Security & Permissions
Secure AI assistance for sensitive business data
AkbAI follows ERPat permissions, tenant boundaries, module access, and user roles before retrieving or processing information.
Security Philosophy
Not an unrestricted AI
AkbAI must behave according to the current user's access rights inside ERPat. Every request passes through identity, tenant, role, module, and permission checks before data is retrieved or processed.
Permission Flow
How every request is checked
From the first message to the final response, each step enforces the user's access.
User Request
A user asks AkbAI a question in natural language.
Identify User
AkbAI confirms who is making the request.
Identify Tenant
The request is scoped to the user's company.
Identify Role
AkbAI determines the user's role and responsibilities.
Check Module Permission
Access to the relevant ERPat module is verified.
Check Data Scope
AkbAI limits results to the user's allowed records.
Retrieve Allowed Data
Only authorized data is fetched through controlled APIs.
Generate Response
Results are summarized into a clear, helpful answer.
Log Activity
Important AI actions are recorded for accountability.
Security Features
Enterprise-grade controls
Tenant Isolation
Each company's data remains separated from other tenants.
Role-Based Access Control
AkbAI follows the same permission rules as ERPat.
Module-Level Permission
Admins control which modules AkbAI can access for each user or role.
Data Scope Restriction
Users only see records within their allowed scope.
Sensitive Data Protection
Payroll, employee records, and personal information require strict permission validation.
Confirmation Layer
Write actions require user confirmation before they run.
Audit Trail
Important AI actions are recorded for review and accountability.
Access Examples
The same assistant, different boundaries
What a user can ask depends entirely on their role and permissions.
Team Lead
Can ask
Who on my team was late this week?Cannot access
Show the full company payroll summary.Employee
Can ask
Show my leave credits.Cannot access
Show another employee's salary.Payroll Officer
Can ask
Summarize payroll cutoff exceptions.May be restricted from
Changing employee master records without permission.Recommended Safety Rules
Principles AkbAI always follows
Never bypass ERPat permissions.
Never expose data outside the user's allowed scope.
Never perform sensitive write actions without confirmation.
Always log important AI actions.
Keep tenant data separated.
Use memory only for safe and approved preferences.
Provide clear refusal messages when access is not allowed.
AI assistance with enterprise-level control
AkbAI helps users work faster while respecting business rules, sensitive data, and access permissions.