Hexagon Infosoft
Workflow Automation & Enterprise SaaS · Case Study

HexaFlow: Engineering a Low-Code Visual Workflow Automation & Multi-Tenant SaaS Engine

A modern, multi-tenant workflow automation platform designed to let engineering, operations, and business teams build, execute, and monitor visual DAG workflows with zero code bottlenecks and transparent execution tracing.

HexaFlow combines an intuitive React Flow canvas with a modular FastAPI backend, multi-tenant workspace isolation, flexible execution triggers (webhooks, cron schedules, Redis worker queues, REST API, and TypeScript SDK), an AES-256 encrypted credential vault, and an integrated AI Studio.

Industry
Enterprise Automation & Low-Code SaaS
Technology
Next.js 15 · FastAPI · React Flow · PostgreSQL · Redis
Platform
Web Visual Canvas · Developer Console · TypeScript SDK
Solution Type
Visual DAG Workflow Engine & Multi-Tenant SaaS
The goal

Business Objective

Hexagon Infosoft architected HexaFlow to resolve the core vulnerabilities of legacy automation platforms: escalating per-task fees, opaque execution black boxes, and multi-tenant data contamination risks.

  • 1Empower technical and non-technical teams to construct complex event-driven automations visually in under 10 minutes without writing code
  • 2Guarantee absolute multi-tenant data isolation across organizations, workspaces, and execution sandboxes at the database query layer
  • 3Provide deterministic DAG execution tracing where every node's input, output, duration, and error payload is transparently explainable
  • 4Protect sensitive enterprise infrastructure with zero-trust credential encryption at rest and SSRF guards on outgoing HTTP nodes
  • 5Deliver an extensible developer platform featuring API keys, OAuth 2.0 app authorization, a TypeScript SDK, and an installable plugin marketplace
Key challenges

Key Challenges

Building a high-scale visual workflow automation engine required overcoming critical challenges spanning graph theory, distributed state isolation, network security, and queue concurrency.

Deterministic DAG Execution & Cycle Prevention

Visual builders allow users to create arbitrary connections. The engine needed to validate directed acyclic graphs in real time, block circular dependencies, execute independent branches concurrently, and persist atomic step-by-step state without race conditions.

Strict Multi-Tenant Query Scoping & Secret Isolation

In a shared SaaS architecture, accidental data leaks between organizations are catastrophic. Every repository call, webhook receiver, background queue task, and scheduled cron job required rigorous enforcement of organization and workspace boundaries.

SSRF-Safe HTTP Egress & Ingress Webhook Verification

Allowing workflows to perform arbitrary HTTP requests introduces Server-Side Request Forgery (SSRF) attack vectors against internal infrastructure. The engine needed kernel-level IP filtering to block access to private subnets while validating cryptographic signatures on inbound webhooks.

Asynchronous Queue Throughput & Retry Pacing

Workflows triggered by high-volume webhook bursts or concurrent cron schedules risked overwhelming backend workers and database connections. The platform needed a distributed Redis job queue with exponential backoff retries and graceful error isolation.

Our solution

Our Solution

We engineered HexaFlow following Clean Architecture and Domain-Driven Design (DDD) principles. The visual presentation layer is cleanly separated from a high-performance FastAPI execution runner, an asynchronous Redis worker queue, and an encrypted persistence layer.

Core Solution Highlights

  • Visual drag-and-drop workflow canvas built with React Flow, supporting 40+ node types, real-time edge validation, and zero-data-loss autosave
  • Deterministic DAG execution engine supporting manual triggers, signed webhooks, cron schedules with timezone awareness, and Redis job queues
  • Zero-trust credential vault leveraging Fernet AES-256 symmetric encryption at rest to securely inject API keys and bearer tokens into workflow steps
  • Integrated AI Studio shell featuring prompt completion, multi-turn chat, RAG embeddings, and classification nodes powered by LLM providers
  • Developer-first ecosystem including OAuth 2.0 app management, scoped API keys, OpenAPI documentation, and an official TypeScript SDK (@hexaflow/sdk)
  • Enterprise governance suite including OIDC single sign-on (SSO), immutable workspace audit logs, and workflow version snapshots with instant rollback
Platform architecture

Platform Architecture & Technology

A modular, decoupled architecture where presentation, workflow orchestration, asynchronous queueing, and secure data persistence operate with strict boundary enforcement.

Next.js 15 & React Flow Client Apps

Presentation & Visual Canvas

  • Next.js 15 App Router with responsive Tailwind CSS and sleek dark glassmorphism
  • Interactive React Flow canvas with custom node renderers, minimap, and snap-to-grid
  • Client-side Zustand state management handling autosave and optimistic UI updates
  • Comprehensive developer console for API keys, webhook endpoints, and OAuth apps
  • Dedicated analytics dashboard featuring success rates, runtime charts, and health telemetry

FastAPI REST Services & DAG Runner

Core Engine & API Gateway

  • FastAPI backend structured into domain-driven modules (auth, workflows, executions, etc.)
  • Topological DAG execution engine resolving node dependencies and branch conditions
  • SSRF guard middleware blocking outgoing HTTP calls to private RFC 1918 IP addresses
  • Pydantic v2 schemas enforcing strict request/response DTO contracts on all endpoints
  • Official TypeScript SDK (@hexaflow/sdk) enabling programmatic workflow invocation

PostgreSQL 16, Redis & Encryption

Data, Queue & Security Vault

  • PostgreSQL 16 relational database with tenant-scoped indexing and Alembic migrations
  • Redis 7 backing distributed job queues, delayed retry schedules, and execution caches
  • Fernet AES-256 encryption at rest protecting workspace credentials and third-party tokens
  • StorageProvider abstraction supporting local filesystem uploads, AWS S3, and Cloudflare R2
  • Containerized Docker Compose scaffolding with automated health checks and migrations
01

Trigger & Ingress Layer

Inbound Webhooks
Cron Scheduler
REST API & TS SDK
Manual UI Trigger
02

Tenant Gateway & Security

JWT / OIDC SSO
Tenant Scoping Guard
Rate Limiting & CORS
03

Execution & Queue Engine

DAG Runner Engine
Redis Job Queue Worker
Step State Machine
04

Node Executors & AI Studio

SSRF-Safe HTTP Node
AI Studio (LLM / RAG)
Condition & Logic Nodes
Integrations & Plugins
05

Storage & Secrets Vault

PostgreSQL 16
Fernet Secrets Vault
S3 / R2 Object Store
Technology stack

Technology Stack

Engineered with cutting-edge open standards, modern Python asynchronous frameworks, and production-proven distributed infrastructure.

Frontend & Canvas

User Interface & Graph Rendering

  • Next.js 15 (App Router)
  • React 19 & TypeScript
  • React Flow (@xyflow/react)
  • Tailwind CSS & Lucide Icons
  • Zustand State Store

Backend & Engine

High-Performance Asynchronous APIs

  • Python 3.11+ & FastAPI
  • Pydantic v2 (Strict DTOs)
  • Topological DAG Runner
  • Clean Architecture & DDD
  • Alembic Database Migrations

Persistence & Queue

Relational Storage & Task Broker

  • PostgreSQL 16 (Tenant-Scoped)
  • SQLAlchemy 2.0 ORM
  • Redis 7 (Job Queue & Cache)
  • StorageProvider (S3 / R2 / Local)
  • Docker Compose Scaffolding

Security & Encryption

Enterprise Zero-Trust Protection

  • Fernet AES-256 Symmetric Encryption
  • SSRF IP Filtering Middleware
  • JWT (Access & Refresh Tokens)
  • OIDC SSO Provider Support
  • Immutable Audit Event Logs

AI Studio & Integrations

Intelligent Workflows & Connectors

  • OpenAI & Claude LLM Connectors
  • Embeddings & Vector Processing
  • PostgreSQL & Raw SQL Nodes
  • Slack & Email Webhook Nodes
  • Plugin Marketplace Registry

SDK, Testing & CI/CD

Quality Assurance & Developer Tools

  • @hexaflow/sdk (TypeScript)
  • pytest (164 Backend Tests)
  • Playwright E2E Smoke Tests
  • OpenAPI v3.1 Specification
  • Health Check Endpoints (/health)
Core features

Core Platform Features

Comprehensive capabilities designed to take enterprise automations from initial prototype to enterprise-grade production reliability.

Interactive React Flow Canvas

Design complex automations on an infinite canvas with 40+ modular nodes, visual edge connection handles, minimap navigation, snap-to-grid alignment, and continuous background autosave.

Deterministic DAG Execution Engine

Execute workflows with mathematical certainty. Topological dependency sorting runs parallel branches concurrently, catches circular deadlocks before runtime, and captures step-by-step I/O snapshots.

Encrypted Credential Vault

Store API keys, OAuth tokens, and database passwords in a workspace-isolated vault encrypted at rest with Fernet AES-256. Values are injected into node executions securely without exposing raw secrets to client apps.

Enterprise AI Studio Suite

Incorporate generative AI directly into workflows with native nodes for prompt engineering, chat completions, document embeddings, semantic summarization, and intent classification.

Extensible Plugin Marketplace

Browse, install, and configure workspace plugins on demand, including built-in connectors for Discord, Microsoft Teams, Field Mapper Pro, and cryptographic HMAC Request Signers.

Distributed Scheduler & Redis Queue

Trigger automations via timezone-aware cron expressions or ingest bursty webhook events into a resilient Redis worker queue with configurable retry policies and exponential backoff.

Multi-Tenant RBAC & OIDC SSO

Manage multi-organization hierarchies with granular workspace roles (Owner, Admin, Member), enterprise single sign-on (SSO) via OpenID Connect, and comprehensive audit trail logging.

Real-Time Observability & Analytics

Track platform health with an automated system monitor inspecting API, Database, Storage, Scheduler, and Queue health every 30 seconds, paired with 7-day and 30-day workflow performance analytics.

HexaFlow Visual Workflow Builder Canvas with connected nodes, execution status badges, and dark glassmorphic UI

Interactive Workflow Studio

Visual DAG Canvas with Real-Time Autosave & Execution Testing

The centerpiece of HexaFlow: an infinite React Flow workspace where teams drag, connect, configure, and test nodes with immediate visual feedback.

  • Interactive node palette featuring triggers, actions, branching logic, AI nodes, and integrations
  • Visual edge connections with animated flow vectors and connection validity enforcement
  • In-canvas manual test execution highlighting active node progress with real-time success/error pills
  • Workflow versioning panel capturing published snapshots with one-click restore capabilities
  • Node configuration flyout with contextual variable picker and output schema previews

Operations & Audit

Granular Step-by-Step Execution Inspector & Event Stream

Eliminates automation black boxes by logging every individual node's input payload, processed output, execution duration, and structured error traces.

Platform Capabilities

  • Comprehensive execution history table filterable by status, trigger type, and date range
  • Interactive DAG execution playback showing exactly which conditional paths were evaluated
  • Raw JSON inspector for inspecting HTTP payloads, webhook headers, and intermediate variables
  • One-click execution replay allowing engineers to re-run failed workflows with identical inputs
  • Exportable audit logs documenting user edits, credential access, and publish events

Intelligence & Integrations

Integrated AI Studio & Modular Plugin Marketplace

Bridges modern machine learning with existing enterprise databases and third-party SaaS services in a cohesive operational environment.

Platform Capabilities

  • Dedicated AI Studio workspace for testing model prompts and prompt templates before production use
  • Zero-code OpenAI credential management with automated token usage tracking
  • Plugin marketplace allowing workspace administrators to install new node types with one click
  • Database connector nodes supporting PostgreSQL queries with tenant schema constraints
  • Real-time system health dashboard monitoring backend API, Redis queues, and database latency
Roles & access

Role-Based Access Control (RBAC)

Granular role hierarchies ensure that developers, operations teams, and compliance officers have precisely scoped access across organizations and workspaces.

Organization Owner

Full administrative ownership across all workspaces, billing subscriptions (Stripe & Razorpay), OIDC SSO configurations, and organization-wide member management.

Workspace Administrator

Manages workspace membership, encrypted credential vaults, marketplace plugin installations, and environment-level developer API keys.

Workflow Builder / Developer

Designs visual workflows, configures triggers and node parameters, publishes versions, tests execution paths, and manages webhook endpoints.

Compliance & Audit Viewer

Read-only access to execution event streams, workflow version histories, system health metrics, and tamper-resistant organization audit logs.

Design approach

Engineering & Architecture Philosophy

HexaFlow was built from the ground up prioritizing clarity, structural maintainability, and zero-compromise security.

  • Clarity Beats Complexity: If a workflow feature requires a lengthy manual to operate, we simplify the UX first before shipping.
  • Every Execution is Explainable: No mysterious drop-offs. Every node run records inputs, outputs, timestamps, and error stacks.
  • Multi-Tenant from Day One: Organizations and workspaces are core architectural primitives, not retrofitted afterthoughts.
  • Contract-First Workflows: The Workflow JSON schema is a versioned public contract, making visual graphs fully exportable and portable.
  • SSRF Defense-in-Depth: Outgoing HTTP nodes strictly block private IPv4/IPv6 address ranges to prevent internal infrastructure reconnaissance.
  • Continuous Quality Assurance: 164 backend unit and integration tests combined with Playwright E2E smoke tests ensure zero regressions.
Results & impact

Measurable Results & Engineering Impact

Empirical metrics demonstrating platform performance, operational efficiency, and architectural robustness.

< 10 Min

Time to First Deployed Workflow

New users register an organization, configure a webhook trigger, add conditional logic, and publish their first live automation in under ten minutes.

100%

Tenant Isolation Compliance

Zero data bleed verified across organizations and workspaces in automated security scans and multi-tenant integration test suites.

164+

Backend Automated Tests Passing

Comprehensive pytest coverage across services, repositories, validators, node executors, and cryptographic credential vaults.

< 150ms

p95 Core API & Execution Overhead

FastAPI asynchronous non-blocking request handling delivers sub-150ms latency for workflow orchestration and trigger ingest.

40+

Production Nodes & Integrations

Comprehensive catalog spanning triggers, branching logic, data mappers, AI studio nodes, relational databases, and communication channels.

FAQ

Frequently asked questions

Unlike consumer-oriented tools that obscure execution errors, HexaFlow prioritizes explainable executions with step-by-step I/O tracing. It features multi-tenancy from day one (organizations, workspaces, and RBAC), a developer-first TypeScript SDK, an integrated AI Studio, and a built-in encrypted credential vault without per-task cost penalties.

Looking to build a custom workflow automation or visual DAG engine?

Hexagon Infosoft specializes in engineering high-throughput automation backbones, low-code visual builders, and multi-tenant enterprise SaaS platforms tailored to your business.