AI ASSISTANT

Talk to your servers.
Like a senior SRE sits next to you.

The AI Assistant turns chat messages into typed, parameter-validated, audit-logged operations across your fleet. Every mutation gates on your click. The model can't invent shell commands — only the registered tool surface is callable.

cloudnan.com / dashboard / ai-assistant
web-01.cloudnan.dev
Read-only mode
why is nginx using 80% cpu on web-01?

Let me check what's happening on web-01 — pulling metrics, the process list, and recent error log entries.

get_metrics(agent_id, range=5m)
list_processes(sort=cpu, top=10)
read_log(path=/var/log/nginx/error.log, tail=100)
Tool result (4,218 chars)

Found it — 1,412 stuck PHP-FPM connections, all waiting on slow MySQL queries. The error log shows max_user_connections warnings starting 14 minutes ago. Want me to restart php-fpm to clear the stuck connections, then investigate the slow query log?

Action requires your approval
restart_service
Clearing the 1,412 stuck PHP-FPM connections will free CPU and let new requests through. Existing requests in flight are dropped.
service: "php8.2-fpm"
force: false
Investigating…
↳ get_mysql_slow_queries · running

How it works

Six gates between your chat message and a running command.

  1. 01

    You ask in plain English

    "Why is nginx using 80% CPU on web-01?" — no syntax to remember, no man pages to read.

  2. 02

    AI picks the right tools

    The model selects from 84+ typed tools. It can't invent shell commands — only the registered tool surface is callable.

  3. 03

    Risk tier gates the action

    Reads auto-run. Writes prompt for Approve / Deny. Destructive ops require a PIN. The HTTP layer enforces every gate.

  4. 04

    Agent executes

    The on-server agent receives a typed RPC over mTLS, runs the validated command, streams output back.

  5. 05

    AI explains the result

    The model summarises what the tool returned in human terms — "load is high because PHP-FPM has 1,400 stuck connections" — and proposes the next step.

  6. 06

    Audit log captures everything

    Every invocation persists with conversation ID, params, status, and output. Replay any session months later for compliance.

Risk model

Three tiers, hard-coded into the protocol.

The model can categorise tools however it wants in chat. The HTTP layer is the source of truth — and it doesn't budge.

Tier · Auto69

Read-only & safe

Reads, lookups, diagnostics. Same blast radius as a SELECT — runs instantly without prompting.

Tier · Approve16

Mutating — your call

Anything that writes. AI prepares the call, you click Approve / Deny. No quiet mutations, ever.

Tier · Danger0

PIN-gated

Destructive operations require a second factor on top of approval — or are flagged not-yet-supported.

Tool surface

84+ production tools across 12 categories.

Each tool is parameter-validated, audit-logged, and risk-tiered. Add new tools by registering them in the open-source agent — no LLM fine-tuning required.

Read-only diagnostics

18 tools — see the full list on the homepage.

Deploy from GitHub

5 tools — see the full list on the homepage.

Databases (PG / MySQL / Redis)

9 tools — see the full list on the homepage.

Security audit & scan

8 tools — see the full list on the homepage.

Network & firewall

5 tools — see the full list on the homepage.

Apps & frameworks

5 tools — see the full list on the homepage.

Process control

6 tools — see the full list on the homepage.

Maintenance & updates

6 tools — see the full list on the homepage.

Mail / extras / control plane

22 tools — see the full list on the homepage.

Architecture

The AI lives in our control plane. Your server only runs typed commands.

Server-resident AI agents are easy to build and dangerous to run. We split the brain out so the box never sees an LLM, an API key, or an unbounded shell.

AI lives here

control plane

  • · LLM API keys
  • · Risk-tier gating
  • · Approval flow
  • · Credit accounting
  • · Audit log
mTLS · gRPC

Agent on your server

open source

  • · Executes typed commands
  • · Command blocklist
  • · Outbound-only — no LLM
  • · No API keys on box

You

browser · panel

  • · See every action
  • · Approve mutations
  • · Roll back if needed
  • · Audit trail forever

Defense in depth

Six layers between chat and root.

Tool registry, not shell

AI calls registered tools only. No raw shell. No bash escape hatch.

Param validation

Every tool has a typed schema. Invalid params reject before the agent ever sees them.

Command blocklist

Agent vetoes rm -rf /, dd, mkfs even when generated. Defense in depth.

Audit log

Every invocation persists with conversation ID + user ID. Replayable forever.

Credit + rate limits

Per-message credit deduction caps cost. No runaway billing from a stuck loop.

Open-source agent

Read every command path on GitHub before installing. No closed binary.

FAQ

Things people ask before turning it on.

Which LLM does Cloudnan use?
OpenRouter routes to a small set of frontier models we've evaluated for tool-calling reliability. The current default is calibrated weekly against our internal eval set; operators can switch via AI_CHAT_MODEL.
Can the AI access servers from a different organisation?
No. Every tool invocation is scoped to the agent / org the conversation is opened against. Cross-org reads or writes are impossible at the repository layer — not by AI prompt convention.
What happens if the LLM hallucinates a destructive command?
Three layers stop it: (1) it can only call registered tools, not arbitrary shell; (2) every tool's parameters are typed and validated; (3) the on-server agent has a command blocklist that vetoes destructive shell patterns even when explicitly invoked.
Does the AI have access to my application data?
Only what you ask it to look at. Database read tools (e.g. get_postgres_connections) return metadata, not row data. SQL execution would surface in approval flow — you click before any query runs.
How much does each AI message cost?
One AI credit per message you send. Plan tiers ship with monthly credit allowances. Tool execution itself is free — the credit only covers LLM tokens.
Can I disable the AI Assistant entirely?
Yes. Each agent has an opt-in flag. Default is off for write tools; you flip it on per server. There's no global AI requirement — every operation also exists as a clickable surface in the dashboard.

Your fleet deserves better.

Get started in minutes.

Deploy agents on your servers, connect securely, and take full control. Start free, upgrade when ready.

  • 7-day free trial
  • No credit card
  • Cancel anytime