Imagine that a supplier tells your purchasing team a shipment will arrive later than expected. First, an employee asks an AI assistant for the status of the related purchase order. The assistant checks ERP and provides an answer. Then, the employee asks it to prepare a revised delivery date. Finally, they ask the assistant to submit the change.
Although these requests may happen in one conversation, each message gives the AI a different responsibility. Additionally, each request may have larger impacts than the user realizes. For instance, a purchase order may affect inventory, production, suppliers, and financial planning. Even a delivery date can have consequences beyond purchasing.
With these AI and ERP concerns in mind, how do you determine when the assistant can provide information, when someone needs to review its work, and when it can change a business record?
What Can a Conversation with ERP Actually Do?
In Implementing Conversational AI Into ERP Software, researcher Siar Sarferaz describes several ways people could interact with AI and ERP through ordinary language. For instance, employees could search for records, navigate to a function, ask for an analysis, or complete a transaction. One example involves asking the system to create a purchase order. In this case, the system validates the details, checks availability and cost, and confirms the budget (Section IV).
A chat window may simply look like a tool for asking questions. However, the functions behind it can change ERP data. Because of this, the boundary between answering and acting cannot depend on the interface.
Consider the status question. The assistant might retrieve the purchase order’s approval status and delivery date. However, the paper specifies that conversational search should show only records the employee is permitted to access. It also describes authorization checks when the interface calls ERP functions (Sections IV–V).
What Changes When AI Prepares the Next Step?
Suppose the supplier confirms a new date, and the employee asks the assistant to prepare a change. It might collect the supplier’s message, check the current order, and flag a production schedule that could be affected. At this stage, the AI is now assembling a proposed business decision, rather than simply finding information.
The conversational AI and ERP paper describes how an assistant can use application context and connect to ERP functions. Namely, complex scenarios may require information from the ERP’s Local Domain Context, “such as configuration data, private methods, and other internal features” (Section V). A proposed amendment, for example, may depend on several connected processes.
That leads to questions for the reviewer:
- Does the supplier’s message apply to this order?
- Is there enough inventory to cover the delay?
- Would the change affect a customer commitment?
An AI-generated explanation may help, but the purchasing manager or other designated reviewer should be able to inspect the source information before accepting the proposal.
When Should the Agent Be Allowed to Act?
Let’s take this discussion a step further. Sarferaz’s paper on agentic AI in ERP proposes requirements for agents that can use tools and carry out steps within ERP, including defined permissions, validation of inputs and outputs, error handling, monitoring, and explanations of decisions (Section IV).
The article’s billing dispute example makes those requirements more concrete. For instance, if a customer questions an increased charge, the agent can compare the invoice with billing history and contract terms. Then, it identifies an overcharge, recommends a credit note, and may generate one. Whether it can release that credit without a person depends on predefined approval thresholds. If met with a complex cases, the agent can redirect to staff (Section VI).
The same approach can help you think through the purchase order. For example, you might allow an agent to submit a routine date change when the supplier has confirmed it and the change meets defined conditions. A change that increases spending, disrupts production, or raises a regulatory concern may need a person’s approval. Submitting an amendment and approving it should also be treated as separate permissions.
Regardless of the use case, the agent should have access only to the fields and actions it needs. Additionally, existing ERP validation and separation of duties rules should still apply. Missing or contradictory information should trigger review.
The agentic paper shows why these limits matter. In controlled dispute tests, the agent classified cases with 81.7% accuracy, compared with 97.3% for the non-agentic approach evaluated. Researchers reported “incomplete email parsing, invalid contract data references, and occasional model timeouts” (Section VI). Those results concern one use case, not a predicted accuracy rate for your ERP. They show why speed alone cannot justify approval authority.
Could You Explain the Decision Later?
Suppose the shipment arrives late and your operations team asks why the purchase order changed. Could you identify who requested the change, which records the agent checked, and who approved it?
The agentic paper calls for explanations and detailed records of the data and decisions behind an action. In its dispute example, the agent documents its steps in the case notes. Its proposed framework also extends ERP change logging to track an agent’s inputs and outputs (Sections IV and VI).
For your purchase order, a useful record would include the following:
- The request, the source information reviewed, and the original and proposed values.
- The checks performed, any exception raised, and the person who approved the change.
- The final ERP action and whether it succeeded.
This gives the business owner a way to investigate mistakes and refine the process. The team also clearly knows who is accountable for deciding which actions the agent may take.
Where Do You Draw the Line?
Start with one workflow and ask the following:
- What may the AI read?
- What may it prepare?
- What may it change?
Then, look at the consequence of an incorrect action. Ask the following to determine safety measures:
- Who must verify the information?
- When is approval required?
- What evidence will you need afterward?
The same purchase order may move from an answer to a proposed change to an ERP transaction. Setting authority at each step allows your organization to benefit from AI and ERP assistance while keeping important business decisions under deliberate control.
This is part of an ongoing series. Feel free to read our introductory post below, and stay tuned!
What Can a Conversation with ERP Actually Do?



Leave A Comment