Workflows
Multi-party saga workflows for machine jobs: ordered steps with execute, verify and compensate, per-step escrow, deadlines and an on-chain receipt.
A workflow coordinates a job that spans several parties: a data provider, a GPU operator, a storage provider and the agent paying for it all. Each party does one step. Each step can hold its own payment in escrow, must be verified before it counts, and can be undone if a later step fails. When the workflow finishes, the network records a receipt that every participant can check.
This is the saga pattern: instead of one all-or-nothing transaction, a sequence of steps each with a compensating action.
Example: a fine-tuning job
| Step | Executor | Escrow | Compensation |
|---|---|---|---|
fetch-data | Data provider | Price of the dataset | Refund the buyer |
train | Training provider | GPU rental for the run | Release unused rental |
store-weights | Storage provider | First storage term | Close the deal |
publish | The buying agent | None | Withdraw the listing |
If train fails verification, the workflow compensates fetch-data and nothing further runs. If all four verify, the workflow finalises and emits its receipt.
Step lifecycle
Pending ──execute──▶ Executing ──verify──▶ Verified
│
└──compensate──▶ Compensating ──▶ CompensatedWorkflow lifecycle
Created ──▶ Open ──▶ Executing ──▶ Verifying ──▶ Finalized
│
└──▶ Compensating ──▶ FailedOpen a workflow
tenzro_workflowOpen takes a workflow id, the orchestrator's DID, the participants and an ordered, non-empty list of steps. Each step has an id, an optional executor DID and a compensation description.
{
"jsonrpc": "2.0",
"id": 1,
"method": "tenzro_workflowOpen",
"params": {
"workflow_id": "finetune-2026-10-07",
"orchestrator_did": "did:tenzro:machine:...",
"participants": ["did:tenzro:machine:data...", "did:tenzro:machine:gpu...", "did:tenzro:machine:store..."],
"saga_steps": [
{ "id": "fetch-data", "executor_did": "did:tenzro:machine:data...", "compensation": "refund" },
{ "id": "train", "executor_did": "did:tenzro:machine:gpu...", "compensation": "release-unused-rental" },
{ "id": "store-weights", "executor_did": "did:tenzro:machine:store...", "compensation": "close-deal" }
]
}
}Run the steps
Steps are addressed by position (step_idx, starting at 0).
tenzro_workflowStepExecutemoves a step toExecuting. Passescrow_amountwith apayerandpayeeto lock that step's payment, and anidempotency_keyso a retried call returns the first result instead of executing twice.tenzro_workflowStepVerifymarks the stepVerified, or failed if the verifier rejects it. Verification can carry witness signatures from the parties.tenzro_workflowStepCompensateruns a step's compensation. Withcascade, it compensates earlier steps too.tenzro_workflowSetStepDeadlinebinds a TEE-attested deadline to a pending step. After the deadline, execution is refused and the step must be compensated, so a stalled provider cannot hold the job hostage.tenzro_workflowFinalizecloses the workflow and emits the on-chainWorkflowReceipt.
Write methods are owner methods: each is signed by the orchestrator or the executor it acts for, and a step that locks escrow is signed by the payer.
Signed step payloads
A step's outcome can be delivered as a DID envelope: a payload signed by the executor's DID. tenzro_verifyDidEnvelope checks authorship and integrity, so a verifier knows the result came from the party that claims it.
Reads
| Method | Returns |
|---|---|
tenzro_getWorkflow | The workflow record |
tenzro_getWorkflowSaga | Steps and per-step status |
tenzro_getWorkflowLifecycle | State transitions over time |
tenzro_getWorkflowReceipt | The on-chain receipt |
tenzro_getWorkflowOperationalMetrics | Timing and outcome metrics |
tenzro_listWorkflowReceipts | Recent receipts |
tenzro_listWorkflowsByCreator / ByParticipant / ByStatus | Filtered lists |
All reads are open.
Templates
A workflow shape that recurs can be published as a workflow template (tenzro_registerWorkflowTemplate) and instantiated by anyone (tenzro_instantiateWorkflow). Templates are discoverable alongside skills and tools; see Skills and tools.
Mirroring to DAML
Organisations that keep their books on a Canton synchroniser can mirror a workflow there, so the same steps and receipt appear as DAML contracts for reconciliation. Mirroring is optional and is run by the operator (tenzro_mirrorWorkflowToCanton). See DAML.
CLI
tenzro workflow open --body workflow.json
tenzro workflow step-execute --workflow-id finetune-2026-10-07 --step-index 0
tenzro workflow step-verify --workflow-id finetune-2026-10-07 --step-index 0 --payload '{"dataset_hash":"0x..."}'
tenzro workflow step-compensate --workflow-id finetune-2026-10-07 --step-index 1
tenzro workflow finalize --workflow-id finetune-2026-10-07
tenzro workflow get-receipt --workflow-id finetune-2026-10-07
tenzro workflow list-by-participant --did did:tenzro:machine:...