Sign in
Open the appliance web address. Anonymous visitors see only the sign-in page; use the owner account created at setup, or your company identity once SSO is configured.
First conversation
Chat answers from the local model by default. Ask it to check its working folder or read a file - you will see the tool calls it makes, and each one lands in the audit trail.
First governed task
Give it a real task in plain language. Read-only tools run immediately; anything destructive waits in Approvals until a person allows it. The Audit page shows the signed record of what actually happened.
Choose the brain
Settings carries the agent brain: local (sovereign) or a stronger cloud model (OpenAI, Azure OpenAI, GitHub Models, or an OpenAI-compatible gateway). Switching to cloud requires explicit consent - task text leaves the machine - and the consent is recorded in the audit trail.