Architecture
One Runtime, Every Channel
The same rules everywhere a request comes from.
Web, voice and API share one versioned runtime, so the same rules apply wherever a request comes from.
Governed By Construction
- Every turn resolves against a typed capability registry — one source of truth for what BOB can be asked to do.
- Each request is checked against identity, workspace membership and permissions before anything runs.
- Unavailable capabilities are refused explicitly — never silently attempted.
Traceable By Construction
- Allowed and denied requests are both written to a tenant-scoped audit trail with the reason for the decision.
- Channels differ in what they allow — WhatsApp, for example, is stricter than web — but the engine is the same.
What It Does Not Do Yet
- The registry is versioned — capabilities change deliberately, not silently.
See It In Your Own Workspace.
Demo workspaces start in sandbox mode — no live data, no executions, nothing leaves the building.