---
title: "How 1flux keeps AI inside your rules"
description: "AI controls in ERP, built into the architecture: in 1flux, AI needs the same permissions as people, fills drafts a person saves and keeps its source on record."
url: https://1flux.ai/platform/ai/control
last_updated: 2026-10-11
---

Control and trust

# How 1flux keeps AI inside your rules

AI controls in ERP start with the architecture. In 1flux, AI works inside the same permissions, drafts, approvals and records as your team.

## In short

1flux keeps AI on the same path as your team. **Import PO with AI** needs the same permission as creating a quotation by hand, fills a draft that a person reviews and saves, and attaches the customer's file with an **AI source** badge and a confidence score. Your approval rules still decide when the quotation can be sent, and a person sends it. Underneath, actions run through one command layer that checks permissions and records whether a person, an import, the system or AI took them.

1. Draft (QT-2026-00118): Draft.
2. Approval: Pending approval.
3. Approved: Approved.
4. Sent: Sent.
5. Accepted: Accepted.

A quotation drafted with AI follows the same lifecycle as any other: draft, approval, a locked PDF, then a person sends it.

The idea

## What are AI controls in ERP software?

AI controls in ERP are the rules that decide what AI can see, what it can change and who signs off on its work. In 1flux, they are the same rules that govern your team.

When AI is bolted onto an ERP, those rules have to be set up again for the AI tool, and the two sets drift apart. 1flux was built so AI and people share one data model, one command layer and one set of permissions, so the controls come with the architecture. Read more in [AI-native vs bolted-on ERP](https://1flux.ai/platform/ai-native-erp).

1. AI that works today

   - Import PO with AI Customer PO or RFQ in, draft quotation out

2. Rules as configuration

   - Workflow engine Stages, approvals and required fields are data, not code

3. Permissions on every record

   - Permissions Roles, record visibility, entity access, row-level security

4. One command layer

   - Commands Permissioned actions that record their source: a person, an import, the system or AI

5. One data model

   - One data model CRM, Inventory and Accounting share linked records, not copies that sync

The controls around AI are the same layers that control everything else in 1flux.

Today

## How does 1flux control AI today?

1flux keeps Import PO with AI inside eight controls, from the permission it needs to the record it leaves behind.

- ### Permission first

  Import PO with AI needs the same permission as creating a quotation by hand, so only people whose role can create quotations can use it.

- ### Drafts a person saves

  The AI fills the quotation builder. The quotation is saved only when a person has reviewed the draft, chosen the customer and saved it.

- ### Source on record

  The customer’s file is attached to the quotation with an **AI source** badge, for reviewers and approvers to check.

- ### A confidence score

  Each import shows one confidence score for the whole extraction, so reviewers know how closely to check.

- ### Approvals still apply

  Approval rules by amount band and quorum apply to AI drafts, and sending waits until the quotation is approved.

- ### People send

  Nothing goes to a customer automatically. A person sends each quotation, by email, secure link or WhatsApp.

- ### Documents can’t give orders

  Uploaded files are treated as untrusted business data, and the model is instructed to ignore instructions written inside them.

- ### One command layer

  Actions run through permissioned commands with an audit trail; stock commands record their source, including AI.

Approvals

## Do approval rules apply to AI-drafted quotations?

Yes. A quotation drafted with Import PO with AI follows exactly the same [approval workflow](https://1flux.ai/glossary/approval-workflow) as one typed by hand.

- **Rules by amount.** Approval rules can target amount bands, with a minimum and maximum total.
- **Any, all or a quorum.** Choose who approves, and how many of them must agree.
- **Sending waits.** Email, secure links and WhatsApp sharing stay blocked until the quotation is approved.
- **Reasons on record.** A rejection returns the quotation to Draft with the approver’s reason.
- **Locked on approval.** The approved PDF and its data are frozen, so the customer receives exactly what was approved.

[Workflows and approvals](https://1flux.ai/platform/workflows-and-approvals)

Every request waiting for you, in one list. Open one to see the move, the note and each approver’s vote.

On the record

## What does 1flux record about AI work?

1flux keeps the source with the work. The customer’s original document stays on the quotation with an **AI source** badge, the import shows its confidence score, and the command layer records whether a person, an import, the system or AI took each action.

Around that sit the [audit trails](https://1flux.ai/glossary/audit-trail) your team already relies on: an Activity tab on companies, contacts, items and suppliers, stage history on deals, tasks and sales orders, and numbered quotation revisions with a required reason. Who can see and change what is set by roles, record visibility and entity access. See [access control](https://1flux.ai/platform/access-control).

Moves, send-backs and approvals stay on the record, with who, when and why.

FAQ

## Questions, answered

Still deciding? [Talk to sales](https://1flux.ai/contact)

### What permission does someone need to use Import PO with AI?

1flux requires the same permission as creating a quotation by hand. Import PO with AI sits in the quotation builder, so only people whose role can create quotations can use it. Admins build roles from more than 100 permissions in 15 module groups, a person can hold several roles, and a non-admin can't grant a permission they don't hold themselves.

### Who saves an AI draft in 1flux?

1flux leaves saving to a person. Import PO with AI fills the quotation builder with a draft: the customer's reference, the date, the currency and the lines. Someone on your team reviews it, chooses the customer and saves. From then on it's an ordinary quotation, with the same approval rules, locked PDF on approval and numbered revisions as any other.

### Do approval rules apply to AI-drafted quotations?

Yes. A quotation drafted with Import PO with AI follows the same approval rules as any other. Rules can target amount bands and need any, all or a quorum of approvers, and sending by email, secure link or WhatsApp is blocked until the quotation is approved. A rejection returns it to Draft with the approver's reason, and an approved PDF is locked.

### How does 1flux handle instructions hidden inside an uploaded document?

1flux treats every uploaded document as untrusted business data. The model is instructed to ignore any instructions written inside the file and to return only the commercial facts it can read, in a fixed structure. Output that doesn't fit the structure is rejected, and a person still reviews every line before anything is saved to the quotation.

### How can reviewers check an AI draft?

1flux keeps the customer's original document attached to the quotation with an **AI source** badge, so a reviewer or approver can open it next to the drafted lines. The import also shows a confidence score for the whole extraction, so a low score tells the reviewer to read every line closely before the quotation is submitted for approval.

### What is the command layer in 1flux?

1flux runs actions through one command layer: permissioned commands that check who is acting, can be retried safely without doing the work twice and leave an audit trail. Stock commands already record their source, whether a person, an import, the system or AI, so AI is held to the same permissions and leaves the same trail as people.

Related

## Keep exploring

### [AI in 1flux](https://1flux.ai/platform/ai)

AI that works on the same records, permissions and audit trail as your team, and drafts quotations from customer POs today.

### [Import PO with AI](https://1flux.ai/platform/ai/import-po)

Drop in a customer's PO or RFQ and get a draft quotation, matched to your catalogue, with a confidence score.

### [AI-native ERP](https://1flux.ai/platform/ai-native-erp)

What AI-native means, how it differs from AI bolted on, and the questions to ask any ERP vendor about its AI.

### [Quotations](https://1flux.ai/products/quotations)

Quotes from your catalogue or a customer's PO, approved, locked and sent.

### [Platform](https://1flux.ai/platform)

One data model, one command layer and one set of rules under CRM, Inventory and Accounting, with AI on top.

Last updated 11 October 2026
