TENANT HARBORPEAK CONO 100 DIVI 100 ENV DEV
live ◆ Offline demo · synthetic tenant · no real data

Hub

Command center. Every answer in this Toolbox is source-tagged to a validated source, every proposed write waits for a human in Approvals, and anything that can't be verified is withheld, not guessed. Synthetic tenant HARBORPEAK — no real data.

7
Consultants
23
Personas
3
Drafts awaiting confirm
12
Writes executed today
Healthy
Write-gate contract
214
MI programs walked
$12.40
LLM cost today / $50

Health ● all live

M3 ION API
Compass / Data Lake
Jira (read-only)
LLM provider (Claude)
Last refreshjust now

Alerts

HIGH 1MEDIUM 2LOW 1INFO 3
Customer C-1088 over credit limit — gating $41k of ordersHIGH
3 items below safety stock (coupling family)MED
Supplier V-2044 lead-time change pending reviewMED

Advisory sessions, agents & recent activity

Advisory sessions

Reduce credit-hold delays (O2C)RECOMMENDED
Month-end close checklistPLANNING
Supplier bank-change reviewPLANNING
3 sessions · 12 steps · 5 drafts queued to Approvals

Agents (background scans)

AR Cash Acceleration18 scans
Procurement Exception11 scans
EDI Reliability9 scans
Month-End Close6 scans

Recent activity

Narrated the June close (CFO lens)09:14
Refused a write — out of allowlist10:02
Confirmed: release credit hold · 471110:20
Correlated OPS-1423 → C-108811:05

Consultants (7)

M3 Implementation Expert @m3consultant

Verifies against MRS001MI before stating any fact. MI API (214 programs walked), config, personalizations.

Order-to-Cash @o2c

OIS100 · OIS017 · CRS610 · MWS410 — orders, pricing, credit, shipping.

Procure-to-Pay @p2p

PPS200 · CRS620 · PPS300 · APS200 — POs, suppliers, receiving, AP.

Inventory & Warehouse @inventory

MMS200 · MMS060 · MMS005 · MMS080 — items, balances, reorder.

Manufacturing @manufacturing

PMS100 · PDS001 · MMS002 — MOs, BOMs, materials.

Finance @finance

GLS · ARS200 · APS200 — ledger, AR, AP, close.

EDI & Integration @edi

ION BOD · MEC · X12 850/810/856/855 · EDIFACT ORDERS/INVOIC — mapping & reliability.

System Health & Connection Status

Live connection status for every system the Toolbox reads or writes, with latency, uptime, and the last successful check. Nothing here is assumed — an unreachable source shows as unknown, never as clean.

M3 ION APIlive
Endpoint/M3/m3api-rest/v2AuthION OAuth · token valid 41mLatency142 msUptime 24h99.98%Last checkjust now
Compass / Data Lakelive
AccessSELECT-only (assertSelectOnly)Latency384 msFreshnesslagged ~15 minUptime 24h99.9%Last check12s ago
Jira (ticketing)live
Accessread-only · JQLSource tagLIVE_TICKET (1.0)Latency210 msLast checkjust now
Birst analyticstime-lagged
Accessgoverned BQL · readSource tagANALYTICS_BIRST (0.8)As of03:00 UTCNotemodeled, verify before acting
LLM providerlive
Modelclaude-sonnetCost today$12.40 / $50.00Warn at$35.00Resetsmidnight UTC
Document corpusindexed
Docs4,210 (Infor + Meridian)TagsDOC_INFOR 0.90Last crawl2h ago

Engine boot & governance arm-state

MI catalog walked (MRS001MI)214 programs ok
Schema catalog loadedok
Write allowlist (per-CONO, default-deny)7 triples armed
Write-gate secret (MERIDIAN_SECRET)present
Audit chainverified
TenantHARBORPEAK · CONO 100 · DIVI 100
EnvironmentDEV
Operator auth modesso (MFA)
Read min confidence0.60
Write min confidence0.90

Chat — the governed front door

Ask about live tenant data or the doc corpus. Every factual claim is validated against a read path before it reaches you and carries its source tag. Writes never happen here — they route to Approvals. What can't be verified is withheld.

You
Tell me about customer C-1088.
DT
Here's the governed profile for C-1088 (Riverside Supply), assembled from live reads plus a lagged lake aggregate.
Riverside Supply · C-1088ON CREDIT HOLD · $12.4k overCRS610MI.GetBasicData
Finance CRS610MI.GetFinancial
Credit limit (CRLM)50,000
Open balance62,400
Overdue (TDIN)18,900
Credit hold (BLCD)1 (held)
Terms (PYCD) / currencyN30 / USD
Open orders DATALAKE_COMPASS · lagged
2 orders on hold$41,000
Lake aggregate informs, never authorizes — verify against a live MI read before acting.
You
What will our total sales be next quarter?
DT
Withheld — that's a forecast of the future. No readable source backs it, so I won't guess. Truth Protocol: no guess shall pass. I can show you trailing sales by period from posted GL if that helps. reason: future / no source
You
Raise C-1088's credit limit to 75,000.
DT
That's a write, so I won't do it from Chat. I drafted it and ran a Consequence Preview — it's waiting for your confirmation in Approvals.
→ routed to ApprovalsCRS610MI.ChgFinancial

Runner — a goal into a governed plan

Give it a business goal; it decomposes into a cited, step-by-step M3 plan. Any step that changes data becomes a draft that waits in Approvals — the Runner never writes on its own.

Goal
Streamline order-to-cash and reduce credit-hold delays for new customers RECOMMENDED
multi-agent · CONO 100 · 4 drafts proposed — review in Approvals · session 7c2a91b4
  1. 1.Read the credit-hold queue and classify by reason OIS300MI.LstHead · HOLD via @o2c
  2. 2.For each held order, pull customer credit + aging CRS610MI.GetFinancial ARS200MI.LstInvoices
  3. 3.Propose credit-limit changes where aging is clean draft → Approvals via @finance
  4. 4.Draft a standard release for orders now within limit draft → Approvals via @o2c
  5. 5.Summarize expected cash-flow impact for the CFO GL · posted
Consultants cited: @o2c · 6 cited @finance · 4 cited. Every factual step traces to a validated read; steps that write are drafts, never auto-executed.

Approvals — Consequence Preview

The draft inbox. Every proposed write waits here. You approve an outcome — the consequences, not a raw field diff. Nothing touches the tenant until all three locks pass and you confirm, and the exact preview you saw is hashed into the audit.

AWAITING HUMAN CONFIRMRaise credit limit — Riverside Supply (C-1088) to 75,000
Proposed write · CONO 100 / DIVI 100 · requested by you
Transaction
CRS610MI.ChgFinancial
Customer
C-1088
Field
CRLM (credit limit): 50,000 → 75,000
Consequence preview — what this change will do
  • WARNING
    2 orders on credit hold totaling $41,000 become releasable.
    2 sources · CRS610/OIS300 · sum of held-order amounts for the customer
  • NOTICE
    3 open AR invoices for the customer — review aging before raising the limit.
    1 source · ARS200MI.LstInvoices · aging 64–74 days
  • UNCHECKED
    Downstream effect on this customer's dunning level could not be determined.
    reason: no readable provider for dunning on this tenant — absence of a warning is not a guarantee
Write gate — triple lock (+ allowlist + preview hash)
Lock 1 · schema — CRLM validated against MRS001MI-derived schema (server-side)
Lock 2 · business rules — anti no-op / blank-overwrite passed (manifest a3f9…)
3 Lock 3 · human confirm — HMAC token issued (single-use, 5-min TTL), waiting on you
Allowlist: 100 → CRS610MI → ChgFinancial permitted (default-deny)
Preview hash 9d17…c4eb — server re-checks it on confirm; a stale preview blocks the write
Confirming runs the three-lock gate server-side and executes exactly once. The UI never holds a write capability. ✓ Written — executed exactly once, recorded in the tamper-evident audit with the preview you saw.

Tickets

Read-only Jira, correlated to M3 entities. Ticket facts and M3 facts are each tagged to their own system of record and never blended. Nothing is written back.

KeySummaryStatusAssigneeCorrelated M3 entitySource
OPS-1423Billing dispute — Riverside Supply invoice 90341Opena.reyesCustomer C-1088LIVE_TICKET
OPS-1417Short shipment reported on order 4688Openj.okaforOrder 4688LIVE_TICKET
OPS-1402Item master cleanup — coupling familyIn reviews.patelItem grp HP-20xxLIVE_TICKET
OPS-1390Supplier lead-time change — Anvil MetalsOpena.reyesSupplier V-2044LIVE_TICKET
OPS-1377Recurring credit-hold on repeat customerOpenm.chenCustomer C-1088LIVE_TICKET

JQL: project = OPS AND status in (Open,"In review") ORDER BY updated DESC · read-only. Remove the credential and this surface fails closed with a specific remediation, never a silent empty state.

Audit

Every governed operation, hash-chained. Each row commits to the one before it — a later edit, deletion, or reorder breaks the chain and fails verification. A confirm row also records the hash of the exact consequence preview the human saw.

✓ chain verified   1,204 entries · genesis → head, no breaksverifyChain() · sha256(prevHash ‖ entry)
seqopprogram/transactionsourceresultpreviewentry_hash
1203confirmCRS610MI.ChgFinancialLIVE_TRNPASSa91c…7f20c4eb…9d17
1202draftCRS610MI.ChgFinancialLIVE_TRNPASS6f4e…1bc3
1201readOIS300MI.LstHeadLIVE_TRNPASS2e0a…8b82
1200writeMMS002MI.UpdItmWhsLIVE_TRNBLOCKED7a13…04df

Our own governance failures — found, dated, published

2026-06-10 An adversarial audit found the write gate's "triple lock" was, as wired by default, a double lock. Fixed and published before any tenant ever connected.
2026-06-24 Narrate degraded an UNVERIFIED claim to a hedged sentence instead of withholding it. Changed to hard-withhold; regression test added.
2026-07-02 Compass read path accepted a query with a trailing DML statement. Locked to a single SELECT (assertSelectOnly); fuzz test added.

Capabilities & governance

What the Toolbox is allowed to do on this tenant, and how it decides what to trust. Writes are default-deny; only an explicitly allowlisted triple can execute. Every claim carries a confidence from its source, with hard floors for reads and writes.

Write allowlist — per CONO, default-deny

CONOProgramTransactionIntentState
100CRS610MIChgFinancialRaise/lower credit limitallowed
100OIS017MIUpdBasePriceChange base priceallowed
100MMS200MIUpdItmBasicUpdate item masterallowed
100PMS100MIUpdMOUpdate manufacturing orderallowed
100CRS620MIChgBankInfoChange supplier bankdenied (no catalog match)

Source-tag confidence ladder (Truth Protocol)

TagMeaningConfidence
LIVE_TRNLive read from your M3 tenant1.00
LIVE_TICKETLive read from a different system of record (Jira) — never blended1.00
DOC_INFORGrounded in Infor documentation0.90
ANALYTICS_BIRSTModeled, time-lagged analytic0.80
DATALAKE_COMPASSData-lake aggregate (lagged)0.80
UNVERIFIEDNo validated source — hard block0.00

Confidence floors

Reads require≥ 0.60
Writes require≥ 0.90
Below floorwithheld, not degraded

Cost gate (per tenant / day)

Spent today$12.40
Warn / hard-block$35 / $50

MI Payload Builder

The ION fluency proof. The Toolbox walks this tenant's own MI catalog at boot (MRS001MI), so every program, transaction, field, type, and required flag comes from the tenant — not a hardcoded list. Pick a program and transaction; the form is schema-driven. It builds and validates the payload; it never executes.

Narrate

Deterministic narration over validated findings — the same facts produce byte-identical output. Every dollar is a finding's own amount, every count a real row count. Any evidence reference that doesn't resolve is dropped and tallied, never narrated. Two lenses, same facts.

EXECUTIVE BRIEFING — Dovrin governed-AI runtime
7 proposed findings across 5 agents · 2 critical · 3 high · 2 medium · $439.5k quantified across the book
  • #1 Procurement Exception — supplier bank-change exposure $214,500
  • #2 AR Cash Acceleration — aged receivables concentration $184,000
  • #3 AR Cash Acceleration — credit-hold backlog releasable $41,000
CRITICAL credit-hold backlog releasable [$41,000] (confidence 0.98)AR Cash Acceleration · lever: cash-flow
Two sales orders sit on credit hold for a customer now flagged over its limit; clearing the limit review makes the backlog releasable.
  • • OIS300MI.LstHead:HOLD=1 (2 rows) — held sales orders, $29,000 + $12,000
  • • CRS610MI.GetFinancial:C-1088 (1 row) — limit 50,000, balance 62,400
PROPOSED NEXT STEP → draft a credit-limit review for C-1088 (routes to Approvals; never auto-executed)
HIGH aged receivables concentration [$184,000] (confidence 0.95)AR Cash Acceleration · lever: cash-flow predictability
Receivables over 60 days rose to $184,000, concentrated in two accounts.
  • • ARS200MI.LstInvoices:AGED>60 (3 rows) — INV5501 (74d), INV5588 (64d), INV5602 (61d)
PROPOSED NEXT STEP → prioritize collection on the two >60-day accounts before extending terms
HIGH supplier bank-change exposure [$214,500] (confidence 0.92)Procurement Exception · lever: cash-flow + margin
A pending supplier bank change would direct open payables to a new account; a payment proposal is queued.
  • • APS200MI.LstInvoices:V-2044 (2 rows) — $200,000 + $14,500 open
  • • APS130MI.LstProposals:V-2044 (1 row) — PP-3001 pending release
PROPOSED NEXT STEP → verify the V-2044 bank change out-of-band before releasing PP-3001
GOVERNANCE: every narrated $ is a finding's own amountUsd, every count a real row count. 1 unresolved ref (next-quarter margin forecast) was dropped and NOT narrated.
HIGH order flow delayed by credit holds [$41,000] (confidence 0.90)Order Management · lever: integration speed
Four orders are on hold (2 credit, 1 short-ship dispute, 1 pricing); the credit ones clear once the limit review lands.
  • • OIS300MI.LstHead:HOLD=1 (2 rows) — orders 4711, 4720
  • • LIVE_TICKET (2 rows) — OPS-1423, OPS-1417 correlate to these holds
PROPOSED NEXT STEP → draft a standard release for orders now within limit (routes to Approvals)
MEDIUM safety-stock shortfall, coupling family (confidence 0.88)Inventory & Warehouse · lever: operational independence
Three items are below safety stock, all in the coupling family; HP-2040 is also allocated short.
  • • MMS060MI.LstViaItem (3 rows) — HP-2040 (36/40), HP-2055 (18/30), HP-2210 (5/25)
PROPOSED NEXT STEP → draft a safety-stock raise on HP-2040 (routes to Approvals with a Consequence Preview)
MEDIUM EDI ASN (856/DESADV) unmapped (confidence 0.80)EDI Reliability · lever: integration speed
The 856/DESADV advance ship notice has no confirmed BOD carrier on this tenant, so it is withheld rather than guessed.
  • • (no resolved evidence — TO_VERIFY)
PROPOSED NEXT STEP → confirm the BOD carrier before enabling the ASN flow
GOVERNANCE: root cause of the recurring credit hold is withheld — it spans a finance decision not recorded in any readable system; withheld, never guessed.

EDI

Translate X12/EDIFACT into M3 EDI BOD drafts — or honestly withhold what can't map yet. Nothing posts; mapped documents become drafts that wait in Approvals.

Mapped (customer role — M3 sells)

EDI→ M3 BODDirectionState
850 / ORDERSLoadM3EDISalesOrderinbounddraft → Approvals
855 / ORDRSPSyncM3EDISalesOrderAcknowledgeoutbounddraft → Approvals
810 / INVOICcustomer invoiceoutbounddraft → Approvals
820 / REMADVLoadM3EDICustomerRemittanceAdviceinbounddraft → Approvals

Withheld (2) — no guess

856 / DESADV ASN has no confirmed BOD carrier yet on this tenant — withheld until verified (TO_VERIFY).
supplier-role 850/855/856/810 M3-buys direction is UNVERIFIED here — not mapped rather than guessed.

NL→SQL Reports

Ask a data question in plain English; get a grounded Compass SQL statement, server-validated as SELECT-only, and not executed. If it can't be grounded in real tables, it says so instead of inventing a query.

Question
"What is the total order value by currency this year?"
✓ Validated — SELECT-only (server-checked)Grounded in: oohead, ocusma
SELECT  OHCUCD AS currency,
        SUM(OHTOTA) AS total_order_value
FROM    oohead
WHERE   OHORDT >= '20260101'
GROUP   BY OHCUCD
ORDER   BY total_order_value DESC

Generated, validated, and grounded — never executed here. In a live engagement, execution is tenant-gated behind the same governance as any read.

Birst — governed analytics

Source-tagged KPI rows from Birst, clearly marked as derived and time-lagged. Analytics inform; they never authorize a write on their own.

Logical query (BQL)
SELECT [Fill Rate] BY [Warehouse]
ANALYTICS_BIRST · as of 03:00 UTCModeled, time-lagged — verify against a live MI read before acting.
WarehouseFill rateLines shippedBackorders
10096.4%4,182151
20091.8%2,905238
30098.1%1,37726
Dovrin Toolbox — interactive demo. Synthetic tenant "HARBORPEAK", fictional data; no real customer, tenant, or proprietary content. A product of Simmer Group LLC · dovrin.com