this 409 is classic. happens because flow is “ghost locked” in backend. docs don’t say it, but /api/v2/flows/actions/unlock returns 404 if you aren’t the one who locked it. very stupid.
The 409 Conflict happens because the flow is locked by another session.
I apologize if this is a beginner question, but does this “ghost lock” create a gap in the audit trail for SOC2? It’s worth a shot to check if the /api/v2/flows/actions/revert mentioned in the earlier reply removes the lock without leaving a record.