NuFiDocs
NuFi Team boxWhat the box is

What the box is

One command puts the whole of NuFi on a machine a department already owns, and a shared folder becomes that department's knowledge.

The NuFi Team box is the whole product — chat, agents, Studio, the console and the admin panel — installed on one machine a department already owns, reachable over the office LAN, with no cloud account and nothing to configure per user.

The idea it is built around is a folder. Each department gets one:

data/drives/legal/      → the Legal team's agent knows what is in here
data/drives/hr/         → the HR team's agent knows what is in here

Drop a file in, and a minute later that department's agent can answer from it and name the file it answered from. There is no upload screen, no per-file permission to grant, and no button to press. The folder is the interface.

What you get

Chathttps://<box>:3080 — the NuFi app, one agent per department
Consolehttps://<box>:3001 — the box's identity authority and model gateway
Admin panelhttps://<box>:3002 — accounts, teams, audit
Studiohttps://<box>:7860 — the flow canvas, with the department routines in it

One login works across all four. A member signs in once, on the box, and never sees a second password.

Where the answers come from

The model runs on the box. By default that is qwen2.5:7b served by Ollama on the machine itself, and it never leaves the box — no request, no document and no question goes to a third party. You can point the box at a bigger model on another machine, or at a hosted provider, when you want to: see Inference profiles.

Retrieval is per department. The Legal agent reads the Legal drive and the Legal vector index; asking it an HR question gets you an honest "that is not in these documents" rather than an answer out of the wrong folder.

Studio is here; Works is optional

NuFi has two agent products. NUFI Studio — the flow canvas — is on every box. NUFI Works — agents that write and run code — is on a box installed with install-box.sh --with-works, on Ubuntu only.

Works runs code its agents write, which means untrusted code, and what makes that safe is not part of Works at all: a kernel boundary, and egress restricted by hostname. On the cloud cluster those are a gvisor runtime class and Cilium. On a box they are the same two things in Docker's shape — every agent run lands in a gVisor sandbox (the runsc runtime the installer registers) on a network with no route out except a proxy that consults an allow list. A Mac cannot host that runtime, which is why the flag is Ubuntu-only; see Works on the box.

Signing in on a box without the flag shows Studio alone. It is not a missing card; it is a box that was not asked for Works.

What it is not, yet

Being straight about this is cheaper than a surprise:

  • It does not read or send email. Nothing in the box touches a mailbox.
  • It does not record or transcribe meetings. It summarises a transcript you give it.
  • Reaching the box from home has been proven against a public coordinator with a real certificate, relay included — but not yet from a laptop on a network other than the box's own. On the LAN it is solid.
  • Updates are not signed yet. nufi-box update fetches the box from GitHub over TLS, checks it, and rolls back on its own if the check fails — but there is no signed bundle behind it yet (day two).

Next