ERPAIIntegration
Questions we answer
Can we trust AI to act on its own?Governance and guardrailsWho allowed the AI to do that?Identity travels with every requestCan someone talk the AI into something risky?Risk-graded autonomyCan we see who did what, and why?One thread from request to resultWhere are the keys kept?One vault, no shared secretsWhy did the AI bill jump, and who spent it?One counted doorwayIs every task getting the right model?Right model, right taskWhat if our AI vendor goes down or raises its price?No single point of supplyAre we paying for tools that do the same job?One tool per jobDoes the AI forget everything between conversations?Governed shared memoryIs this producing real work, or just answers?The digital factoryWhich work should run itself?Managed, not scriptedCan we get more from the Copilot licences we already pay for?Copilot proposes, the platform verifiesWill people actually use it?Meet people where they workHow much time do people lose sorting inbound information?Intake to insight, untouchedCan the same platform run a real business?One governed foundation for every productWhat happens when it breaks at night?Detect, fix, escalateWhere is the list of what is open, and who owns it?One list, closed with evidenceCould we recover if we lost everything?Proven by restoringCan you prove it to an auditor?Challenge before acceptanceDoes it get better over time, or just older?Every lesson becomes a ruleWill this still work after the next upgrade?Clean Core for AIDo our documents match what is actually running?Documentation as a by-product

Portfolio / Secure by Design

The business question · Agent and user authentication

“Who allowed the AI to do that?”

The concept

Identity travels with every request

The person, not the bot, is the unit of access, so every action is attributable.

How it works
Every request carries the sender's verified Microsoft identity, and that person's role decides which tools the agent can even see.
Why it matters
AI can be rolled out to every department without giving any bot the keys to the company, and every action stands up to audit.
The result
The same request from the owner and from a guest reaches different tools, and every conversation is tied to a named person.

See it workingIdentity travels with every requestAnimation

Every request carries the sender's verified Microsoft identity, and that person's role decides which tools the agent can even see. Animated from the platform's real setup.

The business problem

One agent, many people, and no way to tell them apart.

Many AI assistants run on a single shared service account, so every user effectively borrows the same keys. One agent serves the owner, family members and invited guests. Without identity, a guest could reach owner-only tools and nobody could tell who asked for what.

Why this concept

One agent, with each person's Microsoft identity carried into every request and tools granted by role

Separate agents multiply cost and drift apart; a shared account fails any audit. Carrying identity keeps one agent while making every action attributable.

Also considered

  • One shared service account for the agent
  • A separate agent for each kind of user

How it works

Identity travels with every request

Person

Signs in with Microsoft 365

Teams

Stamps the verified identity on every message

Role

Decides which tools exist for this person

Agent

Works only with those tools

Record

Every action tied to a named person

What we put in place

  • Made Microsoft 365 sign-in the front door, so access follows the person, not the bot.
  • Teams stamps every message with the sender's verified identity before the agent sees it.
  • Gave owners, admins and guests different tool lists; a guest never sees owner tools.
  • Put every admin screen behind single sign-on instead of separate logins.

The result

Before

One agent, many people, and no way to tell them apart.

After

The same request from the owner and from a guest reaches different tools, and every conversation is tied to a named person.

The admin tier is still being tightened, and that is tracked in the open.

I design security into the operating model first, so it never has to be bolted on later.

In your organization

A pattern for rolling agents out to departments without giving every bot the keys to the company.

Contact

Looking for someone to lead AI from pilot to production?

I would be glad to walk you through any part of this live and talk about the role you have in mind.

j.walters@erpaiintegration.com

Go deeper: Lessons · The journey · How it’s built · Live health