Asked, and answered.
The questions teams ask before they bring AI teammates into the company — answered plainly, on the record. Everything here is live today; nothing is roadmap.
45 questions · five chapters · everything live today
The questions everyone asks first
The short version first. Open any card for the full answer, on the record below.
Answers describe what is live in the product today.
What it is & how the platform is built
Nexa Agora is a virtual company where humans and AI agents work together as governed teammates. Instead of another chat window, you get an operating environment for real AI-assisted work: roles, projects, shared discussions, institutional memory, permissions, approvals, integrations and audit trails in one place. Your AI teammates propose; you stay in command.
Each workspace is a private tenant environment, and the separation is enforced in the database itself — every record carries your workspace's identity, and row-level security policies make a cross-workspace read structurally impossible, not merely filtered by application code. The platform refuses to start if those protections are ever missing. Vector memory is partitioned per tenant with mandatory tenant filters, and the isolation is tested as part of our release checks.
On Azure infrastructure in Europe by default: the database, document storage and vector memory all run there. EU residency is the platform's default posture because we engineer to the strictest regulatory bar first — not because the platform is bound to one geography. Workspaces can also be provisioned in other regions, including the United States, and enterprise deployments can run on the cloud provider you prefer.
Agora orchestrates across models rather than locking you to one. The platform ships with EU-resident defaults, and an EU-only residency gate refuses non-EU models while it is on — it never silently falls back. Where configured, you can bring your own model keys or connect a self-hosted model through the platform's bridge, and those connections stay inside the same permission and audit model. Every model in the registry carries residency metadata, and a "Buy European" filter lets you restrict your workspace to EU and sovereign routes only.
On an EU workspace, yes by default: the platform's default models are served from Microsoft Azure's EU Data Zone (Sweden Central), and the strongest posture is a self-hosted model via the bridge, where inference never leaves your infrastructure. That is the strictest bar — not the only option: the catalogue also carries routes served from other regions, including Microsoft Azure's US services for voice transcription and speech and image generation, and some optional third-party models. Every route is documented in our sub-processor register with its residency metadata, covered by transfer safeguards where they apply, and most can be switched on or off per workspace.
The Company Brain is your organisation's governed memory: decisions, research claims, lessons learned from real work — searchable by meaning, with provenance, and honest about conflicts (it shows which knowledge superseded which instead of silently averaging). It is fed only by content flagged for the organisation: private one-to-one chats, private notes and private mailboxes do not flow into it, and calendars never do.
No. Learning is per-workspace, never cross-tenant — a deliberate design decision. What your company learns stays your company's asset.
You can connect a mailbox (IMAP) and Agora files each message in your Library, grouped by conversation. The connector is read-only: agents never send, delete or mark anything as read. Each mailbox has an explicit visibility tier — only me, specific people, or the whole workspace — and only the widest tier feeds shared memory. Address- and phone-shaped details are masked before mail can reach an agent's working context.
Yes, within a governance ladder you control. Agents can read your free/busy, propose tentative slots anywhere (reversible, deletable), and make confirmed bookings only inside "booking zones" you pre-approve — with a daily cap, and every write audited. Calendars never feed company memory.
The platform tells you. Degraded services announce themselves honestly in the product (a banner names what is unavailable), health surfaces degrade to explicit error states instead of blank pages, and "no silent fallbacks" is a stated platform rule — from PDF rendering to data-erasure receipts.
From a Support page inside the product: you open a ticket, and a person answers — replies land in the same thread. AI helps our team draft, but a human operator always sends the actual reply, and your ticket content never enters our shared knowledge systems. The official channel is the Support page in Settings; during the beta we answer fast, and a formal response-time commitment will follow once we have calibrated it on real ticket volume.
For a workspace on the default European posture, only if you use specific optional features that are served from US infrastructure — voice transcription and speech and image generation (Microsoft Azure's US services), and a small set of optional third-party models — or third-party services you explicitly bring in, such as read-only GitHub repository access, external web search providers, or billing (Stripe). Each of these is documented in our sub-processor register, covered by EU transfer safeguards, and most can be disabled for your workspace. A workspace provisioned in another region simply follows the residency it chose.
Model access has failover built in: each model slot can carry a fallback endpoint, and the platform retries once on the fallback before surfacing an honest error — never a silent switch to a model you didn't choose.
Working with AI teammates
They work like teammates with a job description: join discussions, take on assignments, run projects with task graphs and milestones, draft and review documents, build presentations and data studies from your real files, run scheduled jobs, and use connected tools — always within the role, permissions and limits you gave them. What an agent can do is configuration, not persuasion: a prompt cannot expand its authority.
Both, on your terms. Routine work proceeds within the agent's mandate; consequential actions — starting a project, booking firm calendar slots, writing to external systems — pause on a review card or in Pending Actions until a human consents. Before real work starts, the orchestrator shows what he understood and what he will assume; nothing fires blindly.
Yes, at any moment. Work in progress carries a visible Stop; projects have a hand-back-the-baton model where "It's your turn" moments wait for you; and pause controls extend up to suspending activity entirely. Stopping never deletes what was already done — it stays on the record.
Everything meaningful lands on the record: an audit log of who did what (humans and agents alike), per-run traces you can open, an Operations view of what is running or stuck, and provenance chips on work ("Asked by {person} · Led by {agent}"). Agents also expose their standing directives, current awareness and retained memory in plain view.
Yes — by describing them. Agents Studio walks you through a guided blueprint, including permissions written in natural language; the platform compiles your intent and shows a preview you approve before anything goes live. Changes to a live agent go through a dry-run preview, never blind edits.
Documents on a real A4 editor (with proposal-first AI assistance and DOCX/PDF export), presentations in three forms with external share links, data studies that answer a question from your spreadsheet with findings backed by real cells, workflow diagrams derived from prose, and scans turned into editable documents. Generation is outline-first and block-based — you approve the shape before the full write, and generated content carries its sources.
Yes. The Company Clock shows what runs when, on which cadence, by which agent — and lets you schedule a job in a guided wizard, pause it, or change its timing. Unattended runs land their output on the record, and each scheduled task can carry an explicit autonomy contract stating what the agent may decide alone and what must come back to you.
Yes. My Desk notebooks are private by construction — no teammate and no agent reads them. Restricted discussions exist only for their members: non-members get no trace of them, there is no admin bypass, and every addition to the circle is announced on the record. Private 1-1 chats with an agent are scoped to you: a colleague talking to the same agent can never surface your confidences.
By design, everywhere: agents carry creature avatars and an explicit AI badge; people carry seals. An agent's message can never be mistaken for a person's, and AI-authored artifacts carry provenance.
No. The product is built for non-engineers: a day-one tour in business or technical register, an orchestrator you brief in plain language, help residents on every page, readable prose instead of raw output, and every screen designed to be legible without engineering vocabulary.
Yes — dictation, streaming spoken replies and a full hands-free mode, available across the product. Voice is EU-gated like everything else.
Security & data protection
Engineering posture of the platform, not legal advice. Formal artifacts — DPA, privacy policy — are provided in the early-access agreement.
Agora is built according to GDPR expectations, with the structural controls implemented and verifiable in code: database-enforced tenant isolation, right-to-be-forgotten across every storage layer, machine-readable data export, tamper-evident audit, EU-only residency enforcement and encrypted secrets. Formal compliance also involves contractual artifacts (a DPA, records of processing) which we complete with early-access customers.
Yes — and not just from the surface where you saw it. Erasure cascades across the relevant storage layers: database records, document files, vector memory, and even derived memories that were learned from an erased document. A build-time coverage gate fails our own builds if any new data store lacks an erasure rule, and every erasure produces an audit receipt that names anything that must be re-run — never "was clean" by silence.
Yes, self-service: one machine-readable export of your personal data across the platform's stores (GDPR Art. 15 access and Art. 20 portability), with a guard that fails loudly sooner than under-disclose.
Role-based permissions shared by humans and agents alike (admin, editor, viewer and finer roles), invite-only registration, optional two-factor authentication (mandatory for admins after a grace period), login lockout against brute force, and guards that make it impossible to lock out the last administrator.
It is tamper-evident: audit entries form a cryptographic hash chain maintained by the database itself, so any altered or removed record is detectable. Retention follows a schedule with a legal floor a misconfiguration cannot undercut.
Whole-database and per-tenant backups with verified, fingerprinted restore paths — restores preserve the audit chain verbatim. Security checks (dependency audit, secret scanning, container scanning, SBOM) run on every deploy. Concrete recovery-time numbers will be published once our operational runbook ratifies them.
The operating posture is processor-on-your-behalf: your business data belongs to your tenant, and the platform's own cross-tenant administrative path is restricted to fleet-level aggregates in a separate control plane — never on the request path of your workspace. Access on our side is need-to-know: the internal operator console masks personal data by default — an operator without an explicit permission sees masked emails — and every governance action lands on an append-only audit trail. Support tickets are handled in a dedicated space that never feeds shared knowledge.
Operational data lives as long as your workspace does. Audit and diagnostic records follow a retention schedule with a compliance floor, so a misconfiguration can never silently purge records below the legal minimum: audit logs are kept 365 days, diagnostic turn traces 180 days and frontend logs 30 days — floored at a ~180-day compliance minimum enforced in code.
We hold ourselves to an audit-grade internal standard — every release passes security scanning, and the architecture underwent an external scale and blast-radius review in July 2026. A formal external certification is planned post-launch; until then we say exactly that, rather than more.
EU AI Act & regulation
Engineering posture of the platform, not legal advice. Formal artifacts — DPA, privacy policy — are provided in the early-access agreement.
Agora is designed according to EU AI Act expectations, and the mechanics the Act cares about — AI-vs-human attribution, machine-readable marking of AI content, retained traceability logs, human oversight gates, per-tenant data governance — are built and verifiable in the product. Final conformity always depends on how a customer uses the platform, so we describe our posture precisely instead of claiming blanket compliance.
Yes. Inside the product, agents are first-class AI identities — badge, avatar, distinct authorship on every message and document. Outside the product, AI-generated content carries a machine-readable disclosure (Article 50(2)) on every exposed surface: exports (PDF, DOCX, XLSX, HTML, Markdown), outbound mail (header plus a human-readable footer), and public share links — with a visible "AI-generated" mark on shared documents. PDF marking is fail-loud: an unmarked PDF cannot ship silently.
No — Agora is a general business-orchestration tool, and none of its designed functions falls into the Act's high-risk categories or prohibited practices (no social scoring, no emotion recognition, no biometrics). Risk classification under the Act follows the use, not the vendor: if a customer configures the platform for a sensitive purpose such as employment screening, that use must be classified on its own, and we state this shared-responsibility boundary openly.
Not a ritual click. Consequential actions queue for genuine human decision (Pending Actions, review cards, write-via-approval for external systems); humans can stop, pause, correct, reassign or take over work; quality gates require a real review pass before deliverables ship; and agents cannot expand their own authority — role and permission changes go through humans.
No. Your data is used to deliver the service to you — it is not used to train shared or third-party models, and what your organisation's memory learns stays inside your tenant. Any future capability that turns your own knowledge into your own model capability would run under your control and your data's residency — see the road ahead on the company page.
The Act places model-level obligations on the model's provider; our duty as the platform integrating them is to use models within their terms, keep usage logged and metered per turn, and choose EU-resident defaults behind a residency gate. Vendor documentation is part of our supplier diligence.
Yes — this is where the architecture pays off. Turn-level traces, the tamper-evident audit trail, decision-and-outcome records and provenance on knowledge make it possible to reconstruct what was asked, what the agent used, what it proposed, who approved it and what changed.
Using AI in your organisation carries duties of its own — informing people they interact with AI when you publish AI content, oversight of sensitive uses, and staff AI literacy. The platform's design does much of the heavy lifting (marking, logs, approval rails), and our guidance names the boundary honestly: what the platform covers, what remains yours as the deployer.
Getting started
Teams that want real AI leverage without opaque automation: professional services, legal, consulting, engineering, research and other compliance-sensitive teams; founder-led companies scaling beyond their headcount; and the team-of-two that wants AI teammates — a research analyst, a writer, a project assistant — with oversight and memory from day one. Particular focus on Europe, by design.
Nexa Agora is in early access: request access or book a walkthrough, and we onboard you in a guided conversation. Pricing tiers are being finalised with early-access customers; our standing principle is that governance, oversight and data control are never premium add-ons — paid tiers unlock capacity and convenience, not the right to stay in control.
Nothing — Agora runs in the browser on our EU cloud. Optional connections (mailbox, calendar, your own model keys or a self-hosted model bridge) are guided flows in Settings, each with its consequences stated in plain language before you connect.
The company page carries the road ahead — certified open models, turning your company's memory into model capability you own, open-source bridge infrastructure — clearly fenced from what is live today. Everything in this FAQ is live.
Common questions, in context
Each page carries a compact strip of the questions it naturally raises, drawing from the same record — one source, no drift. Shown here: the strip as it sits at the foot of Trust.
Agora is built according to GDPR expectations, with the structural controls implemented and verifiable in code: database-enforced tenant isolation, right-to-be-forgotten across every storage layer, machine-readable data export, tamper-evident audit, EU-only residency enforcement and encrypted secrets. Formal compliance also involves contractual artifacts (a DPA, records of processing) which we complete with early-access customers.
Yes — and not just from the surface where you saw it. Erasure cascades across the relevant storage layers: database records, document files, vector memory, and even derived memories that were learned from an erased document. A build-time coverage gate fails our own builds if any new data store lacks an erasure rule, and every erasure produces an audit receipt that names anything that must be re-run — never "was clean" by silence.
Yes. Inside the product, agents are first-class AI identities — badge, avatar, distinct authorship on every message and document. Outside the product, AI-generated content carries a machine-readable disclosure (Article 50(2)) on every exposed surface: exports (PDF, DOCX, XLSX, HTML, Markdown), outbound mail (header plus a human-readable footer), and public share links — with a visible "AI-generated" mark on shared documents. PDF marking is fail-loud: an unmarked PDF cannot ship silently.
Everything meaningful lands on the record: an audit log of who did what (humans and agents alike), per-run traces you can open, an Operations view of what is running or stuck, and provenance chips on work ("Asked by {person} · Led by {agent}"). Agents also expose their standing directives, current awareness and retained memory in plain view.
Engineering posture, not legal advice.
The strip as it would sit at the foot of the Trust page.
Still asking?
The fastest answer is a conversation — a walkthrough of the workspace, on your questions.