How does the AI assistant module work inside the panel?
The AI assistant is a helper that runs inside the panel and works with exactly the same permissions as the person using it. What sets it apart: the model never touches the database directly — it only decides “which action, with what data”, and the action itself is carried out through the panel’s real screens. That means permission checks, audit logging and live updates all run through the path that already exists; no second write path is opened for the assistant.
The assistant has no identity of its own
The assistant is not a separate user and carries no permissions of its own; its ceiling is always the permission set of whoever is currently signed in. A screen or field the user cannot see, the assistant cannot see or open either. The tool catalogue — the list of things the assistant can actually do — is derived automatically from the modules turned on in the company and the user’s own permissions within them; if no module is turned on, the assistant can only talk, not act, and the screen says so plainly.
The ghost cursor: not a show, a real action
When you tell the assistant to “create a trip”, you see a cursor move on its own, land on the trips screen, fill in the form and submit it. That is not a performance — everything under the cursor is real: a real page change, real form state, a real submission, the same API path a human click would use. There is no fake screen, no fake record, no “pretending it happened”; if the assistant is stopped mid-way, the screen stays exactly in its real state — nothing rewinds.
Approval and undo
Every write-class action shows an approval card before it is sent; a company can require this for every single write if it wants (that is the default). Once approved, an action runs on a single-use token — the assistant cannot silently repeat the same action a second time without your say-so. Every mutation is written to a compensation ledger with its before and after state; when the assistant is told to “undo”, that undo is read straight from this ledger and reversed — it is not a restore from backup. If a required field is missing, the assistant asks instead of making something up, and waits for your answer; if you move to another screen before answering, the job stays “pending”, and if you close the panel entirely, the job stops.
Personal data masking
The text sent to the model never carries a real name, phone number or ID number; records are referred to with a blind alias for the model’s purposes (e.g. “Customer-7”), and the real value only ever shows on your own screen. This masking is on by default; a company that wants to turn it off can only do so with a separate approval, and the switch itself is written to the audit trail.
Provider choice and display setting
Which AI provider actually runs behind the assistant is the company’s own choice — the system is built to speak more than one provider format, so a change of provider underneath does not change how the assistant behaves inside the panel. The ghost cursor’s animated display is itself a setting: turned off, steps still run, just without the animation — the flow, the approval and the stop behaviour all keep working exactly the same. What gets turned off is the display, never a safety step.
Example
Picture an operations lead typing to the assistant: “Open a transfer tomorrow at 10 from the airport to Grand Hotel, customer Blue Tour.” The assistant goes to the trip screen and fills in the form, then asks about the missing driver/vehicle assignment and waits; once you reply “assign Ahmet with 34 ABC 123”, the form completes with that information and an approval card appears. Once you approve, the trip is genuinely created, a trip number is assigned, and the action is written to the compensation ledger — if the wrong information was entered, it can be undone from that same ledger with one click.
How it works in Rotenta
- The assistant drawer opens from any panel screen; it only ever sees the permissions of whoever is signed in at that moment.
- Before the request reaches the model, personal data is replaced with a blind alias.
- When the model picks a tool (e.g. “create trip”), the assistant navigates to that screen and fills the form through the real interface.
- If a required field is missing, it is asked in the drawer; the job does not proceed until you answer.
- A write-class action shows an approval card before sending; once approved, it runs on a single-use token.
- Every mutation is written to the compensation ledger on the /asistan/defter screen, where it can be selectively undone.
- You can cut the action off at any time with “Stop”; whatever completed up to that point stays real, and a half-filled form stays exactly as it was.
To see what the assistant can do on specific screens, check our customer management and trip and transfer operations articles, and for the permission side, roles and audit trail. The full picture of how the assistant connects to the rest is in our module guide; to find out which plan includes the assistant, get in touch.
Frequently asked questions
Can the assistant see a record I cannot see myself?
No; the assistant carries no permissions of its own and always works within the permission set of whoever is signed in at that moment.
If I think the assistant got something wrong, can I undo it?
Yes; every write is recorded in the compensation ledger with its before and after state, and can be selectively undone from there.
Does the model see our customer’s real name and phone number?
No; records reaching the model are referred to by a blind alias, and the real value only ever shows on your own screen. This masking can be turned off, but only with a separate approval that leaves its own trail.
What does the assistant do if no module is turned on?
It answers questions but cannot take action; the drawer says so plainly — for example, “no connected tools in this company” — rather than quietly pretending to do something.
Does every single write require approval?
That is the default; a company can change this so approval is only required for specific classes of action.
More in this category
- How does vehicle and driver document tracking work?
Warns on an expired or upcoming vehicle/driver document, and blocks trip assignment when a required one has lapsed.
- How does the vehicle and driver (fleet) module work?
One ledger for your vehicles and drivers that trips assign from and that answers who is available, when.
- How does recurring shuttle planning work?
A route and weekly plan are defined once; public holidays are skipped, one-off exceptions post as billing deductions, and off-plan extra trips enter the statement as their own line.
- How is e-invoicing (e-Fatura/e-Arşiv) integrated?
Tax ID and scenario data carried on the invoice record flow straight through; send status and the tax authority's reference show on the panel in real time.
- How does the Excel data import module work?
A module that validates and previews your existing spreadsheets, isolates the bad rows, and can undo an import if needed.
- How is workflow automation set up?
Trigger + condition + action rules ship as ready templates, every run is recorded as evidence, and a rule bound to a closed module shows as visibly inactive, never silent.
- How does the consent management module work?
Records customer consent per channel, ties sensitive fields to explicit consent, and exports to Turkey's İYS registry.
- How does the customer management (CRM) module work?
One card for people and companies, encrypted sensitive fields, tagging and notes — how Rotenta's CRM module is laid out on screen.
- How does the accounting module: accounts, invoices, cash work?
Current account, invoice, cash and instalment tracking brought together in one accounting module, from proforma to day-close.
- How do PDF outputs and letterhead documents work?
One core engine that puts your letterhead on invoices, statements, receipts and passenger lists, and logs every document it produces.
- How are staff shifts and timesheets managed?
Timesheets are produced from realised trips, deductions carry evidence and a dispute path, staff on leave cannot be reassigned, and period close freezes the past.
- How do reports and profitability analysis work?
Every list you own exports at full fidelity, aging buckets of 0-30/30-60/60-90/90+ days sit on one screen, and period profitability drills all the way down to the source trip.
- How does booking and capacity management work?
A resource x time-slot booking engine that blocks double-selling, tracks option deadlines and converts a confirmed request straight into a trip or service record.
- How do roles, permissions and the audit trail work?
Roles decide who can see what, and the audit trail keeps a permanent record of who changed what and when.
- How does the trip and transfer operations module work?
One record that follows a trip from planning to completion, carrying its passengers, driver, vehicle and price lines together.
- How do contracts and progress billing work?
The contract is the single price source; progress billing is calculated automatically from trip records, penalty clauses apply on their own, and an approved statement becomes an invoice in one click.
- How do quotes and proposals work?
Quote lines read from the published rate list, margin is visible to authorised users, a five-state lifecycle is tracked, and an accepted quote converts to an invoice in one click.
- How does bulk messaging and consent compliance work?
Consent is checked at send time against İYS, the national record; every commercial message carries an opt-out link, and delivery state is kept as evidence.
- How is U-ETDS reporting done?
Every trip already carries the fields U-ETDS reporting needs; send status shows on the trip card and never shows an optimistic 'sent' before it is confirmed.