What the box is
One command puts the whole of NuFi on a machine a department already owns, and a shared folder becomes that department's knowledge.
The NuFi Team box is the whole product — chat, agents, Studio, the console and the admin panel — installed on one machine a department already owns, reachable over the office LAN, with no cloud account and nothing to configure per user.
The idea it is built around is a folder. Each department gets one:
data/drives/legal/ → the Legal team's agent knows what is in here
data/drives/hr/ → the HR team's agent knows what is in hereDrop a file in, and a minute later that department's agent can answer from it and name the file it answered from. There is no upload screen, no per-file permission to grant, and no button to press. The folder is the interface.
What you get
| Chat | https://<box>:3080 — the NuFi app, one agent per department |
| Console | https://<box>:3001 — the box's identity authority and model gateway |
| Admin panel | https://<box>:3002 — accounts, teams, audit |
| Studio | https://<box>:7860 — the flow canvas, with the department routines in it |
One login works across all four. A member signs in once, on the box, and never sees a second password.
Where the answers come from
The model runs on the box. By default that is qwen2.5:7b served by Ollama on
the machine itself, and it never leaves the box — no request, no document and
no question goes to a third party. You can point the box at a bigger model on
another machine, or at a hosted provider, when you want to: see
Inference profiles.
Retrieval is per department. The Legal agent reads the Legal drive and the Legal vector index; asking it an HR question gets you an honest "that is not in these documents" rather than an answer out of the wrong folder.
Studio is here; Works is optional
NuFi has two agent products. NUFI Studio — the flow canvas — is on every
box. NUFI Works — agents that write and run code — is on a box installed
with install-box.sh --with-works, on Ubuntu only.
Works runs code its agents write, which means untrusted code, and what makes
that safe is not part of Works at all: a kernel boundary, and egress restricted
by hostname. On the cloud cluster those are a gvisor runtime class and Cilium.
On a box they are the same two things in Docker's shape — every agent run lands
in a gVisor sandbox (the runsc runtime the installer registers) on a
network with no route out except a proxy that consults an allow list. A Mac
cannot host that runtime, which is why the flag is Ubuntu-only; see
Works on the box.
Signing in on a box without the flag shows Studio alone. It is not a missing card; it is a box that was not asked for Works.
What it is not, yet
Being straight about this is cheaper than a surprise:
- It does not read or send email. Nothing in the box touches a mailbox.
- It does not record or transcribe meetings. It summarises a transcript you give it.
- Reaching the box from home has been proven against a public coordinator with a real certificate, relay included — but not yet from a laptop on a network other than the box's own. On the LAN it is solid.
- Updates are not signed yet.
nufi-box updatefetches the box from GitHub over TLS, checks it, and rolls back on its own if the check fails — but there is no signed bundle behind it yet (day two).
Next
- Install it — one command, four questions
- The first hour — trust the certificate, drop a file, ask a question
- On the LAN and from home — the box's name, the office path, the from-home path
- Using your department's box — the page to send everyone who is not running it