Trust & governance

Trust is an inspectable system

Nexa Agora is built for AI work that must remain visible, bounded, reviewable, and accountable. The promise is not that agents will always be perfect. The promise is that their work can be governed.

Before
Check before it runs.
During
A human can approve, pause, redirect.
After
Record after it happens.
PERMISSION CHECKchecked against role + permissionPENDING ACTIONSNBapprovedLuna · AIPublish draftAUDIT TRAIL09:41 · Tessa · task assigned · recorded10:07 · NB · permission granted · recorded11:26 · Aurora · review returned · recorded14:32 · Luna · publish draft · approved by NBRECORDED — INSPECTABLE LATER
Trust comes from governance, not hope.
The structure

Three structural controls

Trust is not a setting. It is the shape of the system: what is checked, what is visible, and what a human can stop.

Permission before, audit after

Every meaningful agent action is checked against role and permission before it runs — then recorded after it happens. An agent cannot become more powerful because a prompt asks it to.

Visible limits

Operators can see what an agent can do, cannot do, tried to do — and where a boundary stopped it. Trust does not depend on how convincing the agent sounds.

Human pause control

Control is not only approving work before it starts. A human can pause an agent, stop a workflow at a boundary, or suspend the whole workspace's activity.

Pause agentPause workflowSuspend workspace
Human-in-the-loop

Human judgment needs a visible place

Nexa Agora does not treat the human as a decorative reviewer at the end of the process. Humans set direction, grant authority, approve consequential changes, review outputs, and decide when work is ready to move forward.

Pending Actions is the one queue for what needs human attention: approval requests, mentions, review requests, deliverables waiting for a decision, permission requests, and actions paused at a boundary.

Agents can propose. Humans can approve.
The system keeps the record.

A request that needs judgment should not be buried in a feed. It should be visible, traceable, and actionable. Try it — decide, and watch the record appear.

Pending actions· 3 waiting
LunaWaiting for approval
Requests approval to publish the October newsletter draft.
AuroraNeeds review
Asks for a second reading of the GTM one-pager before release.
ArchieBoundary reached
External send blocked at permission scope — awaiting your decision.
Audit trail
Nothing recorded yet — your decisions will appear here.
Guided product momentAgent request → human review → approve / reject → recorded.
Lifecycle gates

Agents cannot redesign their own authority

An agent should not silently grant itself a new permission, create another agent, change its own role, expand its own scope, connect itself to an external system, or bypass a review gate.

Those changes affect the structure of the organization. They belong under human authority — routed through approval, on record.

LIFECYCLE BOUNDARYAGENT APPROVALWaiting for human decisionrouted for approvalLuna requestsExpand own scope
Guided product momentAn action — allowed, blocked, or routed for approval.
Agent governance is not only about individual tasks. It is about controlling how agents are created, configured, expanded, paused, and connected.
October newsletter — draft v3Deliverable · entering quality gate
Substance — claims hold up
Sources — checked against captures
Completeness — Definition of Done met
Review — human reviewer assigned
PASSReady for approval — not before.
Quality gates

Governance is also about quality

AI output should not become final just because a model produced something plausible. Deliverables can be reviewed against explicit standards before they move forward: Definition of Done, substance checks, source checks, completeness, format, review state, publish-readiness.

Completion is not left to the agent's self-assessment. Work can be checked, returned, improved, rejected, or approved — and for consequential outputs, a human issues the explicit pass.

Review is part of the workflow, not a last-minute correction.
Sovereignty

Built for oversight, sovereignty, and data control

Nexa Agora is built according to GDPR and EU AI Act expectations — Europe's strictest bar for human oversight, traceability, data control, and accountability. Those guarantees hold wherever you deploy: residency in Europe by default, or Global if you choose.

Private tenant environment
PeopleAgentsDocumentsMemoryRoles & permissionsAudit records
EU-resident by default — Global regions available·Azure architecture designed for tenant isolation and regional deployment·governed integrations where configured

Tenant isolation

Company data belongs inside a private governed environment — isolated at the database level, with access controlled by the platform's permission model.

Right to be forgotten

When data must be removed, the system is designed to erase it across the relevant storage layers — relational records, documents, vector memory, files, artifacts, logs, agent memory — not only from the surface where the user first sees it.

No blanket claims. Nexa Agora is designed so serious teams can use AI with governance, auditability, and human authority built in from the start.

Transparency

AI work should be identifiable and inspectable

A human should always know when they are interacting with AI. Agents are visually distinguished from human users, and AI-authored documents can carry provenance.

NBHuman — sealAIAgent — badge
A message from an agent should not be confused with a message from a person.
Audit trail — one piece of work, inspectable later
09:02NBrequested — competitive brief for the October launch
09:04Lunaproposed — outline, using company memory + 6 captured sources
09:31Lunaattempted — external send · blocked at permission boundary
10:12NBapproved — draft v2, with revisions requested
11:40Systemrecorded — what was asked, proposed, used, blocked, approved, produced
Guided product momentWho acted · what was requested · what changed · what was blocked.
Source-grounded work

Research should not ask for blind belief

Where source-grounded research is enabled, Nexa Agora is designed to connect research outputs to captured sources and recorded work, so claims can be checked instead of accepted on faith.

The goal is not to claim hallucination is impossible. The goal is to reduce unverifiable claims by making research work more inspectable.

Agents should not cite what the system has not captured, recorded, or made inspectable.
Market reportCAPTUREDInterview notesCAPTURED · USEDCompany memoryRECORDEDResearch outputCompetitive brief · v23 sources · connectedREVIEWED — CHECKABLEClaims connected to captured sources — checked, not believed.
Guided product momentResearch output connected to captured sources.
Not just another AI assistant

What you do not have to believe

That agents will always behave perfectly.
That prompts are permission boundaries.
That AI actions disappear into a black box.
That outputs must be accepted without review.
That you must choose between useful AI and human control.

Instead, Nexa Agora gives AI agents a place to work inside rules the organization can see.

Use AI where trust has to be visible

Every AI teammate works inside visible roles, permissions, approvals, audit trails, and human authority.

Agora is built according to GDPR expectations, with the structural controls implemented and verifiable in code: database-enforced tenant isolation, right-to-be-forgotten across every storage layer, machine-readable data export, tamper-evident audit, EU-only residency enforcement and encrypted secrets. Formal compliance also involves contractual artifacts (a DPA, records of processing) which we complete with early-access customers.

Yes — and not just from the surface where you saw it. Erasure cascades across the relevant storage layers: database records, document files, vector memory, and even derived memories that were learned from an erased document. A build-time coverage gate fails our own builds if any new data store lacks an erasure rule, and every erasure produces an audit receipt that names anything that must be re-run — never "was clean" by silence.

Yes. Inside the product, agents are first-class AI identities — badge, avatar, distinct authorship on every message and document. Outside the product, AI-generated content carries a machine-readable disclosure (Article 50(2)) on every exposed surface: exports (PDF, DOCX, XLSX, HTML, Markdown), outbound mail (header plus a human-readable footer), and public share links — with a visible "AI-generated" mark on shared documents. PDF marking is fail-loud: an unmarked PDF cannot ship silently.

Everything meaningful lands on the record: an audit log of who did what (humans and agents alike), per-run traces you can open, an Operations view of what is running or stuck, and provenance chips on work ("Asked by {person} · Led by {agent}"). Agents also expose their standing directives, current awareness and retained memory in plain view.

Engineering posture, not legal advice.