7 minutes
h1

Connecting Adobe Workfront and Adobe Experience Manager (AEM) at enterprise scale surfaced roadblocks that out-of-the-box features did not cover. If you administer or are planning a similar Workfront and AEM integration, here are seven launch challenges we solved at Qualcomm, and how we solved each.

This past month at Qualcomm, we advanced our content supply chain by connecting Adobe Workfront and Adobe Experience Manager (AEM). We expected complexity, but several of the hardest roadblocks were ones we could not have anticipated — and here is how we solved them.

We spent several months connecting up to seven systems for this phase of our content supply chain, including our internal email platform, our identity platform, and most critically, Workfront and AEM, so creative teams could move assets between them without manual handoffs. What follows are the seven challenges we hit and the solutions we custom built, all of which we were able to leverage Workfront for. For anyone who is about to start, or is in the middle of, launching a content supply chain at an enterprise, we hope these solutions help you too.

Challenge 1: Custom terms of use for assets

Many of the assets in our brand portal and AEM require a terms of use or talent usage agreement that hundreds of external users must see and accept before downloading anything. AEM does have a built-in terms of use pop-up, but it does not support the level of customization we needed across multiple asset types with different usage conditions.

The solution

We moved the entire terms of use process into Workfront. Because legal already reviews and approves the terms of use for every asset before it goes live, we built that requirement directly into the brand and legal approval workflow. Workfront now generates a task for terms of use creation, upload, and assignment for each asset, using a metadata form that captures exactly what legal needs to draft the right terms.

Once legal drafts and assigns the terms of use, we upload it to an internal system built for managing these documents, then use Adobe Workfront Fusion (Fusion) to connect it to the asset. Fusion surfaces the available terms of use options as a dropdown on the custom metadata form, so the correct terms travel with the asset all the way through to publication on the portal.

Challenge 2: Seamless login for external users

External users, including partners, customers, and media, need access to Workfront because every asset they want to use requires brand and legal review. The problem: not all identity platforms, such as Okta, integrate cleanly with the Workfront and AEM admin console, which meant external users were hitting a second login prompt when moving between the brand portal and Workfront. That friction was a real barrier to adoption.

The solution

We solved this with Okta and a custom step-up form. Using Fusion, we converted the fields from that step-up form into an access request in Workfront tied to a service account, which let our team accept or reject each user access request and place approved users into the right groups. Because Workfront requires an internal company ID or email address, we created proxy emails through Fusion so external users could be onboarded without needing a real internal account. Once approved, a user gets access to their assigned group and the assets they are permitted to use, and to Workfront for creative approval. The flow runs across three systems: AEM, Okta, and Workfront.

TIP
Adobe released Federated Guest Access in May, a feature that lets users move between AEM and Workfront without re-authenticating. We have not tested it yet, but it looks like a promising alternative to the proxy email approach, and Adobe has suggested it may extend to more of their platforms over time.

Challenge 3: Missing zip file thumbnails

Zip files are common in an asset library, especially for logo packages that come in many versions and colors but logically count as a single asset. The problem was that thumbnails for those zip files were not appearing in AEM, which made folders difficult to scan and assets harder to find.

The solution

Working with Adobe, we found a workable setting in AEM: when a zip file is uploaded through Workfront, whatever image appears first inside the zip automatically becomes the thumbnail. It is a manual convention rather than a fully automated fix, but it resolved the immediate problem reliably. In the future, we expect to use Fusion to assign the thumbnail image so that it does not appear in the downloaded folder. AI-assisted thumbnail generation may also replace this workaround eventually.

Challenge 4: Re-reviewing new asset versions

Assets are built in Workfront and then uploaded to AEM. But a version may need to be replaced days after launch, or a year later when brand guidelines change. A new version typically means a new round of brand and legal review, a new terms of use, and sometimes entirely different metadata. The Workfront-to-AEM connectionthrough Fusion does not make version swaps simple by default.

The solution

We made versioning a built-in part of the Workfront brand and legal process itself. When someone needs to upload a new version, a new version folder is created in the same location where the original assets are managed. The asset owner returns to that folder, refills the metadata form through Fusion, and changes a status field to trigger the upload. The asset is identified by its AEM ID on the metadata form, so entering that ID replaces the existing metadata and re-triggers the upload scenario automatically.

This approach prevents outdated files from accumulating in the digital asset management (DAM) system under incorrect names, and it ensures every new version passes through the same legal review as the original. Replacing old versions is also a better archiving strategy than keeping older versions on the brand portal.

Challenge 5: Approval paths for external users

Internally, brand and legal approval ran through Workfront, which routes tasks to the right legal and brand teams based on custom form selections like brand or business unit. Adding external users, particularly original equipment manufacturer (OEM) partners and media, meant creating a parallel path so they could get the same approval for using Qualcomm logos and assets in their own materials.

The solution

Once external users had accounts with proxy email addresses in Workfront from the onboarding process, we built a request queue they could submit into just like internal users, with restricted layout templates so they only saw what was relevant to their role. The brand portal now has a button that takes users directly into that Workfront queue: they click it, submit the request, and can communicate with the legal team directly to check status.

The harder part was privacy. Users from different companies submit into the same queue, but no company should ever see another’s requests or personal data. We solved this with a two-stage setup. Requests land first in a request queue project, then move into a separate holding project where brand and legal approval actually takes place. The original submitter stays on the request as its owner so they can track their own status, but they are never exposed to anyone else’s submissions.

Challenge 6: Owner permission for restricted assets

Not every asset in the brand portal should be available to everyone. Some carry restrictions tied to major partnerships, such as a sports team or an automotive brand, where using the asset requires explicit permission from the asset owner, not just a standard approval from the legal team.

The solution

We flag an asset as restricted in its metadata at upload. On the AEM side, restricted assets display with a watermark. When a user attempts to download one, a form prompts them for their information. A service account, which the requestor does not need to interact with directly, passes that request into Workfront and assigns it to the asset owner. The owner reviews the request, leaves a comment, and approves or rejects it. Once approved, the user receives an email with a link to the unwatermarked version.

This flow touches four systems: Fusion for the connection, AEM for the watermarked asset display, Workfront for the approval, and our internal email system for the notification. It also gives us reporting across every restricted-asset request, including visibility into which companies are asking for access to which assets, data that has already proven useful for partner conversations.

Challenge 7: Section setup for campaign assets

This last challenge is not fully solved yet, and we are honest about that. It sits in our backlog because it was not required for launch, but it is the kind of friction that adds up over time.

Campaign uploads often include many assets across multiple languages. Uploading them from Workfront to AEM works smoothly. What does not work smoothly is what happens on the AEM side when those assets arrive: someone on the AEM team currently has to manually create the correct sections, pages, or header areas to receive them. That manual step is a meaningful bottleneck for large campaigns.

The planned solution

We intend to add fields to the metadata form for campaign assets so that the person uploading can specify which sections need to exist in AEM. Fusion would then create those sections automatically and route the assets into them, instead of leaving that structural work to AEM librarians and publishers. When that piece is built, the upload-to-publication path for campaign toolkits becomes fully automated end to end.

What this means for similar integrations

Across all seven challenges, the pattern was consistent: out-of-the-box features in AEM and Workfront do not always cover every real-world enterprise use case, especially once external users enter the picture and multiple systems need to share state. Getting creative with Fusion, service accounts, and Workfront’s request and approval architecture let us build the customizations we needed without waiting on native platform features to catch up.

If you are planning a comparable integration, the single most valuable thing we can recommend is mapping out where external users will need to cross between systems before you build anything. Building those handoffs intentionally, with auditability and legal compliance designed in from the start rather than added later, is what makes the supply chain reliable at scale.

Frequently asked questions

Do you need custom development to support external users across Workfront and AEM?

In our experience, yes, at least today. Native connectors did not cleanly handle external identity, single sign-on, or cross-company privacy for us. We closed those gaps with Fusion, service accounts, and proxy email addresses, though newer features such as Federated Guest Access may reduce the custom work over time.

Why route terms of use through Workfront instead of using the built-in AEM pop-up?

The AEM pop-up did not support the customization we needed for multiple asset types with different usage conditions. Because legal already approves terms in Workfront, building the requirement into that existing workflow keeps the correct terms attached to each asset through publication.

How do you keep one company’s requests private when several companies share the same queue?

We use a two-stage setup. Requests first land in a request queue project, then move to a separate holding project where approval happens. The original submitter remains the owner so they can track status, but no company can see another company’s submissions.

Should we wait for native platform features before building custom solutions?

We chose not to wait, because these capabilities were required for launch. Where Adobe later ships a native equivalent, such as Federated Guest Access, we plan to evaluate it as a possible replacement for our custom approach.

If you are setting up a comparable integration, these guides cover the native building blocks we extended: