Your n8n workflows, one click from the answer
Connect the n8n at a client's site and the device chat can suggest one of your own workflows for the machine it is looking at: patch it, restart a service, whatever you built. Nothing runs until a technician presses Run. Wegweiser is granted three permissions in n8n and asks for nothing else, and a workflow is only ever told about the machine the chat is about.
Wegweiser tells you what is wrong with a machine and why. Until today the next step was yours to take somewhere else. If you automate with n8n, the chat can now take you to it: it suggests the workflow that fits, with its reason, and a technician starts it from the answer.
Your server, your workflows
Wegweiser does not act on your clients' machines, and this does not change that. Integrations > n8n connects an n8n you run, per client or per site of a client, and the workflows it can use are the ones you mark as available in MCP in n8n itself. Only published workflows that start from a webhook or a form can be run from here, and only the published version ever runs: nothing from the editor, saved or not.
Connecting sends you to n8n's own consent screen, where the n8n user you sign in as approves three permissions: read workflows, run workflows and read how runs went. n8n enforces those on its side. Wegweiser cannot build, edit, publish or delete a workflow, list your credentials or install anything on your n8n, and it asks for none of that.
The chat suggests, a technician runs
Ask the chat about a machine with pending updates and, when the evidence supports it, the answer carries a card: the workflow, the machine, what it filled in and why. It has not run. Run starts it on your n8n, the card follows it and shows what the workflow returned, and Dismiss says no. A proposal nobody decides expires after an hour, because a card left overnight describes the machine as it was yesterday.
Each workflow can be limited to masters. And a master can let one workflow run without the click, with their name recorded against it. That permission covers the version n8n runs now: when the workflow changes in n8n, it asks for a click again. One switch pauses everything at once.
Only the chat a technician is reading can suggest a workflow. Ticket triage, analyses and cases never can; a case may name the workflow that would fix what it found, and the technician runs it from the chat.
A workflow is told about the right machine
The machine a workflow acts on comes from Wegweiser's own record of the machine the chat is about: its name, hostname, operating system, client, site, and its IDs in your RMMs where you linked them. The chat fills in the workflow's own inputs and nothing else. A chat about one server cannot be talked into sending a workflow to another.
Build workflows for Wegweiser on a webhook trigger and read the machine from
device in the body. Every proposal and run is kept on the n8n page: who
decided, what was sent, and what came back.