Nebulous platform architecture

Four layers. One governed platform.

Nebulous separates how people engage, how work is orchestrated, how context is grounded and how data is held. Each layer is independently governed, and the whole platform runs inside your own cloud account.

Layer 01

User experience layer

Interactive interfaces and engagement channels for the people who do the work: case workspaces, approval queues and the channels your customers and staff already use.

Every material decision surfaces here for a person to approve, reject or amend, and each decision is recorded against the run.

case workspaceapproval queueengagement channels
Case list interface with an approval card
Layer 02

Orchestration platform

The core engine: multi-agent processes, task routing and automated execution. Work is decomposed across specialist agents, routed by rules you control, and executed only through tools approved for each agent.

Every step carries a risk tier. Anything material pauses for a person, and anything uncertain stops rather than guesses.

multi-agent processestask routingautomated executionrisk tiers
Multi-agent orchestration network
Layer 03

Context layer

Your policies, product documents and reference material become structured context an agent can reason over, with the exact clause quoted on every answer.

Enterprise metadata and real-time retrieval graphs keep that context current, so answers reflect the policy in force today rather than a stale copy.

retrieval graphsenterprise metadataclause-level citations
Policy document with a highlighted clause cited in an answer
Layer 04

Data layer

State management and the records themselves. You copy the data you choose into a database inside your own account, on your own schedule.

Agents read it through controlled, read-only connections and can never change it. Core systems are never called directly, and every read is recorded.

state managementyour databaseread-onlyevery read recorded
Records flowing into an ordered data structure
Products

Nebulous Studio and Nebulous Cloud.

Nebulous Studio

Runs in your environment

Your platform team configures agents and approval thresholds, monitors runs in flight, oversees the approval queue, tests changes safely and reads system health - all inside your own tenancy.

configurationrun monitortest consoleaudit view
Nebulous Cloud

Where agents are authored

Agents are designed, sealed and versioned here, then delivered as releases your systems verify before anything runs. Licences and seats live here; client data and client users never do.

agent builderrelease pipelinelicences
Deployment and operations

What your architecture review
will want to know.

Deployment model
Single-tenant, installed in your own cloud accountOne installation per institution. No shared runtime, no shared database, no shared identity.
Hosting
AWS first, ap-southeast-2 (Sydney)Bedrock, ECS Fargate, Amazon RDS and Step Functions. Every service containerised, so the installation can move without a rebuild.
Identity
Self-hosted OIDC with multi-factor authenticationOne realm per institution, administered by you. Federation to your own identity provider on request.
Data handling
Extracts pushed into a database in your accountRead-only, governed access. Core systems are never called directly and nothing is copied out.
Model layer
Amazon Bedrock behind a provider interfaceModels are pinned per agent and can be changed without rebuilding an agent.
Records
Tamper-evident, append-only, held by youEvery run replayable end to end. Nothing is exported to the vendor at any point.
Delivery and support
Sealed releases; support by ticketConfig update or on-site install. No standing vendor access to your environment.
Governance

Security, governance and observability
wrap every layer.

Security

Sign-in you host, with multi-factor authentication. Every request permission-checked at the gateway and again at the service. Every release seal verified before it runs.

Governance

Every model input and output screened. Risk tiers on every action, a person on every material decision, and fail-closed behaviour whenever something is uncertain.

Observability

Every run recorded end to end in a tamper-evident, replayable record - readable by your risk and audit teams, inside your tenancy only.

Want the architecture deep dive?

We walk risk, security and architecture teams through the full design - identity, permissions, release sealing and the audit record - under NDA.

Book a session