AAkbAIby ERPat

Security & Permissions

Secure AI assistance for sensitive business data

AkbAI follows ERPat permissions, tenant boundaries, module access, and user roles before retrieving or processing information.

Security Philosophy

Not an unrestricted AI

AkbAI must behave according to the current user's access rights inside ERPat. Every request passes through identity, tenant, role, module, and permission checks before data is retrieved or processed.

Permission Flow

How every request is checked

From the first message to the final response, each step enforces the user's access.

01

User Request

A user asks AkbAI a question in natural language.

02

Identify User

AkbAI confirms who is making the request.

03

Identify Tenant

The request is scoped to the user's company.

04

Identify Role

AkbAI determines the user's role and responsibilities.

05

Check Module Permission

Access to the relevant ERPat module is verified.

06

Check Data Scope

AkbAI limits results to the user's allowed records.

07

Retrieve Allowed Data

Only authorized data is fetched through controlled APIs.

08

Generate Response

Results are summarized into a clear, helpful answer.

09

Log Activity

Important AI actions are recorded for accountability.

Security Features

Enterprise-grade controls

Tenant Isolation

Each company's data remains separated from other tenants.

Role-Based Access Control

AkbAI follows the same permission rules as ERPat.

Module-Level Permission

Admins control which modules AkbAI can access for each user or role.

Data Scope Restriction

Users only see records within their allowed scope.

Sensitive Data Protection

Payroll, employee records, and personal information require strict permission validation.

Confirmation Layer

Write actions require user confirmation before they run.

Audit Trail

Important AI actions are recorded for review and accountability.

Access Examples

The same assistant, different boundaries

What a user can ask depends entirely on their role and permissions.

Team Lead

Can ask

Who on my team was late this week?

Cannot access

Show the full company payroll summary.

Employee

Can ask

Show my leave credits.

Cannot access

Show another employee's salary.

Payroll Officer

Can ask

Summarize payroll cutoff exceptions.

May be restricted from

Changing employee master records without permission.

Recommended Safety Rules

Principles AkbAI always follows

1

Never bypass ERPat permissions.

2

Never expose data outside the user's allowed scope.

3

Never perform sensitive write actions without confirmation.

4

Always log important AI actions.

5

Keep tenant data separated.

6

Use memory only for safe and approved preferences.

7

Provide clear refusal messages when access is not allowed.

AI assistance with enterprise-level control

AkbAI helps users work faster while respecting business rules, sensitive data, and access permissions.