front-to-back investment office · agents inside · open source
The portfolio platform that never stops watching.
PortfoliFLOW is a complete investment office in software. Your book lives in it,
front office to investor report; agents watch it on a schedule — limits, quotas,
valuations, cash coverage — and speak only when something is material. Ask, and
they answer with figures — computed, never guessed. Every decision closes in writing.
the product, in three minutesthe detail, in the data roomopen source · AGPL-3.0
Your whole book, live — the moment you log in.
/front-office#overviewthe bookscreenshot
The main features, in one loop · synthetic demo data · click to enlarge
02 / 10 · the problem
Most of what an investment team does all day isn't investing.
where the hours gothe master workbookthe decision trail scattered across inboxesthe quarterly manual limit checkthe 40-page manager report, read line by linethe annual optimisation slidethe standing worry that something is drifting unseen
This is how small teams run large books today — not by choice,
but because nothing was built for them.
PortfoliFLOW is built to take
that list off the desk — into software and agents — so the hours go back to the part that is
actually the job. A structural problem doesn't vanish overnight; but every line above is one the
platform already addresses, and the sections that follow show how.
03 / 10 · why now
Every AI you've been shown waits to be asked. Portfolios don't wait.
Chat assistants answer questions. A book needs something else: a system
that re-reads it on a schedule, notices what changed — and stays silent when nothing did.
Reactive on demand. Proactive by default.
when you ask
Shirley
Chat, voice or Telegram — or a photo of a term sheet. She answers with a view, and with
the numbers to back it: computed by the platform, not by the model.
when you don't
Watch Desk
A scheduled pass over the whole book: limits, quotas, valuation freshness, cash coverage,
the press. Urgency set by deterministic rules, not by the model; the immaterial filtered out;
a finding only when there is one.
04 / 10 · what it is
Not a dashboard over your systems. The system — with agents inside.
The whole book lives here: every holding with its cash flows, NAV, multiples
and returns — private funds and listed lines alike — priced from the live feed and kept current
without anyone re-keying a thing. Most systems show you the book. This one helps you run it.
/front-office#charts · Investment F · private equity · vintage 2020screenshot
Produced for every holding, on demand — two contrasting profiles from the same book · synthetic tenant, as of 2026-06-30
The part of the day that isn't investing — that part is handled now.
05 / 10 · one case, one week
It noticed before you did.
One case from one week on the demo book — what the platform did on its own,
and where it stopped.
15 aug · 07:00 · watch desk
The Watch Desk surfaces one finding: equities above their ceiling, the
computed figure beside it. On a quiet day it surfaces nothing — silence is a
deliberate state, not an empty screen.
16 aug · cases & planning desk
The finding becomes a file: notes, a consultation, a scenario tested against the live
plan — without touching the book.
20 aug · 17:41 · decision of record
The file closes with a decision of record and a journal line. When the
committee asks how the decision was made, you open the file, not your memory.
replaces the decision trail scattered across inboxes
/cases/CASE-0001illustration
CASE-0001 Equities allocation rose above strategic ceiling for the first time.
● open
08-15 · 19:28
Openedsystem
Opened from finding saa:equities. Coverage 38.07% against a 30.00% ceiling; headroom −131,423,394 EUR. Materiality frozen at opening.
08-16 · 09:12
NoteS. Brandt
IC meets Thursday. Two paths to prepare: rotate ~€140m out of listed equities, or revise the ceiling.
08-16 · 09:40
Pinned consultationS. Brandt
Shirley on the two paths:
Consultation excerpt · Shirley
A €140m rotation into government bonds DM and IG credit closes the breach with about €8m to spare and opens no new one — both classes hold well over that in headroom. Raising the ceiling is defensible only if the overweight is a deliberate position, and the current SAA inputs don't support that.
equities coverage38.07% → 29.47%headroom−131.4m → +8.6mstatusBREACH → OK
08-20 · 17:39
Decision recordS. Brandt
Decision of record
Decision
Rotate €140m out of listed equities — €80m into government bonds DM, €60m into IG credit — in tranches through Q4. SAA ceiling unchanged.
Rationale
Overweight not supported by SAA inputs; scenario shows the rotation clears the breach without opening another; ceiling revision considered and declined.
08-20 · 17:41
ClosedS. Brandt
Closing note recorded. Journal · JRN-0018
One finding, one file, one line in the journal. Nobody had to remember to check.
06 / 10 · who decides
Then it hands you the pen.
This is the part most "autonomous" systems get wrong. It doesn't decide.
It brings you the question with the numbers attached — possible moves phrased as
support, never as instruction; urgency set by deterministic rules, not by the model.
Every figure is computed by auditable code. A language model, asked the same
question twice, can drift — even in the number. An institutional book cannot rest on that.
Changing the model does not change the numbers.
Elsewhere, the model is the calculator. Here, the model is the colleague who knows
which calculator to reach for.
And every decision closes in the journal — append-only, gap-free by construction:
the page the auditor reads first.
replaces reconstructing decisions from email
/watch-desk#journalillustration
Journal
append-only
2026-08-20 · 17:41JRN-0018 · CASE-0001 closed — €140m rotation out of listed equities approved acted
2026-08-15 · 19:28JRN-0015 · Finding saa:equities opened as CASE-0001 opened_case
2026-08-15 · 07:00JRN-0014 · Critical — equities allocation rose above strategic ceiling for the first time critical
2026-08-12 · 07:00JRN-0011 · Private-debt headroom narrowed to €1.2m, still inside its cap informational
07 / 10 · the desk you couldn't staff
The analytics a large house runs once a quarter. PortfoliFLOW runs them every night.
The efficient frontier on the live book — a standing view, not a one-off study.
Every class against its cap, projected forward, so a breach is forecast rather than
discovered.
The investor review computed rather than assembled — current on any day. Incoming manager
reports read for you, every value cited to its page.
13 / 18 checks OK2 warnings3 breachesequities 38.07% vs cap 30% · headroom −€131.4m
replaces the quarterly manual limit check · the annual optimisation slide
/back-office#limitsforecast · 2030-12-31
Institutional coverage for a small team. Scale judgment, not headcount.
08 / 10 · shirley
Not a chatbot. A colleague.
Call her and talk, type to her, or send her a photo — at your desk or
on your phone, in your language, around the clock. She answers like a professional: with a view,
and with the numbers behind it.
Here: a term sheet photographed on a conference
floor, weighed against the live book in one turn.
in one turn, sheanalyse_imageget_portfolio_overviewget_limit_coverage
At the investor conference — just met the people behind Unicorn Ventures, raising Fund III: early-stage biotech venture. Photographed the key terms. Could it fit our portfolio?
Got it — early-stage biotech venture, €750m target, a solid record across Funds I and II. Pulled your book: venture sits in your private-equity bucket at 9.34% against a 12% cap, €43m of headroom — so it fits the limits. But the book is 38% equities against a 30% ceiling and that case is open at the IC. Adding equity-like risk this week is a committee decision, not a booth decision.
My read: fits the limits, wrong week to sign. Want the one-paragraph version to use at the booth?
Shirley on Telegram · synthetic demo data
09 / 10 · why trust it
You don't have to trust us. Read it.
PortfoliFLOW is open source under the AGPL-3.0. The code that produces every figure —
the analytics core, the limit engine, the scenario overlay — can be read line by line before an
institution relies on it. And it runs on your own machines, behind your own firewall —
so the first book it watches can be the real one.
The business model is just as simple: the software is free. Institutions whose policies need
a commercial licence, or who want a hosted instance, pay for that.
Built to be reviewed — the standards, the decision log and the isolation model are
in the data room.
Six exhibits from the running application — synthetic demo data throughout —
and the answers a diligence process asks first: where it runs, what it is built to, and why
nothing locks you in.
01 / exhibits
The platform, in six views.
Every screenshot is taken from the running application; the animated pieces
are rebuilt from it. Anything shown here can be reproduced on a local instance in an afternoon.
exhibit a · assistants — shirley
"What should we do with this fund?"
One session
from the demo book: the PM asks which fund is earning its fee; Shirley resolves it herself, answers
with computed figures and the caveats a careful colleague would add, renders the chart on request —
and when asked for a verdict, pulls the limits state unprompted, reports the sleeve is over its cap,
and leaves the decision where it belongs: with the PM.
shirley · session · quarterly prepillustration
I'm preparing the quarterly review. Start with the best performing PE fund: is it actually earning its fee, or am I paying active fees for beta? Sharpe, drawdown, and how correlated it is with the rest of the book.
Best-performing PE fund: Investment U — Sample US Buyout Fund II (2024 vintage, USD, North America).
Performance/risk profile Ann. return: 60.71% · Sharpe: 1.42 · Sortino: 8.82 · Max drawdown: −6.63%
That Sharpe and drawdown combination is the strongest in the entire book, PE or otherwise — only Investment T (a cash-proxy overnight-rate ETF) and the cash sleeves show comparable ratios, and those are trivially low-vol instruments, not a fair comparison.
Essentially zero correlation to everything, including your listed-equity sleeve and the rest of the PE book. That's the answer to your framing: this is not a beta substitute. If it were just repackaged listed-equity beta with a fee wrapper, you'd expect it to track Investment A/B/H reasonably closely — it doesn't, at all. It's behaving as a genuinely idiosyncratic return driver, and it's mildly diversifying against your private debt book too.
The caveat you should carry into the review
Vintage is September 2024 — under two years of NAV history. A 60% annualised return off a short window, still in the deployment/early-markup phase, is exactly the kind of number that regresses once the fund matures. Treat it as encouraging, not proven.
DPI is still zero. Cashflows show $28M called, $0 distributed. The NAV of $50.6M vs. $28M called is a strong unrealized markup (~1.81x paper TVPI), but none of it is banked yet. The risk-adjusted numbers reflect GP marks, not exits.
Bottom line: on the numbers available, it looks like alpha, not disguised beta. But with a 21-month track record and zero distributions, I'd frame it in the review as "promising, unproven" rather than "vindicated," and revisit once you have a realization or two to anchor the DPI.
Now chart its story since inception — the rolling IRR, in one picture for the deck.
callingget_investment_datarender_chart
Chart's up — rolling IRR since inception, on its own axis. The shape tells the story: a noisy first few months, where small denominators swing early IRR hard, including a brief dip below zero; then it settles into a 25–40% band through 2025; and the recent markups have pushed it above 50%.
Read the level with the same caution as everything else on this fund: it's computed on GP-marked NAV, with no realisations behind it yet.
Let me know if you want the same view for another fund, to compare across vintages.
What do you think we should do with this fund?
callingget_limit_coverage
Good performance so far, but a few things temper how much weight I'd put on that number, plus a limits wrinkle worth flagging.
What the data shows
Vintage 2024, North American buyout, $28m called, zero distributed (DPI 0.24x is at portfolio level, not this fund's — Investment U itself hasn't returned any cash yet). Latest NAV $50.6m against $28m called — TVPI is running well above 1x purely on marks.
Annualised return 60.71%, Sharpe 1.42, Sortino 8.82, max drawdown only −6.63%. Statistically that's an excellent profile, but treat it with caution: this is under two years of history on a single asset, all unrealised. Early buyout marks can run hot and then normalise once operational value creation (rather than multiple expansion or leverage-driven re-marking) has to carry the NAV. The Sortino figure in particular is inflated by the near-total absence of downside months in a short series — not something I'd extrapolate forward.
No cash-on-cash proof point yet. Until there's a realisation, the "is this a good fund" question is still open — the mark is the GP's opinion, not the market's.
The part that actually matters for a decision: your limits
At the July Stichtag, your private_equity SAA bucket is in breach — 13.76% coverage against a 12.00% cap, headroom −€23.2m. The corresponding AnlV bucket (anlv_13) is at WARN, 13.76% vs 15% cap. Investment U sits inside this sleeve.
That doesn't mean this specific fund is a problem — it's performing better than most of the book, by a wide margin — but it does mean:
No case for adding to this position or committing further PE capital right now; the sleeve is already over its ceiling.
If you're looking for where to trim to bring PE back under 12%, Investment U is not the obvious candidate on performance grounds alone — you'd be cutting your best performer to fix a limits problem, which is a values-destroying way to solve a compliance issue if better alternatives exist elsewhere in the sleeve.
Worth checking whether the breach is a genuine overallocation or a temporary NAV-appreciation effect (strong marks pushing coverage up without new commitments) — if it's the latter, it may self-correct as the denominator (AUM) grows or as other sleeves get funded, though I wouldn't rely on that.
I'll leave the "hold, trim the sleeve elsewhere, or flag to IC" call to you — that's a portfolio construction decision, not something I'll pronounce on — but the two facts to carry into that discussion are: strong unrealised performance on thin evidence, sitting inside a sleeve that's currently over cap.
exhibit b · back office — saa hypothetical comparison
Did the allocation add anything?
The SAA weights held passively — applied to benchmarks, and applied to the tenant's own
composites — plotted against the actual portfolio. The shaded band is the allocation
effect. The board question, answered as a chart.
Stretch a drawdown, repace a fund's capital calls, insert a hypothetical trade, shock a
market or a currency — the engines recompute over the live plan world, and the book itself is
never touched. A result worth keeping is pinned to a case, frozen as it stood.
Funds without a manager plan are paced by the Takahashi–Alexander model —
published, deterministic — so the projection covers the whole book.
/planning-desk#scenario-analysisplan as filedscreenshot
exhibit e · watch desk — briefing & calibration
Surfacing, and how sensitively.
A scheduled pass over the whole book: limits, quotas, valuation freshness, cash coverage.
A finding surfaces only on material change — on a day without one, it surfaces
nothing.
Below: the calibration that governs the desk, per tenant — thresholds, re-trigger deltas and
urgency floors, with the value in force shown next to each field.
/watch-desk#briefingillustration
Last beat07:002026-08-15 · 1 finding surfaced
On watch4 monitorsSAA limits · AnlV quotas · NAV freshness · Cash coverage
Open findings0
Next beat · 07:00 · daily · enabled
All quiet — nothing material since the last beat.
Criticalsaa:equities · surfaced 15 Aug 2026
Equities allocation rose above strategic ceiling for the first time.
Equities have breached the 30.0% SAA ceiling, now at 38.07% of the portfolio, creating a headroom deficit of €131.4 million. This is a structural overweight against the strategic asset allocation limit — not a one-day mark.
The ceiling is class-specific, so trimming elsewhere creates no room under it. Realistic paths: rotate listed equities into classes with headroom (government bonds DM, IG credit), or revise the ceiling with a documented IC rationale — defensible only if the overweight is deliberate.
Derivation & evidence
limit_coverage · saa:equities · ceiling 30.00% · observed 38.07% · first non-benign observation, no prior acknowledgement · re-trigger Δ 0.5pp
/watch-desk#calibrationscreenshot
exhibit f · investor communication — portfolio review
The review, computed rather than assembled.
NAV, IRR, TVPI and DPI at portfolio level; region, vintage and sector splits; then the same
anatomy per investment. Because it is computed from the live book, it is current on any
day — the written commentary is the only part produced by hand.
On a single workstation, for evaluation or a one-person desk. Containers, migrations, browser.
option b
On-premise
Inside your own infrastructure, under your own network policy and controls. The same containers, your database.
option c
SaaS
Hosted on EU servers under EU and German law, in ISO-certified data centres. No setup on your side.
Routine operation of the platform,
including by its operator, provides no incidental read access to tenant data.
03 / built to standard
Built to be reviewed.
Every architectural decision is recorded before code is written — after Nygard — in an
immutable log of more than 110 ADRs that ships with the repository. Layer boundaries
are enforced by regression tests rather than by convention; tenants are separated inside the
database with row-level security; every action lands in an append-only audit log.
The build is aligned to ISO 25010, arc42 and CERT Python, and designed to comply with and
support DORA resilience principles. Together, these let a reviewer establish how the
system produces its outputs before reading the business logic.
portfoliflow standards
→ decisions ..... ADR before code · 110+ · immutable
→ aligned to .... iso 25010 · arc42 · cert python · dora
→ isolation ..... row-level security, in-db
→ audit log ..... append-only · gap-free
_
04 / no lock-in
No lock-in. Anywhere.
not to a model provider
The model is a setting.
Any model behind an OpenAI-compatible endpoint — Anthropic, OpenAI, Google, aggregators such
as OpenRouter, or local via Ollama, in which case no prompt leaves your infrastructure.
Configured per tenant and per purpose — and changing the model does not change the numbers.
not to a stack
Boring on purpose.
PostgreSQL and Python — your data in your own database, exportable at any time. A market
feed never overwrites the imported record, and a data licence belongs to the tenant, not to
the platform.
not to us
Yours to keep.
The code is yours to run, read and keep — independent of any vendor, ourselves included. For institutions
whose policies don't fit the AGPL's terms, a commercial licence is available: same code,
covering different use cases.
05 / install
A local instance in one afternoon.
A complete synthetic demo book is included, so everything shown on this site
can be reproduced without production data — and without talking to us first.
The repository holds the code, the decision log and the install path. Issues and discussions
are open; contributions run under a CLA and follow the same ADR-first discipline as the
project itself — with or without coding agents.
Linux or macOS · Python 3.11+ · Podman or Docker with a Compose provider · Windows via WSL2
The installer checks prerequisites, asks for an owner e-mail and password,
and ends with a verified status report and the URL to open. Update the platform anytime with a
simple command: git pull.
The README on GitHub documents
this and two further installation paths — download-inspect-run with a published checksum, and the
full manual sequence.