Mailbox ?
Email historyNo conversations yet.
Select a conversation.
Review queue ?
AI DraftsKnowledge base ?
Uploads feed the local_docs (or chroma) backend. Switch backends in Settings.
Sendable documents — files the bot may attach to replies. "Auto-send OK" = public collateral; otherwise a human approves the release
—
Indexing costs — one-off vision + embedding spend; excluded from operational Reports
—
Indexed documents
Test a query
Workflows — transactional intents the AI can extract in any language. Built-in workflows have code fulfilment; custom ones collect the listed fields and route the draft for human review.
AI agents ?
Teams ?
Follow-ups ?
Pending RequestsUsers & roles ?
Role-based Access Control (RBAC)Users
Roles & permissions — tick what each role may do; built-in roles are editable but not deletable
Mock data
⚠ SIMULATED — demo reservation system dataset, not live customer dataReservations
Members
Properties
Email templates ?
Reports ?
or by date range:
Outcome funnel
Confidence calibration
Average model confidence per gate decision — auto-send should sit well above review, review above escalate.
Where the seconds go
Average per stage — the case for fast-model routing.
By team
Daily volume & AI cost
Cost by feature
Cost by provider
My account ?
Your profile, password and sign-in securityLoading…
Settings ?
Loop & auto-war prevention
Automated senders (newsletters, out-of-office, bounces) never receive replies. This limit additionally caps how many times the system may auto-reply to any one sender per hour.
the next auto-reply beyond this is held for human review; human approvals are never limited
Evidence-weighted gate
Deterministic code rule, no extra AI calls: a draft grounded on no knowledge-base content and no verified system data has its effective confidence capped below the auto-send line. Signals compose by MINIMUM — self-score, evidence cap, and judge each may only lower, never raise.
LLM-as-judge — second-opinion scoring
An independent fast-model pass rates each draft against its retrieved evidence, blind to the author model's self-score. The judge can only LOWER a draft's effective confidence (catching over-confident drafts) — never raise it.
Mailboxes
Inboxes NEXUS monitors. Replies always send from the mailbox that received the email. Passwords are stored encrypted and never shown again.
Loading…
Security — two-factor authentication policy
When required, every user without 2FA is sent to My account to enrol at their next sign-in. Users enrol themselves; this switch only makes it mandatory. Applies when sign-in is enabled (AUTH_MODE=on).
Retrieval — AI query rewriting
For emails with several questions, a small AI pass rewrites each question to name its subject ("could you list them?" → "list Shangri-La hotels in Beijing") before searching the knowledge base. Adds one small AI call per multi-question email. The built-in rule-based fix runs regardless.
Sender blacklist
Blocked senders' emails are stored in history but never processed or answered. Manage the list here; block from any draft card.
PII redaction before every model call
Masks guest-originated text sent to the language model. The database, this screen, attachments and outgoing email keep the original. Reservation confirmation numbers (11 digits) and member numbers (7 digits) are never masked. Name detection (NER) is not available in this build.
Below the review threshold (or when the model flags a human matter) Aster sends a holding reply and escalates. Between the thresholds, drafts wait here for review. Above the auto-send threshold, replies go out on their own — if auto-send is on.