Global variables
Global variables hold values that several workflows share, and the credentials workflows use to reach other systems: endpoints, client IDs, API keys, connection strings. Keeping them out of the workflow definition means you can change a value in one place, and a credential never appears in a workflow export. You needglobal-variables.view to see global variables and global-variables.manage to change them.

Global variables for the example workflows. Client IDs and tenant IDs are plain values; client secrets and the connection string are secret, so their values are never shown.
Secret variables
Select Secret when you create a variable that holds a credential. A secret’s value is stored in the environment’s secret store, not in the ContentFlow database. It is never shown again or included in exports.- You can only choose Secret when you create the variable. To change a plain variable into a secret, delete it and create it again.
- A secret’s key can contain only letters, digits and
-, and cannot be renamed. - To change a secret’s value, type the new value; leaving the field blank keeps the current one.
- Deleting a secret variable also deletes the stored secret.
Use a global variable
ContentFlow global variables, Workflow Engine variables, and Script Engine variables and secrets are separate stores. A value added to one is not available to the others.
Expression tester
The Expression tester runs a C# expression or script against a sample document, so you can work out an expression before you put it into a step. You needplayground.view to open it.

The expression tester running the Read a document property example against its sample document. The result shows that it compiled, ran, returned a string, and left the document unchanged.
workflows.manage or mappers.manage, because the code runs with the environment’s identity. Without either, the tester only checks whether the expression compiles. The same compile check, completion and type information are available in the workflow editor’s expression editor.
Call other systems from a script
A Script step, and any expression, can call another system’s API through thehttp helper. It reuses connections, and it caches OAuth client-credentials tokens across runs, so a large batch does not request a token per document. If the API answers 401, the helper fetches a fresh token and retries once.
This script reads a customer’s segment from a CRM API and stores it on the item for a later step. Every credential and endpoint comes from a global variable:
GetWithClientCredentialsAsync throws an error that fails the step on any other non-success response, while SendWithClientCredentialsAsync leaves the response for your script to inspect. When the call is a single request with a fixed shape, prefer the Http Request step: it is visible on the canvas and needs no code.
System settings
The System page holds settings that apply to the whole environment. You needsystem.view to see them and system.manage to change them.
- Clear cache makes ContentFlow read global variables and system settings afresh. A saved change to a global variable already applies at once, so use this when values were changed outside the application.
- Nobly Insight upload request limit caps how many uploads all workflows together may run against Nobly Insight at the same time, from 1 to 30. Each workflow can have a lower limit of its own on its Settings tab. Agree on changes with the people responsible for Nobly Insight’s capacity.
Where to read next
States and recovery
Follow runs and batches, read what each run did and sent, and rerun failures once the cause is fixed.
