The assistant, and what it refuses to be

A box you can type into is the easiest thing in this product to build and the easiest to get wrong. The version worth having answers from the same services the screens use, and says so — including when it cannot.

AIShipped in segment S13 · 863 words
QUESTIONTOOLS CALLEDREVISIONS READANSWER“Why did the cost ofPRD-100 rise 14%since March?”Cost Agent · Recommendresolve(PRD-100, 2026-03-01)resolve(PRD-100, today)costRollup(both)The same services the interface calls.No private read path.330-1140rev A · releasedECO-2214eff. 2026-07-01cost · ERPread-only, as at todayOne line drives it:the control boardsuperseded in July.330-1140 @AECO-2214click to reproduceEvery citation names an object at a revision, so the reader can re-run the resolution and get the same bytes. An agent that cannot cite abstains and escalates.

What it is, and what it is not

A single entry point that routes a question to whichever agent owns its domain and returns one answer with citations. It is the orchestrator with a text box on the front, not a thirteenth agent with its own view of the world.

It is not a chat interface over a search index. That pattern retrieves documents mentioning your terms and writes a fluent paragraph around them, which is convincing and unverifiable. Here a question about a structure returns the resolver's answer, and the citation resolves to the resolution.

It is also not the primary way to use the product. Most work happens on screens built for it, and an assistant positioned as the main interface is usually compensating for screens that are hard to use. This exists for the questions that cross domains, where opening four screens is the slower path.

The mechanism: it inherits everything

The assistant holds no permissions, no tools and no data access of its own. Every capability it appears to have belongs to an agent underneath, and every constraint on those agents applies unchanged.

It runs inside the asking user's permissions. The tenant predicate, role policy and field-level access control all apply, so it cannot surface a part, a document or a programme the person could not open themselves. A refusal is shaped so it does not reveal that something exists — leaking existence through a refusal is still leaking.

Permission tiers apply per agent per tool, so what the assistant can do depends entirely on how you configured the agents behind it. A tenant running everything at Observe has an assistant that reads and explains and cannot write anything, and that is a configuration rather than a mode.

Every answer carries revision-addressed citations and lands in the hash-chained audit trail naming the agents that participated, their tiers, the tools called and the revisions read. There is no audit row that says only that the assistant answered.

The failure it prevents

An engineer asks why a product's cost moved. A search-backed assistant retrieves a change order mentioning cost, a supplier email and an old analysis, and produces a paragraph naming a component and a price increase.

It is specific, plausible and wrong: the component was superseded in July and the price came from a document eleven months old. Nothing in the phrasing signals any of that, and checking it means redoing the analysis the engineer was trying to avoid.

They act on it, or they check it and stop trusting the feature. Both outcomes are worse than having no assistant, because both consumed attention and produced nothing. Routing to the Cost Agent, which resolves the structure twice and subtracts, gives an answer with three cited lines that a reviewer can re-run.

How it meets the rest of the product

Answers link into the product rather than replacing it. A cited part opens the part; a cited resolution opens the resolution with its conditions preserved, so the reader can change a condition and see what happens. The assistant is a way into the screens, not a substitute for them.

Where a question crosses domains, the orchestrator's precedence rules apply: a deterministic service outranks any agent, the domain owner outranks a visitor, and an unresolved disagreement abstains and escalates rather than picking a side.

Abstention is visible. An assistant that cannot support a claim says what it could not establish and what it would need, rather than producing a hedged paragraph. That is less satisfying to read and considerably more useful, because a hedge is indistinguishable from an answer at a glance.

Cost governance applies here as everywhere: per-tenant budgets with per-agent caps, and stated degradation when a budget is reached — expensive reasoning stops first while retrieval and citation keep working.

How it meets your ERP

It can answer questions whose facts span both systems, and it marks which half came from where. “What would this change cost and do we have stock” draws the structure from Manufacturing PLM and the cost and quantities from your ERP, and the two halves are cited differently.

That distinction is not decoration. A resolution Manufacturing PLM can reproduce byte for byte is stronger evidence than a cached read of somebody else's master record, and presenting them identically would make the whole answer look as solid as its weakest part — or as provisional as its strongest.

It will not write to your ERP, and no phrasing of a question changes that. ERP-mastered fields are read-only beneath every agent, so the constraint holds regardless of how the request is worded.

Where the boundary is

It does not act on ambiguity. Asked something that could mean two things, it asks which — rather than choosing an interpretation and answering confidently within it, which is the behaviour that makes assistants feel unpredictable and is indistinguishable from being wrong.

It also cannot answer about data that is not in Manufacturing PLM. A question about something living in a spreadsheet on somebody's drive returns nothing found, not an inference. The honest failure is the one that keeps the other answers worth reading.

Facts

What it isThe orchestrator with a text box — not a thirteenth agent
PermissionsNone of its own; inherits the asking user's
ToolsNone of its own; every capability belongs to an agent
TiersPer agent per tool — an all-Observe tenant cannot write
CitationsRevision-addressed, opening the screen behind them
AbstentionStates what it could not establish, never hedges
ERP factsCited separately, with source and as-of stamp
AmbiguityAsks which, rather than picking an interpretation

Frequently asked

Is this a chatbot over our documents?

No, and the distinction is the point. A search-backed assistant retrieves documents mentioning your terms and writes a fluent paragraph around them. Here a question about a structure returns the resolver's answer, and the citation resolves to that exact resolution.

Can it see things I cannot?

No. It holds no permissions of its own and runs inside yours, so the tenant predicate, role policy and field-level access control all apply. A refusal is shaped so it does not reveal that something exists, because leaking existence through a refusal is still leaking.

What can it actually do?

Whatever the agents behind it are configured to do, and nothing more. A tenant running every agent at Observe has an assistant that reads and explains and cannot write. That is a configuration rather than a mode, and it is enforced beneath the assistant.

Should our team use this instead of the screens?

No. Most work belongs on screens built for it, and an assistant positioned as the main interface is usually compensating for screens that are hard to use. This exists for questions crossing domains, where opening four screens is genuinely the slower path.

What happens when it does not know?

It says what it could not establish and what it would need, rather than producing a hedged paragraph. That reads as less helpful and is considerably more useful, because a hedge is indistinguishable from an answer when somebody is skimming.

Can it answer questions about our ERP data?

It can answer questions whose facts span both, marking which half came from where. A resolution Manufacturing PLM reproduces byte for byte is stronger evidence than a cached read of your ERP, and presenting them identically would misrepresent both halves at once.

Will it write to our ERP if I ask it to?

No, and no phrasing changes that. ERP-mastered fields are read-only at the tool layer beneath every agent, so the constraint holds regardless of how a request is worded. Persuasion does not create capability that was never handed to the agent.