BuildFlow: AI Workflow Execution Platform

Version 1.0 · Market: Germany · Date: 2026-08-07 · Methodology: PRISM 2.1.0

MVP: Month 5–6 DSGVO-native German UI first

1. User Personas

Primary — The Overwhelmed Ops Lead
Role: Operations Manager, COO, or Managing Director
Company: 10–100 employees, German service business
Goal: Turn recurring processes into documented, auditable workflows without technical complexity
Pain: Processes running on email threads and ad-hoc Notion setups; no audit trail; DSGVO risk
Non-negotiables: German UI, EU data hosting, DSGVO AVV, flat-team pricing
Secondary — The Delivery Team Lead
Role: Project Manager, Team Lead, or senior IC
Company: Same as primary buyer
Goal: Execute workflow steps efficiently and track team progress
Pain: Unclear responsibilities; repeated mistakes; no visibility into where things stand
Non-negotiables: Simple daily UX; mobile notifications; no configuration overhead

2. MVP Feature Scope (Phase 1 — Months 1–6)

Feature AreaMVP ScopePriorityStatus
Workflow Builder Drag-and-drop step editor; conditional branching; assignee roles; due date rules; step descriptions P0 — Core MVP
Workflow Run Execution Launch run; assign steps; mark complete; track progress; overdue detection P0 — Core MVP
Audit Log Tamper-evident step records (actor, timestamp, content hash); immutable append-only log P0 — Core differentiator MVP
User Auth Email/password + Google OAuth; role-based access (Admin, Member, Guest) P0 MVP
German UI (de-DE) All core screens in German; English UI option; formal Sie address P0 — Market requirement MVP
Templates Library 10 pre-built service-delivery templates (agency, IT, compliance, HR, facility) P0 MVP
Billing (Stripe EU) Subscription management, EUR invoicing, ZUGFeRD/XRechnung on request P0 — Before paid customers MVP
DSGVO Compliance Stack EU/DE hosting (Hetzner Frankfurt), Privacy Policy in German, AVV template, Article 30 records, sub-processor list P0 — Blocking MVP
AI Workflow Suggestions Claude API integration; step suggestions from process description; "KI-Vorschlag" labels (Art. 52 EU AI Act) P1 — After legal opinion Phase 1 (conditional)
Webhook Integration Outbound webhooks on workflow events; Zapier inbound triggers P1 Phase 1

3. Phase 2 Features (Months 7–18)

FeatureDescriptionTimeline
Client-facing audit PDF exportFormatted PDF audit report for client delivery documentationMonth 9
REST API (basic)Read/write workflow runs; outbound webhook events; API key authMonth 10
Email notificationsStep assignments, completions, overdue alerts via emailMonth 8
Microsoft Teams webhookWorkflow step notifications in Teams channelsMonth 10
GoBD-ready audit logHash chain tamper-evidence; 10-year export; GoBD documentation assessmentMonth 14–18
SSO (SAML 2.0)Azure AD and Google Workspace single sign-on for Growth tierMonth 18
n8n integrationTrigger BuildFlow workflows from n8n automationsMonth 14
DATEV integrationConnect workflow records to DATEV accounting exportMonth 18
AI run summaryAI-generated audit digest for completed workflow runs; "KI-generiert" labelMonth 7–8
Advanced analyticsCompletion rates, bottleneck identification, overdue heatmapMonth 22

4. Technical Requirements

Infrastructure

  • Hetzner Cloud, Frankfurt (Germany) — mandatory from Day 1
  • No customer data outside EEA at any time
  • Kamal deployment pipeline on Hetzner
  • PostgreSQL — tamper-evident audit log table
  • Redis — job queue for notifications
  • Target uptime: 99.5% monthly

Security & Compliance

  • DSGVO Art. 25: privacy by design from architecture level
  • DSGVO Art. 32: encryption at rest and in transit (AES-256, TLS 1.3)
  • Audit log: append-only, hash-chained, no delete capability
  • Role-based access control (Admin, Member, Guest)
  • Anthropic Claude SCC + TIA executed before AI features go live
  • Usercentrics CMP for TTDSG-compliant cookie consent

AI Integration

  • Anthropic Claude API (workflow step suggestions, run summaries)
  • All AI output labeled "KI-Vorschlag" per Art. 52 EU AI Act
  • Acceptable use policy prohibits HR/monitoring use cases
  • EU AI Act risk classification: general purpose AI (not high-risk)
  • Formal legal opinion on high-risk classification required before GA

Localisation

  • de-DE primary language for all product UI
  • English UI as secondary option
  • Legal copy (Datenschutzerklärung, AGB) in German by qualified counsel
  • Formal Sie address throughout German product copy
  • ZUGFeRD/XRechnung invoice format available (e-invoicing mandate)

5. Release Phases and Milestones

Phase 1 · M1–6
MVP Launch
  • DSGVO compliance stack
  • Workflow builder + runs
  • Tamper-evident audit log
  • German UI
  • Stripe EU billing
  • 10 templates
  • Design partner beta
Target: 8–15 paying accounts, MRR €2k–€3.7k
Phase 2 · M7–18
GA + Growth
  • AI workflow suggestions
  • Audit PDF export
  • REST API
  • Teams integration
  • GoBD-ready audit log
  • SSO (SAML 2.0)
  • n8n + DATEV integration
Target: 80 accounts M12, 220 accounts M24
Phase 3 · M19–36
Scale + Enterprise
  • Public API v2 (OAuth 2.0)
  • Advanced analytics
  • Multi-workspace
  • Advanced RBAC
  • SCIM provisioning
  • SOC 2 Type II initiation
  • DACH expansion
Target: 450+ accounts, ARR ~€1.3M
Full Founder Pack Product Roadmap Deck