AI Copilot
The platform, operated in plain language.
A copilot that runs real platform commands from a chat surface — with the tenant's own AI provider, the tenant's own cost caps, and an audit line for every tool call.
Image slot — asset to come
Visual: an early design frame of the Copilot pane.
In development — this page describes what the module is being built to do, not what you can install today.
- Tenant's choice
- AI provider
- 4 levels
- Cost caps
- Every one
- Tool calls audited
Ask, and it does
Type what you want in plain language; the copilot executes the same commands and queries your team would click through.
- “Create a draft invoice for Acme Holdings for €5,000 due in 14 days”
- “Show me the customers who haven't paid in 30 days”
- “Summarise this week's chat in #support”
- Answers stream token by token, live
Image slot — asset to come
Visual: the copilot answering a plain-language request, early design.
Everywhere in the panel
The copilot is one pane away from any screen, and a first-class bot inside Chat.
- A floating pane any module can embed on its own pages
- A launcher in the panel's top bar
- @copilot inside a chat conversation answers in-channel
Your provider, your bill
Each tenant picks its own AI provider and holds its own keys — a compliance decision, not a platform default.
- Provider choice per tenant, including EU-hosted options
- Credentials encrypted the same way payment keys are
- Costs metered per call: per session, per user, per tenant, per day
- Sellable as a metered add-on through the Subscriptions module
Image slot — asset to come
Visual: the provider settings with cost caps, early design.
Auditable by design
Every tool the copilot can touch is declared, and every use of one is recorded.
- A registry of tools, each declared by the module that owns it
- Every invocation logs the user, the tool, a redacted argument snapshot, the cost and the latency
- The audit table is immutable and separate from the general audit log
What every module inherits.
- Installs from the marketplace with no redeploy — the menu and the permission list update immediately.
- Creates its own tables, in its own schema, inside that customer's database.
- Packages are cryptographically signed when they are built, and the signature is checked before the host unpacks one.
- Uninstall switches a module off and keeps its data. Dropping the tables is a separate, deliberate choice.
Works with
Curious where AI Copilot is heading?
Thirty minutes, a live workspace, and an honest view of what is built and what is still ahead.
Book a call