Skip to main content
This page covers the AI controls you operate inside Go Fig. For how Celeste handles your data, which providers receive what, PII redaction, tenant isolation, and what each plan includes, see the Security Hub. The binding version of those commitments is our Data Processing Agreement.

Read the AI interaction audit log

Every Celeste interaction is logged stage by stage. You read the log where the interaction happened: in Celeste chat, under any AI response, click Show work. Each step shows:
  • What Celeste did: the stage, such as finding the relevant tables, generating the query, or preparing the response
  • What data it reached: the tables accessed
  • What it generated: the SQL, where that stage produced any
  • Timing and confidence: how long the stage took, and how confident Celeste was
An organization admin can open any trail in their own organization. Everyone else sees only their own. Nobody can read across organizations. Admin means the Admin role specifically, not any member who happens to hold elevated data permissions.

Review AI activity across your organization

Organization admins get a second, organization-wide view: the AI activity page in organization settings. For any window you choose it lists interactions with when each one happened, who asked, the question, the data it reached, the models used, and the credits it consumed. Filter it to one person, to a date range, or to both. A window can span up to 400 days, measured end to end, and nothing limits how far back it starts. One request returns at most the 500 most recent interactions in that window, and the page shows 25 rows at a time, so a busy window is a page rather than the whole record. When the window holds more than one request returns, the page says so and still reports the total. Every row carries a Decision trail column: Show work opens that interaction’s stage-by-stage trail without leaving the page. Question text is readable for 90 days, counted from when the conversation was opened rather than from the individual question. A question you asked today inside a conversation opened more than 90 days ago is already withheld. Decision trails run on their own clock, counted from the interaction itself. Past 90 days that content is withheld when you read it, ahead of the jobs that delete it. A trail withheld on the conversation clock still shows its shape: the stages that ran, their timing and confidence, and the tables reached, with the written detail and the SQL withheld. Once the interaction itself is past 90 days its trail records are deleted, and there is nothing left to show. Attribution outlives the 90-day content window: looking back a year you still see who asked, when, which models ran, and what it cost, without the question text or the written detail of the trail. It is not permanent. Who asked and when sit on the interaction, while the models used and the credits consumed sit on the usage metering record, which is kept seven years. See audit trail and retention for what is kept beyond that and why.

Turn write-back on for a connector

Celeste is read-only until an administrator turns write-back on, and it is enabled per connector rather than once for the whole organization. Both switches have to be on: the organization-wide one, and then the one on the connector itself. Your plan does not switch write-back on or off. It decides which systems you can connect at all, so a connector your plan does not include is never there to enable in the first place.
Review these settings before enabling them for a connector that reaches customers or a system of record. See read-only and write-back for what Celeste can do once write-back is on.

Opt out of conversation quality review

Go Fig reviews conversation content from real usage internally to evaluate and improve Celeste’s accuracy. Organizations that want to be excluded from this entirely can request it at [email protected] with their organization name.

Control what Celeste can reach

Celeste can only read what the person asking is allowed to read. Configure organization roles, custom data roles, collection and table access, and field-level hide or redact in Access control.