Business data, governed end to end

Your business data.
One governed answer.

TBOC2 connects customer-owned records to a secure operating workspace, validates every publication, preserves source authority, and turns authorized questions into evidence-backed answers.

Operating status Ready
Source syncValidated
Published dataCurrent
Query serviceRead only
Ask TBOCLocal
Ask TBOC

Which active contracts have timecard exceptions this week?

Checking authorized records and source evidence…

Illustrative workspace state

Google-authenticatedSource-awareLocal AICustomer-controlled

A trustworthy operating model

Two systems of record.
One governed view.

TBOC2 does not blur ownership. It keeps the authority of each source explicit while making the information useful together.

01 / Connected sources

Business records stay connected to their source.

Google Sheets can remain authoritative for timecards, labor, contracts, budgets, calendars, and vendor records. Named links take users back to the exact source tab when source context matters.

  • Read-only, scoped collection
  • Scheduled synchronization
  • Visible freshness and lineage
02 / TBOC2 authority

Controlled records stay controlled.

Employee roster and compliance records can remain authoritative inside TBOC2. Ingestion preserves those boundaries instead of overwriting protected operational data.

  • Explicit ownership rules
  • Confidential HR separation
  • Role-aware search and export

From source to decision

A publication path designed to fail safely.

  1. 01

    Connect

    Use scoped credentials for approved sources.

  2. 02

    Validate

    Check schemas, types, identities, dates, and references.

  3. 03

    Publish

    Create a new immutable data generation atomically.

  4. 04

    Serve

    Expose the approved generation through a private, read-only query layer.

  5. 05

    Use

    Power authorized workspaces, reports, exports, and Ask TBOC.

If an import fails, nothing partial is published.The previous usable generation remains available while the failure is reviewed.

The business workspace

Built around the work people actually do.

Each user sees a responsive operating surface shaped by their role, responsibilities, and authorized data.

BUSINESS OPERATIONS

Good morning

Data current · 2 min ago
Active employees128Authorized roster
Open exceptions7Requires review
Active contracts24Source verified
Labor activityLast 8 weeks

Role-aware home

Priorities and summaries reflect the user’s permitted scope.

Named source links

Move from a result to the exact authoritative source.

Reports and exports

Use the same authorization rules beyond the screen.

Freshness visible

Know which publication powers every result.

Ask TBOC

Natural language,
bounded by real authority.

A local language model helps interpret the question and choose from approved, read-only tools. TBOC2—not the model—enforces identity, role, data scope, and evidence.

  • Runs locally with cloud inference disabled
  • No arbitrary SQL and no direct writes
  • HR tools are absent for users without HR authority
  • Answers retain evidence and source context
Answer path Controlled execution
  1. 01Interpret the requestLocal language routing
  2. 02Select approved toolsKnown capabilities only
  3. 03Enforce the user’s roleServer-side authorization
  4. 04Query the published generationPrivate read-only service
  5. 05Return answer and evidenceTraceable to source

Security is part of the data model

Least privilege without implied access.

Authority is explicit. An administrator manages the platform; that alone does not grant access to confidential HR data.

01

Google sign-in

Invited users authenticate through Google. In Google mode, TBOC2 stores no user passwords.

02

Explicit local roles

Observer, operator, HR, and administrator permissions remain distinct and server-enforced.

03

Confidential data controls

Sensitive HR fields stay protected across views, search, sorting, exports, evidence, and Ask TBOC.

04

Separated credentials

Interactive sign-in and unattended source collection use different Google credentials and scopes.

05

Private services

Database, query, and model services can remain inside the customer-controlled environment.

06

Traceable change

Immutable generations make data publication observable, recoverable, and easier to audit.

Available now

Current platform capabilities.

Google Sheets ingestionScoped, scheduled, validated synchronization
PostgreSQL supportStructured operational data connectivity
Excel & CSVGoverned workbook import and snapshot or live CSV patterns
Immutable generationsAtomic publication with last-good preservation
Business workspaceRole-aware operations, reports, and source links
Ask TBOCLocal language routing to approved tools
Role-aware accessServer-side identity and data enforcement
Customer-controlled operationDeploy and operate inside your environment
Explore the full capability model

Purpose-built solutions

Custom applications are available.

When the mission does not fit an off-the-shelf workflow, TBOC2 can be configured or custom-built around your operating model, data authority, roles, and reporting needs.

Discuss your use case

Common questions

Clear answers before access.

Where does TBOC2 run?

It is designed for customer-controlled deployment. Core data, query, and local model services can operate inside the customer environment.

Who owns the data?

The customer does. TBOC2 preserves explicit source authority, uses scoped access, and does not require a third-party hosted data platform.

Which data sources are supported?

Current capabilities include Google Sheets and Drive-connected workflows, PostgreSQL, qualified Excel ingestion, CSV snapshots, and CSV patterns configured for live customer-system data.

Does Ask TBOC send data to a cloud AI service?

The current implementation uses a local model with cloud inference disabled. The model selects approved tools; it does not receive credentials, arbitrary database access, or authority to write.

Can administrators automatically see HR data?

No. Administrative authority and HR data authority are separate. Access to confidential fields requires the explicit HR role.

What happens when a data import fails?

The failed generation is not published. TBOC2 preserves the previous usable generation so operational access does not depend on accepting partial data.

Request access

Start with the data and decisions that matter.

Tell us what your teams need to see, protect, and act on. We’ll map the sources, authority, roles, and operating workflow.

contact@tboc2.comCustomer-controlled deployments

Your email application will open with the inquiry prepared. Nothing is transmitted by this website.