Architecture

One Runtime, Every Channel

The same rules everywhere a request comes from.

Web, voice and API share one versioned runtime, so the same rules apply wherever a request comes from.

Governed By Construction

  • Every turn resolves against a typed capability registry — one source of truth for what BOB can be asked to do.
  • Each request is checked against identity, workspace membership and permissions before anything runs.
  • Unavailable capabilities are refused explicitly — never silently attempted.

Traceable By Construction

  • Allowed and denied requests are both written to a tenant-scoped audit trail with the reason for the decision.
  • Channels differ in what they allow — WhatsApp, for example, is stricter than web — but the engine is the same.

What It Does Not Do Yet

  • The registry is versioned — capabilities change deliberately, not silently.

See It In Your Own Workspace.

Demo workspaces start in sandbox mode — no live data, no executions, nothing leaves the building.