KOBIL AI
Assistant.

One governed assistant inside the SuperApp. Ask questions, query connected tools, and build toward cross-MiniApp workflows with identity, audit, and connector governance from AgentBox.

Live in mPower today. Expanding into governed cross-MiniApp workflows.
KOBIL AI Assistant SuperApp SSO
KOBIL AI Assistant dashboard showing connector hub, chat, approvals and audit activity
Enterprise SSOKeycloak OIDC and silent sign-in
Audit visibilityConnector and approval events
KOBIL digital trust infrastructure
Product definition

Governed chat,
inside mPower.

KOBIL AI Assistant is a productized AgentBox assistant surface for the SuperApp. It is live as a chat MiniApp with real SSO and a production connector portfolio, while broader cross-MiniApp action is the next product direction.

Product scope

Today, the assistant delivers SSO-backed chat, governed connector access and audit visibility. The product direction extends this foundation into cross-MiniApp workflows and enforced approval for sensitive actions.

01 current SuperApp entry point Users open the Assistant MiniApp inside mPower and authenticate through KOBIL OIDC with silent SSO where configured.
02 governed path AgentBox runtime and MCP bridge Chat and connector calls route through managed runtime, policy, connector and audit foundations.
03 product direction Cross-MiniApp workflows As MiniApps expose governed interfaces, the assistant can coordinate app-owned actions with user-scoped identity.
Identity

One SuperApp-aware session

Real Keycloak OIDC, PKCE and silent login support let the assistant avoid a separate user experience where SuperApp SSO is configured.

Connectors

Tool access through governed routes

Jira, Confluence and the partner MiniApp portfolio are live through governed production connector paths.

Evidence

Audit-first product surface

Interactions, connector activity and approval records create a traceable operating record, with enforced approval controls extending that foundation.

Capability readiness

Connected today.
Built to expand.

Live production capabilities and the next product extensions are presented in one clear operating view.

Live in production

SuperApp SSO and chat

Real Keycloak OIDC, silent SSO behavior, session verification and the working chat experience are live.

Live in production

Jira and Confluence

Live production access runs through the governed VPN connector path.

Live in production

Candor, Herald, Todo

Production connectors call each MiniApp's live backend using real-mode, per-user token exchange.

Live in production

Personio, Teams, Timebutler, Kolay

Production connectors provide live governed access to HR, collaboration and workforce systems.

Operational visibility

Audit and approvals

Approval requests, decisions and tool activity are visible today, with enforcement continuing as a product rollout step.

Product expansion

Cross-MiniApp acting

The next product layer will coordinate app-owned actions as MiniApps expose governed callable interfaces.

Production intelligence

Engineering and domain agents.

Source-control workflows and specialized RAG agents run through the same SecureProxy, managed MCP policy and audit foundation.

GitHub + GitLab

GitHub repository, issue and pull-request workflows are production-enabled. GitLab follows the same governed source-control pattern as the next adapter.

GitHub live · GitLab next

Specialized Agents + RAG

Domain-specific assistants are grounded in approved knowledge through SecureProxy-backed embeddings, Chroma retrieval and governed MCP access.

Production ready

Safety Controls

SecureProxy, MCP policy checks, audit events, workspace controls and skill scanning keep agent execution on governed paths.

Operational foundation
Reference architecture

Identity in front.
Governance around tools.

The assistant sits inside SuperApp, but execution and connector behavior are shaped by AgentBox runtime, MCP bridge, audit and policy services. Coverage depends on registered routes and configuration.

SuperApp OIDC identity and session verification Runtime adapters for assistant chat execution Managed MCP bridge for connector calls Approval records and audit stream
Identity brokerOIDC, PKCE, session checks
MCP bridgeManaged connector routing
Approval monitorAdvisory visibility today
Audit streamNormalized evidence events
SuperApp user Opens the Assistant MiniApp with SSO-backed identity.
OIDCPKCESilent SSO
KOBIL AI Assistant Chat, runtime routing, connector governance, approval visibility and audit events.
  1. Authenticate01
  2. Route request02
  3. Call connector03
  4. Record evidence04
AgentBoxMCP bridgeAudit
Tools and MiniApps Live, activating and product-expansion providers stay explicitly labeled by rollout stage.
JiraConfluencePersonioTodo
SuperApp integration model

One conversation.
Many app-owned workflows.

The long-term model is for MiniApps to expose structured tool surfaces that the assistant can call with user-scoped identity. That keeps each MiniApp responsible for its own business rules while AgentBox supplies the assistant, governance and audit path.

Vacation Requests Travel and Expenses CapEx Proposals On-Call Billing Document Signing
Deployment options

One assistant.
Runs beyond mPower too.

The SuperApp MiniApp is one deployment mode of the same governed AgentBox assistant stack, not the only one the architecture supports. The identical chat, connectors, skills/flows and audit foundation is also built to run standalone, independent of mPower.

Embedded

SuperApp MiniApp

Live today in staging and production. Runs inside the mPower webview with silent SuperApp OIDC sign-in.

Self-hosted

Your own Kubernetes cluster

The same stack deploys on a customer-operated cluster behind a customer-chosen hostname, with the runtimes and connectors you choose. Built into the deployment architecture today.

Hosted

KOBIL-hosted, standalone

A KOBIL-hosted deployment mode of the same stack, independent of the SuperApp -- reached directly in a browser, no SuperApp account required.

Access model

Every mode is a zero-install browser experience on any device -- there is no separate desktop application. Sign-in falls back automatically to direct email/password login whenever SuperApp single sign-on isn't present, so the standalone modes need no separate build.

Roadmap focus

Turn foundation
into enforced workflow.

The next product moves are operational, not decorative: enforce approvals, complete connector prerequisites and choose one MiniApp pilot with a real callable interface.

Governance

Enforce

Extend visible MCP approval activity into enforced decision gates for sensitive actions.

  • Pause risky calls until decision
  • Preserve audit trail
  • Test denial and timeout paths
Connectors

Expand coverage

Add new governed tools and MiniApp interfaces on top of the live production connector portfolio.

  • Prioritize high-value systems
  • Reuse identity and policy patterns
  • Validate production outcomes

Each rollout step is scoped against one owned workflow, its connector path and measurable production success criteria.

Indicative pricing

Start with one workflow.
Scale with proven value.

KOBIL AI Assistant starts with a defined technical engagement, then moves to an annual model based on deployment, workflows and governed connector scope.

Entry engagement

Workflow assessment

€4,500one-time

A focused technical and product assessment for one high-value assistant workflow.

  • Workflow and ownership definition
  • Identity and connector readiness
  • Deployment recommendation
  • Pilot scope and success criteria
Request assessment
Enterprise

Enterprise deployment

From €72kper year

A governed assistant deployment scaled across approved teams, workflows and environments.

  • KOBIL-hosted or customer-hosted
  • Connector and workflow scope
  • Security and operating model
  • Support and rollout planning
Discuss enterprise
Indicative terms

Indicative prices exclude VAT. Infrastructure, model-provider usage and exceptional integration work are scoped separately. Final commercial scope depends on deployment model, active users, connector and workflow coverage, and support level, and is subject to technical assessment and product readiness.

Product whitepaper

Technical depth.
Product direction.

14 sections Updated August 2026 Architecture and roadmap

The complete product brief covers architecture, identity and governance, deployment options, the connector model, product roadmap and commercial approach.

KOBIL AI Assistant FAQ

Clear answers.
Practical details.

What is KOBIL AI Assistant?+

It is the governed chat assistant embedded in the KOBIL SuperApp/mPower experience, built as a productized instance on the AgentBox runtime, connector and security stack.

What works today?+

SuperApp SSO, the chat experience, audit events and the production connector portfolio are live. This includes Jira, Confluence, Candor, Herald, Todo, Personio, Teams, Timebutler and Kolay.

How will it work across MiniApps?+

The product direction connects MiniApp-owned callable interfaces through platform identity and governed tool paths. The rollout starts with one owned workflow and expands as MiniApps expose those interfaces.

How are sensitive actions governed?+

Approval activity and tool events are visible and auditable today. Enforced decision gates for sensitive MCP actions are part of the product rollout.

Which connectors are ready?+

Jira, Confluence, Candor, Herald, Todo, Personio, Teams, Timebutler and Kolay are live in production. GitHub engineering workflows are production-enabled, specialized Knowledge Base/RAG agents are production-ready, and GitLab is the next governed source-control adapter.

What should the first pilot be?+

A narrow workflow MiniApp with clear ownership and measurable manual-work reduction, such as vacation requests, travel/expense handling, CapEx proposals, on-call duty billing or document signing.

How is KOBIL AI Assistant priced?+

Indicative pricing starts at €4,500 for a one-time workflow assessment, €18,000 for a fixed-scope 8-12 week production pilot, and €72,000 per year for an enterprise deployment. Final pricing depends on hosting model, active users, connectors, workflows, support and model-provider consumption.

Do I need the mPower SuperApp to use it?+

No. The SuperApp MiniApp is the most integrated way to use it today, but the same assistant stack is also built to run standalone in a browser -- self-hosted on your own Kubernetes cluster, or as a KOBIL-hosted deployment -- with its own sign-in, independent of mPower. There is no separate desktop application; standalone access is zero-install, in any browser.

Production pilot

Choose one MiniApp.
Prove the workflow.

Contact KOBIL team