TBOC2 connects customer-owned records to a secure operating workspace, validates every publication, preserves source authority, and turns authorized questions into evidence-backed answers.
TBOC2 does not blur ownership. It keeps the authority of each source explicit while making the information useful together.
01 / Connected sources
Business records stay connected to their source.
Google Sheets can remain authoritative for timecards, labor, contracts, budgets, calendars, and vendor records. Named links take users back to the exact source tab when source context matters.
Read-only, scoped collection
Scheduled synchronization
Visible freshness and lineage
02 / TBOC2 authority
Controlled records stay controlled.
Employee roster and compliance records can remain authoritative inside TBOC2. Ingestion preserves those boundaries instead of overwriting protected operational data.
Explicit ownership rules
Confidential HR separation
Role-aware search and export
From source to decision
A publication path designed to fail safely.
01
Connect
Use scoped credentials for approved sources.
02
Validate
Check schemas, types, identities, dates, and references.
03
Publish
Create a new immutable data generation atomically.
04
Serve
Expose the approved generation through a private, read-only query layer.
05
Use
Power authorized workspaces, reports, exports, and Ask TBOC.
If an import fails, nothing partial is published.The previous usable generation remains available while the failure is reviewed.
The business workspace
Built around the work people actually do.
Each user sees a responsive operating surface shaped by their role, responsibilities, and authorized data.
BUSINESS OPERATIONS
Good morning
Data current · 2 min ago
Active employees128Authorized roster
Open exceptions7Requires review
Active contracts24Source verified
Labor activityLast 8 weeks
Role-aware home
Priorities and summaries reflect the user’s permitted scope.
Named source links
Move from a result to the exact authoritative source.
Reports and exports
Use the same authorization rules beyond the screen.
Freshness visible
Know which publication powers every result.
Ask TBOC
Natural language, bounded by real authority.
A local language model helps interpret the question and choose from approved, read-only tools. TBOC2—not the model—enforces identity, role, data scope, and evidence.
Runs locally with cloud inference disabled
No arbitrary SQL and no direct writes
HR tools are absent for users without HR authority
Answers retain evidence and source context
Answer path Controlled execution
01Interpret the requestLocal language routing
02Select approved toolsKnown capabilities only
03Enforce the user’s roleServer-side authorization
04Query the published generationPrivate read-only service
05Return answer and evidenceTraceable to source
Security is part of the data model
Least privilege without implied access.
Authority is explicit. An administrator manages the platform; that alone does not grant access to confidential HR data.
01
Google sign-in
Invited users authenticate through Google. In Google mode, TBOC2 stores no user passwords.
02
Explicit local roles
Observer, operator, HR, and administrator permissions remain distinct and server-enforced.
03
Confidential data controls
Sensitive HR fields stay protected across views, search, sorting, exports, evidence, and Ask TBOC.
04
Separated credentials
Interactive sign-in and unattended source collection use different Google credentials and scopes.
05
Private services
Database, query, and model services can remain inside the customer-controlled environment.
06
Traceable change
Immutable generations make data publication observable, recoverable, and easier to audit.
Available now
Current platform capabilities.
Google Sheets ingestionScoped, scheduled, validated synchronizationPostgreSQL supportStructured operational data connectivityExcel & CSVGoverned workbook import and snapshot or live CSV patternsImmutable generationsAtomic publication with last-good preservationBusiness workspaceRole-aware operations, reports, and source linksAsk TBOCLocal language routing to approved toolsRole-aware accessServer-side identity and data enforcementCustomer-controlled operationDeploy and operate inside your environment
When the mission does not fit an off-the-shelf workflow, TBOC2 can be configured or custom-built around your operating model, data authority, roles, and reporting needs.
It is designed for customer-controlled deployment. Core data, query, and local model services can operate inside the customer environment.
Who owns the data?
The customer does. TBOC2 preserves explicit source authority, uses scoped access, and does not require a third-party hosted data platform.
Which data sources are supported?
Current capabilities include Google Sheets and Drive-connected workflows, PostgreSQL, qualified Excel ingestion, CSV snapshots, and CSV patterns configured for live customer-system data.
Does Ask TBOC send data to a cloud AI service?
The current implementation uses a local model with cloud inference disabled. The model selects approved tools; it does not receive credentials, arbitrary database access, or authority to write.
Can administrators automatically see HR data?
No. Administrative authority and HR data authority are separate. Access to confidential fields requires the explicit HR role.
What happens when a data import fails?
The failed generation is not published. TBOC2 preserves the previous usable generation so operational access does not depend on accepting partial data.
Request access
Start with the data and decisions that matter.
Tell us what your teams need to see, protect, and act on. We’ll map the sources, authority, roles, and operating workflow.