 21: Create shared workflow**
4. On the workflow canvas, add the application that belongs to the consumer group, **DemoA-Group1** created in [*Section 3.1: Create Application*](/v1/docs/users-guide-create-update-revoke-third-party-groups-1#31-create-application).

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-k2tve3ia.png)

**Figure 22: Add application to workflow graph**
5. Add a dataset placeholder node to the workflow and assign it to the publisher group, **DemoB-Group2**.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-f01x4bbo.png)

**Figure 23: Add dataset placeholder – DemoB-Group2**
6. When prompted, select **DemoB-Group2** as the publisher group that will populate this dataset placeholder.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-kp82rhu0.png)

**Figure 24: Select publisher group – DemoB-Group2**
7. Repeat *Steps 5 and 6* to add another dataset placeholder node and assign it to the publisher group, **DemoC-Group3**.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-aibjw1kb.png)

**Figure 25: Add dataset – DemoC-Group3**

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/Screenshot (2839).png)

**Figure 26: Select publisher group – DemoC-Group3**
8. Connect the application node to both dataset placeholder nodes to define the workflow data flow.
9. When you connect the application node to a dataset placeholder node, the **SELECT PORTS** dialog box appears. Enter the following:

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-qaog0an7.png)

**Figure 27: Select port**

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-atgu9p8s.png)

**Figure 28: Connect nodes**
  1. From the **Target port** drop down list, select the appropriate port for the connection.
  2. Click **SELECT PORTS** to confirm the connection.
10. Click **SAVE DRAFT** to save the workflow.

Saving the workflow as a draft makes it available to the publisher groups, allowing administrators of the assigned publisher groups to access the draft workflow in their respective accounts and populate the placeholder nodes assigned to them.

### 6.2 Fill the Placeholder Nodes with Actual Data

After the consumer group creates the shared workflow and assigns placeholder nodes, members of the publisher groups populate the placeholder nodes with their own resources.

Each publisher group can update only the placeholder node assigned to its group. Publisher group administrators cannot add, remove, or modify other nodes in the workflow.

Perform the following steps as a publisher group administrator:

1. Log in to the **DemoB** account and click the **Workflows** menu item in the Fortanix CCM left navigation panel.
2. On the **Workflows** page, click the **Draft** menu item. The draft shared workflow created by the consumer group appears in the list.
3. Select the workflow and locate the **placeholder node** assigned to the publisher group **DemoB-Group2**.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-vkv87y0y.png)

**Figure 29: Fill placeholder nodes with data**
4. Click the placeholder node to add the dataset.

In the **DATASET** form, select the dataset created earlier in [*Section 4.1: Create Dataset*](/v1/docs/users-guide-create-update-revoke-third-party-groups-1#41-create-dataset) from the list.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-dgya0ygd.png)

**Figure 30: Select dataset – publisher group 1**
5. Click **SAVE DRAFT** to save the updated shared workflow.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-s7skc1yp.png)

**Figure 31: Save draft – publisher group 1**
6. Log in to the **DemoC** account and repeat *Steps 1 to 5* as an administrator of the publisher group **DemoC-Group3**, and select the dataset created earlier in [*Section 4.1: Create Dataset*](/v1/docs/users-guide-create-update-revoke-third-party-groups-1#41-create-dataset).

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-t59bi5fu.png)

**Figure 32: Save draft – publisher group 2**

After all publisher groups populate their assigned placeholder nodes, the shared workflow is complete and ready for approval.

### 6.3 Request Approval to Create Approved Workflow

After all publisher groups fill their assigned placeholder nodes, the shared workflow is ready for approval.

Each publisher group must review and approve the workflow before the consumer group can complete the approval process.

> [!NOTE]
> NOTE
> 
> The consumer group cannot approve the workflow until all publisher groups approve it. This ensures that each publisher group explicitly consents to the data being shared.

Perform the following steps to request and approve the shared workflow:

1. Log in to the **DemoA** account as a consumer group administrator.
2. In the Fortanix CCM left navigation panel, click the **Workflows** menu item.
3. Click the **Draft** menu item and select the shared workflow for which you want to request approval.
4. Click **REQUEST APPROVAL** to send the approval request to all the publisher groups.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/Screenshot (3293).png)

**Figure 33: Request shared workflow approval – consumer group**

A confirmation dialog appears. Click **REQUEST APPROVAL** to submit the approval request to the publisher groups.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-7x5urp62.png)

**Figure 34: Confirm action**

The workflow moves to the **Pending** state.
5. Go to the **Pending** tab to view workflows awaiting approval.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/Screenshot (3294).png)

**Figure 35: Pending approval – consumer group**
6. Log in to the **DemoB** account as a publisher group administrator. Navigate to the Workflows menu item and click the **Pending** menu item.
7. Select the shared workflow from the list and click **VIEW REQUEST** for the shared workflow.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-33pvkx4n(1).png)

**Figure 36: Request workflow approval – publisher group 1**
8. In the **APPROVAL REQUEST FOR CREATING WORKFLOW** dialog box, click **APPROVE**.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/Screenshot2856).png)

**Figure 37: Approve workflow – publisher group 1**
9. Log in to the **DemoC** account and repeat *Steps 7 and 8* above to approve the workflow as an administrator of the publisher group **DemoC-Group3**.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-hntv9fzp(1).png)

**Figure 38: Approve workflow – publisher group 2**

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-ncntx3mu(1).png)

**Figure 39: Approve the workflow – publisher group 2**
10. After all publisher groups approve the workflow, log in to the **DemoA** account as the consumer group administrator and approve the workflow to complete the approval process.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-hbzor26n(1).png)

**Figure 40: Workflow approval request**

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-2y5ygkfx(1).png)

**Figure 41: Approve workflow – consumer group**
11. In the Fortanix CCM left navigation panel, click the **Tasks** menu item and locate the workflow approval request. click **APPROVE** to finalize the workflow approval.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/Screensho20(2865).png)

**Figure 42: Approve tasks – consumer group**
12. The workflow now appears in the **Approved** tab.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-plvf0j78.png)

**Figure 43: Workflow approved – consumer group**

> [!NOTE]
> NOTE
> 
> After a shared workflow reaches the Approved state, it cannot be modified.
> 
> To make changes, edit the workflow to create a new version using **EDIT WORKFLOW** as described in [*Create, Update, Clone, and Delete Workflows*](/v1/docs/users-guide-create-update-clone-and-delete-workflows-1). After approval, the new version replaces the previous one.

### 6.4 Run the Shared Workflow

Only the consumer group administrator, who owns the workflow, can run a shared workflow. The members of the publisher groups cannot run the workflow.

Use one of the following methods to run the shared workflow:

- To run the workflow using **Run** in the Fortanix CCM user interface for an application, configure the compute cluster and Job Specification in the consumer group. *For more information, refer to* [*Run the Workflow - Web Interface - ACI Applications*](/v1/docs/users-guide-run-the-workflow-web-interface-aci-applications-1)*.*
- *To run the workflow for an AWS Nitro application, refer to* [*Run the Workflow - Web Interface - AWS Nitro Applications*](/v1/docs/workflow-applications-using-fortanix-enclave-os-aws-nitro-1)*.*

After the workflow runs, execution logs are available only to the consumer group. The members of the publisher groups cannot view the workflow execution logs.

## 7.0 Manage Tokens

### 7.1 Revoke Token

A collaboration token can be revoked by a publisher group administrator.

Revoking a collaborating token does not affect existing active collaborations between the publisher group and consumer group that were established using that token. Any existing shared workflows continue to function as expected.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-co3cmzne.png)

**Figure 44: Revoke token**

### 7.2 Revoke Status

Perform the following steps to revoke a collaboration between a consumer group and a publisher group:

1. Navigate to the **COLLABORATION GROUPS** page.
2. Locate the collaboration entry you want to revoke.
3. Click the overflow menu ![Overflow.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/20205446543124.png) for the corresponding row and select **REVOKE** from the drop down menu to revoke the collaboration.

You can revoke the collaboration from either the consumer group or the publisher group.

After you revoke the collaboration, the shared workflow cannot progress, and collaboration between the groups stops.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/fortanix-confidential-computing-manager-collaborating-groups-and-shared-workflow-using-aws-nitro-and-aci-applications-v2.0-image-a5za3sx1.png)

**Figure 45: Revoke collaboration**

## Related

- [Create, Update, Clone, and Delete Workflows](/fortanix-ccm-create-update-clone-and-delete-workflows.md)
