1. What Nexus One Is and Why It Matters
Understand the sovereignty model: data stays on your premises, only results travel back, and how Nexus One fits into the broader My connections ecosystem.
Nexus One is a sovereign OUPI device you install on your own premises. It runs OUPI capabilities locally, meaning your files never leave the device. Missions can dispatch work to it, but only the result — an artifact, an answer — travels back to the platform. Everything else stays behind your walls.
This matters for two reasons: compliance and reach. Data that must not leave your infrastructure (regulated records, proprietary designs, sensor feeds) can now be processed by @oupi without ever crossing the network boundary. And local resources the cloud simply cannot touch — machines on an air-gapped network, files on a factory floor — become accessible to your missions.
Credits for work performed on the device are debited from your OUPI account, exactly like any other action on the platform. There is no separate billing model to learn.
Nexus One lives inside the broader My connections ecosystem. My connections is the hub where every surface that extends @oupi beyond the platform is managed: the Chrome extension, OUPI Desktop, the Office add-in, Teams and Slack bots, the Orbe voice device, and Nexus One itself.
All connections share the same pairing model (a five-minute, single-use code generated from My connections), the same status dashboard, and the same revocation controls. @oupi is aware of which connections are online and on which machine, so a mission can combine a Nexus One for local file processing with the Chrome extension for a web lookup — seamlessly, in the same workflow.
Nexus One is unique among connections because it adds a full device console: telemetry, anchors, skills, and granular grants. But it is still managed from the same "My connections" page.
The sovereignty model rests on two mechanisms: anchors and grants.
Anchors are folders on the device that you explicitly expose to OUPI. A mission can only read and write inside anchored folders; everything else on the device remains invisible. You add or remove anchors from the device console at any time, so the scope is always under your control.
Grants determine what @oupi is allowed to do: read anchors, run skills, produce artifacts — per device or per device group. The default posture is "entire fleet sovereign," meaning nothing is granted until you decide. You open permissions deliberately, device by device or group by group (e.g., "Workshop," "Site A"), and you can revoke them just as quickly.
This layered approach — anchors for data scope, grants for capability scope — ensures that sovereignty is not just a label but an enforceable, auditable boundary.
The device console gives you operational visibility and control for each Nexus One. It surfaces:
• Live telemetry and health — know instantly if a device is online and performing. • Capabilities — what the device can run. • Anchors — which folders are exposed, editable on the fly. • Artifacts — results the device has pushed back to the platform. • Device skills — reusable procedures produced locally, with code, manual, and instructions. You can enrich a skill, version it, share it with your team, or propose it to OUPI. Each skill shows whether it has been tested and where. • Remote access — a secure tunnel protected by your OUPI login, off by default. "Authorize local login" lets you approve an on-device login attempt via a six-character code.
Group your devices to manage rights in bulk instead of one by one.
Start with the tightest scope possible. Anchor only the specific folders a mission needs, grant only the required capabilities, and expand later if necessary. Because the default is fully sovereign (nothing granted), you are always one click away from revoking access — but you cannot un-send data that was already exposed by an overly broad anchor.
Open My connections, select "Pair a Nexus One," and generate a pairing code. Enter it on your device within five minutes. Once paired, open the device console: check its health status, review its capabilities, and create your first anchor by exposing a test folder. Confirm the anchor appears in the console before proceeding.
Nexus One is your sovereign edge: data stays on your premises, only results travel back. It pairs via a five-minute code from My connections — the same hub that manages all your OUPI surfaces. Sovereignty is enforced through anchors (which folders are visible) and grants (which capabilities @oupi may use), both revocable from the device console. Device skills let you build, version, and share reusable local know-how. Remote access is off by default, and the entire fleet starts fully sovereign until you explicitly open permissions.