Different work,
different assistant.
The work is not one job, so the worker is not one bot. In Odient you spin up a role-scoped assistant for each job - its own permissions, model, persona, and actions - and each one does its own work on the same governed engine.
One engine. Different keys.
Give one AI the keys to your whole ERP and you have built a liability. An assistant should never be a new superuser role. Scope a team instead: each assistant sees only its own world, acts only where you allow, and lands every move in the audit trail.
The public one cannot reach your CRM.
Betty lives on your website. She answers from your Helpdesk and knowledge base, opens a ticket when she needs to, and that is the whole of it. No CRM, no accounting, no customer records, no writes. The fear you would have about a public bot is the exact thing you set. That is the feature.
Frequently asked questions.
What is a role-scoped AI assistant?
One assistant per job, each with its own permissions, model, persona and allowed actions, all on the same governed engine. Your internal assistant can see your modules and draft governed writes; your public-facing one reads Helpdesk and the knowledge base, and nothing else. What you scope out cannot be reached.
Can a public assistant leak CRM or accounting data?
No. Not by policy; by scope. Betty’s world is Helpdesk and the knowledge base; CRM, accounting and customer records are outside it, and every attempt writes one audit record, allowed or blocked. The fear you would have about a public bot is the exact thing you set.