Skip to content

How does the AI assistant module work inside the panel?

Updated

The AI assistant is a helper that runs inside the panel and works with exactly the same permissions as the person using it. What sets it apart: the model never touches the database directly — it only decides “which action, with what data”, and the action itself is carried out through the panel’s real screens. That means permission checks, audit logging and live updates all run through the path that already exists; no second write path is opened for the assistant.

The assistant has no identity of its own

The assistant is not a separate user and carries no permissions of its own; its ceiling is always the permission set of whoever is currently signed in. A screen or field the user cannot see, the assistant cannot see or open either. The tool catalogue — the list of things the assistant can actually do — is derived automatically from the modules turned on in the company and the user’s own permissions within them; if no module is turned on, the assistant can only talk, not act, and the screen says so plainly.

The ghost cursor: not a show, a real action

When you tell the assistant to “create a trip”, you see a cursor move on its own, land on the trips screen, fill in the form and submit it. That is not a performance — everything under the cursor is real: a real page change, real form state, a real submission, the same API path a human click would use. There is no fake screen, no fake record, no “pretending it happened”; if the assistant is stopped mid-way, the screen stays exactly in its real state — nothing rewinds.

Approval and undo

Every write-class action shows an approval card before it is sent; a company can require this for every single write if it wants (that is the default). Once approved, an action runs on a single-use token — the assistant cannot silently repeat the same action a second time without your say-so. Every mutation is written to a compensation ledger with its before and after state; when the assistant is told to “undo”, that undo is read straight from this ledger and reversed — it is not a restore from backup. If a required field is missing, the assistant asks instead of making something up, and waits for your answer; if you move to another screen before answering, the job stays “pending”, and if you close the panel entirely, the job stops.

Personal data masking

The text sent to the model never carries a real name, phone number or ID number; records are referred to with a blind alias for the model’s purposes (e.g. “Customer-7”), and the real value only ever shows on your own screen. This masking is on by default; a company that wants to turn it off can only do so with a separate approval, and the switch itself is written to the audit trail.

Provider choice and display setting

Which AI provider actually runs behind the assistant is the company’s own choice — the system is built to speak more than one provider format, so a change of provider underneath does not change how the assistant behaves inside the panel. The ghost cursor’s animated display is itself a setting: turned off, steps still run, just without the animation — the flow, the approval and the stop behaviour all keep working exactly the same. What gets turned off is the display, never a safety step.

Example

Picture an operations lead typing to the assistant: “Open a transfer tomorrow at 10 from the airport to Grand Hotel, customer Blue Tour.” The assistant goes to the trip screen and fills in the form, then asks about the missing driver/vehicle assignment and waits; once you reply “assign Ahmet with 34 ABC 123”, the form completes with that information and an approval card appears. Once you approve, the trip is genuinely created, a trip number is assigned, and the action is written to the compensation ledger — if the wrong information was entered, it can be undone from that same ledger with one click.

How it works in Rotenta

  1. The assistant drawer opens from any panel screen; it only ever sees the permissions of whoever is signed in at that moment.
  2. Before the request reaches the model, personal data is replaced with a blind alias.
  3. When the model picks a tool (e.g. “create trip”), the assistant navigates to that screen and fills the form through the real interface.
  4. If a required field is missing, it is asked in the drawer; the job does not proceed until you answer.
  5. A write-class action shows an approval card before sending; once approved, it runs on a single-use token.
  6. Every mutation is written to the compensation ledger on the /asistan/defter screen, where it can be selectively undone.
  7. You can cut the action off at any time with “Stop”; whatever completed up to that point stays real, and a half-filled form stays exactly as it was.

To see what the assistant can do on specific screens, check our customer management and trip and transfer operations articles, and for the permission side, roles and audit trail. The full picture of how the assistant connects to the rest is in our module guide; to find out which plan includes the assistant, get in touch.

Frequently asked questions

Can the assistant see a record I cannot see myself?

No; the assistant carries no permissions of its own and always works within the permission set of whoever is signed in at that moment.

If I think the assistant got something wrong, can I undo it?

Yes; every write is recorded in the compensation ledger with its before and after state, and can be selectively undone from there.

Does the model see our customer’s real name and phone number?

No; records reaching the model are referred to by a blind alias, and the real value only ever shows on your own screen. This masking can be turned off, but only with a separate approval that leaves its own trail.

What does the assistant do if no module is turned on?

It answers questions but cannot take action; the drawer says so plainly — for example, “no connected tools in this company” — rather than quietly pretending to do something.

Does every single write require approval?

That is the default; a company can change this so approval is only required for specific classes of action.

More in this category

Get a quote

Leave your details and we'll get back to you the same day.

By submitting you acknowledge the Privacy Notice.