How it works

From company knowledge to the next task

Employees use NomOS web chat. Coding agents retrieve knowledge through MCP from their own tools. Both receive sources, policies and previous decisions for the task. Your team reviews new results and records what can be used again next time.

How NomOS uses your company knowledge.

You define which sources and policies apply. For each request, NomOS supplies the model with the relevant information and records the basis for the answer and subsequent decisions.

  1. Select and approve sources

    Your subject-matter owners approve sources and define who may access them. Each source has a recorded owner, data class, current version and validity period.

  2. Define policies and approval responsibilities

    You specify the applicable policies and required approvals. NomOS links them to previous decisions in the impact graph. When you update a stored policy, NomOS uses it in the next check.

  3. Use the relevant knowledge to answer the request

    NomOS checks who is making the request and which information they may access. It supplies the selected model with the relevant sources and policies. You can see which sources were used for the answer.

  4. Review proposals and approve actions

    Agents can submit knowledge and decision proposals through MCP. Responsible people review them in NomOS. Through validate_action, an agent can also request a policy check on a planned action. That assessment alone does not technically stop an external action.

  5. Record results and corrections

    NomOS records submitted proposals, decisions and results captured through integrated paths. Errors and superseded policies remain identifiable. When a similar case arises, you can check whether an earlier decision still applies.

You can walk through this sequence on an invented case, using a rule that applies at your company: the guided demo, about two minutes.

How NomOS handles policies and exceptions

The impact graph connects the case with the applicable policies, approvals and exceptions. Superseded or prohibited options remain visible without being treated as valid choices.

Example impact graph: sources, policies, approvals and exceptions for a business case.
The impact graph shows which sources and decisions belong to a case. Click to enlarge.

Agents contribute through MCP

Retrieve knowledge and policies, read decisions, propose new findings and track their status. The connection links work in the agent’s tool with review in NomOS.

MCP capabilities in detail ↗

Which actions can NomOS control?

NomOS checks permissions for access to its content and capabilities. Enforcement for external actions depends on the execution path. These three levels describe the integration scope to assess, not a blanket guarantee from connecting an MCP client.

  1. 1

    Connected

    People who use NomOS receive answers with approved sources. At this level, access outside NomOS is not controlled.

  2. 2

    Guarded

    Preflight checks, hooks and gateways govern the known paths. Any remaining bypasses are documented.

  3. 3

    Enforced

    Effective actions demonstrably pass through the control point. Together with your infrastructure, such as controlled outbound traffic and short-lived credentials, technical measures prevent anyone from bypassing the governed path.

Only the third level counts as enforced governance. An MCP connection, a prompt instruction or an application-level wrapper is not enough. The level reached is assessed and stated for each execution path.

The next step: desktop controls

NomGate is planned as a local service to control connected AI access and agent actions according to NomOS policies. NomApp is planned to make knowledge and approvals accessible on mobile. Both are planned extensions; NomOS MCP capabilities work independently of them.

Explore the platform outlook ↗

Try NomOS in two workflows

The 30-day pilot reveals which knowledge two real workflows require, who decides and which policies apply. Similar cases can then build on the same approved foundation.

Further steps are only automated once their policies and approvals are in place. Subject-matter owners maintain sources, resolve conflicts and review changes. IT owns the integrations. We record this ongoing effort alongside any time saved.

Implementation in three steps: build the foundation, use reviewed results and automate clearly governed workflows.
From an approved foundation to governed automation.