Skip to main content
All work

Enterprise operations

Conversational AI Agent for Live ERP Data

The hard part: Letting non-technical staff query live ERP data without ever giving the model database access.

A natural-language interface over live ERP data. Non-technical staff ask plain-English questions and get ORM-safe, role-gated answers in seconds.

  • Claude MCP over live ERP
  • Enterprise ERP client
  • Shipped 2025
  • Still in production

NL→SQL

Plain English to live data

100%

Prompt-injection hardened

Seconds

From question to answer

Conversational AI Agent for Live ERP Data — Enterprise operations
Photo: Behnam Norouzi / Unsplash

How it actually runs

  • Model
  • Guardrail
  • Deterministic
  1. Plain-English question

    Asked by non-technical staff

  2. Intent → query

    Claude MCP translates

  3. Role validated

    Checked before execution

  4. ORM-safe execution

    No raw SQL reaches the DB

  5. Live ERP

    Scoped to what they could already see

  6. Answer + report

    Generated from results

The problem

Every business question needed a developer. Operators queued report requests, waited days, and made decisions on stale numbers.

The approach

We built an agent that translates plain-English questions into ORM-safe queries against the live database. Role-based access is validated before execution. Prompt-injection safeguards, retry queues and async processing make it safe to expose to non-technical staff. Delivered through Claude MCP for real-time interaction.

The outcome

Answers in seconds instead of days. Developers off the report queue. No raw SQL ever touches the database.

Business operators were drowning in manual report requests. Every insight required a developer query, a ticket, and a wait.

What we built

A natural-language interface over live ERP data, delivered through Claude MCP. Staff type a question. The agent translates it into an ORM-safe query, validates the caller’s role, executes it, and returns an answer or a generated report.

  • ORM-safe query execution: no raw SQL reaches the database
  • Role-based access validated before every call
  • Prompt-injection safeguards on every input
  • Retry queues, conflict handling and async processing for reliability
  • AI-driven report generation from query results

NL→SQL

Plain English to live data

100%

Prompt-injection hardened

Why it is safe to hand to non-technical staff

The model never gets direct database access. It proposes, the ORM layer disposes. Every query is scoped to what the user could already see in the UI, and adversarial inputs are caught before they reach the runtime.

Result: answers in seconds, developers off the report queue, and an audit trail on every question asked.

More like this

Healthcare Insurance Claims Automation — HealthcareHealthcare

100%

Claims processed automatically

80%+

Manual data entry eliminated

Healthcare Insurance Claims Automation

A Canadian health platform was keying every OHIP claim, eligibility check and reconciliation by hand.

The hard part: Three government interfaces — OHIP, MCEDT and EDI — each with its own failure modes, running unattended overnight.

OHIP real-time eligibility checks, MCEDT payment reconciliation and automated XML/EDI batch claims. What took a team days now runs overnight without oversight.

  • OHIP + MCEDT
  • Runs overnight, unattended
  • Healthcare platform

Read case study

Line of Credit Lending Platform — Financial servicesFinancial services

0

Manual steps in the credit lifecycle

100%

Audit trail coverage

Line of Credit Lending Platform

A lending book run out of spreadsheets, where one person understood the formulas.

The hard part: Removing every manual step from a credit lifecycle while keeping a complete audit trail on each state change.

Full lending lifecycle built from scratch: Plaid bank verification, Stripe disbursements and repayments, multi-location credit rules, automated statements and interest.

  • 2 payment rails
  • Lending enterprise
  • Shipped 2024

Read case study

Email Intelligence SaaS Platform — Consumer SaaSConsumer SaaS

5

AI providers unified

3

Scan cadences: 5-min, 2-hr, daily

Email Intelligence SaaS Platform

Turning a Gmail inbox into structured, actionable events — at scale, without leaking a single token.

The hard part: Five AI providers behind one registry, structured outputs schema-checked before anything downstream trusts them.

LLM pipeline that classifies Gmail into structured life events with Zod-validated outputs. Five AI providers behind one gateway, AES-256-GCM token storage, three-tier monetisation.

  • 5 AI providers unified
  • SaaS startup
  • Australia

Read case study

Next step

Discuss a similar build.

Tell us what your version of this problem looks like. The first 45 minutes are free and specific.

Straight to the engineer. No form, no gatekeeper.

Straight to the engineerReply in 4 business hoursNDA on request

Accepting new engagements · Q4 2026