The first hour
Trust the certificate once, drop a file into a department folder, and watch the agent answer from it.
The install is done and the banner is on screen. This is the shortest path from there to the thing the box is for.
1. Trust the box's certificate, once per laptop
The box issues its own certificates, so the first visit warns you. Each laptop trusts the box once:
http://nufi.local/That page serves the certificate. Install it, and every NuFi URL on the box is a normal padlock from then on. On the machine that ran the installer this is already done.
./nufi-box ca-cert # prints where the certificate file isThe warning screen is the certificate, not a fault
Until a device trusts the box's certificate, its browser stops with "Your connection is not private" and you have to click Advanced → Proceed. That is what a private certificate authority looks like from the outside, and it is expected — not a sign that anything is wrong.
It goes away for good on that device once the certificate is installed. Until then the connection is still encrypted; the browser simply has no way to know who issued the certificate.
Two things worth knowing before you promise a room full of laptops that this takes a minute:
-
Some managed corporate laptops disable the Advanced button by policy, and installing a certificate authority may need administrator rights. On those machines the box is unreachable until IT allows it.
-
If the certificate will not download in the browser, fetch it directly — Chrome and Edge cancel downloads over plain HTTP:
curl -O https://nufi.local:3080/nufi-box-ca.crt # warns once, then downloads
2. Sign in
Open https://nufi.local:3080 and use the admin login from the banner. The same
login works on the console, the admin panel and Studio — you will not be asked
for a second password.
3. Give your colleagues accounts
The page to send them once they have one is Using your department's box.
There is no sign-up page, and that is deliberate: a department appliance is not a public service, so who may sign in is a decision an administrator makes rather than something anyone with the address can do for themselves.
A fresh box has exactly two accounts — the administrator the installer created, and the watcher daemon's own. Everybody else is added by hand:
./nufi-box user add hana@legal.example --name "Hana Kim" email: hana@legal.example
password: 4f9c2ad81b7e0c35
Write it down now — it is not stored anywhere you can read it back.
They can change it once signed in.The password is generated rather than chosen, for the same reason the installer generates the administrator's: an administrator inventing one per person is how every account on a box ends up sharing a password. It is printed once and not kept in readable form.
./nufi-box user list # everyone who can sign inThat same login works on all four products. A person added here can open the app, the console, the admin panel and Studio without a second password, and they get their own copy of the department routines the first time they open Studio.
4. Put a document in a department folder
cp 계약검토_표준조항.txt <data dir>/drives/legal/That is the whole of it. A watcher scans the drives every twenty seconds, waits for a file to stop changing before it touches it, then uploads it to that department's agent and embeds it.
./nufi-box logs nufi-ingestINFO added legal/계약검토_표준조항.txt → 3c7d56c0-… (embedded=True)embedded=True is the moment the document became knowledge. It usually lands
within a minute of the copy.
Over the network the same folders are shares — \\nufi\legal, \\nufi\hr —
so a department can drag files in from Finder or Explorer without touching a
terminal.
5. Ask the department's agent
The department agents live one level into the model picker, and only in the full interface. If the chat is in Basic mode, switch it to Advanced first — the avatar menu at the bottom-left has the toggle. Then open the model button at the top-left, choose My Agents, and pick the Legal assistant. (In Basic mode the picker shows only the plain model, and the department agents are not offered — which looks like they are missing when they are not.)
Now ask something only that document answers:
자동연장 조항이 있는 계약은 만료 며칠 전까지 통보해야 하나요?
The answer comes back with the file name above it. That citation is the point: the number came out of the department's own document, not out of the model's training.
If you ask it something the documents do not cover, it should decline rather than invent. That behaviour is what the box's acceptance run measures.
What to expect from the answers
The box ships with qwen2.5:7b, which is small enough to run on a machine
without a GPU. Small models are uneven: they sometimes print their search call
as text before making it, and occasionally start a sentence in the wrong
language. The retrieval underneath is not what is wobbling — the passage and
the citation are right.
A larger model is the lever. On the same 32-question acceptance set, moving
from qwen2.5:7b to qwen2.5:14b took the score from 10 to 21 with nothing
else changed. See Inference profiles.
When another machine cannot reach the box
Work down this list; each step tells you something the one before it did not.
| What you see | What it means |
|---|---|
| Certificate warning, then it works | Normal. That device has not trusted the certificate yet. |
nufi.local not found, but https://<box-ip>:3080 works | The network is fine and mDNS is not resolving. Use the address; the certificate covers it too. |
| Neither the name nor the address works, from a phone | Check the phone's own IP. If it is not on the box's subnet it is on another network — a guest SSID, a second band, or an extender with its own range. |
| Neither works, and the device is on the same subnet | The access point has client isolation on, which blocks device-to-device traffic entirely. Nothing on the box can change that; it is a router setting. |
| Nothing at all, from every device | ./nufi-box doctor on the box itself. |
Android phones cannot resolve .local names. Android has no system-wide
mDNS resolver for ordinary lookups, so Chrome on Android will not open
https://nufi.local:3080 however healthy the box is. Use the address instead.
iPhones resolve .local normally.
On iOS the certificate needs a second step that is easy to miss: after installing the profile, go to Settings → General → About → Certificate Trust Settings and switch it on. Without that, the certificate is installed and still not trusted.
To see whether a request reached the box at all while somebody is trying:
./nufi-box logs caddyEvery request is logged. It will not tell you which device — Docker's network rewrites the source address on the way in — but "a request arrived and got a 200" against complete silence is usually the whole answer.
Add a department later
./nufi-box drive add financeFolder, share, team and agent, in one command.
Next
- Day two — the commands you will actually use
- Routines on a clock — a weekly report that writes itself
- Backups — and how to put one back