GenAI in Enterprise

AI Fact Sheets and FAQs

 

Explore how Alteryx integrates Responsible AI practices across its suite of products. Our detailed AI Fact Sheets provide a thorough overview of our AI models, including our transparency, data handling, and accountability measures. The FAQs address common questions about data usage, encryption methods, and user controls. Refer to the legend for explanations of key terms used throughout our AI documentation. Learn more and understand how Alteryx ensures trust and reliability in its AI-driven solutions.

 

 

AI Fact Sheets and FAQs

Naming Updates
Some features were renamed. Former names are shown in section headers for clarity.

 
 
AI Tools Fact Sheet (formerly GenAI Tools)

General Background

Description Allows customers to embed requests to their own LLMs directly into their designer workflows, helping to solve advanced data problems like mapping data from one format to another and cleaning up messy categorical data.
Is personal data used in the training or operation of this model? Any personal data included by the user in prompts will be sent to the selected model provider.
Base Model Customers bring their own credentials for supported models from supported providers.
Model Type LLM (Large Language Model)
Model Customization No

Third-Party LLM Responsibility

To the extent that this product or feature utilizes a third-party LLM, please refer to the respective provider’s documentation for information on their data handling practices. This document describes how Alteryx’s product interacts with and uses the LLM, but the model’s management of data is governed by the third-party provider.

Transparency and Explainability

Model Outputs Explained Large language model outputs are not inherently explainable

Human Agency and Oversight

Is the Feature Optional? Yes
Human in the Loop? Yes

Trust and Accountability

Base model trained with customer data? No
Training data de-identified? This is managed by the model provider chosen by the customer and may vary based on which model provider is selected.
Customer data shared with model vendor? Using the feature sends prompts to the chosen provider. No data is shared if the feature is not used.
Data deletion? AI Tools does not store any data sent to the LLM or any responses received from the LLM. That data only exists at rest in the user’s workflow on their machine. Users can choose to delete data from their local machine.
Data retention? Prompts and generated content may be retained by the chosen model provider based on their terms & conditions for a set period of time.
Data processing location? Data processing performed before model inference occurs in the region where the Analytics Cloud environment is deployed. Gemini uses a global endpoint and model inference is not subject to the same regional-processing commitment and may occur outside that region. Alteryx does not guarantee in-region model inference.
Data storage details? AI Tools does not store any data sent to the LLM or any responses received from the LLM. That data only exists at rest in the user’s workflow on their machine. LLM connection information and credentials are stored in Alteryx One.
Data encrypted in transit and at rest? Yes

Reliability and Safety

Logging and Auditing Mechanisms Available? Yes
Guardrails? LLM Provider safety systems apply. Alteryx supplies prompt-level controls but does not add separate content filtering
Impact Assessment Conducted? Yes
Compliant with Applicable Regulations? Yes
Input/Output Consistency? Outputs are non-deterministic by nature. Determinism can be increased by adjusting model settings and prompts. Output consistency is never guaranteed.

Fairness and Inclusivity

Data Sources? The feature compiles prompts for the LLM using user-provided inputs and metadata from the uploaded data, such as column names and sample values. See ‘Customer data shared with model vendor’ for more details.
Bias detection and mitigation in place?

LLM Provider safety systems apply. There is no native bias scanner in AI tools.

Empower Social Good

Designed for Ethical Use? Yes
 
AI Tools FAQ (formerly GenAI Tools)

What is the AI feature, and what is its intended use and purpose?

The AI Tools Palette enables customers to connect to a large language model (LLM) directly within a Designer workflow. This allows users to quickly prepare and transform data with advanced capabilities such as auto-mapping different datasets, identifying variations of the same value in a column, and creating streamlined workflows with minimal manual effort

What data does the AI system require?

To produce responses, AI Tools send only the compiled prompts as defined by the user generated prompt templates and input data. This data is used only during the operation of the feature and is not retained for future fine-tuning.

Can users disable the AI features?

Yes, the AI Tools Palette is an optional feature that can be disabled by the Organization Admin. It is provided as a separate installer package, similar to the Alteryx Intelligence Suite, giving customers full control over enabling or disabling its functionality

How is my data processed and stored as it flows through the AI system?

Data processing performed by Alteryx before model inference occurs in the region where your Analytics Cloud environment is deployed. When a request is sent to Google’s Gemini models, model inference is performed through a global endpoint and may occur outside your Analytics Cloud region. As a result, Alteryx does not guarantee that model inference occurs within the same geographic region as your Analytics Cloud deployment. Any credentials and connection information are securely managed within Alteryx One.

What encryption methods are used to protect data at rest and in transit?

  • In Transit: Data is encrypted using HTTPS with TLS 1.2/TLS 1.3.
  • At Rest: While AI Tools does not store operational data, LLM connection credentials are securely stored in Alteryx One using AES-128-CBC with a per-environment key stored in Google Secret Manager (GSM). Data processed by the customer remains within their workflow environment and is protected according to their security configuration.

What testing and validation are performed throughout the AI model’s lifecycle?

AI Tools are designed to connect customers to their own provisioned AI models. Lifecycle management, testing, and validation of those models are managed by the customer. Alteryx ensures tool’s compatibility and provides thorough testing to ensure the quality and reliability of the integration.

 

For more AI FAQs, please visit the Alteryx Artificial Intelligence FAQ page. View the Alteryx Copilot Architecture and Data Flow Diagrams on our Alteryx Trust Center.

 
Ask Alteryx Fact Sheet (formerly Alteryx Copilot)

General Background

Description Ask Alteryx is an AI-powered workflow assistant that enables users to interact in a conversational way to streamline workflow creation and receive tailored recommendations using Generative AI.
Is personal data used in the training or operation of this model? No
Base Model Google Gemini
Model Type LLM
Model Customization The model is provided with information about Alteryx Designer as context, including how to configure Alteryx Designer Tools.

Third-Party LLM Responsibility

To the extent that this product or feature utilizes a third-party LLM, please refer to the respective provider’s documentation for information on their data handling practices. This document describes how Alteryx’s product interacts with and uses the LLM, but the model’s management of data is governed by the third-party provider.

Transparency and Explainability

Model Outputs Explained The model will explain its thinking process and why it made certain recommendations in the chat response sent to the user.

Human Agency and Oversight

Is the Feature Optional? Yes
Human in the Loop? Yes, Ask Alteryx will often ask the user for confirmation or feedback before taking any action on the canvas.

Trust and Accountability

Base model trained with customer data? No
Training data de-identified? N/A
Customer data shared with model vendor? Yes, workflow metadata as well as raw chat messages sent by the user are sent to the model vendor for use in preparing the response. If Data Awareness is enabled, Ask Alteryx may access a sample of user data at specific tool anchors only with user permission, and only when necessary to answer a question accurately.
Data deletion? Ask Alteryx stores conversation message history including sanitized workflow information.  Conversation history is retained for 90 days and then deleted, but users can request it to be deleted on demand. Data is deleted when a user is deleted.
Data retention? Conversation history is retained for 90 days and then deleted unless the user requests deletion sooner. Prompts are retained by the model vendor for 30 days to detect and mitigate abuse.
Data processing location? Data processing performed before model inference occurs in the region where the Analytics Cloud environment is deployed. Gemini uses a global endpoint and model inference is not subject to the same regional-processing commitment and may occur outside that region. Alteryx does not guarantee in-region model inference.
Data storage details? Metadata that helps Ask Alteryx operate is stored in the Alteryx One Control Plane in the environment being used. Customer-provided chat messages and Ask Alteryx responses (conversation history) are stored in the Alteryx One Data Plane associated with the workspace selected by the customer, or in the US1 Alteryx One control plane for Ask Alteryx trials.
Data encrypted in transit and at rest? Yes

Reliability and Safety

Logging and Auditing Mechanisms Available? Ask Alteryx maintains extensive logging mechanisms to ensure transparency and system integrity, including customer-facing debug information, system logs, and internal service logs.
Guardrails? Yes
Impact Assessment Conducted? Yes
Compliant with Applicable Regulations? Yes
Input/Output Consistency? Yes, although because Generative AI models are nondeterministic, users should expect some variability in response to a given prompt.

Fairness and Inclusivity

Data Sources? Ask Alteryx creates prompts to send to the underlying model from information such as: the chat message entered by the user, workflow metadata sent by Alteryx One during a chat session, conversation history, information about how to configure tools in Alteryx One, Alteryx Help Documentation, and Alteryx Knowledge Base. If Data Awareness is enabled, data is retrieved from the Designer Browse Everywhere (YXBE) file—a temporary snapshot of data at anchor points after running a workflow. Learn more about Browse Everywhere data.
Bias detection and mitigation in place? Yes

Empower Social Good

Designed for Ethical Use? Yes
 
Ask Alteryx FAQ (formerly Alteryx Copilot)

What is the AI feature, and what is its intended use and purpose?

Ask Alteryx is an AI-powered workflow assistant designed to help you build workflows more efficiently. You can Ask Alteryx questions about Designer or get assistance with adding tools to your workflow in a natural, conversational way. Ask Alteryx uses Generative AI to analyze your current workflow and provide tailored recommendations. It can even add preconfigured tools directly to the canvas. With Ask Alteryx, you can spend less time building workflows and get to actionable insights faster.

 

What data does the AI system require?

To produce responses, Ask Alteryx uses:

  • The chat message sent by the user
  • Conversation history
  • Workflow metadata (e.g., tool configuration, connection details, selected tools, column names, and data types at tool anchors).

This data is used only during the operation of the feature and is not retained for future fine-tuning.

 

Can users disable the AI features?

Ask Alteryx is included with Alteryx One and as part of the Professional and Enterprise Pricing Tiers for free, on an opt-in basis. Ask Alteryx can be disabled by using Custom Roles in the Workspace Admin panel and the Account Admin Panel.

How is my data processed and stored as it flows through the AI system?

Data processing performed by Alteryx before model inference occurs in the region where your Analytics Cloud environment is deployed. When a request is sent to Google’s Gemini models, model inference is performed through a global endpoint and may occur outside your Analytics Cloud region. As a result, Alteryx does not guarantee that model inference occurs within the same geographic region as your Analytics Cloud deployment. Any credentials and connection information are securely managed within Alteryx One.

What encryption methods are used to protect data at rest and in transit?

  • In Transit: Data is encrypted using HTTPS with TLS 1.2 or TLS 1.3.
  • At Rest: Data is encrypted using AES-256 in both the Alteryx One Control and each Data Plane.

What testing and validation are performed throughout the AI model’s lifecycle?

Logging, auditing, and bias mitigation processes are in place. Alteryx performs extensive manual and automated testing to compare Ask Alteryx chat responses against expected outcomes to ensure quality and consistency. When developing a new Ask Alteryx agent, the same testing process is followed, and the new agent is only released if it meets Alteryx’s quality standards.

 

For more AI FAQs, please visit the Alteryx Artificial Intelligence FAQ page. View the Ask Alteryx Architecture and Data Flow Diagrams on our Alteryx Trust Center.

 
Auto Insights Fact Sheet (formerly Magic Reports, Auto Insights Playbooks, and Magic Documents)

This consolidated fact sheet covers the following Auto Insights AI capabilities:

1. AI Assistant for Custom Reports (formerly Magic Reports)
2. AI Suggested Use Cases (formerly Auto Insights Playbooks)
3. AI Export Options for Preset Reports (formerly Magic Documents)

 

General Background

Descriptions (unique by capability)
AI Assistant for Custom Reports AI Suggested Use Cases AI Export Options for Preset Reports
Allows customers to quickly translate the findings of their Report into actions by summarising, rephrasing, translating or creating an executive summary. Supports customers identifying high value analytics use cases tailored to their specific business, role or problem and creates a synthetic dataset to match the use case to build a proof-of-concept Report. Allows customers to quickly translate their findings into a presentation, email, or message to share it with their team and stakeholders.

Model details (all three capabilities indicate)

Is personal data used in the training or operation? No (Personal data is not used in operation)
Base Model Azure OpenAI – GPT-4o (unless specified by customer to BYO)
Model Type LLM (Large Language Model)
Model Customization No

Third-Party LLM Responsibility

To the extent that a capability utilizes a third-party LLM, please refer to the respective provider’s documentation for information on their data handling practices. This document describes how Alteryx’s product interacts with and uses the LLM, but the model’s management of data is governed by the third-party provider.

Transparency and Explainability (all three capabilities indicate)

Model outputs explained Yes

Human Agency and Oversight (all three capabilities indicate)

Is the Feature Optional? Yes
Human in the Loop? Yes

Trust and Accountability

Shared answers (all three capabilities indicate)
Base model trained with customer data? No
Training data de-identified? Yes (managed by the underlying GPT-4o model from Azure OpenAI)
Data retention? Prompts and generated content are retained by the model vendor for 30 days.
Data processing location? Data processing performed before model inference occurs in the region where the Analytics Cloud environment is deployed. Gemini uses a global endpoint and model inference is not subject to the same regional-processing commitment and may occur outside that region. Alteryx does not guarantee in-region model inference.
Data storage details? Data is stored within the same regional infrastructure as processing
Data encrypted in transit and at rest? Yes
Capability-specific answers (where they differ)
AI Assistant for Custom Reports AI Suggested Use Cases AI Export Options for Preset Reports
Customer data shared with model vendor? On user request, content and insights displayed in the Custom Report; raw underlying data not included unless row-level displayed. On user request, only metadata (e.g., column names and representative sample values); raw underlying data is not shared. On user request, content and insights displayed in the Preset Report; raw underlying data not included unless row-level displayed.
Data deletion? Users can delete generated content; also deleted when the Custom Report is deleted. Users can delete generated content; also deleted when the user is deleted. Users can delete generated content; also deleted when the Preset Report is deleted.

Reliability and Safety (all three capabilities indicate)

Guardrails? Yes (e.g., data curation, content filtering, bias mitigation, ethical guidelines, user feedback loops, continuous monitoring, collaborative research, etc.)
Impact assessment conducted? Yes
Compliant with applicable regulations? Yes
Input/Output Consistency? Yes

Fairness and Inclusivity

Shared answers (all three capabilities indicate)
Bias detection and mitigation in place? Yes
Capability-specific answers (where they differ)
Capability (Data sources used to compile prompts) AI Assistant for Custom Reports AI Suggested Use Cases AI Export Options for Preset Reports
All content and insights displayed in the Report; raw underlying data not included unless row-level detail displayed (eg, in a table) User-provided inputs and metadata from uploaded data (e.g., column names and sample values) User-provided inputs and all content and insights displayed in the Preset Report; raw underlying data not included unless row-level detail displayed.

Empower Social Good (all three capabilities indicate)

Designed for Ethical Use? Yes
 
Auto Insights FAQ (formerly Magic Reports, Auto Insights Playbooks, and Magic Documents)

This consolidated FAQ covers:

1. AI Assistant for Custom Reports (formerly Magic Reports)
2. AI Suggested Use Cases (formerly Auto Insights Playbooks)
3. AI Export Options for Preset Reports (formerly Magic Documents)

 

What is the AI feature, and what is its intended use and purpose?

Shared (all three capabilities indicate)

  • Powered by Azure OpenAI GPT-4o (unless specified by customer to BYO)
  • Designed to be user-initiated (optional) and support user review/edits of the output.

AI Assistant for Custom Reports (unique)

Alteryx Custom Reports – AI Assistant helps customers quickly translate findings into actions by summarising, rephrasing, translating, or creating an executive summary.

AI Suggested Use Cases (unique)

Supports customers identifying high-value analytics use cases and generating synthetic data, missions and reports tailored to their needs in minutes, helping users see how Auto Insights can help on their data journey.

AI Export Options for Preset Reports (unique)

Allows users to generate a presentation, email, or message based on their Preset Report, and tailor the results using inputs such as audience, objective, tone of voice, language, and whether AI-generated business recommendations should be included.

 

What data does the AI system require?

Shared (all three capabilities indicate)

  • Raw underlying data is not shared by default.
  • If row-level data is displayed (e.g., in a table), that displayed row-level content can be included in what is sent for generation.
  • Personal data is not used in operation.
  • Shared data is only used to perform the operation and is not retained for future fine-tuning or other uses.

AI Assistant for Custom Reports (unique)

Content and insights displayed in reports.

AI Suggested Use Cases (unique)

Only metadata (e.g., column names and sample values) or the prompt the customer inputs is shared with the vendor.

AI Export Options for Preset Reports (unique)

Content and insights displayed in the Preset Report are shared with the model developer to generate presentations, emails, or messages.

 

Can users disable the AI feature(s)?

Shared (all three capabilities indicate)

  • Yes. All three capabilities are optional and can be disabled.

How is my data processed and stored as it flows through the AI system?

Data processing performed by Alteryx before model inference occurs in the region where your Analytics Cloud environment is deployed. When a request is sent to Google’s Gemini models, model inference is performed through a global endpoint and may occur outside your Analytics Cloud region. As a result, Alteryx does not guarantee that model inference occurs within the same geographic region as your Analytics Cloud deployment. Any credentials and connection information are securely managed within Alteryx One.

What encryption methods are used to protect data at rest and in transit?

Shared (all three capabilities indicate)

  • Data is encrypted both in transit and at rest.

 

AI Suggested Use Cases and AI Export Options for Preset Reports (details)

  • In transit: TLS 1.2 / TLS 1.3 over HTTPS
  • At rest: AES256 encryption (environment-dependent)
  • Azure: Server-Side Encryption with Customer-Managed Keys (SSE-CMK)
  • AACP: Google’s default encryption (AES-256)
  • On-Prem: Configured according to customer preferences

 

What testing and validation are performed throughout the AI model lifecycle?

Shared (all three capabilities indicate)

  • Logging, auditing mechanisms, and bias mitigation processes are in place.
  • Alteryx conducted extensive manual testing across scenarios/datasets to evaluate output quality and consistency, and repeats testing before adopting newer model versions.
 
AI Insights Agent for Google Gemini Enterprise Fact Sheet

General Background

Description Enable an AI Agent to access the Insights MCP from Google Gemini Enterprise. Customers will be able to ask the agent questions about their datasets and get meaningful responses.
Is personal data used in the training or operation of this model? Potentially if the customer has personal data in their dataset.
Base Model gemini-2.5-flash (Google)
Model Type N/A
Model Customization N/A

Third-Party LLM Responsibility

To the extent that this product or feature utilizes a third-party LLM, please refer to the respective provider’s documentation for information on their data handling practices. This document describes how Alteryx’s product interacts with and uses the LLM, but the model’s management of data is governed by the third-party provider.

Transparency and Explainability

Model Outputs Explained Gemini provides the frontend for the agent. The output is worded by the LLM used and includes a link to Auto Insights to allow the user to verify the data.

Human Agency and Oversight

Is the Feature Optional? Yes
Human in the Loop? Yes, human makes the requests to the agent.

Trust and Accountability

Base model trained with customer data? N/A
Training data de-identified? N/A
Customer data shared with model vendor? N/A
Data deletion? N/A
Data retention? N/A
Data processing location? Data processing performed before model inference occurs in the region where the Analytics Cloud environment is deployed. Gemini uses a global endpoint and model inference is not subject to the same regional-processing commitment and may occur outside that region. Alteryx does not guarantee in-region model inference.
Data storage details? The agent uses a DB to store session data that allows it to maintain context between user interactions.
Data encrypted in transit and at rest? Yes

Reliability and Safety

Logging and Auditing Mechanisms Available? Results return a link to the data for the user to audit if they want.
Guardrails? Access controls, agent can only access datasets the user has access to, in a specific Aleryx One workspace selected by the user.
Impact Assessment Conducted? Yes
Compliant with Applicable Regulations? Yes
Input/Output Consistency? Yes

Fairness and Inclusivity

Data Sources? N/A
Bias detection and mitigation in place? N/A

Empower Social Good

Designed for Ethical Use? Yes
 
AI Insights Agent for Google Gemini Enterprise FAQ

What is the AI feature, and what is its intended use and purpose?

This is an AI Agent that accesses the Insights MCP to retrieve information about a customer’s datasets.

What data does the AI system require?

Insights dataset.

Can users disable the AI feature?

Yes.

How is my data processed and stored as it flows through the AI system?

Data processing performed by Alteryx before model inference occurs in the region where your Analytics Cloud environment is deployed. When a request is sent to Google’s Gemini models, model inference is performed through a global endpoint and may occur outside your Analytics Cloud region. As a result, Alteryx does not guarantee that model inference occurs within the same geographic region as your Analytics Cloud deployment. Any credentials and connection information are securely managed within Alteryx One.

What encryption methods are used to protect data at rest and in transit?

  • In transit: Traffic between external clients and our services is encrypted using TLS 1.2+. Within the control plane Kubernetes clusters, inter-service traffic is protected by Linkerd mutual TLS over TLS 1.3, using Linkerd’s default AEAD cipher suites.
  • At rest: Encryption is in Place – Tested as a part of our ISO 27001 and SOC 2 audits.

What testing and validation are performed throughout the AI model lifecycle? 

The agent translates user messages into queries againts Aleryx Auto Insights and re-words the responses into user friendly language. The responses are manually verified against the results visible in Auto Insights’ user interface.

 
Alteryx MCP Fact Sheet

General Background

Description Alteryx MCP is an Alteryx-hosted MCP gateway and collection of individual MCP servers that let external agents securely run trusted Alteryx workflows and analyze approved datasets through a single integration surface using their agent platform of choice.
Is personal data used in the training or operation of this model? No. Customer/workflow inputs and outputs may pass through the service transiently, and underlying workflows or datasets may contain personal data depending on customer configuration.
Base Model N/A – this is not a foundation model. It is an MCP gateway/service that can be used from a customer’s preferred external agent platform such as ChatGPT, Gemini Enterprise, and Microsoft Copilot Studio.
Model Type N/A
Model Customization N/A

Third-Party LLM Responsibility

To the extent that this product or feature utilizes a third-party LLM, please refer to the respective provider’s documentation for information on their data handling practices. This document describes how Alteryx’s product interacts with and uses the LLM, but the model’s management of data is governed by the third-party provider.

Transparency and Explainability

Model Outputs Explained Outputs are explainable insights, workflow/app results, supporting breakdowns, visualizations, and links for deeper exploration in Alteryx.

Human Agency and Oversight

Is the Feature Optional? Yes. Public preview plans include workspace-level enable/disable controls, and feature access will also be gated by the AIAgents capability.
Human in the Loop? Yes. The primary pattern is interactive chat with an authenticated user, and unattended/headless automation is explicitly out of scope for this offer.

Trust and Accountability

Base model trained with customer data? No. The MCP Gateway/Server is an execution/integration layer, not a trained customer-data model.
Training data de-identified? N/A
Customer data shared with model vendor? Yes, at the external agent layer, outside of Alteryx’s control.
Data deletion? Assets configured to expose Datasets and Workflows to the MCP Server are subject to Data Deletion policies.
Data retention? Retention is minimal for the Alteryx MCP solution itself. Logs, telemetry, and some control-plane metadata may be retained per platform policy; generated images used by Insights MCP are stored in Redis cache with a time-to-live, and workflow-tool data follows documented retention/deletion plans.
Data processing location? Data is processed/workflows are executed in the configured Alteryx One region (for example US1, EU1, AU1), with requests scoped to a single authenticated workspace.
Data storage details? The gateway is deployed in the same region as the Alteryx One platform, avoids cross-region transfer by itself, and stores minimal control-plane metadata. It does not maintain its own business-data store.
Data encrypted in transit and at rest? Yes. TLS is used in transit, secrets are encrypted at rest.

Reliability and Safety

Logging and Auditing Mechanisms Available? Yes. MCP Server includes structured logs, metrics, tracing, and audit trails/tool-invocation logging with user or token context.
Guardrails? Yes. Guardrails include workspace permissions, assistant-side allowlists, toolset/read-only policy enforcement, feature flags, rate limiting, quotas/throttling, and read-only dataset access patterns.
Impact Assessment Conducted? Yes
Compliant with Applicable Regulations? Yes
Input/Output Consistency? Yes. A key value proposition of using Alteryx One is grounded, repeatable execution of governed workflows and explainable insights instead of ad hoc model reasoning.

Fairness and Inclusivity

Data Sources? Approved datasets, registered workflows, analytic apps, workflow metadata, and platform context available within the authenticated workspace.
Bias detection and mitigation in place? N/A – the results provided by Alteryx MCP are deterministic in nature.

Empower Social Good

Designed for Ethical Use? Yes
 
Alteryx Skills Fact Sheet

General Background

Description Alteryx Skills is a set of MCP tools, skills, and agent plugins that enable AI-first access of the Alteryx platform
Is PII used in the training or operation of this model? No. Customer/workflow inputs and outputs may pass through the service transiently, and underlying workflows or datasets may contain PII depending on customer configuration
Base Model N/A – there is no bundled model. It is a set of tools and prompting that can be used from a customer’s preferred external agent harness such as Claude Code, Codex, and Antigravity
Model Type N/A
Model Customization N/A

Third-Party LLM Responsibility

To the extent that this product or feature utilizes a third-party LLM, please refer to the respective provider’s documentation for information on their data handling practices. This document describes how Alteryx’s product interacts with and uses the LLM, but the model’s management of data is governed by the third-party provider

Transparency and Explainability

Model Outputs Explained Alteryx MCP and Skills tools provide outputs that the customer’s agent may choose to use in explanations. It is not guaranteed by Alteryx

Human Agency and Oversight

Is the Feature Optional? Yes. Customers must choose to access Alteryx from their agent platform.
Human in the Loop? This is dependent on the agent platform the customer chooses to use.

Trust and Accountability

Base model trained with customer data? N/A
Training data anonymized? N/A
Customer data shared with model vendor? Yes
Data deletion? Assets (workflows, datasets) created with Alteryx Skills and saved within the Alteryx One Platform are subject to standard Alteryx One data deletion policies.
Data retention? Assets are retained until deleted by the above policy. Alteryx one logs and telemetry follow standard Alteryx One platform data retention policies.
Data processing location? Data is processed/workflows are executed in the configured Alteryx One region (for example US1, EU1, AU1), with requests scoped to a single authenticated workspace.
Data storage details? Alteryx Skills does not store any unique data. Assets created with Alteryx Skills are stored per Alteryx One platform policy, in the configured control plane or data plane for the authenticated workspace.
Data encrypted in transit and at rest? Yes. TLS is used in transit, assets are encrypted at rest.

Reliability and Safety

Logging and Auditing Mechanisms Available? Alteryx One performs audit logging when assets are accessed via Alteryx Skills.
Guardrails? Yes. Guardrails include workspace permissions, toolset/read-only policy enforcement, and rate limiting.
Impact Assessment Conducted? Yes
Compliant with Applicable Regulations? Yes
Input/Output Consistency? Yes, since Alteryx Skills builds and executes workflows, the consistency guaranteed by Alteryx Workflow execution is available to agents using Alteryx Skills.

Fairness and Inclusivity

Data Sources? Data and workflows available to the user in the Alteryx One platform as well as any local files and workflows that customers may choose to expose to their agents.
Bias detection and mitigation in place?

N/A

Empower Social Good

Designed for Ethical Use? Yes
 
Alteryx Skills FAQ

What is the AI feature, and what is its intended use and purpose?

Alteryx Skills is a set of MCP tools, skills, and agent plugins that enable AI-first access of the Alteryx platform

What data does the AI system require?

The system requires whatever data the customer provides that is relevant to the problem they are attempt to solve, in addition to the assets available to the customer in the Alteryx One platform.

Can users disable the AI features?

N/A – no AI is used internal to Alteryx for this feature

How is the data processed and stored as it flows through the AI system?

Workflows can be built locally or within Alteryx One. Workflows built locally stay on the user’s machine, although some data may be sent to Alteryx One endpoints to provide workflow building assistance. Assets built in the cloud (workflows, datasets) are processed and stored in the Alteryx One control plane and data plane, depending on the action and asset.

What encryption methods are used to protect data at rest and in transit?

In Transit: Data sent to and from Alteryx One is encrypted using HTTPS with TLS 1.2 or TLS 1.3.

At Rest: Asset metadata is encrypted using AES-256 in the Alteryx One Control Plane.

Asset data encryption varies, since it can be controlled by the customer.

What testing and validation are performed throughout the AI model’s lifecycle?

Alteryx performs extensive manual and automated testing to compare Ask Alteryx skill responses against expected outcomes for a variety of models to ensure quality and consistency. When developing a new Ask Alteryx skill, the same testing process is followed, and the new skill is only released if it meets Alteryx’s quality standards.

 
Alteryx Insights for OpenAI Fact Sheet

General Background

Description Enable the Alteryx Insights for OpenAI Plugin to access the Alteryx MCP from OpenAI. Customers will be able to ask the agent questions about their datasets.
Is PII used in the training or operation of this model? Only if the customer has PII in their dataset
Base Model Depends on the model the customer selects (only GPT models are available in OpenAI)
Model Type N/A
Model Customization N/A

Third-Party LLM Responsibility

To the extent that this product or feature utilizes a third-party LLM, please refer to the respective provider’s documentation for information on their data handling practices. This document describes how Alteryx’s product interacts with and uses the LLM, but the model’s management of data is governed by the third-party provider.

Transparency and Explainability

Model Outputs Explained The LLM interprets the user’s question and orchestrates the steps to answer it, while the analytical execution is performed by the Alteryx MCP over governed data. Responses include a link back to Alteryx, enabling full traceability and easy validation of the results.

Human Agency and Oversight

Is the Feature Optional? Yes
Human in the Loop? Yes, human makes the requests to the agent

Trust and Accountability

Base model trained with customer data?  N/A
Training data anonymized? N/A
Customer data shared with model vendor? N/A
Data deletion? N/A
Data retention? N/A
Data processing location? Data processing performed before model inference occurs in the region where the Analytics Cloud environment is deployed. Gemini uses a global endpoint and model inference is not subject to the same regional-processing commitment and may occur outside that region. Alteryx does not guarantee in-region model inference.
Data storage details? The Alteryx MCP is stateless and the chat sessions are stored in OpenAI
Data encrypted in transit and at rest? Yes

Reliability and Safety

Logging and Auditing Mechanisms Available? Results return a link to the data for the user to audit if they want
Guardrails? Access controls, the app only has access to the datasets the user has access to, in a specific Aleryx One workspace selected by the user
Impact Assessment Conducted? No
Compliant with Applicable Regulations? Yes
Input/Output Consistency? Yes

Fairness and Inclusivity

Data Sources? N/A
Bias detection and mitigation in place? N/A

Empower Social Good

Designed for Ethical Use? Yes
 
Alteryx Insights for OpenAI FAQ

What is the AI feature, and what is its intended use and purpose?

The Alteryx Insights for OpenAI plugin lets authorized Business/Enterprise users ask natural-language questions about enabled Alteryx Auto Insights datasets from inside ChatGPT.

ChatGPT provides the conversational AI experience and may decide to call Alteryx MCP tools. Alteryx remains the governed analytics system of record: it authenticates the user, enforces workspace and dataset permissions, runs the requested deterministic analyses, and returns metrics, summaries, visualisations, and links back to Alteryx for validation and deeper exploration.

The intended use is governed conversational analytics over approved datasets.

What data does the AI system require?

The feature may use the user’s ChatGPT prompt and conversation context within ChatGPT, the user’s Alteryx identity and OAuth authorisation context, the selected Alteryx workspace, and structured MCP tool-call parameters generated by ChatGPT.

On the Alteryx side, the Alteryx MCP uses only authorized data and metadata needed for the requested operation, such as enabled datasets, measures, segments, filters, date ranges, scoped analytic results and may also return specific filtered rows of data.

Can users disable the AI features?

Yes. The plugin is opt-in from both the OpenAI and Alteryx access perspectives. Companies can enable or disable the Alteryx Insight for OpenAI org-wide in their OpenAI environment. Individual users must connect the app and authenticate to Alteryx using OAuth before it can access Alteryx resources on their behalf.

Alteryx access is also permission-scoped: users need an Alteryx account/license, access to the relevant Alteryx One workspace, access to the underlying datasets, and the datasets must be enabled for MCP exposure.

How is my data processed and stored as it flows through the AI system?

Data processing performed by Alteryx before model inference occurs in the region where your Analytics Cloud environment is deployed. When a request is sent to Google’s Gemini models, model inference is performed through a global endpoint and may occur outside your Analytics Cloud region. As a result, Alteryx does not guarantee that model inference occurs within the same geographic region as your Analytics Cloud deployment. Any credentials and connection information are securely managed within Alteryx One.

What encryption methods are used to protect data at rest and in transit?

In transit, external traffic between ChatGPT and Alteryx One uses HTTPS/TLS, and the MCP endpoint is fronted through the same Alteryx One edge pattern as other platform traffic. Within Alteryx control-plane Kubernetes clusters, inter-service traffic is protected with Linkerd mutual TLS over TLS 1.3.

At rest, Alteryx data and cached artifacts are protected by Alteryx One platform encryption controls in the applicable regional environment. Existing platform controls are tested as part of Alteryx ISO 27001 and SOC 2 audits.

Any data stored by ChatGPT, including conversation history or tool-call transcripts, is protected according to the customer’s OpenAI contract, edition, admin settings, and OpenAI security controls.

What testing and validation are performed throughout the AI model’s lifecycle?

The Alteryx Insight for OpenAI does not introduce an Alteryx-managed AI model lifecycle because the LLM/agent behavior is provided by OpenAI and the customer-selected GPT experience. The Alteryx MCP Server is an API/tool layer that exposes governed Alteryx analytics capabilities to third-party agents.

Validation focuses on authentication, authorisation, tool behaviour, analytical correctness, and traceability. Relevant testing includes OAuth and MCP authentication validation, permission and workspace scoping checks, verification that only enabled and authorised datasets are available, manual verification of responses against the Auto Insights UI, and security review of the authentication flow.

Responses include links back to Alteryx so users can inspect and validate the underlying analysis. OpenAI’s model testing and lifecycle controls are governed by OpenAI and the customer’s OpenAI configuration.

 
Agent Studio Fact Sheet

General Background

Description Agent Studio is an application in Alteryx One.
Customers can publish existing Alteryx assets for AI consumption:

  • Datasets are exposed through Insights MCP tools powered by Auto Insights algorithms, enabling repeatable, verifiable, and governed AI-driven answers.
  • Workflows and Analytics Apps are exposed as MCP tools and executed via CEFD, allowing AI models to leverage existing specialised business logic.

Agent Studio also provides a guided way to create Alteryx Agents governed “chat with your data” experiences that business users can interact with through natural language in Alteryx One.
Creators can connect agents to MCP-enabled datasets, add instructions and guardrails, and define starter questions for users.

Is PII used in the training or operation of this model? Potentially if the customer has PII in their dataset
Base Model Gemini 3 Flash
Model Type N/A
Model Customization N/A

Third-Party LLM Responsibility

To the extent that this product or feature utilizes a third-party LLM, please refer to the respective provider’s documentation for information on their data handling practices. This document describes how Alteryx’s product interacts with and uses the LLM, but the model’s management of data is governed by the third-party provider.

Transparency and Explainability

Model Outputs Explained The LLM interprets the user’s question and orchestrates the steps to answer it, while the analytical execution is performed by the Alteryx Insights MCP over governed data. Responses include a link back to Alteryx Auto Insights, enabling full traceability and easy validation of the results.

Human Agency and Oversight

Is the Feature Optional? Yes
Human in the Loop? Yes, human makes the requests to the agent

Trust and Accountability

Base model trained with customer data? N/A
Training data anonymized? N/A
Customer data shared with model vendor? N/A
Data deletion? N/A
Data retention? N/A
Data processing location? Data processing performed before model inference occurs in the region where the Analytics Cloud environment is deployed. Gemini uses a global endpoint and model inference is not subject to the same regional-processing commitment and may occur outside that region. Alteryx does not guarantee in-region model inference.
Data storage details? Agent configurations and access control are stored in Alteryx One.
Data encrypted in transit and at rest? Yes

Reliability and Safety

Logging and Auditing Mechanisms Available? Agent Studio maintains extensive logging mechanisms to ensure transparency and system integrity, including customer-facing debug information, system logs, and internal service logs.
Guardrails? Access controls, the agent only has access to the datasets the user as access to and selected.
Impact Assessment Conducted? No
Compliant with Applicable Regulations? Yes
Input/Output Consistency? Yes

Fairness and Inclusivity

Data Sources? N/A
Bias detection and mitigation in place? N/A

Empower Social Good

Designed for Ethical Use? Yes
 
Agent Studio FAQ

What is the AI feature, and what is its intended use and purpose?

Agent Studio is an application in Alteryx One that lets customers create governed AI agents for “chat with your data” experiences. Creators can connect agents to MCP-enabled datasets, add instructions and guardrails, and define starter questions for business users.

For dataset-backed agents, the AI interprets the user’s question and orchestrates approved analytics operations in Alteryx, including Auto Insights-powered analysis. The analytical execution happens over governed Alteryx data, and responses can link back to Auto Insights so users can validate results.

What data does the AI system require?

Agent Studio may use:

  • The user’s prompt or chat message
  • Saved agent configuration, including instructions, guardrails, and dataset dependencies
  • Workspace, entitlement, authorization scope, and dependency-check information
  • Metadata and governed dataset context such as measures, segments, filters, date ranges and specific filtered rows of data
  • Results returned by approved Alteryx analytics services, such as Auto Insights

This data is used only during the operation of the feature and is not retained for future fine-tuning.

Can users disable the AI features?

Yes. Agent Studio is optional, and access can be controlled through Alteryx One entitlements, workspace access controls, user permissions, and dataset-level authorisation. Agents are blocked unless the user has access to all underlying dataset dependencies.

How is my data processed and stored as it flows through the AI system?

Data processing performed by Alteryx before model inference occurs in the region where your Analytics Cloud environment is deployed. When a request is sent to Google’s Gemini models, model inference is performed through a global endpoint and may occur outside your Analytics Cloud region. As a result, Alteryx does not guarantee that model inference occurs within the same geographic region as your Analytics Cloud deployment. Any credentials and connection information are securely managed within Alteryx One.

What encryption methods are used to protect data at rest and in transit?

In transit, traffic between external clients and Alteryx services is encrypted using TLS 1.2 or later. Within the Alteryx platform, service-to-service traffic is protected with mutual TLS where applicable.

At rest, data is encrypted. The attached fact sheet notes that encryption controls are tested as part of Alteryx ISO 27001 and SOC 2 audits.

What testing and validation are performed throughout the AI model’s lifecycle?

Agent Studio responses are validated against the results available in Auto Insights. The agent translates user messages into queries against Alteryx Auto Insights, then rewrites the results into user-friendly language. Responses are manually verified against Auto Insights UI results, and links back to Auto Insights support traceability and validation.

Agent Studio also maintains logging and auditing mechanisms, including customer-facing debug information, system logs, internal service logs, security events, agent activity records, and configuration audit records.