October 2026 Release Highlights
The October release is one of our most significant platform releases this year, with new capabilities for MCP governance, agentic automation, hosted SFTP, event-driven workflows, data ingestion, and B2B operations.
Here’s what’s new.
Celigo MCP Management
AI agent pilots stall when they reach production. Access runs through shared service accounts, every vendor ships its own rules, and IT has no way to see who did what or revoke access cleanly.
The result is an audit gap security teams cannot approve at scale.
Celigo MCP Management is the one governed layer for enterprise AI access. It gives teams one place to find every agent and MCP server, control who uses which tools, and ground every answer in company knowledge, with every call traced to a real person.
→ Join our upcoming webinar to see how Celigo MCP Management brings MCP Server and MCP Gateway together to build and govern the tools agents use.
MCP server proxy: Upstream MCP connections & capability governance
Connect a Celigo MCP server to third-party native MCP servers such as Salesforce, HubSpot, and Snowflake, and govern all of their capabilities from one place.
Attach an upstream MCP connection to bring in its tools, resources, and prompts. Capabilities are discovered automatically and can be enabled or disabled individually. Override the name, description, and annotations on any proxied capability so AI agents see your organization’s guidance rather than the generic upstream text. Add Celigo-built capabilities alongside proxied ones on the same server.
Your existing governance applies to every call: authentication, end-user groups, capability sets, network policies, and request logging. Mix vendor tools and Celigo-built flows on the same server and see every call in one request log.
→ Learn more about the MCP server proxy
MCP server end-user connections
Tools now execute under each end user’s own identity and permissions in the downstream app. Every action is attributed to the right person, downstream access controls are respected, and the audit trail in the downstream app reflects who actually made the call.
Mark a connection as requiring end-user credentials. Each end user connects to their own account once, and that credential is automatically shared across all MCP servers built on the same parent connection. Any auth type works: OAuth, API key, basic auth, and token.
→ Learn more about MCP server end-user connections
Prebuilt MCP servers in the Marketplace
Browse, inspect, and install Celigo-built MCP servers from the Marketplace without having to build from scratch.
- See exactly which tools, prompts, and connections it exposes, and read any tool’s full input and output schema before you commit.
- Connection and configuration values are prompted at install and validated before the server goes live.
MCP server rate limits and usage quotas
Set up to three independent limits per MCP server: a server-wide rate limit to protect downstream systems from traffic bursts, a per-user rate limit so no single end user consumes the server’s full capacity, and a usage quota to govern cumulative consumption over a longer period. All three are optional.
When a limit is reached, callers receive a standard 429 response with a retry-after header. Throttled requests appear in the request log with the consumer’s identity and the limit type that was hit.
→ Learn more about MCP server rate limits and usage
Agentic automation
Intelligent document processing for AI agents
AI agents can extract structured data from invoices, purchase orders, receipts, spreadsheets, and other documents directly into the output schema you define, without requiring an external extraction tool.
Hand an agent a PDF, image, or spreadsheet, and it returns schema-aligned JSON, ready to map into NetSuite, Salesforce, or any downstream system. Agents detect document-extraction intent and automatically invoke processing without any setup beyond the existing agent schema. Field-level confidence signals are available as optional schema fields.
Supported formats: PDF, PNG, JPEG, TIFF, and XLSX. Typed, scanned, and handwritten documents are all supported. Multi-page tables merge into one list.
Code execution for BYOK AI agents
Agents on a bring-your-own-key model connection can run code as a built-in tool, so they compute, transform data, or run logic mid-task without a custom script step.
Available now for OpenAI, Azure OpenAI, Anthropic, and Gemini.
Platform
Celigo-hosted SFTP file server
Celigo now hosts a standards-based SFTP file server on top of Celigo Storage. Enable it for an environment, create one isolated account per trading partner, and partners connect with any standard SFTP client. Files they upload land directly in Celigo Storage for your flows to process. Files your flows stage are available for partner pickup.
→ Learn more about the Celigo-hosted file server
Celigo Topics
Topics is a native publish-and-subscribe event bus built into the Celigo platform. Publish a message to a named, durable topic and every subscribing flow receives it independently, keeps its own place in the history, and resumes exactly where it left off after an outage or a pause.
- Flows publish through a new connectionless publish step
- External systems publish in batches through the Topics API using existing API tokens
- Multiple flows subscribe through a Topics listener, each keeping their own cursor
- Failed events land in error management with retry
Network policies
A stolen credential is useless from outside an approved network. Define named, reusable IPv4 and IPv6 allow and deny lists once and apply them across workspace logins, MCP servers, end-user authentication, and API tokens without re-entering ranges on each resource. PATs inherit the workspace policy automatically.
Enforcement begins only after a CIDR is configured, so existing endpoints experience no immediate change in behavior. Blocked logins and calls are recorded in audit and request logs with the source address. Full API support is available for programmatic management.
→ Learn more about network policies
SCIM 2.0 provisioning
Automate user lifecycle management from your identity provider. New team members get the right access the moment they’re added in the IdP. When someone leaves, disabling their account immediately revokes their Celigo sessions, PATs, and API tokens.
- MCP end users arrive with their groups and server access already in place
- Existing invited users are adopted with no duplicates or migration needed
- Per-integration custom access grants are never overridden
- The account owner cannot be deactivated or downgraded via SCIM
Validated with Okta, Entra ID, Auth0, OneLogin, and Google Workspace. Requires the SCIM entitlement alongside SSO.
→ Learn more about provisioning users with SCIM
Long-runtime alerts for flows
Get an email when a flow runs longer than expected, so stuck or slow flows surface before a downstream partner or business stakeholder reports missing data.
Set a threshold per flow or as an integration-wide default. A historical runtime chart covering the last 24 hours, 7 days, 30 days, or 90 days helps you pick a defensible value, with a suggested threshold and estimated trigger frequency to reduce alert noise.
→ Learn more about long-running flows
Celigo Storage query API
Run SQL directly against files stored in Celigo Storage, without a staging database or warehouse round-trip.
Supports CSV, JSON, NDJSON, and Parquet files. Target a single file or an entire folder path. The full SQL dialect is available: SELECT, WHERE, GROUP BY, JOINs, window functions, CTEs, subqueries, and more. Results come back as fully typed JSON.
Common use cases: Aggregating records into a single journal entry, reconciling exports from two systems, deduplicating multi-source file drops, and enriching a transaction file against a customer master before loading.
Celigo Storage: Integration folders, folder transfer, and overage management
Users can now access Celigo Storage via their integrations without requiring Admin rights. Each integration gets its own system folder with permissions inherited from your existing access control.
- Access follows integration roles: Manage roles get full control of the folder’s contents. Monitor roles get read-only access. Files at the root of Storage are visible only to Admins and Owners.
- Whole folders in, whole folders out: Upload an entire folder tree in one action with nested structure preserved, or download any folder as a single .zip. Available to anyone with access to the folder, including Monitor users.
- Stay ahead of storage limits: The View option on the Subscription page breaks usage down by environment, including the contents of the recycle bin. Email alerts fire at 80%, 100%, and 120% of the total allowance, with a link to request an upgrade.
→ Learn more about Celigo Storage
NetSuite REST API support
The NetSuite connector now supports SuiteTalk REST Web Services and custom RESTlets as first-class options for record-based exports, lookups, and imports, without a separate HTTP connection.
SuiteTalk REST is faster than Saved Search at scale, requires no additional SuiteAnalytics Connect license, and gives simpler access to custom records and fields. Celigo now supports all three ways to integrate with NetSuite: Celigo RESTlets, SOAP Web Services, and SuiteTalk REST. Existing integrations are unchanged.
Learn more about using NetSuite REST APIs in exports or imports.
Mapper 2.0 and Transformations 2.0 improvements
Building and maintaining mappings is faster and carries less risk of unintended changes.
- Clone rows to reuse configuration without rebuilding from scratch. Clone a single row, an object, or an entire object array. Destination fields are left empty for you to fill in.
- Set rows inactive to skip a mapping in preview and flow execution without deleting it. Inactive rows and their children are marked visually and excluded at runtime.
- Nested object scoping prevents fields added under one object from copying to siblings automatically.
- Cause record to fail is a new option when a source or input field has no value, available across all import adaptor types.
- Instant preview reflects your latest mapping and body parameter edits immediately, with no extra click needed.
- Empty rows are dropped on save, so your mapping stays clean without manual cleanup.
Learn more about Mapper 2.0 and Transformation 2.0
B2B Manager
Parse and generate EDI X12 and EDIFACT documents on Google Drive, Box, Dropbox, Azure Blob Storage, Google Cloud Storage, and Celigo Storage, using the same EDI profiles already available on FTP, S3, AS2, and VAN.
EDI flows can now route through the file system a trading partner already uses, instead of being forced onto FTP or S3. Parsing, generation, and functional acknowledgment generation behave the same. Celigo Storage now handles EDI, so you can stage EDI documents between flows without external file infrastructure.
Data ingestion
NetSuite JDBC as a Celigo Sync source
Connect NetSuite JDBC as a native source in the Create sync wizard and select multiple objects in a single pass.
- Query via SuiteQL or standard SQL
- Export directly from a NetSuite workbook
- Join across SuiteAnalytics tables without the limitations of Saved Search
→ Create a sync from NetSuite JDBC
Chunk-based streaming for merge imports
Merge operations now load to your warehouse in 250 MB chunks, so records become queryable as each chunk lands rather than only when the full sync finishes. A failure late in a large run no longer requires a restart from scratch. Append and replace mode imports are unaffected.
Microsoft SQL Server as a Celigo Sync destination
Microsoft SQL Server is now a supported destination in Celigo Sync, joining Snowflake and NetSuite Analytics Warehouse.
→ Create a sync to Microsoft SQL
Object-level selection for manual runs and full resyncs
Choose which objects to include when triggering a manual run or a full resync, rather than running every object each time.
- Resync a single object after a schema change
- Re-run only the objects that failed
- The selection list shows each object’s last-run status
- Unselected objects keep their data, sync state, and last-run status untouched
- Run details reflect only what you selected, so record counts, durations, and errors match the actual run
- Scheduled runs continue to process every object on the sync
→ Learn how to choose objects to include in a sync
Read the full release
This post focuses on the biggest October updates. For the complete list of shipped changes, including technical enhancements, fixes, and smaller updates, use the changelog.
Integration insights
Expand your knowledge on all things integration and automation. Discover expert guidance, tips, and best practices with these resources.