Skip to content
In development

AI Copilot

The platform, operated in plain language.

A copilot that runs real platform commands from a chat surface — with the tenant's own AI provider, the tenant's own cost caps, and an audit line for every tool call.

Image slot — asset to come

Visual: an early design frame of the Copilot pane.

In development — this page describes what the module is being built to do, not what you can install today.

Tenant's choice
AI provider
4 levels
Cost caps
Every one
Tool calls audited

Ask, and it does

Type what you want in plain language; the copilot executes the same commands and queries your team would click through.

  • “Create a draft invoice for Acme Holdings for €5,000 due in 14 days”
  • “Show me the customers who haven't paid in 30 days”
  • “Summarise this week's chat in #support”
  • Answers stream token by token, live

Image slot — asset to come

Visual: the copilot answering a plain-language request, early design.

Everywhere in the panel

The copilot is one pane away from any screen, and a first-class bot inside Chat.

  • A floating pane any module can embed on its own pages
  • A launcher in the panel's top bar
  • @copilot inside a chat conversation answers in-channel

Your provider, your bill

Each tenant picks its own AI provider and holds its own keys — a compliance decision, not a platform default.

  • Provider choice per tenant, including EU-hosted options
  • Credentials encrypted the same way payment keys are
  • Costs metered per call: per session, per user, per tenant, per day
  • Sellable as a metered add-on through the Subscriptions module

Image slot — asset to come

Visual: the provider settings with cost caps, early design.

Auditable by design

Every tool the copilot can touch is declared, and every use of one is recorded.

  • A registry of tools, each declared by the module that owns it
  • Every invocation logs the user, the tool, a redacted argument snapshot, the cost and the latency
  • The audit table is immutable and separate from the general audit log

What every module inherits.

  • Installs from the marketplace with no redeploy — the menu and the permission list update immediately.
  • Creates its own tables, in its own schema, inside that customer's database.
  • Packages are cryptographically signed when they are built, and the signature is checked before the host unpacks one.
  • Uninstall switches a module off and keeps its data. Dropping the tables is a separate, deliberate choice.

Curious where AI Copilot is heading?

Thirty minutes, a live workspace, and an honest view of what is built and what is still ahead.

Book a call