How Nova is built
Architecture: a fixed core with extensions around it
Nova consists of a fixed core plus connectors and extensions that can be adapted faster without changing the core.
- Fixed coreIdentities, roles, workflows and audit log.
- ConnectorsFor SAP, AD, Entra ID, SCIM and Keycloak.
- Data in PostgreSQLOne single database in your infrastructure.
Layer model
Four layers, one fixed core
The extensions include the AI assistant, your own workflows and customer-specific plugins. The core itself changes only in a controlled, documented way.
Extensible
Moves with your needs
- AI assistantoptional · local or cloud
- Your own workflowsstages · approvers
- Pluginspartners · in-house
Connectors
The bridges into your systems
- SAP ERP & S/4HANARFC · BAPI
- Active Directory / LDAPLDAPv3
- Microsoft Entra IDGraph API
- Cloud appsSCIM 2.0
- KeycloakAdmin REST
Nova core
Controlled changes · documented
- IdentitiesLifecycle & organisation
- RolesBusiness roles & risk
- WorkflowsRequests & approvals
- Audit trailWho · when · origin
Data
In your infrastructure
- Adaptable without changing the core
- Fixed core
Principles
What the architecture means for your operations
-
The core does not move.
The core holds identities, roles, workflows and the audit log.
Changes to the core
TestedDocumentedFormal change management
This is what you build your compliance on.
-
Connectors and extensions change independently of the core.
If a target system changes, for example when moving to S/4HANA Cloud, only the connector is affected; the core stays unchanged.
- Connectors are replaceable.
- The AI assistant is optional.
- Custom logic lives in plugins, such as your own anomaly detection.
A connector for S/4HANA Cloud is on the roadmap.
-
You retain control.
- You can develop plugins and connectors yourself.
- Maintenance can be handled by a service provider of your choice.
- What happens to the source code if we go out of business is set out in the contract.
Operations
Resources and sustainability
How much power and hardware your installation uses depends mainly on your environment. Nova itself is built to run on little infrastructure.
-
One process, one database
Nova runs as a single instance: one Python process and one PostgreSQL database on a single server.
- No Java application server, message bus or Kubernetes cluster on your own servers.
- Nova handles more load with threads in the same process.
- Test and production environments can run on the same container image.
-
AI only on request
The core works without a language model. AI is switched off by default.
- Requests, approvals, provisioning, reconciliation and recertification make no AI calls.
- Role mining candidates and the healthcheck work without AI.
- Instead of a cloud provider, you can connect a local model via Ollama in your own data centre.
-
Your data centre, your power
Nova runs on your infrastructure, on premises or in your private cloud. You decide which data centre and which power supply it uses.
-
Our own servers
Nova's website, handbook and demo system share one cloud server operated by Hetzner Online GmbH in Nuremberg. According to Hetzner, its servers have run entirely on hydropower since 2008.
Next step
Ask your questions live on the system.
30 minutes via video call on the demo system: you name your use cases, we show the relevant functions.
Request a demoRead on
- Integrations
Protocol and status for each system, searchable and filterable.
- Trust Center
Policies, audit log documentation and mappings for GDPR, NIS-2 and CRA.