Skip to main content

Governance intelligence for access, cloud, and SaaS. Now in early access

Nuxari
AI Governance Assistant

AI that recommends. Workflows that decide.

Nuxari AI classifies intent, recommends workflows, and explains findings. The backend workflow engine executes. AI never bypasses approval gates or calls external systems directly. Guardrails are architectural, not configurable.

Design principles

The AI accelerates governance. The platform governs.

Two systems. One boundary. The AI never crosses it.

Intent, not execution

The AI identifies what you are asking and recommends the appropriate governance workflow. It does not act. The workflow engine acts, after the required approval is completed. This is architectural, not configurable.

Findings explained, not invented

Ask about a control pack finding and get a plain-language explanation with remediation context drawn from the finding data. The AI summarizes what the data shows, it does not fabricate status or invent compliance posture.

Provider-agnostic by design

Nuxari uses an AI abstraction layer. The model is replaceable, Azure OpenAI, Anthropic, or OpenAI, without changing workflows, guardrails, or the evidence chain. For regulated customers, Azure OpenAI keeps AI traffic within your tenancy.

Guardrail model

Every AI interaction follows the same path

The correct pattern is not a suggestion, it is the only path available. The AI has no route to execution that bypasses validation or approval.

  • ·AI classifies intent and recommends a workflow, it does not act
  • ·Backend validates the recommendation against RBAC and tenant scope
  • ·Approval gate enforces human authorization before any action
  • ·Workflow engine executes deterministically, AI is not in the execution path
Correct execution path, always
01
User request

Natural language or structured input

02
AI classification

Intent identified · Workflow recommended · No action taken

03
Backend validation

RBAC checked · Tenant scope enforced · Request validated

04
Approval gate

Human approver authorized · Approval record created

05
Workflow execution

Deterministic action · External system called by backend only

06
Audit evidence

SHA-256 hashed record · Control-mapped · Immutable

Nuxari AI Assistant
Which users have admin access but have not used it in 60 days?
U
N
I found 4 users with active admin roles and no privileged activity in 60+ days: David Park (Entra Global Admin), Mia Torres (GitHub Org Admin), Raj Kumar (AWS Admin), Carol Osei (Entra Admin).

Requires manager approval before any access changes execute.

What it does

Accelerate governance decisions, not replace them

The assistant surfaces what matters, drafts what takes time, and routes what needs approval. It compresses the parts that do not require human judgment, not the parts that do.

  • ·Natural language access queries across connected identity systems
  • ·Workflow drafting from a plain description of the required action
  • ·Finding explanation in plain language with remediation context
  • ·Approval summary generation for reviewers who need full context quickly
Hard limits

A defined role, not a general-purpose agent

The AI role is fixed: classify, recommend, explain, summarize. Authorization, final approval, and privileged execution are not delegated to the AI, by architecture, not by configuration.

  • ·Classify user intent and map it to the right governance workflow
  • ·Recommend access templates by department and job function
  • ·Explain control findings with full remediation context
  • ·Draft approval summaries so reviewers have complete information
  • ·Surface stale access patterns and flag them for human review
  • ·Answer questions within your organization's data scope only
ai_guardrails.policyNOT CONFIGURABLE
01AI cannot grant, revoke, or modify access in any connected system
02AI cannot call Entra, Okta, AWS, or GitHub directly
03AI cannot bypass or skip the approval workflow for any action
04AI cannot make final authorization decisions
05AI cannot invent compliance status or audit outcomes
06AI cannot store or expose credentials, tokens, or secrets
07AI cannot override RBAC or cross tenant isolation boundaries
08AI cannot execute privileged actions without human approval
ai_provider.config.json
{
"provider":"azure_openai",
"deployment":"gpt-4-turbo",
"region":"eastus",
"tenantBound": true,
"dataResidency":"customer-tenant",
"fallback": {
"provider":"anthropic",
"model":"claude-3-5-sonnet"
 },
"guardrails": {
"executionBlocked": true,
"externalCallsBlocked": true,
"approvalBypassAllowed": false
 }
}
Model layer

The model is replaceable. The guardrails are not.

Nuxari uses an abstraction layer between the AI model and the platform workflows. The active model can be changed, Azure OpenAI, Anthropic, or OpenAI, without touching the governance logic, approval gates, or audit chain.

  • ·Azure OpenAI preferred for regulated customers, AI traffic stays in your tenancy
  • ·Model-agnostic design, swap providers without changing workflows or guardrails
  • ·Active model visible to platform administrators at all times
  • ·Customer data is never used for model training or fine-tuning
AI Governance Assistant

Ask Nuxari. Get governed answers.

Nuxari AI explains findings, surfaces priorities, and recommends workflows, always inside the approval boundary. It never executes access changes autonomously.

  • ·Natural language queries across all connected identity systems
  • ·AI recommends the workflow, the engine executes after approval
  • ·Findings explained in plain language with control context
N
Nuxari AI·Active
acme-corp
Which access drift findings need immediate attention?

I found3 critical access drift findingsrequiring immediate attention. These identities have access that diverges from approved baselines across production systems.

FindingSeverityIdentityStatus
FIND-2041Criticalsvc-payments@acme.corpOpen
FIND-2039Highadmin@legacy.acme.corpOpen
FIND-2031Criticalroot@acme-prod-01Pending

Actions require approval before execution. I can prepare remediation workflows for review.

Approval required before any action
FAQ

Common questions

Can the AI execute access changes directly?

No. The AI assistant classifies requests and recommends workflows. Any access change, grant, revoke, modify, must go through the Nuxari workflow engine and pass the required approval gate. The AI has no execution path to connected systems.

What AI model does Nuxari use?

Nuxari uses an abstraction layer, not a single hardcoded model. The default deployment uses Azure OpenAI or Anthropic Claude depending on environment configuration. The active model is visible to platform administrators. The model is replaceable without changes to workflows or guardrails.

Is my data used for model training?

No. Nuxari does not use customer data to train or fine-tune models. Azure OpenAI and Anthropic API terms both prohibit using API inputs for training without explicit opt-in. Nuxari does not opt in on your behalf.

Can I use Azure OpenAI for data residency requirements?

Yes. For regulated customers, Azure OpenAI is the preferred deployment path, AI inference traffic stays within your Azure tenancy and region. Contact the team to configure your environment for Azure OpenAI.

How does the AI know about my environment?

The assistant operates on data within your Nuxari organization scope only. It reads findings, workflows, access records, and audit events that belong to your organization. It does not have access to data from other tenants. Tenant isolation is enforced at the API layer, not the prompt layer.

What happens if the AI makes an incorrect recommendation?

Recommendations are advisory. A human approver reviews and authorizes any action before it executes. An incorrect AI recommendation that a reviewer approves produces an approval record showing that the action was human-authorized. The AI recommendation is logged alongside the approval for full traceability.

Get started

Build the operating layerfor governance work.

See how Nuxari Ops reduces manual IT work, eliminates access drift, and generates audit evidence automatically, across your entire enterprise.