Shazer Ali, Muhammad Ali Hassan, Huzaifa Ahmad, Aashish Jai, Basit Shafiq, Xiaoqian Jiang, Erman Ayday, Jaideep Vaidya
Modern healthcare analytics increasingly relies on complex AI-driven workflows operating over sensitive datasets across institutional boundaries. Ensuring secure, auditable, and policy-compliant execution of these workflows remains a significant challenge. Existing systems typically treat workflow generation, policy enforcement, and execution auditing as separate concerns, resulting in fragmented governance mechanisms. This article proposes a governance-aware workflow lifecycle architecture for AI-driven analytics workflows that integrates natural language workflow synthesis, blockchain-based policy enforcement, and auditable execution, embedding governance directly within the workflow lifecycle. In our framework, large language models translate user requests into executable analytics workflows represented using Business Process Model and Notation (BPMN). Access control policies defined in XACML are compiled into smart contracts that enforce policy compliance and record immutable audit logs on a blockchain. Sensitive datasets remain off-chain while metadata and compliance events are securely recorded. We implement a prototype platform for healthcare analytics demonstrating the generation and execution of survival analysis workflows. We further evaluate the robustness of LLM-generated workflows through an ablation study examining how prompt structure affects BPMN diagram correctness and completeness. Results highlight both the promise and limitations of automated workflow generation in regulated analytics environments. Our work demonstrates the feasibility of integrating governance mechanisms directly into AI workflow infrastructures, providing a foundation for secure and auditable analytics in sensitive domains.