Governed AI Workers Inside NetSuite, With a Human Approval Gate on Every Write
The problem
The finance and operations leaders had already tried generative AI and had the chatbot prototypes to show for it. None reached production, for well-documented reasons. A language model cannot be allowed to guess an account balance, a tax code or an inventory valuation. Sending thousands of transaction lines into a context window exhausts the budget and drifts. And no audit committee grants an ungoverned agent write access to the general ledger. What they needed was not a smarter model but a governed way for any model to work.
What we did
We deployed Aissistor, DataOngoing’s agentic ERP framework, in a two-week sprint against the existing NetSuite roles. A central router dispatches work to specialized workers: an AP matcher, a GL margin-leak detector, a saved-search auditor and a contract inspector. Each worker acts only through formal Model Context Protocol tools: execute_suiteql for parameterized, read-only queries, get_record_schema for structure, and propose_transaction_draft for anything that would change the ledger. Reads go straight to NetSuite. Writes stop at a staged review where the accounts payable supervisor sees the highlighted variance and clicks approve before the record is committed.
01Inputs
- Vendor PDF bills through OCR
- A natural-language question from the CFO
- The scheduled nightly diagnostic
02Central router
- Agent dispatcher and state machine
- Context from the corporate knowledge base
03Specialized workers
- AP matching worker
- GL margin-leak detector
- SuiteQL forensic auditor
04Governed MCP tools
- execute_suiteql, read-only
- get_record_schema
- propose_transaction_draft
05Production ledger
- Reads return live SuiteQL rows
- Drafts stop at the human approval modal
- Approved drafts commit to the ACID ledger
How the mechanism works
- Tool calls, not free text
To inspect a customer balance the worker calls execute_suiteql with a parameterized query and receives structured rows from the NetSuite tables. The model summarizes and flags anomalies in data it did not generate, and every figure in its answer traces to a row.
- The human-in-the-loop financial guardrail
A worker can audit 5,000 purchase orders and find 14 duplicate vendor invoices, or assemble a proposed vendor bill from an OCR scan. It cannot commit either. The draft lands in a review modal with the variance highlighted; the supervisor approves, and NetSuite writes the record under that person’s role.
- Subagent decomposition
One prompt does not solve an ERP problem. A research agent pulls transaction notes, vendor contracts and payment history; a forensic agent analyzes GL distributions and margin percentages; a documenter assembles the board summary with audit links back to the records.
Results
| Measure | Before | After |
|---|---|---|
| Vendor bill ingestion, OCR to ERP | 6-8 minutes per multi-page invoice | 14 seconds with a line-item three-way match |
| System code audit | 3-4 weeks of advisory time | 48-72 hours, automated static scan |
| GL clearing-account leak detection | Quarterly manual samples | Nightly automated sweep |
| Answers on financial data | Unverifiable chatbot summaries | Every figure bound to a live SuiteQL record set |
| Time to production | 6-12 months for an enterprise AI program | One two-week sprint into existing NetSuite roles |
What to take from it
- AI without governed tools is a liability
Never let a model reach the ERP through scrapers or unpermissioned database drivers. Demand formal MCP interfaces with role-based tokens and a read/write boundary you can audit.
- The goal is removing administrative tax, not people
Senior accountants should be analyzing cash strategy, not keying twelve-digit invoice numbers from scanned PDFs. The worker does the keying; the person does the judgment.
- Deterministic architecture outperforms model size
A disciplined model with precise SuiteQL tools beats a far larger general model that is guessing. Governance is the feature.
Composite retrospective; client shown as an archetype and figures illustrate the mechanism. Related: Floor-to-Ledger Device and Document Automation
Talk to the architect, not a salesperson
AI automation for private-equity portfolios, measured in basis points: a few hours of operating-partner time in, hundreds of engineering hours and margin out, delivered as working code in two-week sprints.