Skip to main content

Ask the Catalyst Assistant

The Catalyst Assistant answers questions about the Catalyst resources you already have access to — projects, App IDs, workflow runs, components, agents, policies, metrics, and logs. An App ID is the identity Catalyst issues to each workload you run; see Identities. For what the assistant is and how Diagrid operates it, see Catalyst Assistant. Diagrid operates it for your organization, so it runs server-side and you supply no model API key of your own.

It only reads. The assistant has no tool that creates, updates, deletes, terminates, pauses, or reruns anything, so no phrasing of a question can make it change your organization. Anything you decide to act on, you still do yourself in the console, the CLI, or the API.

Availability

The Catalyst Assistant is not enabled by default. To have it turned on for your organization, reach out to your Diagrid representative. If the assistant is not in your console, that is why.

How it sees your resources​

Your question carries your own Catalyst login. The assistant calls read-only Catalyst tools as you, so it can reach exactly the projects and resources your own roles permit, and nothing more — it cannot widen its view by being asked nicely, and it cannot see another organization's data.

One assistant serves a Catalyst region rather than a single organization or user, and the Catalyst management API is regional — so the assistant grounds its answers in the data of the region it runs in. An organization reachable from more than one region has a separate assistant in each, with separate conversations.

What you can ask​

The assistant is granted a fixed set of read-only Catalyst tools. Every question below resolves to one of them.

AreaAsk it
Organization and projects"Which projects do I have, and what region is each in?" · "Which managed services are enabled on this project?"
App IDs and connectivity"Is my App ID ready?" · "Is a development tunnel connected to it?"
Workflows"Where is workflow run <id> stuck?" · "Show me the failed runs of client_onboarding."
Components"Which pub/sub brokers and key-value stores are configured in this project?" · "Which settings are set on that component?"
Agents and MCP servers"Which agents and MCP servers are registered here?" · "What tools does that MCP server advertise?"
Access policies"Why was that call refused?"
Metrics"Am I near my quota on this project?"
Logs"What did my App ID actually print when it failed?"
Audit"What changed in this organization yesterday?"
Templates and regions"What can I start from in this project?" · "Which regions can my organization use?"

Two of these are worth calling out, because nothing else answers them as directly:

  • "Where is it stuck?" — for a workflow run, the assistant returns the run's status, timings, and the execution graph showing which step it is on or failed at. There is no CLI equivalent of that graph.
  • "Why was that refused?" — an access policy denies by default, so an operation missing from its rules was never granted rather than blocked at runtime. The assistant reads the policy and tells you which it is.

Two details save you a confusing answer. A workflow name filter matches the registered workflow name exactly, so client_onboarding finds runs and Client Onboarding comes back as an empty list rather than an error. And listing components returns every kind together — brokers, key-value stores, subscriptions, configurations, resiliency policies, and HTTP endpoints — because there is no filter by component kind.

Where to ask​

  • Catalyst console — the assistant opens in a panel alongside the page you are on, and some pages offer a button that opens it already pointed at what you are looking at.
  • diagrid chat — the same assistant from your terminal. See the diagrid chat reference for the command and its flags.
diagrid login
diagrid chat

diagrid chat needs a user login (diagrid login); an API key carries no user identity for the assistant to verify. Nothing about the conversation runs on your machine — the model, the tools, and the prompt are all served by the assistant. Its opening banner names the assistant, its mode, and the data-sharing level in force for your organization, because those are the promises being made about what it may do on your behalf.

What it will not tell you​

Some things are absent from the assistant's tools by design, not filtered out afterwards:

  • Anything that changes state. No creating, updating, deleting, terminating, pausing, resuming, or rerunning.
  • Financial and credential surfaces. Billing, invoices, payment methods, service-account keys, and workload-identity tokens have no place in an assistant and are not in its tool set.
  • Inline component setting values. Describing a component shows the type, version, readiness, and the names of its settings. Inline values are withheld; secret references are shown as references.

Beyond that, a data-sharing level set for your whole organization decides how much of a response the assistant may use:

  • metadata — the default, and the conservative choice. Resource metadata such as names, statuses, and timestamps. Business data — workflow input and output, custom payloads, and other values returned by the API — is withheld.
  • full — additionally allows the read-only payloads needed to answer a question accurately.

The level is enforced, not advisory, and an unset level always resolves to metadata rather than to "share everything". Reading logs is the one place where the level can stop the assistant outright: where your organization's level does not permit it, the assistant tells you so rather than returning what reads like an empty log. Your organization's level is set by Diagrid; ask your Diagrid contact if you need it changed.

Limits you may run into​

The platform caps what the assistant spends on your organization's behalf, per month and per region — so an organization served by an assistant in more than one region has a separate monthly allowance in each. A cap is reported as the platform stopping the question rather than as a failure, and the reason is one of a fixed set: a monthly budget exhausted, a single question that grew too large, too many questions running at once, or a question that ran out of time. Questions that fail, time out, or are cancelled still count against the allowance, and the usage figure the assistant reports is an estimate, not a bill.

A conversation answers one question at a time. While an answer is still running, another question on the same conversation is refused — cancel the one in flight, or start a new conversation.

If the assistant is not available to you​

There is no self-service toggle, by design. Four separate things must be true, and you set none of them yourself:

  1. The Catalyst Assistant is included in your organization's plan. Diagrid grants this.
  2. It is switched on for your organization. Diagrid does this too — ask your Diagrid contact.
  3. Diagrid has made it visible in the console for your organization.
  4. Your Catalyst role allows you to call it.

The fourth is the most common surprise. The permission to use the assistant comes with organization-wide Catalyst roles only, because the assistant is reached through an organization-wide credential. A collaborator invited with a project-scoped role does not get it, even in an organization where everything else is switched on. Ask your organization administrator for an organization-wide Catalyst role.

diagrid chat names the reason when it cannot start: not included in your plan, included but not switched on, still being set up (wait a few minutes and run it again), setup failed (contact Diagrid support — retrying will not clear it), or authenticated with an API key, which carries no user identity.

note

The Catalyst Assistant is not the same thing as connecting an AI coding assistant to Catalyst. That one runs on your machine as part of your own coding assistant, uses your local diagrid login, defaults to sharing full responses, and can operate workflow runs. The Catalyst Assistant is hosted by Diagrid, defaults to metadata, and only reads.

Next steps​