It does the work, then it stops and asks
Nova reads your workspace, shows every call it made, and proposes the change. Nothing is written until a person confirms it.
↳ Watch the sequenceProduct

Product / NovaModule 03
Nova reads the whole record — every deal, document, revision and visit, with the run of your workspace and nothing outside it. It reasons over that structure, prepares the change, and hands the change back to you unexecuted.
The limits are written up on the security page.
Writes are intercepted before they execute. Nova prepares the change, signs it, and hands it back unfinished. You approve, and only then does it run — under your own session, against the account that confirmed it.
This is the part most assistants skip, because a gate makes the demo slower and the product safer. Nothing reaches your data until a person says so.
NovaPropose, then wait
Each tool call is logged with its arguments, its result and how long it took, and streamed to the panel while it runs. You are not told what it did afterwards; you watch it work.
An assistant you cannot audit is an assistant you are trusting. We would rather you checked.
Every one of these is a deliberate limit, published so that a security review can start from the same facts we have. The full write-up is on the security page.
Nova’s access to a workspace is a per-user setting and it is opt-out: a person switches it off for themselves rather than a company switching it on for everyone. The opposite reads better and is not true.
Two parts of this are enforced in code and one is not. Every write Nova proposes is checked against a minimum role before you are asked to confirm it, and financial figures — revenue, margin, invoices — are refused outright below manager. The rest of Nova’s read scoping is an instruction to the model, and an instruction is not a boundary. We would rather you knew which is which.
Nova reads under a service identity, so every query it makes names the organisation it is allowed to read. That constraint is written into the query itself rather than inherited from the session. It is one of several layers separating one company’s data from another’s, and it is enforced differently from the rest, which is why it is named here rather than folded in with them.
Nova’s reasoning runs on a third-party model — currently OpenAI or Google — reached through the Lovable AI Gateway, which may process a request outside the EU under standard contractual clauses. Before a tool result reaches the model, a minimisation layer removes direct identifiers — email, phone, address, personal and organisation numbers, bank details, tokens — truncates free text, and records which fields it removed without recording what was in them. Workspace content is not used to train any model: the setting that would permit it is off, and the gateway holds its model providers to the same restriction.
Sixty-plus tools, and every one of them is pointed at your own records: deals, documents, revisions, visits and the people attached to them. There is no tool that reaches the open web, another company’s workspace or an inbox, because none was built. Nova has no way to send a message or draft one; when it finds the clients that have gone quiet, it hands you the list and the reasoning, and what you say to them is yours to write.
The other direction is just as narrow. Nova can read the workspace it was opened in and propose a change to it, but the change waits for you: it is prepared, shown and left unexecuted until a person confirms it, and then it runs under that person’s own session. Every call it makes is logged while it runs. The result is an assistant with the whole record in front of it and no way to act on it alone.
NovaReach
An assistant that cannot be stopped is not an assistant. It is a second person with your password.
Tell us roughly how you work and we will come prepared.