Which Flow Designer activities can send customer data outside the platform
Verified 2026-09-15 · 39 claims · sources tier 2
Also known as BRE Request, Notify URL, Use Authenticated Endpoint, secure variable.
The Start Media Stream activity streams live caller and agent voice media out of the call 19. WarmTransfer's reading of the sources is that Flow Designer carries at least 15 distinct activities or product features that can move data or media to a destination outside Webex Contact Center, though the article never presents such a list itself 8.
Web requests and API integrations
The HTTP Request activity supports 7 HTTP methods, 4 of which write to the receiving destination, and Cisco documentation describes no mechanism for an administrator to restrict which methods a flow author may use 9. Setting the activity's Use Authenticated Endpoint toggle to off replaces the connector configuration with a free-text Request URL typed directly into the flow, with no allow-list, domain restriction, or approval step described 22. Furthermore, the article contains no statement restricting the address an HTTP Request may target, with terms such as allowlist, firewall, egress, and residency occurring 0 times 11. The response timeout and retry count settings for the HTTP Request activity are each described as accepting any unlimited value 21.
The Business Rules Engine (BRE) Request activity arrives with the caller's phone number already configured as an Automatic Number Identification (ANI) query parameter, requiring a flow author to actively delete it to prevent transmission 4. The BRE Request documentation names no authentication mechanism, connector, or credential field, in contrast to the HTTP Request activity which explicitly documents Basic Auth and OAuth 2.0 options 5.
For identity verification, the Verify OTP activity provides an optional Notify URL field that posts a status payload to any endpoint specified by the flow author, without requiring a connector or credential field 23.
Voice media and recordings
Cisco documents from both ends that caller audio captured via the Record activity can be uploaded to an external third-party server or API using the HTTP Request activity 12. This upload can occur through the Request Body Value File sub-option, and a second file path exists through the HTTP Request activity's Form Data content type 1213. Cisco states that audio recorded by the Record activity is stored in an unencrypted format, advises against recording sensitive information with it, and documents uploading that audio to third-party endpoints 14.
The Start Media Stream activity streams live caller and agent voice media out of the call 19. The Flow Designer documentation states no destination, protocol, authentication, encryption, or payload description for the activity, although the activity appears in Flow Designer's self-loop limit table with a limit of 20 1920.
SIP headers and browser egress
Incoming session initiation protocol headers are ingested into a flow variable in JSON form, holding up to 20 headers and 1000 bytes 10. Outgoing SIP headers configured during transfer activities are capped at 20 headers per INVITE 18. Cisco provides an outbound-data warning naming 5 categories of information not to place in SIP headers, which is scoped to the smallest payload the platform transmits 17.
The Screen Pop activity sends flow variables to a free-text external URL by opening it in the agent's browser, with no connector, credential, or domain restriction described 15.
Egress visibility and logging controls
The documentation for Flow Designer says nothing about transport security for any outbound call, with the terms encryption, transport layer security, in transit, and at rest each occurring 0 times 2. Furthermore, the word audit does not appear in the Flow Designer documentation, describing no audit trail for outbound calls, changes to egress configurations, or use of the decrypt control 3.
Operational visibility into outbound calls per interaction is restricted to the Debug pane, which retains only the most recent 100 interactions for the flow 6. Flow log decryption applies solely to calls initiated after the flow is published, preventing an investigator from enabling decryption to read data that a flow transmitted prior to that point 7. While the documentation states that a secure variable prevents the logging and storing of a value, it never states whether a secure variable may be placed in an outbound payload 16.
Applicability
Across the claims in this article, the evidence covers Cisco Webex Contact Center, verified as of 2026-09-15. The deployment model is not covered by any claim in this article.
What remains uncertain
Whether Flow Designer Functions code can open a network connection is not covered by any claim in this article.
Cisco documentation states that a secure variable prevents logging and storing a value, but whether a secure variable may be placed in an outbound payload is not covered by any claim in this article 16.
What a Control Hub integration connector stores and who may create it is not covered by any claim in this article.
Payload and rate limits for the egress activities are not covered by any claim in this article.
Whether reserved SIP header patterns are stripped from outgoing INVITEs is not covered by any claim in this article.
See also
- The Webex Contact Center Flow Designer activity set
- The Start Media Stream activity and what feeds on it
- What each Webex Contact Center connector type stores
- Author-written functions in Flow Designer
See also
Part of
- The Webex Contact Center Flow Designer activity set — An inventory drawn across the activity set
Related to
- Webex Contact Center data locality by country — Every route is a question about where customer data goes
- What Cisco AI voice features retain of call audio and transcripts — Two routes carry caller audio out of the platform
Referenced by
- Webex Contact Center integration connectors — The credential mechanism for three of the egress routes
- What each Webex Contact Center connector type stores — The credential for each governed egress route
- The Webex Contact Center Flow Designer activity set — Which activities send data outward
- The Flow Designer virtual agent activitiesstub — One of the routes by which caller content leaves the platform
- Author-written functions in Flow Designer — Whether function code can reach a network decides if it is a route
- The Flow Designer failure code vocabularies — The HTTP Request activity has the least error machinery
- The Start Media Stream activity and what feeds on it — Filed as an egress route on silence and the dedicated article names no recipient
Claims
| # | Claim | Status | Confidence | Verified |
|---|---|---|---|---|
| 1 | A flow variable marked for external override can be changed from Control Hub by an administrator or a supervisor and the change applies immediately to calls already in progress. Build and manage flows with Flow Designer · Flow Designer, custom variables and external override | fact | 0.90 | 2026-09-15 |
| 2 | The Flow Designer article says nothing about transport security for any outbound call: encryption transport layer security in transit and at rest each occur 0 times. Build and manage flows with Flow Designer · Flow Designer, counted against the rendered article | fact | 0.90 | 2026-09-15 |
| 3 | The word audit does not appear anywhere in the Flow Designer article, which describes no audit trail for any outbound call, for any change to an egress configuration, or for any use of the decrypt control. Build and manage flows with Flow Designer · Whole document, full-text search of the extracted text | fact | 0.90 | 2026-09-05 |
| 4 | The BRE Request activity arrives with the caller's phone number already configured as a query parameter, so a flow author must actively delete it to stop it being sent. Build and manage flows with Flow Designer · BRE Request step 3, ANI | fact | 0.90 | 2026-09-05 |
| 5 | The BRE Request section names no authentication mechanism, no connector and no credential field, unlike the adjacent HTTP Request section which names Basic Auth and OAuth 2.0. Build and manage flows with Flow Designer · BRE Request, whole section | fact | 0.90 | 2026-09-05 |
| 6 | The only per-interaction visibility into an outbound call is the Debug pane, which holds the most recent 100 interactions for the flow. Build and manage flows with Flow Designer · Debug flows step 4 | fact | 0.90 | 2026-09-05 |
| 7 | Flow decryption applies only to calls initiated after the flow is published, so an investigator cannot enable it and then read what a flow sent before that point. Build and manage flows with Flow Designer · Debug flows > Decrypt flow logs | fact | 0.90 | 2026-09-05 |
| 8 | Flow Designer carries at least 15 distinct activities or product features that can move data or media to a destination outside Webex Contact Center; the article never presents such a list itself. Build and manage flows with Flow Designer · Assembled from Activities in Utilities, Activities in Contact Handling, Activities in Voice, Create and manage functions, Export a flow | inference | 0.60 | 2026-09-05 |
| 9 | The HTTP Request activity supports 7 HTTP methods, 4 of which write to the destination, and the article describes no mechanism for an administrator to restrict which methods a flow author may use. Build and manage flows with Flow Designer · HTTP Request step 3, Method Types | fact | 0.90 | 2026-09-05 |
| 10 | The raw session initiation protocol headers of an incoming call are stored in a flow variable in JSON form with up to 20 headers and 1000 bytes. Build and manage flows with Flow Designer · Flow Designer, predefined variables, the incoming headers variable | fact | 0.90 | 2026-09-15 |
| 11 | No statement restricts the address an HTTP Request may target: allowlist firewall egress and residency each occur 0 times in the article. Build and manage flows with Flow Designer · Flow Designer, counted against the rendered article | fact | 0.90 | 2026-09-15 |
| 12 | Cisco documents, from both ends, that a Record activity's captured caller audio can be uploaded to an external third-party server or API through the HTTP Request activity. Build and manage flows with Flow Designer · HTTP Request step 3, Request Body Value, File sub-option; Record step 8, Output Variables note | fact | 0.90 | 2026-09-05 |
| 13 | A second file path for uploading a Record activity's captured caller audio to an external third-party server exists through the HTTP Request activity's Form Data content type, in addition to the File sub-option. Build and manage flows with Flow Designer · HTTP Request step 3, Request Body Value, File sub-option; Record step 8, Output Variables note | fact | 0.90 | 2026-09-05 |
| 14 | Cisco states that audio recorded by the Record activity is in an unencrypted format and advises against recording sensitive information with it, and documents uploading that audio to a third-party server through the HTTP Request activity. Build and manage flows with Flow Designer · Flow Designer, Record activity and HTTP Request content type File | fact | 0.90 | 2026-09-15 |
| 15 | Screen Pop sends flow variables to a free-text external URL by opening it in the agent's browser, with no connector, no credential and no domain restriction described. Build and manage flows with Flow Designer · Screen Pop step 3, URL Settings and Screen Pop URL | fact | 0.90 | 2026-09-05 |
| 16 | The article states that a secure variable prevents logging and storing of a value and never states whether a secure variable may be placed in an outbound payload. Build and manage flows with Flow Designer · Use variables and expressions > Custom variables > Secure Variables; Create Custom Flow Variables step 10 | fact | 0.90 | 2026-09-05 |
| 17 | Cisco's most explicit outbound-data warning names 5 categories of information not to place in SIP headers, and it is scoped to the smallest payload the platform sends. Build and manage flows with Flow Designer · Blind Transfer step 4; repeated verbatim in Bridged Transfer step 6 | fact | 0.90 | 2026-09-05 |
| 18 | Outgoing SIP headers in Webex Contact Center's Flow Designer are capped at 20 headers per INVITE. Build and manage flows with Flow Designer · Blind Transfer step 4; repeated verbatim in Bridged Transfer step 6 | fact | 0.90 | 2026-09-05 |
| 19 | The Start Media Stream activity streams live caller and agent voice media out of the call, and the article states no destination, protocol, authentication, encryption or payload description for it. Build and manage flows with Flow Designer · Activities in Voice > Start Media Stream, complete section | fact | 0.90 | 2026-09-05 |
| 20 | The Start Media Stream activity appears in Flow Designer's self-loop limit table with a limit of 20, so the platform documents the activity's existence even though the activity's own section omits its destination, protocol, authentication, encryption and payload details. Build and manage flows with Flow Designer · Activities in Voice > Start Media Stream, complete section | fact | 0.90 | 2026-09-05 |
| 21 | The HTTP Request response timeout and retry count are each described as accepting any unlimited value. Build and manage flows with Flow Designer · Flow Designer, HTTP Request activity | fact | 0.90 | 2026-09-15 |
| 22 | Turning off the Use Authenticated Endpoint toggle replaces the connector with a free-text Request URL typed into the flow, and the article names no allow-list, domain restriction or approval step for it. Build and manage flows with Flow Designer · HTTP Request step 3, Use Authenticated Endpoint and Request URL | fact | 0.90 | 2026-09-05 |
| 23 | The Verify OTP activity carries an optional Notify URL that posts a status payload to any endpoint the flow author names, with no connector and no credential field. Build and manage flows with Flow Designer · Verify OTP step 4, Advanced Settings | fact | 0.90 | 2026-09-05 |
| 24 | Cisco's own worked example for Virtual Agent variable passing sends the caller's phone number, with key ANI and value NewContact.ANI. Build and manage flows with Flow Designer · Virtual Agent step 4, Variable Passing, worked example | fact | 0.90 | 2026-09-05 |
| 25 | The JSON that reaches Google Dialogflow is parsed by a fulfilment application that Dialogflow reaches through a webhook configured in Dialogflow, which is a second hop outside Webex Contact Center. Build and manage flows with Flow Designer · Virtual Agent step 4, Variable Passing | fact | 0.90 | 2026-09-05 |
| 26 | Webex Contact Center sends the Virtual Agent key-value parameters to Google Dialogflow as a JSON value in the request.query_param.payload object. Build and manage flows with Flow Designer · Virtual Agent step 4, Variable Passing | fact | 0.90 | 2026-09-05 |
| 27 | Virtual Agent V2 requires a Google CCAI connector and a CCAI configuration created in Control Hub, so the credential relationship with Google is held by the connector rather than by the flow. Build and manage flows with Flow Designer · Configure Virtual Agent V2 activity > Before you begin, second bullet | fact | 0.90 | 2026-09-05 |
| 28 | Cisco warns that the optional Variable Passing parameters on the Virtual Agent activity may contain personally identifiable information, and offers no masking, redaction or opt-out for that field. Build and manage flows with Flow Designer · Virtual Agent step 4, Variable Passing, first sentence | fact | 0.90 | 2026-09-05 |
| 29 | Activity configuration can be copied and pasted across organisations and browsers. Build and manage flows with Flow Designer · Flow Designer, copy and paste activities | fact | 0.90 | 2026-09-15 |
| 30 | A connector governs credentials rather than destinations: the Flow Designer article describes a connector as a common location to store credentials, and the same activity lets a flow author turn off the authenticated-endpoint toggle and type a destination URL directly. Build and manage flows with Flow Designer · HTTP Request, Connector field and Use Authenticated Endpoint toggle | inference | 0.60 | 2026-09-05 |
| 31 | The article never states what fields a connector record holds, in what form, or where the underlying credential values are stored, although it names a Credentials section on the edit page. Set up integration connectors for Webex Contact Center · Edit a Connector; whole article | fact | 0.90 | 2026-09-05 |
| 32 | Cisco describes the Salesforce connector as essentially creating the domain section of the URL for an HTTP Request. Build and manage flows with Flow Designer · HTTP Request, Connector field description | fact | 0.90 | 2026-09-05 |
| 33 | Creating a Webex Contact Center HTTP connector requires ticking a checkbox authorising the connector to read, write, modify and delete data in the Contact Center solution. Create Webex Contact Center HTTP connector · Create Webex Contact Center HTTP connector, authorisation step | fact | 0.90 | 2026-09-05 |
| 34 | The HTTP Request activity publishes no failure code variable no failure branch and no undefined error node and a flow can only test the returned status code by hand. Build and manage flows with Flow Designer · Flow Designer, HTTP Request activity and Configure error handling | fact | 0.90 | 2026-09-15 |
| 35 | Neither the Flow Designer article's self-loop table nor the system limits article's copy lists Function among the throttled activities, so no published ceiling caps how many times a function can be re-entered in one interaction. Build and manage flows with Flow Designer · System-enforced self-loop limits table, all 21 rows; the system limits article's Self-loop limits for Flow Designer activities table | fact | 0.90 | 2026-09-05 |
| 36 | The complete published statement on what code inside a function may use is that common native libraries are available and custom modules are not supported; the native libraries are never enumerated. Build and manage flows with Flow Designer · Create and manage functions, FAQ on library limits | fact | 0.90 | 2026-09-05 |
| 37 | No sentence in the functions documentation or its frequently asked questions uses the words network, internet, outbound, egress, sandbox, isolation, firewall, allow-list or proxy. Build and manage flows with Flow Designer · Create and manage functions and its FAQ subsection, exhaustive keyword search of extracted text and raw body | fact | 0.90 | 2026-09-05 |
| 38 | Cisco states that media streaming facilitates call transcription, summarization, suggested responses and sentiment analysis, and names no recipient of the stream anywhere in the article. Enabling media streaming for specific queues · Opening paragraph; whole article searched for destination, endpoint, webhook, third party, vendor and partner | fact | 0.90 | 2026-09-05 |
| 39 | The Start Media Stream activity exposes 2 configurable fields, Activity Label and Activity Description, and no destination, credential or address field. | fact | 0.90 | 2026-09-05 |
Sources
Build and manage flows with Flow Designer
Create Webex Contact Center HTTP connector
Enabling media streaming for specific queues
Set up integration connectors for Webex Contact Center
Cite this page
APA
WarmTransfer. (2026, September 15). Which Flow Designer activities can send customer data outside the platform. WarmTransfer. https://warmtransfer.net/knowledge/wxcc-flow-data-egress
BibTeX
@misc{warmtransfer-wxcc-flow-data-egress,
title = {Which Flow Designer activities can send customer data outside the platform},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/wxcc-flow-data-egress},
note = {Verified 2026-09-15}
}