close
dot CMS

Workflows & Approvals

Governance From Draft To Publish

One governance model across every site you run. Control what goes live. Track every change, including work done by an AI assistant.

 

Built for teams where legal, brand, or a regulator signs off before publishing. Certified to ISO 27001, ISO 42001, and SOC 2 Type II.

image

Workflow & Approvals in Action

demo.dotcms.com
Demo preview

Accountable Publishing

Four controls behind accountable publishing

For teams operating under requirements such as HIPAA and GDPR, publishing controls aren't just process improvements. They help restrict who can act, document what happened, and maintain evidence of how content moved from draft to live. 

  • workflow & approval  card 1

    Control who can act

    Use role-based permissions to control who can view, create, edit, and publish across sites, folders, content types, and individual content. Permissions can inherit through the content hierarchy, while SAML can synchronize roles from your identity provider.

    AI-assisted operations through the dotCMS MCP server use permissioned API credentials, extending the same access controls to automated actions. 


  • workflow & approval  card 2

    Trace every decision

    In dotCMS, Workflow history is logged with user, date, and time details, creating a verifiable audit trail. Maintain a clear record of changes, approvals, and publishing activity without manual tracking. 



  • workflow & approval  card 3

    Review before publish. Restore when needed.

    Configure multi-step workflows, Four Eyes approval, or multiple approvers before content advances. Keep authoring and production environments separate with push publishing, and bring back an earlier content version when a change needs to be reversed. 



  • workflow & approval  card 4

    Independently verified

    dotCMS is certified to ISO/IEC 27001:2022 for information security and ISO/IEC 42001:2023 for AI management systems, holds SOC 2 Type II attestation, and is certified under TX-RAMP Level II. Governance here isn’t asserted - it’s independently audited.


Compliance-led publishing

How Workflows Support Regulated Content Operations 

Limit access and demonstrate accountable handling of personal data.

GDPR requires organizations to protect personal data against unauthorized processing and to implement appropriate technical and organizational safeguards. It establishes accountability: organizations must be able to demonstrate how they meet their obligations. Permissions, governed approval processes, and change history can contribute to those controls when content operations involve personal data. 


Review GDPR & privacy controls about Review GDPR & privacy controls

Control access to sensitive content and maintain evidence of activity.

HIPAA's Security Rule requires covered entities and business associates to control access to electronic protected health information, authorize access according to role, maintain audit controls, and protect information from improper alteration or destruction. Role-based permissions, controlled workflow actions, approval steps, and activity history in dotCMS can support those safeguards. 


Explore dotCMS for healthcare about Explore dotCMS for healthcare

AI INSIDE YOUR GUARDRAILS

Put AI to work without bypassing your controls

Connect AI assistants to dotCMS without creating a separate path around your governance. AI-assisted actions through the MCP Server use permissioned credentials and can operate within your existing workflows, so configured review and approval requirements still determine what moves forward. 

Same permissions

Create a dedicated AI user and API token with only the access it needs.

Same workflows

AI can work through predefined workflow actions and approval processes.


Same accountability

Keep AI-assisted content activity visible through your existing governance and logging mechanisms.

Independently certified AI management

 dotCMS holds ISO/IEC 42001:2023 certification covering its AI management practices across customer-facing dotAI capabilities and internal AI tooling.


Explore dotCMS for your organization

image

dotCMS Named a Major Player

In the IDC MarketScape: Worldwide AI-Enabled Headless CMS 2025 Vendor Assessment

image

Explore an interactive tour

See how dotCMS empowers technical and content teams at compliance-led organizations.

image

Built for Compliance. Certified for AI.

dotCMS is ISO 27001 and ISO 42001 certified — The first and only CMS platform with independently verified security and AI governance.