Technical Tip: Workflow Management not available in NGFW policy-mode
Description
This article indicates that the Workflow Management feature is only available in NGFW profile mode. The Workflow feature (used for approving and tracking config changes) is tightly integrated with the policy structure.
Scope
FortiGate.
Solution
Change Summary with Workflow in the GUI is only supported for firewall policies in profile-based VDOMs, not in NGFW (Next-Generation Firewall) policy mode.

This is due to key differences in how each mode handles policy structures:
- Profile-based mode uses traditional IP/port/protocol matching, allowing for straightforward change tracking.
- NGFW mode introduces policies based on applications, users, and devices, which are more dynamic and complex to audit using standard GUI tools.
- The GUI Workflow feature is designed around the more static nature of profile-based policies and doesn't yet fully support the flexible, context-aware structure of NGFW policies.
This limitation is due to backend configuration differences and the current design scope. For NGFW-mode environments requiring detailed change tracking, it is recommended to use FortiManager.
