Back home
The platform

One runtime. Many agents. Your permissions.

A guided tour for finance and operations leaders. What the platform is, how it keeps each user’s ERP permissions intact, and what going live actually takes.

Sees only what each user is allowed to see Compute and data hosted in Sydney A person approves every change to your ERP
01 · Permission model

Your permissions are the agent’s permissions.

Most AI-for-ERP tools connect with one service account and hope nobody notices. That account can read everything, so the AI can too. We took the harder path.

The test we set ourselves

Two people ask the same agent the same question: “show me project profitability.” One is a company accountant with access to a single entity. One is a group financial controller. They get different answers, because their ERP permissions are different.

Company accountant 1 entity
3 projects · her company only
Group financial controller group
13 projects · every entity

Writes

posting · approving · editing

Run as the user’s own ERP credentials. The ERP enforces its own write rules. We do not second-guess them.

ERP is source of truth · audit-clean

Sensitive reads

P&L · payroll · confidential GL

Run as the user’s own ERP credentials. Never a shared account. Tunable per tenant if your policy is stricter than ours.

classified at the agent · enforced at runtime

General reads

vendor lists · GL accounts · invoice lookups

Service account, filtered to that user. Fast and cacheable. The user’s role rewrites every query before the agent sees a row.

filtered before the agent reads · audit-tested
Principle 1

The ERP is the source of truth.

We never re-implement your permission logic. We pass identity through.

Principle 2

Sensitivity is declared, not remembered.

Every action an agent can take declares its class, so the runtime picks the right identity path without per-agent wiring.

Principle 3

Tested, not promised.

The permission paths ship with tests that actively try to break them. A leak is a P0.

Principle 4

Honest about the gaps.

When your access covers some entities and not others, an aggregate says so and names what it left out. The alternative is quietly dropping rows.

02 · Multi-entity

One tenant. Many companies. Handled.

Most mid-market finance teams run more than one entity, and every ERP models that differently. A company switcher sets the active company, and the agent scopes every answer to it.

Sage Intacct beta

Company access follows each person’s own Intacct role. One connection covers every company that person can already see.

SAP Business One beta

Each company sits in its own database. Ask for a group figure and we gather it company by company, then tell you which ones your access did and did not cover.

SAP Cloud ERP beta

The same per-person company model, with an order posted into a live system to prove the path end to end.

Sage X3 roadmap

Next on the connector list. The same company model applies when it lands.

MYOB Acumatica roadmap

Covered today by our advisory and custom builds. A platform connector is on the roadmap.

03 · Surfaces

Build the agent once. Use it anywhere.

The permission model travels with the agent, so it holds wherever your team works.

beta

Web app

Chat, approvals, admin, audit and the agent catalog at your own subdomain.

beta

Claude, over MCP

Your team’s own AI client calls the same agents. Permissions come along, so there is no client that can suddenly read everything.

next

Inside your ERP

Sage shipped Agent Builder in its R2 release. When we plug into it, the agents appear in Sage itself. Microsoft Copilot, Teams and ChatGPT follow the same path.

all three call the same runtime
Web app
Claude
Your ERP
Levcore agent runtime
permission resolver · semantic layer · approvals · audit
Levcore · Web app · Approvals demo data
Waiting on you
SO draft · PO-4471 · Harborview Retail needs review
SO draft · PO-4468 · Brindabella Group ready
Enquiry · spare parts pricing responded
the one place changes are approved
Claude · via Levcore MCP demo data
Which customers are past 60 days?
Brindabella Group$48,200 · 72d
Coastal Traders$12,940 · 65d
permission-scoped · runs as sarah
same agent · same permissions · different surface

What is MCP, exactly?

An open standard that lets AI assistants call business tools safely. Build the agent once and plug it into Claude today, with Copilot and ChatGPT to follow.

Where we build, and where we plug in

On SAP Business One there is no native AI to compete with, so we build the surface ourselves. On Sage Intacct, Sage’s R2 release shipped Agent Builder and a native MCP server, so we plug in and let Sage carry the chat layer. On MYOB Acumatica we lead with advisory and custom builds. Same agents, surfaced where native AI does not already cover them.

04 · How it learns

Gets to know your business. Without training on your data.

It uses your data. It never trains a model on it. Answers are grounded in your live records plus context you approve: your terminology, your reports, your conventions. Retrieved fresh on every question, never baked into a model.

That distinction is the value. Fine-tuning on your data is hard to audit, hard to undo, and weakens the security story. Retrieved context is the opposite: visible, editable, deletable, and it is what makes the agent feel like it already knows your business.

Your glossary
in design

Speaks your team’s language

When your team says supplier and the ERP says vendor, or your dimensions are Department by Project, the glossary captures it. Built with you at onboarding, editable by your admin afterwards.

Your registered reports
in design

The reports you’ve already tuned

Register an Intacct report or a B1 saved query you have already tuned, and the agent reaches for it when a question matches instead of rebuilding the answer from raw data.

The honest version

No fine-tuning on customer data. Not now, not planned. Today the agents ground answers in your live ERP data and cite the source records. The glossary and registered reports are how we plan to make that feel native to your business.


05 · Making changes

Nothing changes in your ERP until a person says so.

Agents prepare the work and show you what they found. A person checks it and approves it. Only then does anything reach your ERP, and every step is recorded.

Your ERP
Levcore cloud · Sydney
Agent drafts the change
A person reviews and approves
Posted to your ERP
Reads are filtered to that person before the AI sees them. Changes are drafted, never posted on their own.

This path runs end to end on SAP Business One and SAP Cloud ERP: a real order, approved by a person, posted into a live system. Today it is used for sales orders. Other document types follow the same rule: draft, review, approve, post.

nextBringing the same approach to fully on-premise installs.

06 · Going live

What onboarding actually takes.

From contract signed to your team asking real questions. Sequenced, predictable, with a senior Leverage Technologies consultant on the line rather than a self-serve wizard.

1.

Fundamentals

Currency, financial year, timezone, GST display, multi-entity, your subdomain. About 30 minutes.

2.

Connect your ERP

OAuth for Sage Intacct, a guided connection for SAP Business One. We walk your IT lead through it.

3.

Align on your terminology

A senior advisor sits with your finance lead to capture your terminology, dimensions and conventions.

4.

Register your reports in design

Your existing custom reports become things the agent can call by name. Today, agents ground answers directly in live ERP data.

5.

Invite your team

Users sign in with their own accounts. ERP consent happens once per user, on first use. You are live.

Depth scales with you

The terminology conversation can be a short admin walkthrough, a guided first cut with an advisor, or an entity-by-entity pass across hundreds of GL accounts. We size it to what will make the agents feel native.

Calendar shape

Contract to connection in about a day. Terminology alignment runs one to two weeks of advisory time in parallel.

Your team can run it

Everything is done on screen: adding a person, connecting your ERP, changing what someone is allowed to see. You do not need a developer to keep it running.

07 · Stack

The stack, in plain terms.

Hosted in Sydney. Your data sits in its own space in a standard database, your ERP credentials are encrypted, and every action is logged. Nothing unusual, nothing your IT team has not reviewed before. The detail is below.

Hosting region
Sydney, Australia
Database
Postgres · per-tenant isolation · AU-hosted
Authentication
Email and password, per-tenant
in design SSO
LLM
Managed (Anthropic or OpenAI), or bring your own key
managed inference may process outside Australia
Audit logging
Every action · per-tenant · export-ready
ERP token storage
Per-tenant envelope encryption
Your documents
Deleted on a schedule once the order is done
Email
Sent and received in the Sydney region

For a deeper architectural picture, internal review only, talk to your Leverage Technologies contact.