Intelligence Approval Workflows: Ensure Data Quality and Streamline Processes

Organizations collect intelligence from many different sources, but not all data arrives in a consistent format or through automated feeds. Manual submissions, file imports, and form-based contributions often require review before becoming part of a trusted intelligence repository. Previously, draft content in OpenCTI could typically move between two simple states: Open or Validated. While effective for basic use cases, organizations often need greater visibility into the review status of a draft and who’s responsible for the next action. This is precisely the gap that we’re addressing with our new draft intelligence workflows.
TL;DR
- Configurable multi-step approval workflows: OpenCTI now lets organizations build custom review chains for draft intelligence with fine-grained RBAC, keeping quality control and governance transparent and easy to set up.
- Workflows can be applied to any draft intelligence: Unstructured, human-sourced intelligence (analyst notes, tips, customer reports) via manual creation, file import, form intake, or the browser extension.
- Granular RBAC at status and transition level: Control who can view, edit, manage, or advance a draft, including dynamic roles and cross-organization sharing, for full accountability at every stage.
- Built for scale and governance: ISACs, MSSPs, large enterprises, government bodies, and teams handling external intelligence all benefit from consistent, auditable review before data is published.
Organizations can now configure multi-step approval workflows with fine grained role-based user access (RBAC) to ensure quality control and data governance, while keeping the process transparent and easy to implement. Whether it’s an ISAC collecting member-submitted observations, an MSSP fielding incident reports from customers, or internal teams contributing their own intelligence, draft workflows ensure ingestion processes are consistent and scalable.
Watch the video for an introduction to draft approval workflows in OpenCTI:
Manual vs Automated Intelligence
Automated and manual threat intelligence serve very different purposes, and organizations need both. Whereas automated feeds are built for scale, continuously ingesting structured, pre-vetted data like indicators and reports from trusted sources, manual intelligence is built for context, capturing what only a person can observe. For instance an analyst’s investigation notes, a partner’s tip-off, or a customer’s description of an incident, arriving unstructured and unvetted. That difference is exactly why manual submissions can’t simply flow into the same pipeline as automated feeds: they require a review step that automated sources have often already earned.
Submitting Manual Intelligence in OpenCTI
In OpenCTI manual submissions are saved in ‘Draft’ mode, so they can first be reviewed before entering the knowledge base. There are a few ways manual intelligence can be submitted in OpenCTI:
- Manual draft creation: Analysts can create a draft directly in OpenCTI and populate it from scratch, building out entities and relationships within the isolated workspace before review.
- File import: When importing a file, users can select draft validation mode so the system automatically generates a draft and routes the extracted results into it for review, instead of writing directly to the main knowledge base.

File import options in OpenCTI
- Form intake: Contributors can submit structured input via form toggles on entity list pages (Reports, Incidents, Threat Actors, Indicators, and more), the ‘Import using a Form’ option in the standard import dialog, or a shared form link distributed to external or non-expert contributors (e.g., ISAC members, MSSP customers) who need to submit incidents or observations without direct platform access.

Example of an OpenCTI intake form
- XTM browser extension: With the Filigran browser plugin, analysts can capture intelligence while browsing, flagging web pages, articles, or indicators encountered in the field, and send them straight into a draft for review, streamlining collection at the source without leaving the browser.

The XTM Browser Extension allows you to ingest data directly from your web browser
Flexible Workflows to Meet Any Organization’s Needs
Every organization has its own intelligence processes. Some may require only a few straightforward review steps, while others need detailed approval chains involving analysts, managers, and specialized teams. The new Draft Workflows can easily be adapted to your organization’s needs. Administrators can create custom statuses, connect them through transitions, and define how drafts move from one stage to the next. Workflows can be kept simple, or expanded to support complex operational processes.

Example of a Draft Workflow in OpenCTI
With intelligence approval workflows, organizations can:
- Define custom review and approval stages
- Control which users or roles can move a draft forward
- Restrict editing rights at specific stages
- Maintain visibility into the status of intelligence submissions
- Ensure only properly reviewed intelligence enters the platform

Workflows can include as many steps as needed
Applying Role-Based Access Control to Workflows
For organizations that require additional governance, workflows can incorporate role-based controls that determine who can perform specific actions or approvals. This provides a structured way to manage collaboration while preserving accountability throughout the review process.
RBAC within a workflow can be controlled at two different levels:
- 1/ Status: This setting controls who can view, edit or manage the draft content. Access control can be applied when the user enters or exits the draft.

Configuring status rights for Drafts
- 2/ Transition: This setting controls which user(s) can transition to the next step:
- Who can trigger the transition (who can move the draft to the next status, regardless of editing rights on the draft).
- Who can view, edit or manage the draft content.
- Provide other organizations access to the draft content in the context of cross organization work.

Configuring transition rights for a step in the workflow
Built-in validation checks help ensure workflows remain coherent before publication, providing administrators with guidance during configuration.
Playbooks can also be configured to run automatically when the new intelligence has completed the approval process.
Key Use Cases
Organizations that manage high volumes of intelligence submissions or operate in highly regulated environments can particularly benefit from intelligence approval workflows, including:
- Information Sharing and Analysis Centers (ISACs): Information-sharing communities that need controlled submission and approval processes. With members submitting intelligence from varied sources and skill levels, a formal review step ensures only vetted, actionable data reaches the wider community.
- Managed security service providers (MSSPs): Coordinating intelligence between teams and customers. Approval workflows give MSSPs a consistent way to validate findings before they’re passed to clients, protecting both accuracy and client trust.
- Large enterprises: With multiple teams and review layers. Draft workflows let intelligence move through the right chain of stakeholders, from analysts to leadership, without bottlenecking day-to-day operations.
- Government and public-sector organizations: These environments often require auditable, multi-stage sign-off before intelligence can inform decisions, especially when countering foreign information manipulation and interference (FIMI) campaigns.
- Teams collecting intelligence from external sources: External submissions can vary widely in reliability, so a review layer helps confirm credibility and context before intelligence is acted upon or shared further.
Community Versus Enterprise Edition
Basic workflow management is included in the Community Edition, including the ability to define multiple steps in the approval workflow and perform the review process without having to leave the platform. The following advanced features are included in the Enterprise Edition:
- Enforce RBAC at each step: Define who can view, edit, or manage a draft at every stage. Authorized members can be specific users, groups, or organizations, or dynamic roles like “the draft creator” or “the draft’s author organization,” ensuring only the right people can act on it at each point.
- Control who can advance each step: Independent of edit rights, you can specify exactly which user, group, or organization can push a draft to its next step. For example, you can specify that only managers can move the draft forward.
- Enable cross-organization collaboration: When platform segregation applies, drafts can be shared with other organizations before specific edit rights are assigned. You can pre-define which organizations automatically receive the draft at a given step, or leave it open so the user chooses who to share with when that step is reached.
Conclusion
At its core, Draft Approval Workflows help organizations improve the quality of their intelligence. By introducing structured review gates before intelligence is published, teams can validate submissions, verify context, and ensure data meets internal standards before it enters the platform. The result: higher-quality intelligence, stronger governance, and a more consistent process for collecting, reviewing, and approving data before it enters your platform.
Would you like to see Draft Approval Workflows in action? Book a demo with one of our threat intelligence experts, or start a free 30-day trial of OpenCTI Enterprise Edition.
Read more
Explore related topics and insights
Your SOC Doesn’t Have a Data Problem. It Has a Coordination Problem.

Four Ways OpenCTI Turns Data into Strategic Threat Intelligence
