+1-905-282-9675 query@smartmilestones.com
Select Page

SM Space · AI Assistant

AI Assistant for ERP Data and Everyday Work

SM Space includes an AI assistant for ERP work: ask a question about your own records, or ask for a report, in plain words. It signs in as you, so it sees exactly what you see and can do only what you could do yourself. An administrator decides which parts of the system it may reach, and how firmly you must confirm anything it changes.

It has no permissions of its own. That is not a limitation of the design — it is the design.

Last updated: September 2026

A question, and an answer

“which suppliers did we spend most with last quarter?”

  • Northgate Ltd$214,800
  • Braemar Ltd$138,200
  • Summit Metals$96,400

from 312 purchase orders · Jul–Sep · the live records, not a copy

The same question, two people

“list this month’s purchase orders”

M. Alvarez · finance

PUR-000312 · Northgate $24,000

PUR-000318 · Braemar $6,400

R. Okafor · site

PUR-000312 · Northgate

PUR-000318 · Braemar

no value column — it asked as them

it has no permissions of its own to fall back on

Ticked, not coded

what the assistant may reach, in this company

  • ✓ Purchase orders · readconfirm: none
  • ✓ Purchase orders · approvetype it back
  • ✗ Payrolloff
  • — Bank detailsalways hidden

Saved. No release required.

a setting an administrator changes, not a change we deploy

“Yes” is not enough

“approve the Northgate order”

  • Which one? PUR-000312 · $24,000 · Northgate Ltd
  • yes
  • that is not specific enough — which order?
  • approved · PUR-000312 · as D. Whitfield · 16:22

the refused “yes” is the whole point — a screen shows you what you are agreeing to, and a sentence does not

Above: a plain question answered from live purchase orders; the same question asked by two people, where the one without permission simply gets no value column because the assistant asks as them; an administrator ticking which parts of the system the assistant may reach and how firmly each change must be confirmed, saved without a release; and an approval where a bare “yes” is refused as too vague until the user names the order.

What you can do

  • Ask a question about your own records in plain words
  • Ask for a report and answer a few questions instead of building it
  • Find the right screen by describing the work, not by knowing its name
  • Get an honest “I do not have that” instead of a confident wrong answer
  • Be asked which one you meant when a word could mean two records
  • See only what you are allowed to see, because it asks as you
  • Decide, as an administrator, which parts of the system it may reach
  • Choose how firmly someone must confirm each kind of change
  • Give it your own house rules, glossary and worked examples — and change any of it without a developer or a release

01

It Works With Your Permissions, Not Around Them

The first question everybody asks is what it can see. The answer is: exactly what you can see, and nothing else.

The SM Space assistant signs in as the person using it, so it can see and do exactly what they can — nothing more. It has no account of its own and no elevated access. Every rule that decides what you may see or do when you click a button applies word for word when you ask for it in a sentence: your field permissions, your approval limits, segregation of duties, the workflow’s routing, the reversal window.

Two people, the same words, different answers. M. Alvarez in finance asks for this month’s purchase orders and gets 19 of them with the values on. R. Okafor, a site supervisor whose role hides the cost fields, asks for this month’s purchase orders and gets the same 19 orders with no value column. Ask it to approve PUR-000312 as him and it will not: he is not an approver on that step, and that was decided long before the assistant was asked.

So the sentence worth keeping is this one: the assistant cannot become a way around your permissions, because it does not have any of its own.

The same question, asked by two people

M. Alvarez · Finance manager

“list this month’s purchase orders”

OrderSupplierValue
PUR-000312Northgate Ltd$24,000
PUR-000318Braemar Ltd$6,400
PUR-000321Summit Metals$14,000

19 orders · values included

R. Okafor · Site supervisor

“list this month’s purchase orders”

OrderSupplier
PUR-000312Northgate Ltd
PUR-000318Braemar Ltd
PUR-000321Summit Metals

the same 19 orders, no value column — his role hides it, and the assistant asked as him

refused R. Okafor asks it to approve PUR-000312 — he is not an approver on that step, so the answer is the same one the button gives him

Nobody wrote a rule for the assistant. It is the rule that was already there, reached from a sentence instead of a screen.

M. Alvarez in finance and R. Okafor on site ask for this month’s purchase orders in the same words. Both get the same 19 orders. Only one of them gets the values, because only one of them is allowed to see them.

02

You Decide What the AI Assistant for ERP Can Reach

What the assistant may touch is a setting, not a code change.

An administrator chooses which parts of the system the assistant may reach, and how firmly a user must confirm anything it changes. They open one screen and see every group of functions the system actually has — the list is generated from the running application, so it cannot quietly go out of date the way a written one would. They tick what the assistant may reach, and whether it may only read or also write. Saving it is the whole job: no developer, no release, no call to us.

And it is per company. Two businesses on the same system can disagree about what their assistants may touch, and both get their way. We set an outer limit and each company picks what it wants inside it — so a company can always narrow what is available and can never widen it, and we cannot quietly hand back something a customer switched off.

A short list is refused to every assistant in code, whatever anyone ticks: signing in, users, roles, companies, provisioning, and the access screen itself. An assistant that could edit the screen governing it would not be governed at all.

Administration · AI Assistant Access

Every group of functions this system has, listed from the application itself — so nothing on this screen can go out of date.

  • Purchase orders Read confirm: none
  • Purchase orders Approve confirm: type the reference back
  • Sales orders Read confirm: none
  • Customers & suppliers Read, create confirm: agree to the record
  • Payroll
  • Leave requests
  • Bank details always hidden
  • Users and roles always hidden

saved No release required, and it applies to the next question somebody asks

Your company’s own answer. Another company on the same system can tick none of it, and both are right.

Purchase orders on, and approving one needs the reference typed back. Payroll off. Bank details hidden to everybody, whatever anyone ticks. Saved, and it applies to the next question somebody asks.

03

Confirmation Before Anything Changes

The obvious safety measure is to forbid the assistant from doing anything that commits — no approving, no posting, no reversing. That is what the first version did, and we took it out on purpose.

It is worth saying why, because the caution looked responsible. Blocking the word “approve” inside the assistant did not add a control. It added a second, weaker copy of one that already existed a layer down, where it could drift out of step with the real one — and it removed most of what people wanted an assistant for.

But there is a risk that is real, and it belongs to chat. “Yes” in a conversation is vague about which thing you just agreed to. A screen shows you what you are confirming. A sentence does not.

So the answer is a confirmation rule rather than a ban, and an administrator sets it per kind of change: nothing at all for reading; show me the finished record and wait for me to agree, for creating and editing; and for anything that cannot be undone, make me type the record’s own reference back. With that last one set, “yes” will not approve a purchase order. You type approve PUR-000312, or nothing happens. Two house rules go with it: one record per confirmation, never a batch, and read the record again before committing it.

The honest limit. That confirmation is an instruction the assistant follows, not a lock on the server. What stops a change you were never allowed to make is your own permissions, exactly as from a screen. What the confirmation stops is a change you were allowed to make landing on the wrong record.

Assistant · signed in as D. Whitfield
  • approve the Northgate order
  • Which one? PUR-000312 · $24,000 · Northgate Ltd
    Type approve PUR-000312 to confirm.
  • yes
  • That is not specific enough to act on — which order?
  • approve PUR-000312
  • Approved · PUR-000312 · as D. Whitfield · 16:22
  • ReadingNothing to confirmit just answers
  • Creating and editingAgree to the recordthe filled-in record, shown before it is written
  • Approving, posting, reversingType the reference back“yes” will not do it

An administrator sets that level per kind of change. The confirmation is about which record — whether you may approve it at all was decided before the assistant was asked.

Asked to approve the Northgate order, it names PUR-000312 at $24,000 and asks for the reference back. “Yes” is refused as too vague. “Approve PUR-000312” approves it, as D. Whitfield, at 16:22.

04

It Says When It Does Not Know

An assistant that admits it does not know is worth more than one that does not.

It reads what is available a module at a time rather than trying to hold the whole system at once, and it has been taught the words people actually say. Nobody asks for “Purchase Orders”. They say raise a PO, chase the supplier order, why has this not been received. Those words are stored against the screen they belong to, so the question lands on the right one instead of being guessed at from a list of tool names.

It looks where a person would look. Ask for “the orders from summit” and it searches the names of the records an order points at, not only the order’s own columns — so Summit Tech Distributors is found even though that word is one table away. Ask for orders “where the vendor is ACM” and two suppliers match: it comes back with both and asks which you meant, rather than choosing one and reporting confidently on half your data.

And when it does not own the answer, it says so. Ask for leave requests in a company where nobody has switched Leave on for it, and you are told there is no Leave tool here and that an administrator can add it — not given a number that came from nowhere.

Assistant · three questions
  • list the orders from summit
  • 4 purchase orders for Summit Tech Distributors
    the word is on the supplier, not on the order — the search reaches it anyway
  • purchase orders where the vendor is ACM
  • Two suppliers match ACM: ACM Limited (SUP0001) or ACM Metals (SUP0044)?
    it will not choose for you when both are real
  • show me this month’s leave requests
  • I do not have a Leave tool in this company. An administrator can switch it on for me on the AI Assistant Access screen.

Three answers, and the last one is the point. “I do not have that” is a normal answer here, not a failure — an assistant that invents a number is worse than one that says no.

Orders “from summit” found by a name that lives on the supplier rather than the order. “ACM” matches two suppliers, so it asks which. And leave requests, which nobody switched on for it: I do not have that here.

How the SM Space AI assistant for ERP compares

The one-line answers buyers ask for, and then the one that matters more — what it does not do.

  • Acts as the signed-in person No service account, no elevated access, no permissions of its own.
  • Access set per company An administrator ticks what it may reach, on a screen, with no release.
  • Confirmation per action Nothing, agree to the record, or type the reference back.
  • No bank details, ever Account numbers, IBANs and routing numbers are stripped before it sees anything.
  • Grounded, not trained It reads a live list of what it may reach rather than a model trained on your data.
  • Answers from live records The same data the screens show, at the moment you ask.
  • Builds reports It asks the questions the Report Designer asks and drafts it for you.
  • Says when it does not know A question it does not own gets “I do not have that”.
  • Your own words Add what your company calls a screen, and that word works too.
  • Cloud Runs in a web browser, nothing to install.

What it does not do. It cannot do anything you could not do yourself — which also means it can do things you would regret, and that is what the confirmation rule is for. It is not a second permission system: the confirmation is an instruction it follows, and your own permissions are the control. It never sees bank details, social insurance numbers, dates of birth or salaries, because those fields are removed before it is shown anything. It does not learn your business over time or get better the more you use it. And it cannot widen what it is allowed to reach — the screen that governs it is one of the few places no assistant may go.

How it fits with the rest of SM Space

It is not a separate chatbot with a copy of your data. It is the same system, reached with a sentence.

  • Purchasing & procurement asked through
  • Sales & invoicing asked through
  • Accounting & finance asked through
  • Customer & supplier records asked through
  • Reporting & dashboards asked through
The assistant, signed in as you It calls the same interfaces the screens call, on the same live records — it has no database of its own and no copy of yours
  • obeys Your own permissions — the same ones the screens use
  • obeys What an administrator ticked, in your company
  • obeys Your house rules, glossary and worked examples

The assistant calls the same interfaces the screens call, on the same live records, with the same rules — which is why its answer is never out of date, and why it can be trusted with a purchase order at all. Ask it about purchasing and procurement, sales and invoicing, accounting and finance or your customer and supplier records, and it is reading the record itself rather than an overnight extract of it.

It also composes reports. Ask for one and it walks you through the same questions the Report Designer asks, then checks its own draft before you ever see it — the full story is on reporting and dashboards. And one thing it is never shown, anywhere: bank account numbers, IBANs and routing numbers are stripped out of everything it reads.

Who this AI assistant for ERP is for

Companies of roughly 20 to 500 people who have the data and no time to go and get it — where the question you want answered is one screen away from the screen you are on, and somebody senior would want to know exactly what an assistant can see before letting one near the accounts. SM Space is a cloud ERP system: it runs in a web browser, with nothing to install.

Frequently asked questions

What can the SM Space AI assistant do?
Three things. It answers questions about your own records — “which suppliers did we spend most with last quarter?” — from the live data rather than a copy. It builds a report by asking you the same questions the Report Designer asks. And it finds the screen you want when you describe the work instead of naming the screen. It is part of the SM Space ERP system, not a separate chatbot with its own copy of your data.
Can it see data I am not allowed to see?
No. It calls SM Space as you, using your own sign-in, and has no account or access of its own. A field your role hides is missing from its answer exactly as it is missing from your screen. Two people can ask the same question in the same words and correctly get different answers — because the assistant is asking as each of them, not as itself.
Can it change or approve things on its own?
It can only ever do what you could do yourself, and only when you ask it to. For each kind of change, an administrator sets how firmly you have to confirm: nothing for reading, agree to the finished record for creating and editing, and for anything that cannot be undone, type the record’s own reference back. With that last one set, answering “yes” is refused — you type approve PUR-000312 or nothing happens.
Who decides what the assistant can access?
An administrator in your own company, on a screen, in a few ticks. The list they tick is generated from the running system, so it is never out of date, and the choice is yours alone: another company on the same system can make the opposite choice. Nothing about it needs a developer, a release, or us. A company can always narrow what we make available and can never widen it.
Can it see our bank details?
No, and not as a setting somebody could switch on. Account numbers, IBANs, routing and transit numbers are stripped before the assistant is shown anything at all — along with social insurance numbers, dates of birth and salaries. Those fields are not in the catalogue it reads, so there is nothing for an administrator to tick and nothing for the assistant to ask for.
Can we use our own AI model?
Yes. What the assistant knows about SM Space — its house rules, glossary, worked examples and the list of what it may reach — is kept as ordinary settings in your system, in plain English rather than in any one vendor’s prompt language. So the model behind it can be changed, or pointed at one of your own, without rewriting any of that. It is also why the assistant is grounded in a live list of what it may reach rather than trained on a copy of your data.

Ask it something, with your own permissions.

Book a 30-minute demo and ask it a question about a company like yours.

Book a 30-minute demo