> ## Documentation Index
> Fetch the complete documentation index at: https://docs.insight.nobly.dk/llms.txt
> Use this file to discover all available pages before exploring further.

# Authoring with an AI assistant

> Let an AI assistant read and draft ContentFlow workflows and document mappings, check them against Nobly Insight, and investigate runs, with your own ContentFlow permissions.

ContentFlow can expose an environment to an AI assistant over the **Model Context Protocol (MCP)**, the same open standard as [AI assistant access](/mcp/introduction) to Nobly Insight. An assistant connected to it can:

* read workflows, document mappings, and the Nobly Insight document types they are written against
* draft and validate changes
* try mappings on sample documents and check them against Nobly Insight
* investigate runs and their logs
* run guided tests

This suits work with many similar decisions, such as migrating a legacy import into a ContentFlow workflow and mapping, or explaining why a batch failed.

The assistant connects **as you**. Every request carries your identity and passes the same [ContentFlow permissions](/contentflow/access) as the application. Someone without `workflows.manage` cannot change a workflow through an assistant either.

## Prerequisites

* The ContentFlow MCP endpoint is provisioned per environment. Confirm it is switched on for the environment you want to connect to.
* Your user group holds the ContentFlow permissions for the work you want the assistant to do; see [What the assistant can do](#what-the-assistant-can-do).
* Your computer can reach the environment's ContentFlow API, which is usually only available from your organisation's network.

## What the assistant can do

Each capability needs the same permission as the matching screen:

| Capability | Permission |
| - | - |
| Read workflows, their versions and the step catalogue | `workflows.view` |
| Create, update, validate, publish, restore and delete workflows | `workflows.manage` |
| Read document mappings, classic mappers and shared lookup tables, try mappings on samples, and check them against Nobly Insight | `mappers.view` (and `document-type-rules.view` for the tables) |
| Create, update, publish, restore and delete document mappings | `mappers.manage` |
| List Nobly Insight document types and their keyword configuration | `mappers.view` |
| Read global variable names and plain values (never secret values) | `global-variables.view` |
| Find runs and batches, read a run, its document and its logs | `states.view` |
| Create and run guided tests | `workflows.test` |
| Check that an expression compiles | `playground.view`, `workflows.manage` or `workflows.test` |

A sample through a mapping never runs expression rows, unless you hold `mappers.manage` or `workflows.manage` and the assistant uses the variant that runs them. An assistant cannot rerun failed runs.

## What changes live processing

The assistant works on the same drafts and versions you do, and the same rules apply:

* **Publishing a workflow or a mapping changes what runs**, at once.
* **Writing to a workflow that has never been published is live at once**, because such a workflow runs its draft.
* **A full guided test is a real run** of the draft. It performs the draft's uploads, callbacks and emails.

The ContentFlow server tells assistants to ask you before they publish, restore or delete, before they write to a never-published workflow, and before a full test run. Treat that as a courtesy, not a control. Your permissions are what limit the assistant. Use an account with only the permissions the task needs, and work in a test environment when you let an assistant draft changes.

Everything an assistant writes is a normal ContentFlow change. The editor shows it with the canvas laid out from the steps, and the published versions record who published.

## Connect an assistant

The endpoint is the address of your environment's ContentFlow API followed by `/mcp`. The assistant discovers your identity provider from the endpoint, and you sign in on your usual sign-in page. Assistants that support a static bearer token can use a token from your identity provider instead.

Once connected, ask the assistant to check which permissions it has before you start. It can then tell you which of the capabilities above are open to you.

## Where to read next

<Card title="API clients and service accounts" icon="plug" href="/integrations/api-clients" horizontal>
  Create a dedicated machine identity for a sending system, grant its group access, rotate its secret, and disable an integration.
</Card>

<Card title="AI assistant access" icon="robot" href="/mcp/introduction" horizontal>
  Connect an assistant to Nobly Insight itself, and what every request still has to pass.
</Card>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.