Notes Sep 21, 2026 2 min read

Why four automation vendors are not one operating model

typescriptnestjspostgresqlautomation

RepositoryArchitectureRun locallyThreat model

Context

A team can run n8n, Zapier, Make, and Power Platform and still not know who owns an automation, which artifact is actually running, or whether two alerts are the same incident. Each vendor dashboard answers some of that for its own product. None of them is a portable record across all four, and none of them should be asked to pretend the others expose the same management API.

Cross-Platform Automation Control Plane is the lab where that boundary stays inspectable.

Decision

Next.js is the only operator surface. The NestJS API revalidates the OIDC access token and enforces role checks; hiding a button is not authorization. PostgreSQL owns the catalog, releases, incidents, and audit. A worker drains a transactional outbox. Each platform package keeps its native artifact in Git — an n8n workflow, a Zapier integration, a Make blueprint, a Power Platform solution — and emits HMAC-signed telemetry that is metadata only: no provider credentials and no business payloads.

A high-risk release needs an approver who is not the proposer. Local checks can prove the artifact, the schema, and the synthetic fixtures. They cannot prove that Zapier, Make, or Power Platform executed it in a hosted account. That proof stays outside the repository.

What I rejected

Wrapping four products in one imaginary management API, and copying execution payloads or connection secrets into the control plane so a single screen can “show everything.” Both claims are false, and the second turns observability into an exfiltration path. I also rejected letting the proposer approve their own gated release.

Failure scenario

A telemetry event is replayed, or the same subject tries to approve the release they proposed. The event id is unique, so the aggregate does not double-count. The independent-approver policy rejects self-approval. If the local n8n runtime is down, the catalog and prior evidence remain in PostgreSQL. A blueprint that passes static checks is not recorded as a successful hosted run.

Evidence

pnpm app:start brings up the web app, API, worker, PostgreSQL, Keycloak, n8n, and the synthetic operations API. Architecture states what each platform can honestly prove. The threat model maps telemetry spoofing, self-approval, and payload leakage to controls. Kubernetes and Terraform definitions are reviewable packaging, not a live deployment. Synthetic data only; not a customer process and not a certification.

Inspect: Repository · Architecture · Run locally · Threat model