AI guardrails
The “Nova AI” chat can not only read data in Nova but also change it. Nova enforces the limits for this on the server – regardless of which model answers and what it suggests.
Only with the permissions of the signed-in identity
The chat does not access the database itself. It calls tools, and every tool runs one of Nova’s endpoints internally – in the session of the identity using the chat. Permission checks, validation, logging and follow-up actions are therefore the same as in the interface. The chat does not extend the identity’s permissions.
Some tools combine several endpoints into one flow. Writing tools of this kind are available to administrators only; self-service such as filing access requests is the exception.
One tool list per assistant
Under “Administration › AI Assistants”, administrators define for each assistant which tools it may use.
- If the model calls a tool outside this list, Nova rejects the call – including indirect routes, for example through an export.
- Releasing all tools is possible only for assistants restricted to administrators. The preset “Admin Chat” always has all tools and always remains restricted to administrators.
- Assistants open to administrators only are hidden from other identities, and Nova rejects their requests to them.
- The chat does not change the tool lists, the sign-in policy, the lifecycle routines or the AI routine assistants, nor settings that contain secrets such as the AI configuration. This is possible only in the administration interface.
Confirmation before destructive actions
The chat does not run tools that Nova marks as destructive – for example those that delete – straight away. It first shows the “Confirmation required” card with the action and its arguments; under “Current state” it shows the affected object where available. The action runs at the earliest with the identity’s next message: through “Confirm and execute” or, if the identity agrees in a typed reply, through a renewed model call with confirmation. The following applies:
- A confirmation counts only in the immediately following message from the same identity to the same assistant, and for 10 minutes at most.
- Tool and arguments must match the preview exactly; otherwise Nova asks for a new preview.
- The model cannot confirm on its own: Nova rejects a confirmation in the same message that produced the preview.
- “Confirm and execute” runs exactly the stored call. For the reply to it, the model has read-only tools only.
- The chat runs at most one destructive action per message.
Secrets stay out
No tool accepts passwords, client secrets, tokens or API keys as parameters. Nova checks this for every tool definition at start-up and on every call; the chat also refuses to clear a secret. Secrets are entered in the interface. In tool results and previews, Nova replaces such fields and values stored encrypted with a placeholder.
Limits per message
| Limit | Value |
|---|---|
| Model calls in the tool loop | 12 |
| Destructive actions | 1 |
| Same tool call with the same arguments | 3, then blocked |
| Size of one tool result | 12,000 characters, truncated beyond |
| Tool results in total | 60,000 characters, no further calls after that |
Nova sets no token or cost budget per identity or period.
Traceability
- Nova marks log entries created during a tool call with
via: ai_chat:<assistant>in their details. Under “Monitoring › Audit Log”, the “Origin” filter set to “AI chat” shows exactly these entries. - What gets logged is what the called endpoint logs – whether it is called from the chat or from the interface. Nova writes no entry of its own per message or per tool call.
- Nova stores the chat history per identity and assistant so that it can be reopened under “Chat History”. In Nova, every identity sees only its own histories and can delete them – one by one or with “Clear all”. The history is therefore not evidence; the audit log is what counts.
Which data the chat sends to the model is described in Overview and modes.