Overview and modes
Nova uses language models for analyses, suggestions and a chat that lets people operate Nova in plain language. AI complements Nova; by default it is switched off.
Principles
- The core works without AI. Identities, entitlements, access requests and approvals, provisioning, reconciliation and recertification do not call a language model. Without AI, only the AI features themselves are missing.
- AI proposes, people decide. Analyses, descriptions, role candidates, import parsers and steps for lifecycle routines are suggestions. Entitlements and master data change only when an authorised identity adopts or runs a suggestion.
- The chat acts only on request. It works with the permissions of the signed-in identity; actions marked as destructive run only after explicit confirmation. See AI guardrails.
Modes
| Mode | Where requests go |
|---|---|
| Off | nowhere – the interface does not offer its AI features |
| Local | to an Ollama endpoint, for example in the organisation’s own data centre; an administrator enters the endpoint URL and the model |
| Cloud | to Anthropic (Claude) or OpenAI, optionally through a custom base URL |
Every identity chooses the mode with the “NOVA-AI” switch in the header: “Off”, “Local” or “Cloud”. Nova remembers the choice in the browser; the default is “Off”. When switching, Nova checks whether the chosen mode is set up and otherwise switches to “Off”. The healthcheck has an AI setting of its own.
AI is set up under “AI Configuration” in the menu that opens when clicking one’s own name in the header; only administrators can save there. For the cloud, the following can be selected:
- Claude (Anthropic): Claude Opus 5.5, Opus 5, Sonnet 5, Sonnet 4.6, Opus 4.8 and Haiku 4.5
- OpenAI: GPT-4o, GPT-4o Mini, GPT-4.1 and GPT-4.1 Mini
Operations sets the API key as an environment variable on the server (CLAUDE_API_KEY or OPENAI_API_KEY). The interface only shows whether it is set.
Where Nova uses AI
- The “Nova AI” chat with assistants. Three are preset: “Access Requests” finds roles and files access requests, which go through the usual approval workflow; “Help & Navigation” answers questions and only reads; “Admin Chat” is open to administrators only and may use every tool.
- “AI user analysis” of an identity: risk assessment, anomalies and a comparison with other identities in the same organisational unit. Administrators can edit and save the result.
- Reports: from a description, AI generates the queries and layout of a report.
- Role mining: Nova computes the business role candidates without AI; AI names, describes and assesses them. See Role mining.
- Migration Workbench: AI writes the parser for an import file. See Migrating from SAP IdM.
- Suggestions during setup: the description of a business role, expressions for field mappings and steps for lifecycle routines, composed from fixed building blocks.
- Further uses: “Governance Analysis” (without AI, the questions remain open for manual assessment), the classification of findings in the “AI Healthcheck” and a pre-check under “Report a problem”.
Which data is sent to the model
In “Local” mode, the following data goes to the configured Ollama endpoint; in “Cloud” mode, to Anthropic or OpenAI.
| Feature | What the model receives |
|---|---|
| Chat | the messages; name, department, roles, business roles and organisational units of the signed-in identity; the results of the tools called |
| “AI user analysis” | name, email, department, location, status and type of the identity; its organisational units; names and risk of its business roles and entitlements; names and types of the target systems; the number of comparison identities |
| Reports | the description, a chosen template and the structure of the database tables; in the report dialogue, after each run, also the column names, row count and first result row of each query |
| Role mining | names, descriptions and risk of the entitlements, key figures, names of organisational units and positions; for person-bound candidates, names of identities |
| Migration Workbench | an excerpt of the file (the first rows, at most 20,000 characters), the chat messages and the result of the last dry run with up to 15 rejected records |
| Suggestions during setup | the description entered; names of the objects a suggestion may refer to, such as entitlements, business roles and organisational units – for open access requests including the requester’s name |
| Governance Analysis | questions and target answers from the questionnaire, stored facts about Nova |
| AI Healthcheck | up to 100 open findings with subject and details |
| Report a problem | description, type of report, current page and an attached screenshot |
If a model does not support tool calls, the chat falls back to a simpler mode. It then sends a data extract along, including the organisation chart with the names of its members and, in the “Access Requests” assistant, the requestable roles.
The server set-up decides
Nova can only reach a model that has been set up. Without an API key on the server, Nova rejects every cloud request before any data leaves the system. Anyone who wants to rule out cloud providers sets no key and, if needed, runs a model through Ollama in their own infrastructure.