Meet Novi. The AI teammate with your whole company in her head.
Novi is a deployed, working business agent. She reads where your team already works — Google Chat, Meet, Loom, Drive, Telegram — remembers with permission awareness, answers with citations, and acts: tasks, projects, durable memory, live operational data, images, web research, and delegation to engineering agents. All through one governed brain.
The model is not the product. The governed operating layer around it is.
Most business AI feels shallow because company context is fragmented.
Chat threads, meetings, SOPs, dashboards, vendor notes, Drive docs, and operational databases all hold pieces of the truth. The company brain gives Novi and connected agents a governed way to remember, cite, and act on that context.
What happened
Raw messages, meeting transcripts, Loom and Telegram voice transcripts, source links, action items, image metadata, reminders, turn logs, and audit trails live in Supabase.
What the company decided
Reviewed SOPs, decisions, project summaries, recurring workflows, and lessons become indexed notes — with governance tiers up to company rules and laws — then get promoted into a human-readable GitHub/Obsidian vault.
What is true right now
Novi can use guarded tools for tasks and projects, Drive search, thread summaries, live operational systems, public web search, image flows, her own codebase, and delegation to engineering agents.
A general business assistant, not a search box.
Ask in plain language, in the tools your team already uses. Novi figures out which of her capabilities the request needs, checks permissions, and does the work.
"What did we decide about the Q3 supplier?"
Permission-filtered hybrid search over everything ingested — chat, meetings, Looms, docs, notes — with citations on every answer and four retrieval depths from cheap to deep.
"Add a task, mark it done, start a project."
Action items are created and updated instantly and audited. Projects and durable memories are drafted first, then created only after you confirm the exact record.
"Are any fulfillment orders blocked?"
Read-only connectors into operational Baserow and MySQL answer with current state — sync health, app errors, order status — always stamped "checked live at" and never passed off mock data as real.
"Novi, remember this."
Novi drafts the exact durable note — title, body, type, tags, visibility — and saves only after you confirm. Notes are searchable immediately and flow through review governance to the curated vault.
"What's in this screenshot?" "Make me a diagram."
Images posted in Chat or Telegram are stored privately and used as vision context. Novi can repost any stored image you're allowed to see, or generate new images and post them back to the conversation.
"Ask the engineering agent to build it."
Novi hands scoped software tasks to registered engineering agents (e.g. Hermes), which work autonomously and open a PR for human review. High-risk work is held for admin approval before it starts.
Nobody falls through the cracks.
If someone is @-tagged in a channel and hasn't replied in 24 hours, Novi posts one polite, batched nudge. An emoji reaction counts as a reply; "cc/fyi" tags never nag; history imports never trigger pings.
Assignments get noticed, never auto-filed.
Novi can scan normal channel conversation for assignments and resolutions, then ask in-thread: "Track this as an action item?" Nothing is created until a person clicks confirm — and the click is re-authorized server-side.
"Novi, how do you handle permissions?"
Novi can search and read her own source code and docs, answer with commit-pinned permalinks, and even file a scoped change request for her own behavior — after you confirm the spec.
The Brain API is the gatekeeper.
Google Chat and Telegram are the user surfaces, and the same Brain API and MCP connector expose controlled access to external agents. No side agent gets database credentials or bypasses permission checks.
The chat agent is a planning tool loop, not a single-shot chatbot.
Every DM or mention runs the full agentic loop: plan, pick a tool, pass its permission guard, execute, observe, repeat as needed, then synthesize a cited answer. Novi posts a 🤖 working indicator instantly and edits it in place when the answer is ready, so slow multi-tool turns never time out.
Real conversation memory: Novi stores both your turns and her own replies per conversation, so "what did you just say?" and "what about that other customer?" work like talking to a person.
A personality: a warm, sharp coworker with opinions — leads with the answer, brief by default, dry humor when it fits, flags risks early, and says "I can't see that" plainly. Tone tightens automatically in shared channels.
Quality-gated: offline agent evals and a quality gate run before any prompt, tool, or retrieval change ships; every turn writes a sanitized, gradeable trace for diagnostics.
DM answers use requester access. Channel answers use requester access intersected with audience access. Private DMs, sensitive channels, protected images, and restricted Drive files never leak into broader answers — and tool selection by the AI is never authorization: every tool runs its own server-side guard before executing.
Every tool Novi can pick up — all guarded, all audited.
This is the complete shared registry behind Novi in chat and the ask_novi MCP surface. Read tools are always available; write and action tools are offered only to callers allowed to write, and several require an explicit draft-then-confirm step or admin authority.
Memory, threads, and the public web
Permission-filtered hybrid search over chat, meetings, Looms, docs, and notes — with conservative, balanced, deep, and legacy semantic modes and citations on every result.
Key points, decisions, and open questions from the current Chat thread, Telegram DM, group, or forum topic — only messages the audience may see.
Grounded public web search for current or external facts the brain can't answer — labeled, cited, freshness-stamped, and treated as untrusted data that never overrides company memory.
Getting work tracked and done
Your open tasks, filterable by status, with private items withheld from channel answers (and a nudge to DM for them).
Adds a task instantly — title, details, due date, priority — inheriting the visibility of where it was created.
Mark done, reopen, reschedule, rename, reprioritize, or add resolution notes — by id or just a distinctive part of the title.
Drafts a first-class project record (including from a pasted pod-profile) and creates it only after you approve the draft.
Capture, governance, and supersession
The "@novi remember this" flow: drafts the exact note — title, body, type, tags, confidence, visibility — and saves only after explicit confirmation.
Moves a note through review: request review, review, accept, reject, or deprecate. Admin-only transitions are enforced server-side.
Replaces an accepted fact, rule, SOP summary, or decision with a new note and marks the old one superseded — truth changes by replacement, never silent edits.
Finds documents, messages, or accepted notes the candidate may duplicate or contradict, and files reviewable conflict rows before anything is accepted.
Marks a conflict resolved or dismissed after human review — required before accepting a candidate with open conflicts.
Lets any team member propose a change to accepted knowledge instead of editing it directly.
Accept, reject, or cancel an open change request.
Applies an accepted supersession request through the same governed replacement path, preserving who approved it.
Elevates reviewed knowledge to rule tier — higher-authority memory that ranks above ordinary notes.
The highest tier: company law. Feature-flagged, admin-only, fully audited.
The files your team actually works in
In a DM, searches Drive as you — results are exactly the files you can open. In a channel, searches only admin-mapped folder roots so a requester's extra access can't leak files to the room.
Drafts and, after explicit approval, activates the Drive folder roots a channel may search.
Lists active and disabled Drive roots mapped to each channel.
Disables or re-enables a mapping without deleting its audit history.
What is true in the business right now
Manufacturing and fulfillment orders straight from operational Baserow — current production and fulfillment state, stamped "checked live at".
Application state from MySQL: data-sync health, recent app errors, and customer or vendor status — read-only, never stale chat summaries.
Seeing and creating, inside the permission boundary
Pulls up a previously stored image the requester and audience may access and posts it back into the current Chat or Telegram conversation.
Generates a new image from your prompt, stores it under the conversation's visibility, and posts it back — no public URLs, ever.
Novi as a working colleague — and her own expert
Hands a software task to a registered engineering agent that works autonomously and opens a PR for human review. High-risk work (deploys, migrations, credentials) is held at an approval gate.
Releases a held high-risk delegated task — admin-only, refused for anyone else.
Searches Novi's own source repository to answer "how do you work?" questions with commit-pinned links.
Reads exact files and line ranges from her own code and docs, citing immutable line-anchored permalinks.
Scopes a change to Novi's own behavior into a structured spec, shows you the draft, and files it to the engineering agent as a GitHub issue only after you agree.
Connected agents and IDEs get additional direct-contract tools through the per-user connector: ask_novi (the full loop), answer_from_brain, write_brain_memory (immediate indexed write for trusted callers), promote_to_curated_note, and create_reminder — all scoped to the calling user's token.
read retrieval only write creates or changes records, audited action outward-facing effect admin server-enforced authority draft → confirm a human reviews the exact artifact before it exists.
She doesn't just answer. She notices.
The brain runs background workers that watch for dropped balls and turn raw activity into structured work — always with a human in the loop before anything binding happens.
Unanswered tags get one smart bump
Tagged and silent for 24h? Novi posts one batched, @-pinging nudge per thread. Emoji reactions count as replies, "cc/fyi" runs are exempt, and history imports never trigger pings.
Assignments become proposals
Novi can scan normal conversation for assignments and resolutions and ask in-thread before tracking anything. The confirm click is re-authorized server-side; nothing is auto-filed.
Notes land where the team works
Company-visible meetings can post their summary and action items to a named Chat channel automatically — deduped per meeting, never leaking invite-only content to broader rooms.
Docs stay current on a schedule
Scheduled Drive SOP resync keeps ingested procedure docs aligned with the live files, so answers cite the version your team actually follows.
Raw history becomes durable knowledge only after review and promotion.
The vault is not the retrieval database. Supabase is the searchable source of truth; the vault is a human-readable GitHub/Obsidian mirror of accepted, promoted notes.
During the conversation
Novi drafts title, body, memory type, tags, source summary, and inherited visibility. The user confirms before anything becomes durable. A bare /novi remember opens a form, same review flow.
From Drive and SOPs
Drive/SOP text is ingested into document rows and indexed chunks, with scheduled resync. The editable SOP stays in Drive; durable notes cite and summarize it.
Conflicts, requests, tiers
New candidates are checked for conflicts against existing knowledge. Anyone can file a change request; admins accept and apply via supersession. Rules and laws sit above ordinary notes as higher-authority memory.
The Brain is not only for chat.
The same governed brain powers IDEs, coding agents, and dashboards. A personal token represents the user — it can only read or write what that user can.
Per-user MCP tokens
Claude, Codex, Cursor-style tools, Hermes, OpenClaw, and dashboards connect through the Brain API or the published brain-connector MCP server. One npx command and two env vars and your agent has the company brain.
ask_novi— the full plan → tools → cited-answer loopsearch_brainandanswer_from_brainwrite_brain_memoryandpromote_to_curated_notelist_action_items,create_action_item,update_action_itemcreate_reminderandsummarize_thread
Agents can work, but not free-run
Novi hands scoped work to registered agents such as Hermes. High-risk actions like production writes, merges, migrations, credential changes, or customer-visible changes require approval gates and audited callbacks.
Chat request -> Novi -> delegated task -> connector -> status callback -> Novi updates the thread with the PR link.
External agents do not connect directly to the database, scrape protected images, or bypass Brain API permissions.
The brain listens where the team already works.
Google Chat is the primary interface and Telegram is live alongside it — including voice. Meetings, Looms, Drive docs, and compliant manual imports round out the record.
Primary surface
DMs work instantly for org users — no admin setup. Channel mentions, passive ingestion, history backfill, images as vision context, thread history, and follow-up nudges.
Meetings and videos
Transcript ingestion with action-item extraction. Meetings default to invite-list visibility; a company-wide tag makes them company-visible, optionally posting summaries to a named channel.
Working documents
Metadata-first discovery, explicit document ingest, scheduled SOP resync, and reviewed durable notes that point back to the source file.
Groups, DMs, and voice
Approved groups and linked DMs are logged; photos flow through the same protected image pipeline; voice notes are transcribed and indexed as text. Mention @novi and she answers right there.
A personal memory system asks, "Can my agent remember?" A company brain asks, "Can the system remember the right thing, show it to the right people, hide it from the wrong people, cite where it came from, and let multiple humans and agents use it without turning permissions into a mess?"
Cloud Run API and workers, GitHub Actions continuous deploys gated on build + tests, Secret Manager-backed credentials.
Supabase Postgres with pgvector and deny-by-default row-level security; content chunks, brain notes, actions, projects, audit logs, image metadata, and visibility policies.
Model-routed planning and synthesis, embeddings, versioned prompts, per-call token/cost logging, offline agent evals, and a quality gate before rollout.
Novi in Google Chat and Telegram: instant working indicator, async delivery, durable multi-turn conversation memory, and cited answers.
GitHub/Obsidian mirror for reviewed durable notes, compiled SOP/wiki pages, source manifests, and a "request a change" path for readers.
Permission filtering before model context, per-tool guards, full audit records, draft-then-confirm gates for memory/projects/code changes, admin approval for high-risk delegation, and sanitized traces — no secrets, raw URLs, or private identifiers ever reach logs or answers.