ERP & Core Business

Dynamics 365

Microsoft Dynamics 365 spans finance, operations, sales and service. Because it usually sits alongside the rest of a Microsoft estate, it is often the system an assistant is asked to answer from first.

ERP & Core BusinessRead-scopedPermission-awareAudited lookupsArabic & English

Microsoft Dynamics 365 spans finance, operations, sales and service. Because it usually sits alongside the rest of a Microsoft estate, it is often the system an assistant is asked to answer from first.

What Dynamics 365 holds, and why that matters here

Dynamics 365 is modular, and Saudi deployments vary widely in which modules are live — some run finance and operations, some only sales and customer service, many run a combination assembled over years. What is consistent is that it holds the operational record and that access is licensed, so most people who need answers from it do not have direct access.

Its position inside the Microsoft estate matters practically. Identity usually already exists in Entra ID, which means the assistant can recognise a signed-in employee and answer within their existing permissions rather than asking who they are.

  • Finance and operations — orders, invoices, inventory, vendor and customer records.
  • Sales — accounts, opportunities, quotes and their stage.
  • Customer service — cases, their status and history.
  • Field service — work orders, scheduling and technician assignment.
  • Supply chain — stock positions, transfers and replenishment.

Questions this connection lets Elbi answer

What is the status of this case?

Case state and last update, answered to the customer directly rather than by an agent reading it out.

When is the engineer coming?

Work order scheduling for field service, which is the most-asked and least-automated question in that module.

What is the stock position?

Inventory by site for staff who need a number before they commit to one.

What stage is this deal at?

Opportunity stage and next step for sales managers who would otherwise ask the salesperson.

Has this invoice been settled?

Payment status against a customer account.

What did we agree with this customer?

Terms and pricing on the account record, so the answer is the same regardless of who is asked.

How the connection works in practice

  1. You decide what is readableBefore anything is connected, you define the scope: which records, which fields, which operations. The assistant is given a narrow, named view of Dynamics 365 rather than general access, and that view is agreed in writing during deployment.
  2. A question arrives in natural languageA customer or an employee asks something ordinary — "where is my order", "am I covered for this", "what did I spend last month". No syntax, no menu, no reference number required if the person is already identified.
  3. The assistant works out what is being askedThe question is matched to an intent and the details it needs. If something essential is missing, it asks for that one thing rather than presenting a form.
  4. It reads only what it is allowed to readThe lookup runs inside the permission scope you defined, and inside the permissions of the person asking. Someone who cannot see a record in Dynamics 365 cannot see it through Elbi either — the assistant does not become a way around your own access rules.
  5. The answer is written back in plain languageA record is not an answer. The result is turned into a sentence in the language the question was asked in, with the parts that matter surfaced and the internal codes left out.
  6. Anything it cannot do goes to a personReads are safe to automate. Anything that changes money, entitlement or a legal position can be routed to a human for confirmation — you decide which side of that line each action sits.

Scope, control and what stays yours

Direction of accessRead by default. Any write-back — creating a ticket, updating a record, logging a lead — is enabled deliberately, per action, and can be held behind human confirmation.
Who can see whatThe assistant answers within the permissions of the person asking. Identity is established through your own sign-in, not invented by the assistant.
CredentialsThe connection uses credentials you issue and can revoke, scoped to the narrow view agreed at deployment. Revoking access is something you do on your side, without our involvement.
Where data goesRetrieved records are used to answer the question in front of the assistant and are not retained afterwards beyond your configured conversation retention.
AuditEvery lookup can be recorded — what was asked, what was retrieved, which agent, which conversation — so the connection is reviewable rather than opaque.
If it is unavailableIf Dynamics 365 cannot be reached, the assistant says so plainly and offers a person. It does not guess at a value it could not retrieve, and it does not present a cached figure as though it were live.

What this replaces

Where Dynamics is deployed alongside the wider Microsoft estate, the assistant can do something unusually clean: recognise the employee from the sign-in they already have, and answer only what that person is entitled to see. No separate account, no second permission model to maintain, and no risk of the assistant becoming a way around access rules that were carefully set elsewhere.

For customer-facing use the value is the same as any system of record — case and order status stop being questions that require a person. For internal use it is broader, because Dynamics tends to hold the answers that cross departmental boundaries, which are exactly the ones that get asked by email and answered slowly.

The practical constraint is module sprawl. Many organisations run modules that were configured at different times by different partners, with overlapping data. Deciding which module is authoritative for each question is genuinely the hardest part of the deployment, and it is a business decision rather than a technical one.

How different sectors use it

Retail and consumer

Order and delivery status at volume, with stock visibility across branches.

Field service organisations

Appointment and technician-arrival questions, which dominate contact and are almost entirely answerable from the work order.

Professional services

Project and invoice status for clients who would otherwise email an account manager.

Manufacturing

Production and supply questions asked by sales staff mid-conversation.

Getting the value out of it

A connection is only as useful as the questions it is pointed at. The pattern that works is to start from the contact you already receive rather than from what the system can technically expose. Pull a month of chat transcripts and call notes, count the questions, and connect for the top five. That is almost always where the volume is, and it is usually duller than anyone expects — status, eligibility, balance, hours, documents.

The second thing that decides success is scope discipline. It is tempting to connect broadly and let the assistant work out what is relevant. It works far better to expose a small, well-named set of operations and expand once you have seen a month of real questions against them. A narrow connection is easier to reason about, easier to audit, and far easier to explain to whoever signs off on it.

The third is knowing what not to automate. Reads are safe. Anything that moves money, changes an entitlement or creates a commitment should either stay with a person or pass through one. The assistant is at its best when it removes the lookup and leaves the judgement.

What connecting it actually involves

  1. Agree the questions firstNot the fields, the questions. A month of real transcripts, counted, gives a ranked list of what people actually ask. That list decides the scope; the scope decides the connection. Starting from what Dynamics 365 can technically expose produces a broad connection answering questions nobody asked.
  2. Define the readable viewYour team decides which records and fields the assistant may see, and which it must never see. This is written down, signed off, and is the document you will hand to whoever audits the deployment later.
  3. Issue scoped credentialsYou create the credentials, on your side, scoped to that view. They are yours: you can rotate or revoke them without involving us, and doing so takes effect immediately.
  4. Map your instanceCustom fields, renamed objects, local terminology and the particular way your organisation uses the system are mapped during deployment. Nobody has a stock configuration and the work assumes you do not either.
  5. Rehearse the unhappy pathsMissing record, ambiguous match, system unavailable, customer asking about someone else's account. These are tested deliberately before launch, because they are what determines whether people trust the assistant, and they are what most pilots skip.
  6. Launch narrow, widen on evidenceGo live on the top few questions, watch a month of real traffic, then widen. Every deployment that widened first and measured later has produced the same result: an assistant nobody trusts and a project that quietly stops.

Governing a connection you will have to defend

A connected assistant is a data-processing decision before it is a technology one. Under the Saudi Personal Data Protection Law, the questions that matter are the ordinary ones: what personal data is being processed, on what lawful basis, for how long it is kept, who can see it, and what happens when someone asks for it to be deleted. A lookup against Dynamics 365 touches most of those at once.

The practical answer is scope and evidence. Scope means the assistant reads a narrow, named view rather than holding broad access, so the question "what could it see?" has a short and checkable answer. Evidence means every lookup can be recorded — the question, the retrieval, the agent, the conversation — so a review after the fact is reading a log rather than reconstructing a story.

The part most organisations underestimate is consent. If a customer is going to have their record read during a conversation, that has to be something they agreed to, in language they understood, in the language they speak. Retrofitting consent after launch is far more painful than designing the flow around it, and it is the single most common reason a pilot stalls at legal review rather than at the technical stage.

What organisations typically see

0
of contact is status, eligibility or balance — the questions a connected system answers directly
0
coverage for lookups that previously waited for office hours
0
faster first response when the answer is retrieved rather than requested
0
internal tickets raised for questions the assistant can answer itself

How this is done elsewhere, and where it goes wrong

The mainstream pattern across the industry is now well established: a conversational layer in front of systems of record, retrieving rather than remembering, escalating rather than improvising. Where deployments fail, they fail in recognisable ways.

The most common failure is connecting everything at once. A broad connection is harder to reason about, harder to permission correctly, and produces an assistant that occasionally surfaces something it should not — which is the single fastest way to lose internal trust and have the project shut down. Narrow beginnings survive; broad ones get switched off.

The second is treating the assistant as a reporting tool. Systems of record are optimised for transactions, not analysis, and an assistant asked to compute across large volumes will be slow and occasionally wrong. Point it at facts about a specific record and it is excellent; point it at "summarise our quarter" and it is the wrong instrument.

The third is forgetting the unhappy path. Systems go down, records are missing, a customer asks about an order that does not exist. What the assistant does in those moments defines how it is perceived far more than what it does when everything works — which is why saying "I could not reach that system" is a feature, not an admission.

Common questions

Whichever you point it at. Part of deployment is deciding which module is authoritative for each question, because in practice several often hold overlapping data.

Where identity is in Entra ID, yes — a signed-in employee is recognised and answered within their own permissions.

Where you enable it. Reading is the default; adding a note or raising a case is turned on deliberately and can require confirmation.

No. The connection runs between your assistant and your system, using credentials you issue and control. What the assistant may read is the narrow scope you defined, and you can revoke it at any time without going through us.

Most deployments are. Custom fields, renamed objects and bespoke workflows are normal, and the connection is mapped to your instance during deployment rather than assuming a stock configuration.

It can, where you enable it. The default is read-only because that is the safe starting point. Write actions are turned on individually and can require a person to confirm before they commit.

Connect it to your own systems

A working assistant against your own records, in both languages.