Employee Smart Assistant
Super AdminAccount
Administrator
Super AdminTenants
Create and manage workspaces. Suspend, resume, force sign-out, or sign in as a tenant's user for support.
No tenants yet.
Create a workspace above to provision an isolated tenant.
| Name | Slug | Status | Plan | Subscription | Users | Created | Actions |
|---|
Platform billing
Cross-tenant commercial operations. Assign plans per workspace on Tenants.
Billing is not enabled on this deployment.
Plans & trials
Configure subscription tiers, feature bundles, limits, and free-trial defaults.
Billing is not enabled on this deployment.
Platform policy
Enable commercial billing and configure the provider and marketing defaults.
Days before the end date at which the in-app banner and email warnings begin.
Applies to manually-assigned plans. During grace the workspace is read-only; after grace it is fully suspended. 0 = suspend on the first daily check after the end date. Stripe/Moyasar plans renew automatically.
Comma-separated. The sales contact email above is always included.
Free trial defaults
Applied when a workspace is set to Trialing without explicit dates.
Plan catalog
Set features and limits for each plan. Changes apply to the active catalog version.
| Setting | Enabled / value |
|---|
Platform Security
CORS allowed origins, CSRF protection, and HTTP security headers for the whole deployment.
Origin changes apply immediately. Toggle changes apply on the next request.
Comma- or newline-separated. Include scheme and port, e.g. https://app.example.com.
Protections
Advanced. Leave empty to use the built-in SPA policy — a malformed value can break the app UI.
Super Admins
Platform superadmins can manage every workspace. Grant this only to trusted operators.
Add a super admin
Create a brand-new platform operator account.
Promote an existing account
Grant super admin to a current workspace user.
Current super admins
Operations Dashboard
Central visibility for system health, user activity, and governance alerts.
Governance Panel Alerts
Stale connectors, quota issues, and other governance signals.
No alerts found. System healthy.
Governance issues such as disabled MCP connectors will show up here.
| Time (UTC) | Alert Type | Severity | Message |
|---|
Users Management
Manage accounts, roles, company access, and token limits.
No users found.
Add a user or import from ERP to get started.
No users found.
User Usage Tracking
Per-user Personal Assistant queries and token usage.
No usage data.
Usage appears after users chat with the Personal Assistant.
| User | Queries | Tokens | Lifetime / Limit |
|---|
Billing & plan
Workspace subscription, usage meters, and upgrade options.
—
—Usage this period
Included features
Audit Log
Permission, domain, company, account, and password changes (newest first).
No audit entries yet.
Admin changes to users, permissions, and accounts are recorded here.
| Time (UTC) | Actor | Action | Target | Details |
|---|
Knowledge Base
Add trusted documentation so the assistant can answer policy and process questions with reliable references.
Use it for: system user guides, finance and admin policies, SOPs, and other business knowledge not stored in ERP.
Example questions: "How do I generate a sales report?" or "Am I allowed to approve this request?"
Upload & Index Document
Tip: use clear document titles and tags to improve retrieval quality.
Indexed Documents
Review what is searchable by the assistant.
No documents yet
Upload policies, SOPs, or user guides so the assistant can cite them when users ask process or policy questions.
Observability Metrics
Monitor request volume, response speed, token usage, and recent failures.
Recent Errors
Latest failed requests from the last 7 days.
No recent errors.
When requests fail, they appear here with status and latency.
| Time (UTC) | Request ID | Endpoint | Status Code | Latency (ms) |
|---|
Appearance
Choose the color scheme for the interface.
Theme
Language
Set the display language for the interface.
Theme Customization
Adjust primary and neutral tones and base font size. Changes apply immediately; they are stored in the browser like the light/dark preference.
Primary color
Choose the primary action color used for buttons, links, and active states.
Neutral color
Tints secondary text and muted UI; blends with your main text color for readable contrast.
Font size
Base size for the interface and chat messages.
Font Color
Override the default text color. Resets when you switch theme.
Models
Manage which AI models are available across the platform.
Add a model
Choose a curated model from the catalog or register a custom endpoint.
- OpenAI
- Anthropic
- Gemini
- OpenRouter
- DeepSeek
- Kimi
- Private LLM
- Ollama
Configured Models
Edit, enable/disable, or remove models registered in this workspace.
No models configured yet
Add one from the catalog or register a custom endpoint.
| Label | Provider | Model ID | Source | Tier | Max Tokens | Recommended | Actions | Enabled |
|---|
AI Fallback
Automatic premium→free model fallback: provider health, routing policy, and switch history.
Provider health
Fallback policy
Fallback history
| Time | User | From | To | Reason | Switch (ms) | Error |
|---|
Workflows
All durable workflow instances in this workspace: monitor, cancel stuck runs, and trigger recovery.
Workspace health
Instance counts by status. Click a tile to filter the list below.
Instances
| Workflow | Owner | Status | Step | Updated | Detail | Actions |
|---|
Integrations
Connect your ERP or business system to power AI responses with live data.
No integrations yet
Before chat can answer questions about orders, inventory, or customers, connect your ERP data source. Add an integration to enable ERP mode with live answers.
One-time setup · takes a few minutes
Add integration
ERP (on-prem)
SQL database, OData sign-in, and schema cache for your NST deployment.
Schema Cache
Clear cached schema for a specific company when table structures change.
Connection details
Agent Builder
Create named AI assistants with custom prompts, model overrides, and data restrictions.
New Agent
Define prompts, model, domains, skills, and KB scope for this assistant.
Prepended to the standard ERP prompt. Leave mode-specific ERP SQL rules intact.
Optional: force a specific model for this agent.
Unchecked = no restriction (all domains).
Pick which skills (built-in tools, MCP connectors, custom HTTP tools) this agent can use. Leave all unchecked to inherit the caller's role-level access.
Comma-separated tags. KB retrieval restricts to documents whose tags match any of these. Leave empty to allow all KB docs.
Available to install
Ready-made agents for your connected system. Installing adds them to your agents, disabled — you choose what to switch on.
Your agents
No agents yet. Click "+ New Agent" to create one.
Specialized agents can restrict data domains, override the LLM, and scope knowledge-base retrieval.
Scheduled Reports
Automate recurring ERP queries and deliver results via email or webhook.
New Report
Set what to run, when to run, and where to deliver.
Standard 5-field cron: min hour day month weekday
Enabled reports run automatically on their schedule.
Dry-run preview
Query executed; nothing was delivered.
No reports yet. Click "+ New Report" to create one.
Schedule BI queries to run automatically and deliver results by email or webhook.
Run History
Skill Store
Browse every skill the platform exposes — built-in tools, MCP connectors, and custom HTTP tools — and configure per-agent access.
No skills match the current filter.
Tools
Browse all tools available to the AI — built-in, MCP, and custom HTTP.
New Custom Tool
Register an HTTP endpoint the AI can call with typed parameters and optional auth.
No tools match the current filter.
Use "+ New Tool" to add a custom HTTP endpoint, or open MCP Connectors to manage integrations.
MCP Connectors
Connect external MCP servers to expose their tools to the AI.
New MCP Connector
Point the agent at an MCP server endpoint and control who can use its tools.
No MCP connectors yet. Click "+ New Connector" to add one.
Add SSE or HTTP endpoints, or use built-in system connectors like Outlook and Telegram.
Channels
Link Telegram (and soon WhatsApp / Teams) so you can chat with the assistant from those platforms.
Inbound bot webhooks for Telegram, WhatsApp, and Teams. Users link their account once via /bind, then chat with the assistant from the platform.
Linked accounts
No channels linked yet.
Link Telegram
- Open Telegram and message your organization's bot.
- Send
/bind— the bot replies with a 6-character code. - Paste the code below and click Link.
Telegram
Telegram bot
unknown
Telegram bot
Talk to @BotFather on Telegram to create a bot, then paste the token and a strong webhook secret below. Telegram requires HTTPS for webhooks — use a tunnel (cloudflared / ngrok) in development.
-
1
Bot token —
-
2
Webhook secret —
-
3
Webhook URL —
Bot credentials
Stored encrypted in the secret store. Leave blank to keep the existing value.
Echoed by Telegram
in X-Telegram-Bot-Api-Secret-Token. Anything random and ≥32 chars is fine.
Webhook
Telegram POSTs every message to this URL. Must be reachable over HTTPS.
Default:
Microsoft Teams
Microsoft Teams bot
unknown
Microsoft Teams bot
Register an Azure Bot, enable its Microsoft Teams channel, and point the messaging endpoint at
/api/channels/teams/webhook. Paste the bot's app id and client secret below. Teams
senders auto-link to users who connected Microsoft in their Outlook settings.
Default messaging endpoint:
Bot credentials
Microsoft App (client) id of the Azure Bot registration. Leave blank to keep the existing value.
Stored encrypted. Leave blank to keep the existing value.
Usually
botframework.com for a multi-tenant bot.
WhatsApp
WhatsApp
unknown
Pick a provider, then paste its credentials below. Twilio: point the "When a message comes in"
webhook at /api/channels/whatsapp/webhook. Meta Cloud API: point the app's WhatsApp
webhook at /api/channels/whatsapp/meta/webhook.
Default webhook (selected provider):
Bot credentials
How this workspace sends and receives WhatsApp messages. Switching providers keeps saved credentials for both.
From your Twilio console. Leave blank to keep the existing value.
Stored encrypted. Also used to verify inbound webhook signatures.
The WhatsApp-enabled Twilio number (sandbox or registered sender).
Permanent system-user access token from your Meta app. Stored encrypted.
From WhatsApp → API Setup in the Meta app dashboard (not the display number).
Used to verify inbound webhook signatures (X-Hub-Signature-256). Stored encrypted.
Must match the verify token you enter when registering the webhook in the Meta app.
Set this if you're behind a reverse proxy so signature validation uses the public URL.
Proactive templates
Proactive templates
Pre-approved templates for messages sent outside WhatsApp's 24-hour window (e.g. the morning
digest, which looks for one named morning_digest with a single body variable
{{1}}).
No templates registered.
| Name | Content SID | Lang | Description |
|---|
Microsoft 365
Outlook mailboxes
unknown
Outlook mailboxes
Connect personal mailboxes for summarize and reply. Requires an Azure app registration with Graph scopes and the redirect URI below.
Azure app credentials
Stored encrypted. Leave blank to keep the existing value.
Default:
— add this exact URL as a
"Web" redirect URI in your Azure App Registration.
Opens Microsoft login after save. Requires the outlook permission on your account.
Routing & conversation behavior
Behavior of chats over Telegram, WhatsApp and Teams.
Only runs on your Connector-mode model — messages are never sent to a third-party model for routing. When off, ambiguous messages stay in the previous mode (keyword routing still applies).
After this many idle hours a channel chat starts a fresh conversation. 0 disables.
All linked accounts
Every channel ↔ user link across the system. Revoking forces the user to /bind again on the next inbound message.
No channel bindings yet.
Users appear here after they complete /bind on Telegram, Teams, or WhatsApp.
| Channel | ERP user | Display name | Channel id | Bound at |
|---|
Auto-routing telemetry
How auto mode routed recent messages between PA and Connector. Message text is never recorded.
No routing decisions recorded yet.
Decisions appear here once users chat in auto mode (/mode auto).
| When | Channel | ERP user | Route | Decided by |
|---|
Tool Audit Log
Record of every tool execution — user, tool, duration, and outcome.
No tool calls recorded yet.
Executions appear here when the assistant invokes tools during chat.
| Time | User | Tool | Type | Args | ms | Result |
|---|
Feedback & Issue Reports
Thumbs up/down ratings and user-submitted issue reports across assistant responses.
Rating reason tags
Issue reason tags
Recent issue reports
No feedback recorded yet.
Ratings and issue reports appear here once users respond in chat.
| Time | User | Tags | Comment | Session |
|---|
Company profile
How we are as a company — injected into every chat for all users. Set tenant defaults, then optional overrides per ERP legal entity.
User Memories
Cross-user view of persistent memories the assistant carries into every chat turn. Filter by user or category, audit history, force-forget anything.
| User | Category | Content | Source | Created | Status |
|---|
No memories match your filters.
Try clearing filters or click a user card above to focus on one account.
Policy Simulator
Preview a user's effective permissions, data domains and company scope, and run "what-if" probes — nothing is persisted.
Choose someone in Run as above — we’ll show their effective permissions and let you run safe “what‑if” checks.
Permissions
Green = granted (role default or override). Red = denied.
Data domains
Allowed companies
Tools the user would see
What‑if probes
Run safety gates without persisting changes.
What-if: chat request
What-if: SQL validation
What-if: flip a permission
Toggle one or more permissions and see the resulting diff. Nothing is saved.
Approval decisions
Recent gated tool calls from the durable ledger. Replay re-evaluates a call under the CURRENT policy — nothing runs, nothing is persisted.
| Time | User | Tool | Status | Resolved by | Policy replay |
|---|---|---|---|---|---|
| No gated calls recorded yet. | |||||