Skip to main content
Built on Your JD Edwards Security Model

A Controlled, Auditable Security Model for AI Agents

ERP Suites AI Agents run on the ERP Suites AI Platform within OCI, securely interacting with JD Edwards without exposing credentials, bypassing security, or moving data outside your environment. The platform is designed with a defense-in-depth model, ensuring:

  • Data stays within OCI
  • Actions are controlled & auditable
  • Access respects your JDE security model
AI Security Built Into the Execution Layer

How Are AI Agents Secure in JD Edwards?

JD Edwards AI agents are designed with a clear principle:
The agent is not trusted by default.

Instead of introducing a new access layer, the AI operates as a controlled execution layer within your existing JDE security model.

icon-checkmark

User-Bound Identity, Not Independent Access

AI agents do not operate as their own users or with elevated privileges.

Every action is performed on behalf of an authenticated JD Edwards user, ensuring:

  • Actions align to known identities
  • Permissions are enforced at the user level
  • No expansion of authority beyond what is already defined
icon-checkmark

No Stored Credentials or Persistent Access

User credentials are never stored or exposed.

Access is managed through secure, session-based authentication using short-lived tokens, ensuring that:

  • Access is temporary and controlled
  • There is no persistent credential risk
  • Sessions are tied directly to authenticated users
busy-diverse-professional-business-team-600nw-2380776443
icon-checkmark

Constrained Execution Paths

AI agents cannot take arbitrary actions.

Every request must map to:

  • Approved JD Edwards functions
  • Defined orchestrations

If an action does not meet these constraints, it is denied.

This ensures AI operates within strict, predefined boundaries.

icon-checkmark

Data Stays Within Defined Boundaries

JD Edwards remains the system of record, with controlled and limited data movement.

Each customer operates within a dedicated OCI environment with strict isolation boundaries, ensuring:

  • Data is never shared across tenants
  • Customer data is not used to train public models
  • Data remains fully contained within its environment
Office Collaboration AI Security Chart
icon-checkmark

Full Auditability and Traceability

Every interaction is tracked.

From the initial request to the final action, the system ensures:

  • Complete visibility into what occurred
  • Traceability of actions back to the user
  • Support for governance, compliance, and auditing
icon-checkmark

A Controlled AI Model

The role of the AI agent is clear:
It helps execute permitted work. It does not expand authority or bypass controls.

This ensures AI enhances productivity while remaining fully aligned with existing ERP governance and security frameworks.

Business woman hand typing on keyboard with secured lock concept around
From Request to Controlled Execution

How the Agent Works in Defined Security Framework

Every AI agent interaction follows a defined, secure path, ensuring actions are validated, permitted, and fully traceable. Rather than operating independently, the agent acts on behalf of an authenticated user and executes only through approved functions and orchestrations. This controlled framework helps ensure AI remains aligned with existing JD Edwards security controls from request through execution.

AI Agent Security

icon-step-1

User Authenticates

The process begins with a verified user. Authentication is handled through secure login methods, establishing a session tied to that user.

icon-step-2

AI Interprets the Request

The AI agent receives and interprets the user’s request. It does not act independently—it operates on behalf of the authenticated user.

icon-step-3

Permissions Are Enforced

Before any action is taken, the request is checked against:

  • User’s JDE permissions
  • Defined roles and access controls

If the user is not authorized, the action does not proceed.

icon-step-4

Action Is Routed Through Approved Paths

All actions must map to:

  • Approved JD Edwards functions
  • Defined orchestrations

Requests that fall outside these paths are denied.

icon-step-5

Action Is Executed Within Boundaries

If approved, the action is executed within the system, without bypassing existing controls or expanding authority.

icon-step-6

Everything Is Logged and Traceable

Every step, from request to execution, is recorded. This ensures full visibility, auditability, and accountability for all actions.

Controlled vs Uncontrolled

How JD Edwards AI Agent Security Compares

Not all AI solutions are built to operate within JD Edwards security controls. Without the right architecture, this can introduce risk around execution, permissions, and visibility.

Security Area

ERP Suites' Solution

JD Edwards AI Agents

Uncontrolled AI Solution

Identity

Agent acts on behalf of an authenticated user

AI operates without clear user mapping

Permissions

Enforces existing JD Edwards user permissions

Actions may not align to defined user roles

Execution Control

Only approved functions and orchestrations are allowed

Actions may occur without defined boundaries

Access Layer

Operates as a controlled execution layer

Can become an invisible or uncontrolled access point

Data Handling

JD Edwards remains the system of record with strict data boundaries

Data movement and usage may be unclear

Credentials

No persistent human credentials; uses short-lived tokens

Potential reliance on persistent credentials

Auditability

Full traceability of every request and action

Limited visibility into actions and outcomes

Built-In Benefits

What This Means for Your Team

Your team can adopt AI agents without introducing a new layer of uncertainty because actions remain governed, visible, and aligned with your existing JD Edwards environment.

yellow-circle-doublecheck

Operate AI Without Introducing New Risk

AI agents can take action inside JD Edwards, but within a model your team already understands and controls.

yellow-circle-doublecheck

No New Access Model to Manage

AI operates within your existing users, roles, and permissions, so your team doesn’t need to redefine how access is governed.

yellow-circle-doublecheck

No Loss of Visibility Into System Activity

Every action remains tied to a user and can be traced, so your team can maintain oversight of what is happening in the system.

yellow-circle-doublecheck

No Uncertainty Around Data Handling

Data stays within controlled boundaries, so your team knows where data resides and how it is used.

Business consulting
Frequently Asked Questions

Common Security Questions

Can an AI agent perform actions a user is not authorized to do?

Does the AI agent have its own system access or credentials?

Are user credentials stored or exposed?

Can the AI agent execute any request it receives?

Where does the data go during AI processing?

Can AI actions be tracked and audited?

Does the AI bypass existing ERP security controls?

What prevents unintended or unsafe actions?

How do we prove compliance (SOC 2, etc.)?

Can employees see data they shouldn’t?

Is customer data used to train AI models?