Vianordis
--:--:-- UTCVianordis / ED. 02 / 2026
§ 07 — App support

Bicameral

Put consequential AI actions behind a human decision.

Bicameral embeds identity-bound assistants into enterprise applications, turns requests into visible proposed actions, and lets authorized users approve or reject execution before work crosses into operational systems.

01Problem

Enterprise assistants become risky when advice and action look the same.

A useful assistant must eventually do more than answer questions. The moment it sends a message, creates an event, changes a record, or triggers an operational task, teams need to know whose identity is in use, what will happen, and who authorized it.

  • Users cannot always distinguish a suggestion from an action that will change a business system.
  • Assistant interfaces are rebuilt separately in every application, producing inconsistent controls and blind spots.
  • Operational requests reach tools without a clear human approval step or visible final status.
  • Skill output is buried in chat text instead of being presented as usable tables, cards, lists, or code.
  • Identity, tenant context, agent assignment, and directory data are difficult to connect consistently.
02Solution

Bicameral creates a governed interaction layer between people, agents, and tools.

Bicameral provides a reusable assistant surface, authenticated agent sessions, typed action responses, explicit approval cards, and structured result rendering. Host applications keep their own context while Bicameral standardizes how users request work and authorize consequential actions.

  • Each human-to-agent session is authenticated and bound to an explicit agent identity.
  • Proposed email, calendar, record, and operational actions are shown with approve or reject controls.
  • Skill results return in compact, task-oriented views instead of forcing users to interpret raw payloads.
03Benefits

Make enterprise AI useful without making it opaque.

Bicameral gives product teams a consistent assistant experience and gives operators a visible decision point before supported actions execute.

Keep people in control

Separate a proposed action from its execution so an authorized person can inspect the request before approving or rejecting it.

Standardize assistant governance

Use the same session, action, approval, error, and result patterns across every application that embeds the Bicameral widget.

Reduce integration work

Adopt reusable React components, hooks, server clients, and Next.js route factories instead of building a new assistant stack per product.

Turn output into a workspace

Present successful skill output as tables, cards, lists, or code and open detailed results without leaving the assistant context.

Bind work to identity

Use organization authentication, explicit agent assignment, and tenant-scoped directory context rather than anonymous assistant sessions.

Surface failures clearly

Return authentication, connection, parsing, execution, and approval errors to the interface instead of silently hiding failed work.

04How it works

From request to authorized result in three steps.

  1. 01

    Authenticate and bind

    The host application supplies the user access token and Bicameral opens an H2A session with the assigned personal or service agent.

  2. 02

    Ask and review

    The user describes the task while the assistant returns text, structured skill output, navigation, search results, or a proposed action.

  3. 03

    Approve and complete

    For supported consequential actions, the user reviews the summary and explicitly approves or rejects the request before checking its final status.

05Features

What product teams and users can do with Bicameral.

Embeddable assistant widget

Add a draggable chat entry point and responsive assistant overlay to React or Next.js applications through a shared provider.

Identity-bound H2A sessions

Resolve a personal or service agent, create an authenticated session, retain conversation context, and expose session errors directly.

Human approval cards

Review and approve or reject email, calendar, record-change, and operational actions with clear pending, approved, and rejected states.

Structured skill results

Show execution status, duration, errors, compact previews, and expanded result views for agent skills.

Generative UI actions

Render tables, card grids, lists, code blocks, device state, navigation links, and ranked search results inside the conversation.

Reusable server integration

Use typed API clients and Next.js route factories for sessions, messages, approvals, identity, contacts, briefings, and threads.

06Architecture

Architecture and control model.

Bicameral separates the host application, assistant interface, authenticated proxy routes, agent services, and enterprise directory connections so each boundary remains explicit.

  • A React component library provides the chat provider, widget, overlay, message views, approval cards, hooks, and structured result modal.
  • The host application supplies a Keycloak access token and chooses the API base path, agent settings path, and assigned agent resolver.
  • Next.js route factories proxy sessions, messages, approvals, identity, contacts, briefings, conversations, and threads without exposing server credentials to the browser.
  • The Bicameral API manages agent sessions, assistant messages, identities, approval state, and briefing data.
  • Agent Portal clients expose persona, memory, skill marketplace, installation, and skill-definition operations for the assigned agent.
  • Limitless UI renders structured skill output as compact tables, cards, lists, and code with an expanded detail view.
  • An optional Ops API contact provider uses mTLS and tenant context to combine organization directory and CardDAV contacts.
07Use cases

Where Bicameral fits.

Email and calendar assistance

Draft routine communication or prepare calendar work, then require a person to review the recipient, subject, and action before approval.

Record-change workflows

Let an assistant prepare a CRM, service, or administrative update while keeping the proposed modification visible before execution.

Operational actions

Expose device state, search results, navigation, and executable operations in one interface with approval available for consequential steps.

Embedded product assistants

Give multiple Vianordis applications a shared assistant experience without duplicating session, approval, and result-rendering logic.

Managed agent rollout

Connect users to personal or service agents with configured personas, memory retention, skills, permissions, and guardrails.

08Integrations

Connect the assistant plane to existing enterprise services.

Bicameral is packaged as an application integration layer rather than a standalone chat silo.

Keycloak

Keeps access tied to organization accounts, roles, and sign-in policy.

Bicameral API

Lets approved systems connect without ad hoc exports or manual copy-paste.

Agent Portal

Shows how this service fits into the wider Vianordis environment instead of standing alone.

gscChatCore

Shows how this service fits into the wider Vianordis environment instead of standing alone.

FreeIPA / LDAP

Shows how this service fits into the wider Vianordis environment instead of standing alone.

CardDAV

Connects address-book data so people and organizations remain visible in context.

Ops API

Lets approved systems connect without ad hoc exports or manual copy-paste.

Next.js

Shows how this service fits into the wider Vianordis environment instead of standing alone.

React

Shows how this service fits into the wider Vianordis environment instead of standing alone.

Limitless UI

Shows how this service fits into the wider Vianordis environment instead of standing alone.

Server-Sent Events

Shows how this service fits into the wider Vianordis environment instead of standing alone.

Custom APIs

Lets approved systems connect without ad hoc exports or manual copy-paste.

09Trust

Security and trust signals.

Bicameral is designed to make identity, authorization, action state, and integration boundaries visible to product, security, and compliance teams.

Human authority

Supported consequential actions remain pending until a user explicitly approves or rejects them.

Organization identity

The host supplies a Keycloak JWT and H2A sessions are bound to an explicit personal or service agent.

Protected mutations

Server route factories require authentication and validate same-origin requests before state-changing operations.

Tenant directory scope

The optional contact provider filters organization users by tenant and excludes service accounts and the current user.

mTLS operations link

Directory and CardDAV access through Ops API uses a client certificate, private key, trusted CA, and API key.

Honest failure handling

Connection, authentication, response, approval, and skill failures are surfaced rather than silently converted into success.

10 — Pricing

Start with published pricing, then map the approval workflows that matter.

Bicameral is listed at €8 per user per month on the Vianordis rate card. A demo is the fastest way to review agent assignment, supported actions, approval boundaries, host applications, and required integrations.

11FAQ

Questions technical buyers usually ask.

Who is Bicameral for?

Bicameral is for organizations adding assistants to business applications where identity, agent assignment, structured output, and human approval must remain visible.

Which actions can require approval?

The current approval model covers sending email, creating calendar events, modifying records, and executing operational actions. Each request can be pending, approved, or rejected.

Can Bicameral be embedded in an existing application?

Yes. The frontend is distributed as a React library with a provider, widget, overlay, hooks, typed clients, and Next.js route factories.

How are skill results displayed?

Skills can return status, duration, errors, and structured output. Bicameral renders supported output as compact tables, cards, lists, or code and can open a detailed result view.

How is access controlled?

The host application supplies the organization access token, server routes reject unauthenticated requests, mutations use origin checks, and sessions resolve an explicit agent identity.

Does Bicameral currently provide end-to-end encrypted human messaging?

Not in the current release. Direct H2H sending is disabled until PQXDH session establishment and authenticated encryption are integrated, so the product does not present plaintext transport as end-to-end encryption.

12 — Next step

Give enterprise assistants a visible line between recommendation and action.

See how Bicameral can add identity-bound sessions, structured results, and explicit human approval to the applications your teams already use.