FlowRunner
Pricing
Theme
Start Free

ServiceNow Just Described the Layer We Build. Here Is How It Scores.

ServiceNow's AI Workflow Factory promises one governance model and one audit trail across agents from any vendor. We graded the announcement against the six OaaS Criteria, the same test we graded ourselves on first.

A FlowRunner From the Founder card on a navy field: the statement 4 of 6 vs 3 of 6, the line Same test, two vendors., and two columns of six blocks labeled FlowRunner and ServiceNow showing which of the OaaS Criteria each meets, meets partially, or does not meet.

On October 6, ServiceNow announced AI Workflow Factory. Strip the product names out of the press release and what is left is a description of the layer FlowRunner was built to be. In ServiceNow’s words: build applications and agents with ServiceNow or any tool your teams use, then run them “under one governance model and one audit trail,” with AI Control Tower governing “the workflows, decisions, and agent actions” and Action Fabric extending “that same governed loop to third-party AI agents and tools.”

I have been making one argument for a while. Building an agent is the easy part. Running many of them, from different vendors, against the same systems, with approvals and an audit trail someone can defend, is the hard part, and it is a layer, not a feature. On Monday the largest workflow company in enterprise software said the same thing on its own newsroom.

That is good news for the category. It also raises the obvious question: does their announcement meet the requirements for that layer? A week ago we published six of them, the OaaS Criteria, with a public test for each and a grading rule that applies to everyone: a capability every flow author must rebuild is not a platform capability. We graded FlowRunner first. Four of six, with the two misses named. So this is the second grading, done the same way, from ServiceNow’s own published materials: its press releases and technical articles written by ServiceNow employees on its community site, each named and dated below. It is not a hands-on evaluation, and I say where the documentation runs out.

The two scores side by side

CriterionFlowRunnerServiceNow
1. Agent-invoked human escalationMeetsMeets
2. Durable suspensionMeetsMeets
3. Governed coordination over the mediated surfacePartialPartial
4. Auditability on a self-serve plan with a published priceMeetsDoes not meet, by design
5. Agent-callable compositionMeetsMeets
6. Interrogable escalationPartialPartial

Four of six and three of six, with the same two partials. The reasoning for each ServiceNow cell follows. The FlowRunner cells are explained on the criteria page, and I will not repeat them here.

What this grading is based on

Everything below comes from ServiceNow, in writing, in public:

What it is not based on: hands-on use or a sales conversation. ServiceNow publishes no prices anywhere on its site. Where the documentation does not answer the test, I say so in the cell rather than guessing, and the invitation at the end of this post is real.

1. Agent-invoked human escalation: meets

The test, criterion 1 on the criteria page: can an agent decide at runtime to stop and ask a person, and get the answer back as something it reasons over? Or is there only an approval step placed on the canvas at design time?

ServiceNow’s AI Agents FAQ says that during an interaction “the AI agent may ask the human user for feedback and/or permission to proceed” and “may change its approach depending on the feedback.” In the agent-building walkthrough, a tool set to supervised mode “will ask the user for their input to verify their thought process,” while autonomous mode means “the user only sees output.” An agent can also be given the platform’s Ask for Approval step as a subflow tool, which routes a decision to named approvers and returns the result to the agent.

Two things the documentation does not say: which channel the supervised prompt reaches the person through, and whether “the user” can be someone other than the person already in the conversation. Those matter for the test, and I could not find them. The provision itself is there, at the platform level and not rebuilt per agent, so this is a pass with that note.

2. Durable suspension: meets

The test, criterion 2: can a run wait as long as the business process takes, in days or months, not in the platform’s timeout window?

In ServiceNow’s Flow Designer approvals overview, the Ask for Approval action waits for the approvers, and a due date is optional: you can “pick a due date” and choose whether the approval should “approve, reject, or cancel if the approval is still pending by the date you define.” No due date, no deadline. That is the right default for an approval, and it meets the criterion.

3. Governed coordination over the mediated surface: partial

The test, criterion 3, has two halves. For the actions the platform mediates, are ordering, conflict detection, and escalation provided by the platform rather than reimplemented per agent? And does the vendor state plainly which actions it does not mediate?

The mediated surface is real and it is large. Action Fabric has three parts: an MCP server that lets an outside agent, whether Claude, Copilot, or something homegrown, call ServiceNow actions; an MCP client that lets ServiceNow agents call tools in other systems; and Agent2Agent, which lets a ServiceNow agent hand a subtask to, say, a Workday agent and get the result back. Everything that crosses that surface is inside the governed loop and the audit trail. That is the architecture the criterion asks for.

One thing worth noticing first: the product page describes the scope more carefully than the announcement does. The page says “any AI agent can execute governed ServiceNow actions headlessly through MCP, A2A, and traditional protocols.” Governed ServiceNow actions. The press release says the governed loop “extends to third-party AI agents and tools,” which a reader will take to mean those agents are governed wherever they act. The page’s version is the accurate one.

The second half is where ServiceNow deserves credit the press release does not give itself. The same technical article states two limits plainly: the AI Gateway that enforces policy on MCP traffic “does not currently govern A2A traffic,” which runs on per-agent OAuth or API keys instead, and on the MCP client side, gateway enforcement is “not on by default.” That is exactly the kind of boundary statement criterion 3 rewards, and it sits in the documentation rather than in the announcement, where “one governed loop” has no asterisk.

What I could not find anywhere is the larger boundary. An agent that holds its own credential to Workday and writes directly never touches Action Fabric, and no layer, ServiceNow’s or ours, can govern a write it never sees. A ServiceNow integration partner put it plainly in September: “Everything it does outside ServiceNow is an integration.” Nor does any document I found describe what happens when two mediated actions from different agents conflict on the same record. Partial, on the same reasoning that gives FlowRunner a partial on this criterion.

4. Auditability on a self-serve plan with a published price: does not meet, by design

The test, criterion 4: is the audit trail included on a self-serve plan with a published price, or reserved for the custom-priced top tier?

ServiceNow does not publish a price for anything. The Action Fabric page says it “is available with the ServiceNow AI Platform” and offers a conversation with an expert. Whether AI Control Tower is included with Now Assist or licensed separately is not stated publicly either; on ServiceNow’s own community a customer asked exactly that in January 2026 and got conflicting answers, including a ServiceNow employee saying it is charged separately. I am not grading the audit trail itself, which by every account is comprehensive. The criterion measures reach: at what price does governance start for a buyer who does not have an enterprise contract? For ServiceNow the answer is that such a buyer is not the customer. That is a business model, not a product gap, and it is the reason a company like FlowRunner exists. FlowRunner’s audit trails and role-based access start at $299 a month, on a plan anyone can buy from the pricing page.

5. Agent-callable composition: meets

The test, criterion 5: can existing workflows, actions, and knowledge be exposed to agents as tools with their own inputs and return values, or does composition run only one way, with agents placed as steps inside workflows?

In the agent-building walkthrough, an agent is given flow actions and subflows as tools, calls them with inputs the model fills in, and uses each one’s output in the next step. Through Action Fabric’s MCP server, an outside agent can call ServiceNow capabilities the same way. Existing workflows are callable by agents, with inputs and return values, and agents also run as steps inside workflows. Composition runs in both directions. Meets.

6. Interrogable escalation: partial

The test, criterion 6: when an agent escalates a decision, can the person receiving it question the automation about that decision and get an answer drawn from the run, before deciding?

Inside a Now Assist conversation, the person approving an agent’s plan is in a chat with the agent, so asking “why this one” before saying yes is at least possible, though I found no documentation describing it as a designed capability. For an approval routed to someone outside that conversation, through an approval record delivered by email or Teams, I found nothing that lets the approver interrogate the agent. That is the same shape as everyone else’s partial, FlowRunner’s included, and ServiceNow’s conversational surface arguably puts it closer than most. If anyone at ServiceNow can show me an approver outside the chat asking the agent a question and getting an answer from the run, I will change the cell.

Where ServiceNow is ahead

Three places, stated once.

The system of action is wide. Action Fabric exposes ServiceNow’s workflows, approvals, playbooks, catalogs, audit trails, and configuration database to any agent, and ServiceNow says AI Control Tower discovers AI assets across more than 30 enterprise integrations. FlowRunner reaches 2,100 systems through its integrations, but ServiceNow is the system of record for IT and HR service management in a large share of the companies it sells to, and governing what happens inside your own system of record is a position no outside layer can match. All of it, though, is inside a ServiceNow contract and inside ServiceNow’s loop. For the agents and systems that do not pass through Action Fabric, the advantage does not apply, and that is the boundary the announcement leaves unstated.

The one question the announcement does not answer

What does the governed loop not see?

I ask it of ServiceNow because I have to answer it for FlowRunner. Our connectors and our MCP tools are the surface we govern. An agent with its own credential to a target system, writing directly, is outside it. We say so on the criteria page, and criterion 3 exists to reward vendors who say so. A claim of one governed loop over all third-party agents is only true for the agents that go through the loop. Every buyer evaluating this layer, from any vendor, should ask the question before the contract is signed, and should expect a plain answer.

What this means if you do not have a ServiceNow contract

The category just got confirmed from the top. The requirements do not change with the size of the vendor. If you run agents from more than one vendor against the same records, you need a layer that lets the agent stop and ask a person, holds a run open for as long as the decision takes, writes the audit trail at execution time, and tells you honestly what it cannot see.

ServiceNow will provide that for enterprises that run ServiceNow. FlowRunner provides it for everyone else, starting free, with the governance features at $299 a month, and with its own two misses published next to its four passes.

If ServiceNow, or anyone, thinks a cell above is wrong, the test for each criterion is public. Show me the documentation and I will update the grade. That argument is the point of publishing a test at all.

Frequently asked questions

What did ServiceNow announce on October 6, 2026?

AI Workflow Factory, globally available, which combines Process Mining, Autonomous Engineer, Build Agent, and App Engine into what ServiceNow calls a continuous workflow improvement loop. Its AI Control Tower governs the workflows, decisions, and agent actions in the loop, and through Action Fabric that governance extends to third-party AI agents and tools. Autonomous Engineer is in early access.

How does ServiceNow score on the OaaS Criteria?

Three of six on what it documents today: it meets agent-invoked human escalation, durable suspension, and agent-callable composition. It scores partial on governed coordination, because it does not state what its governed loop does not see, and partial on interrogable escalation. It does not meet the auditability criterion as written, because ServiceNow is not sold on a self-serve plan with a published price. That last one is structural, not a gap in the product.

How does FlowRunner score on the same criteria?

Four of six. FlowRunner meets agent-invoked escalation, durable suspension, auditability on a self-serve plan, and agent-callable composition. It scores partial on governed coordination, because ordering and conflict handling across mediated writes is built per flow today, and partial on interrogable escalation, which is on the roadmap as a platform capability.

Is this a FlowRunner versus ServiceNow comparison?

No. ServiceNow sells to enterprises that run ServiceNow. FlowRunner sells to operations teams and builders in mid-sized companies that need the same layer without an enterprise contract, starting free and with audit trails and role-based access at $299 a month. The point of grading both is that the requirements are the same whoever the vendor is.

Editorial policy

See how this would work on your stack

A 30-minute walkthrough against your actual setup, or a quick message to scope the fit. No slides, no signup.