BPMN governance for industrial enterprises

From documents to governed BPMN — fast, and auditable.

AI drafts the process from your existing documents. Your people review and approve it. Nothing reaches your teams without sign-off.

On-premise — the application and your process data run inside your perimeter

OpsCodex Studio
OpsCodex Studio — BPMN editor with an AI-drafted process
The editor, with an AI-drafted process open
Six-eyes, enforced
author · reviewer · approver
Append-only audit
write-once at the database level
BPMN XML export
standards-conformant, approval on record

The problem

Process knowledge is scattered. Turning it into trustworthy BPMN is slow.

01

Knowledge is scattered

Process knowledge lives in PDFs, slide decks, screenshots and SOPs — never in one modellable place.

02

Modelling is slow and personal

Hand-modelling each process takes days, and the result depends on who drew it.

03

Notation drifts

Diagrams differ between teams, so they aren’t comparable — or reusable.

04

The approval trail is fuzzy

When an auditor asks who approved this, and when? — nobody can answer with confidence.

It is not the models that fail. It is the process base underneath them.

21

of organisations have a mature governance model for agentic AI. The gaps named most often: decision boundaries, real-time monitoring, and audit trails across the full chain of actions.

Deloitte, April 2026, n = 3,235 ↗

≤ 10

of respondents report scaling AI agents in any individual function — while 88 % report using AI somewhere.

McKinsey, State of AI, Nov 2025 ↗

> 40

of agentic AI projects will be cancelled by the end of 2027, Gartner forecasts — escalating cost, unclear value, inadequate risk controls.

Gartner, June 2025 ↗

How it works

Four steps from raw document to approved, exportable process.

AI does the heavy lifting on the draft. Governance is built into the path — not bolted on after.

01

Ingest

Drop in the documents you already have — PDFs, slides, screenshots, SOPs. OpsCodex reads them in.

02

Draft

The AI proposes a BPMN draft with surgical, editable suggestions. You refine the model directly, with every element editable. Naming templates and shared notation keep every draft consistent across teams.

03

Review & approve

An assigned reviewer and approver sign off — separation of duties is enforced, with an audit log at every step.

six-eyes principle
04

Export

Approved processes export as standards-conformant BPMN XML, with the approval on record.

OpsCodex Studio
Step 02 in motion. A supplier-complaint SOP becomes an editable BPMN draft — the author refines a task, and the Process Advisor auto-fixes one of its findings.

See it on one of your own processes →

Why BPMN

The notation isn’t old. It’s settled.

BPMN 2.0 is maintained by the OMG and published as ISO/IEC 19510:2013 — a standard, not a vendor format. It stopped changing because it works. That stability is what lets your models outlive the tools that drew them. Far from fading, it has become the notation the agent era orchestrates on.

An OMG standard, ratified by ISO

Published by the OMG and standardised as ISO/IEC 19510:2013. The XML OpsCodex exports is readable by any conformant tool — no format lock-in, by design.

What agents run on

UiPath models processes in BPMN 2.0 in Maestro, its agentic orchestration product; Camunda, Flowable and Trisotech orchestrate their AI agents on it too.

Backed where it counts

Since October 2025, Fidelity, NatWest, Deutsche Bank and Capital One jointly back an open-source BPMN orchestration platform under Linux Foundation governance ↗ — regulated industries are betting on the standard, not away from it.

OpsCodex governs those models; execution engines run them. Same notation, different job.

The new risk

Your teams will use AI for process work — with or without control.

Somewhere in your organisation, someone is already pasting an SOP into a public chatbot and asking for a flowchart. The draft looks plausible. It carries no review, no approval, no audit trail — and by next week it’s the version people quietly work from. Ungoverned AI drafts are tomorrow’s audit findings.

Governance

AI proposes. Accountable people decide.

Every process moves through a mandatory Author → Reviewer → Approver split. Roles are assigned, sign-off is explicit, and the record can’t be quietly edited later.

Separation of duties

The author can’t approve their own work. The split is enforced by default, and there is no silent way around it: an exception takes an administrator, a written justification, and its own entry in the log.

Append-only audit

Every state change is written to an append-only log. The application has no path that edits or deletes it — the exact boundary of that guarantee is spelled out on the security page.

One query away

When an auditor asks who approved what and when, the answer is on record — with a timestamp.

Approval chain — assigned, explicit
Authordrafts the model
Reviewerchecks & comments
Approversigns off

The product

The loop, and the record it leaves.

OpsCodex Studio
The six-eyes loop. The reviewer pins a comment and sends the draft back; the author models the fix, resolves the comment and resubmits — the full loop on the record.
OpsCodex Studio
OpsCodex Studio — version history and audit timeline
The history that holds up. Versions, workflow transitions and sign-offs in one timeline — comparable, queryable, on record.

After the export

Modelled, approved — and then forgotten.

Most process initiatives don’t fail in modelling. They fail the day after: the approved diagram lands in a repository, and the shop floor keeps working from a Word file last saved in 2023. Documentation nobody reads protects nobody.

In daily work

From approved model into everyday work.

The approved process isn’t the end of the pipeline — it’s the single source for everything your teams see.

Process Concierge

Ask, don’t search.

Your people ask in plain language: how do I escalate a supplier defect? They get the steps from the approved process. Answers come from governed models only — and each one names the process and revision it came from.

Operating instructions & SOPs

Instructions that can’t drift.

Work instructions and SOPs are generated from the approved BPMN itself. When the process changes and is re-approved, the instructions follow. Diagram and instruction stay in step, because one is generated from the other.

Browser extension

Answers where the work happens.

The concierge lives in a browser extension, right next to your ERP, MES or ticket system. No portal to remember, no second screen — ask while you work.

OpsCodex Sidekick
The concierge at work. The Sidekick panel recognises the ERP tab, opens the governed work instruction, and answers with the exact title from the approved process — typed straight into the form next to it.

Everything your teams see has passed the six-eyes workflow. One source of truth — from model to shop floor.

Security & trust

Built for data that has to stay in-house.

An assistant every employee can ask is only acceptable if it runs inside your perimeter. OpsCodex does — on-premise, not on someone else’s multi-tenant cloud.

On-premise, in your perimeter

OpsCodex runs inside your own environment — not multi-tenant SaaS. Documents and models stay in your tenant; AI inference goes to the provider you configure, or to a private endpoint inside your perimeter.

Role-based access

Granular roles map to the governance workflow. People see and do exactly what their role allows — nothing more.

Append-only audit

Audit events are write-once at the database level. Database triggers reject updates and deletes, and the application role holds no rights to grant itself either.

Human sign-off required

AI output is a proposal. Nothing exports until a human approver has signed — there is no fully-automated path.

You can leave.

A governance product only earns trust if it does not trap you. Every approved process exports as standards-conformant BPMN 2.0 XML that any compliant tool can read. The AI provider is swappable in the admin UI — Anthropic, OpenAI, Google or your own endpoint — so no model vendor is baked in. Deployment is self-hosted and single-tenant, and there is no proprietary storage format in between.

Your process base outlives any vendor, model or engine change — including us.

Read the full security posture →

The moment of truth

The auditor asks: who approved this?

Today

“I think Mr Weber signed that off… back in March?”

“Which SharePoint folder is the current one?”

“The approval mail might be in Christina’s inbox.”

Four folders. Two mail threads. One shrug.

With OpsCodex

One query. Author, reviewer, approver, timestamp, hash.

A Monday, soon

Monday, 8:40. The audit question lands.

8:40 — The auditor asks for the approval chain on your complaints process. You run one query. By 8:41 it’s answered: author, reviewer, approver, timestamp, export hash. The rest of the audit is routine.

14:15 — On the shop floor, someone asks the concierge how to escalate a supplier defect. They get the approved steps — not the 2023 PDF, not a colleague’s best guess.

Same source. Same truth. Every day — not just on audit day.

FAQ

Frequently asked questions.

What is OpsCodex?

OpsCodex is an AI-assisted BPMN governance platform for industrial and regulated enterprises. AI drafts BPMN 2.0 processes from the documents you already have — PDFs, slide decks, SOPs — and named reviewers and approvers sign off before anything reaches your teams. It runs on-premise, inside your own environment.

Is OpsCodex available on-premise?

Yes — on-premise is the primary deployment model. OpsCodex runs inside your perimeter, and your documents and models stay in your tenant. AI inference goes where you configure it: an external provider under your own contract, or a private endpoint inside your perimeter. There is no multi-tenant cloud dependency.

Which BPMN standard does OpsCodex support?

OpsCodex models processes in BPMN 2.0 and exports standards-conformant BPMN XML as specified by the OMG. Approved processes stay portable: the exported XML is readable by any conformant tool, and layout fidelity is worth testing against your own target tools during a pilot.

How is OpsCodex different from BPM suites like Camunda or SAP Signavio?

Classic BPM suites focus on modelling repositories or workflow automation. OpsCodex focuses on the governance gap before and after: AI drafts the model from your existing documents, an enforced author–reviewer–approver split decides what becomes official, and approved processes feed daily work as searchable answers and generated work instructions. It complements execution engines rather than replacing them.

Does the AI approve processes on its own?

No. AI output is always a proposal. Every process passes a mandatory six-eyes workflow — author, reviewer and approver are different people — and nothing is published or exported without a human sign-off, recorded in an append-only audit log.

Who is OpsCodex for?

Process owners, quality managers and operational-excellence teams in industrial and regulated enterprises — organisations that need audit-proof process documentation: who approved what, when, and in which version.

Who is behind OpsCodex?

OpsCodex is developed by Mews Partners, a consultancy advising industrial and regulated enterprises on PLM and process governance. The product grew out of that practice, which is why its governance model mirrors how approvals actually run in industrial organisations rather than imposing a generic workflow. Product ownership sits with Tillmann Schatz, Senior Manager at Mews Partners; demo requests are answered directly by the product owner rather than routed through a sales team.

Is the six-eyes workflow mandatory for every process?

It is the default, and it cannot be bypassed silently — but it is not a straitjacket. Administrators can enable an exception path for cases that genuinely need one. Even then the review still has to be completed on the current version, the administrator must enter a written justification, the exception is recorded as its own decision in the audit trail, and the process carries a distinct “exception approved” status rather than being indistinguishable from a normally approved one. Auditors can therefore list every exception ever granted and read the reason for each.

Isn’t BPMN outdated?

No. BPMN 2.0 stopped changing because it was finished, not because it was abandoned. BPMN 2.0 is maintained by the OMG and published as ISO/IEC 19510:2013, and has stayed deliberately stable, so a model drawn today is still readable by any conformant tool years later. It is also what the current generation of AI orchestration runs on: UiPath models processes in BPMN 2.0 in Maestro, its agentic orchestration product; Camunda and Flowable orchestrate AI agents on it; and in October 2025 Fidelity, NatWest, Deutsche Bank and Capital One launched an open-source BPMN orchestration platform under Linux Foundation governance. A notation that stops changing is what makes a process base portable.

Can other systems and AI assistants read our approved processes?

Yes. That is the point of keeping the approved version in one place. OpsCodex publishes each approved process as a frozen release snapshot, and that snapshot is the single source everything else reads: the employee portal, and a read-only interface for AI assistants over the Model Context Protocol. Process logic therefore lives in a governed layer of its own instead of being locked inside the modelling tool, the same argument data teams make for a semantic layer, applied to processes. Consumers get more than text: every answer carries its governance envelope (revision, approver, release date, review status and a link back to the process), so an assistant can cite rather than claim. Access is read-only by construction: the interface has no write operations at all, and drafts and work-in-progress revisions are not in the published snapshot in the first place, so there is nothing to filter out. It is off by default, opened per token, and every access is logged.

Built for industrial & regulated enterprises

See OpsCodex on your own processes.

Bring one of your own processes — a PDF, a slide deck, a messy SOP. In the demo we run it end-to-end: ingest, AI draft, six-eyes approval, export — and the concierge answering questions on it. You’ll see your process governed, not ours.

Tillmann Schatz
“OpsCodex came out of our consulting work — after watching too many approved processes die in repositories. Bring one of your own! I’ll run it end-to-end and answer the hard questions myself.”

Tillmann Schatz, Senior Manager at Mews Partners — advising industrial enterprises on PLM and process governance · LinkedIn ↗

Request a demo →

[email protected] · answered personally