Short answer
AI ERP trust comes from visible boundaries before automation expands.
AI2COE AI ERP trust controls keep diagnostic evidence, source-file handling, no-write-back boundaries, role authority, segregation-of-duties context, human approval, agent authority, denied actions, audit metadata, rollback boundaries, and owner validation visible before any transaction-changing capability is considered.
These controls describe the product operating model and implementation review requirements. They do not claim certification, completed customer validation, independent assurance, or unlimited agent authority.
Source-file handlingGeneral contact forms are for scoping, not private operational data; diagnostic upload paths process source files for report generation and then purge source files under the stated boundary.
No ERP write-backIndustrial IQ diagnostics do not create, update, approve, post, merge, delete, release, or move source-system records.
Human reviewFindings, candidates, signals, recommendations, and action queues require accountable owner review before operational action.
Evidence classesObserved, Derived, Estimated, and Hypothesis labels keep source-backed findings separate from assumptions and planning signals.
Role and authority scopeImplementation review records who can read, prepare, submit, approve, reverse, suspend, and audit each workflow action.
Segregation of dutiesFinancial, procurement, inventory, quality, payroll, statutory, and source-system actions need named approver boundaries and conflict review.
Transaction integritySource-system writes are denied by default; any approved handoff needs idempotency, error handling, rollback, and audit metadata.
Environment separationDemo, pilot, and production authority are separated during scoping; public demo pages do not imply production credentials or access.
Agent authorityERP agents must have explicit authority level, denied actions, tool scope, owner approval, suspension path, and audit trail.
Implementation reviewProduction transaction authority requires security, trust, data-handling, legal/procurement, process-owner, and rollback review.