Two queue settings people miss: the confirmed status has to be explicitly enabled on the queue, or your confirm-step automation will wait forever on annotations that can never reach that state. And while an annotation is in_workflow you cannot modify its content - back off and let the workflow finish instead of fighting it. Treat exported, not confirmed, as your done signal for downstream pipelines.

Context: Rossum official Annotation Lifecycle guide: the confirmed and rejected statuses must be explicitly enabled on the queue or they never appear. While an annotation is in_workflow, its content cannot be modified, and manual interaction with it can conflict with automated workflows. exported is the typical terminal state after all hooks pass.