PRODUCT STRATEGY · APPLIED AI · BUILD · ARCHITECTURE
O-HR had twenty years of Australian HR practice written down and nowhere for it to live. Castle Digital designed and built Nooma, an AI practice companion that walks a practitioner through an investigation, a performance process or a restructure, writes the work product, and keeps a record that holds up when someone asks to see it.

SHARE THIS
THE BRIEF
Human resource information systems do a real job. They hold employee records, run payroll, track leave and meet Single Touch Payroll obligations. That foundation is not optional.
But the architecture came out of supply chain software. A new starter is receipted like a unit of stock. Turnover is calculated like inventory turnover. Across roughly twenty major platforms and seventy-five years of development, not one was founded by someone who had actually done the job.
So the judgement-led work sits above all of it, held together by nothing more than Microsoft. An employee relations register in Excel. Succession planning rebuilt from scratch every year. Board papers written after dinner. O-HR founder Jessie Ivancic had spent close to twenty years running HR functions and had the methodology for all of it. What she did not have was a way to put it in anyone else's hands.
WHAT WE BUILT
Nooma is the intelligence layer for everything that happens above the HRIS. It serves three quite different users from one platform, and each needed a different account model underneath the same practice engine.
HR professionals. An in-house function with six permission tiers, business units mapped to reporting lines, and visibility scoped by role and remit.
HR consultants. A portfolio of client organisations under one account, each isolated from the others. Do the work for a client on the platform, or put them on it and keep oversight from above.
Business owners. Employees, responsibility, and no HR department. Structure, documents and guidance to do properly what they can do themselves.
Expert-designed processes for investigations, performance management, offboarding and position management. Each runs step by step, generates the documents as it goes and records decisions at the point they are made.
Purpose-built agents for culture and psychosocial risk, employment relations queries, offboarding and position design. Each is scoped to a defined task with its own knowledge base, forms and decision gates.
Drafts appear in an editable canvas beside the workflow. The practitioner rewrites, approves and exports. Nothing leaves the platform as a finished document without a human touching it.
A dual-layer culture instrument fed by everyday HR work rather than annual surveys. Sentiment on the inner ring, behaviour on the outer, weighted by participation so no single event distorts the picture.
Every piece of work in flow, in one place. A system view for the function, a leader view for the team and a personal view for the practitioner, replacing spreadsheet trackers and status meetings.
Authorisations are requested, received and recorded inside the flow of work. Every decision is timestamped and written to a record that cannot be edited afterwards.
Administrators upload their own policies, procedures and templates alongside the compliance library, so the platform works from the organisation's own sources as readily as it works from ours.
Individual and team plans, centralised billing for organisations, seat provisioning by an account owner, and tier-gated access to workflows and tools.
THE PRODUCT
Nooma walks a practitioner through an investigation, step by step, and writes the record as it goes.
A performance process, structured and documented, so the paperwork holds up if it is ever questioned.
THE HARD PART
This platform handles investigations into real people, at real workplaces, with real consequences. That ruled out most of the patterns the industry currently treats as normal. Five constraints shaped every decision about the data model and the agent design.
The agent generates, surfaces and structures. It cannot initiate, progress or complete a workflow on its own. Every step waits for explicit human action, and decision gates are a hard stop.
A governed corpus of Australian employment law and regulation, lawyer-verified templates, and the organisation's own uploaded documents. No open web and no path outside the defined scope.
Decisions are captured at the moment they are made rather than reconstructed later. Workflow records are retained for seven years, consistent with employer obligations under the Fair Work Regulations 2009, then permanently deleted.
Role, seniority and organisational remit determine what a user can see, enforced in the permission layer rather than hidden in the interface.
Identifier fields can be left blank or filled with employee numbers, and documents can be exported and completed offline, so personally identifiable information need never enter the AI processing layer.
The same thinking runs through every AI build we take on. See how we embed AI properly.
HOW WE WORKED
Every workflow began as a practice document written by a CHRO, not a feature request. Our job was to decompose it without losing the judgement embedded in it. Business steps and engineering components rarely mapped one to one, and forcing them would have flattened the practice into a form wizard.
The work was reviewed as it went by an Industry Council of senior HR leaders representing more than three hundred years of collective Australian HR experience, whose most useful contribution was often telling us where AI should not be used at all. Independent bias testing ran alongside, with students from the University of Sydney and the University of Melbourne and O-HR's in-house responsible AI analyst.
Know, do, document. Twelve times over.
The source was a practice procedure written against the Fair Work Act, the Respect at Work amendments, state work health and safety and psychosocial hazard regulations, and case law. Every step in it carries the same three things: guidance the practitioner needs to know, tasks they have to complete, and documents that must exist afterwards. That structure became the interface. Chat carries the guidance, the task panel carries the work, and canvas and the document library carry the record.
The gates are where the governance lives. Interim actions at step two cannot be implemented until the line manager accepts or declines them. The preliminary assessment at step three decides whether a formal investigation runs at all, and closes the matter properly if it does not. The evidence matrix at step eight is drafted by AI from the case record, then reviewed, edited and locked by the practitioner. Findings go to a decision maker whose determination is the authorisation, timestamped against the person who sent it. The platform helps make sense of evidence and never rules on its value or accuracy.
THE BUILD
Small HR teams have historically been locked out of the trust infrastructure large organisations take for granted. Security, data residency, audit trails and regulatory certification sat behind six-figure contracts and eighteen-month implementation cycles. A core commercial goal was to give an individual practitioner the same standards.
Model access runs under a data processing agreement that prohibits training on customer data and deletes inputs within thirty days. O-HR is building its security and AI governance programme to SOC 2 Type II and ISO 42001:2023 in partnership with Scrut Automation, with certification targeted by 2027.
Application. React single-page app, a platform API carrying auth, tenancy, billing and catalog, and a separate AI service running the agent runtime.
AI. Anthropic Claude for chat and generation under zero-retention terms, embeddings on a version-pinned model, every subprocessor disclosed and reviewed annually.
Data. Managed PostgreSQL and Redis on private networking, and a MongoDB Atlas cluster in ap-southeast-2 for case runtime and vectors.
Hosting. Australian region, private VPC with default-deny firewall rules between tiers, a load balancer as the only public ingress.
Access. No standing production access for engineers. Bastion only, named identities, MFA, session logging, documented break-glass procedure.
Delivery. Pipeline is the only deploy path, with scoped credentials and production secrets held separately from staging.
Business services. Stripe for billing, Klaviyo for marketing contacts, transactional email and identity each under a signed agreement.
Marketing site. Webflow, twenty-six pages and six CMS templates, handed over for the client's team to run.
Recovery objectives. Proposed RPO under five minutes and RTO of four hours for the primary data stores, with a restore test each quarter and the result recorded.
Separation. Production shares no credentials, data or hosts with any other environment.
Approval. Design approved before build, then re-approved as implemented once the environment exists.
ARCHITECTURE
Most agencies hand over a running system and leave the client to explain it. For a platform holding investigation records, that explanation is the product. So alongside the build we produced a current-state architecture of the staging environment and a target-state design for production, written to be approved before the build rather than reverse-engineered after it.
The target-state document sets out twelve designed controls, each keyed to a numbered marker on the topology and mapped to an indicative Trust Services Criterion: edge protection, network segmentation with default deny, a single controlled ingress, administrative access separation, privileged access via bastion with no standing production access, data tier isolation, object storage by signed URL only, in-region managed backup with a tested restore, session handling, change and deployment control, monitoring with a defined on-call route, and centralised logging with alerting on authentication failures and privilege changes.
It also names six decisions that carry real cost and needed a client call rather than a default: whether to put a WAF at the edge, whether to route model traffic through an Australian-hosted gateway, managed versus self-hosted data services, the availability target, the number of environments, and whether the session token change lands before launch. And it states plainly that the controls are designed rather than operating, because the evidence of operation comes from the implemented system and its observation window.
WHERE IT STANDS
The platform is in final testing with the practitioners who helped shape it, and the waitlist is open. Castle Digital continues to work with O-HR across product, engineering, architecture and go to market.
The Castle team have been instrumental in bringing Nooma to life. A true partner in every sense.
Jessie Ivancic
CEO & Founder

Book a free 30-minute call. We'll talk through what you're working on, what we'd do, and whether we should partner. No pitch deck, no PDF brochure.
Book a free 30-minute call
Book a free 30-minute call