Gesta
Help

Security and privacy

Understand Gesta access, local protection, activity data, tokens, and evidence handling.

Gesta handles organization settings, agent activity, protection decisions, and potentially sensitive evidence. Configure access and retention according to your organization's security and privacy requirements.

Machine and service boundary

The Gesta runtime runs on each enrolled machine. Context matching, output measurement, and configured pre-action or pre-submission safeguards are evaluated where the agent works.

Measuring agent output does not require source files or complete diffs to leave the machine. Structured counts, events, and protection decisions can be sent to the Gesta service. Readable content can also leave the machine when an organization enables features that retain session evidence, capture original Sensitive Data samples, or send compacted evidence to a Recap model. The sections below describe those configured exceptions.

This endpoint boundary applies whether the Gesta service is managed or self-hosted. In a self-hosted deployment, the service and its stored record can remain inside the organization's own environment.

Roles and access

Members

Members can connect their own machines and review their personal activity.

Owners

Owners can manage organization-wide settings and review team-level information, including connected agents, Context Rules, Operational Policies, Sensitive Data rules, approvals, and Team Activity.

Assign the Owner role only to people responsible for organization governance or security operations. Review membership when responsibilities change.

See Manage members and roles for invitations, role changes, and access reviews.

Connect tokens

The Console creates a user-bound connect token when an employee opens Connect.

  • Generate the command while signed in as the employee who owns the machine.
  • Do not share the command or token.
  • Do not paste it into tickets, chat, documentation, or source control.
  • Create a fresh command when reconnecting another employee.
  • Revoke reusable connect tokens that should no longer enroll new machines.

Revoking a connect token prevents new installations from using it. Existing connected machines use their own runtime credentials.

Organization Library privacy

Context Rule matching occurs on the enrolled machine. The employee's original prompt does not need to be sent to the organization service to select a rule.

Gesta can record that a rule matched so Owners can understand usage. Context match evidence should not be treated as proof that the agent completed the requested task.

Sensitive Data evidence

Sensitive Data findings may include metadata, stable fingerprints, and, depending on configuration, an original prompt sample captured for audit review.

  • Restrict access to legitimate reviewers.
  • Treat exported findings as sensitive.
  • Define retention according to the underlying data category.
  • Do not copy real finding content into ordinary support channels.
  • Test detectors with synthetic values.

Sessions and evidence

Session records can include user and agent identity, repository or work context, tools, token usage, safety checks, output measurements, and readable user and assistant messages. Readable transcript content is redacted and bounded before upload, but it may still contain company or customer information supplied during the session.

Not every integration produces the same level of detail. Present only fields supported by the connected agent and action.

Gesta does not include model reasoning, tool calls, tool output, system messages, or environment wrappers in the readable transcript stored for session detail. Tool usage and output measurements can still be recorded separately as structured metadata.

See Existing session history for the authoritative collection boundary when a machine first connects.

Define:

  • who can review personal and team activity;
  • how long sessions and evidence are retained;
  • how exports are approved and handled;
  • when evidence must be removed under company policy;
  • how employee monitoring expectations are communicated.

Recap processing

My Recap and Team Recap use a configured summary model. Only the compacted prompt-and-answer evidence described in Understand daily recaps is sent to that model.

The compacted prompt-and-answer evidence leaves Gesta when the configured AI endpoint is an external service. Review that provider's processing location, access controls, retention, and contractual terms before enabling Recaps. Bounded readable transcript evidence remains available through Gesta's own session evidence path and is not sent wholesale merely to generate a Recap.

Local protection

The Gesta runtime keeps recent validated organization settings available on the employee machine. This allows applicable guidance and safeguards to continue when the organization service is temporarily unavailable.

Keep runtimes current and connected so changes propagate promptly. Review degraded agents in the Console.

  • Use company identity for Console access.
  • Apply least privilege to organization roles.
  • Review Owners and connected machines regularly.
  • Disable obsolete rules instead of leaving unclear standards active.
  • Test new policies and detectors with safe, synthetic examples.
  • Require explicit confirmation before destructive or irreversible work.
  • Review approval and block outcomes for false positives and coverage gaps.
  • Document retention and employee-notice requirements before broad rollout.

Review organization-wide detector and upgrade controls in Organization settings.

On this page