AI agents for business: what they do at a manufacturer or distributor
An AI agent is software that takes a request, such as an emailed purchase order, works out the steps, uses your systems to carry them out and hands the result to a person to approve. Agents read messy documents and draft routine replies well, and they still make mistakes that a person has to catch. At a smaller manufacturer or distributor, good first jobs include order entry from email, quote drafting for review, supplier follow-up and stock questions. This guide explains each job in plain words, the guardrails to set before an agent touches your ERP, and how to start.

What an AI agent is, in plain words
OpenAI’s practical guide to building agents defines agents as “systems that independently accomplish tasks on your behalf.” Anthropic’s engineering post on building effective agents draws a finer line. In a workflow, “LLMs and tools are orchestrated through predefined code paths.” In an agent, the model decides the steps and which tools to use as it goes. An LLM, or large language model, is the kind of AI behind ChatGPT and Claude.
An agent at a plant or a warehouse has four parts:
- A language model reads the request and decides the next step.
- Tools let it look things up or make changes, such as reading a customer record or creating a draft order in the ERP.
- Instructions set the job, the rules and the actions it may not take.
- An approval step puts a person between the agent and anything that leaves the building or changes a record.
How an agent differs from a chatbot or an automation
A chatbot answers questions and takes no action in other systems. OpenAI’s guide says applications such as “simple chatbots, single-turn LLMs, or sentiment classifiers” are not agents. A rules-based automation, such as a Zapier or Power Automate flow built from fixed steps, does the same thing every time and does not decide what to do next. RPA, short for robotic process automation, replays recorded clicks on a screen. An agent reads the request and chooses its own steps, which is why it needs the guardrails described below. RPA vs AI agents compares the last two in detail.
What AI agents do well today
OpenAI’s guide tells teams to look first at work that has resisted ordinary automation, in three situations:
- Judgment calls with exceptions and context, such as deciding whether a request qualifies for a refund.
- Rules that have grown too many to maintain, where every update is costly or error-prone.
- Unstructured data, which the guide describes as “interpreting natural language, extracting meaning from documents, or interacting with users conversationally.” Unstructured data means text in emails, PDFs and scanned forms, as opposed to fields in a database.
At a manufacturer or distributor, that describes purchase orders that arrive in every customer’s own layout, requests for quote written in a customer’s own words, and supplier emails that bury a new ship date in the third paragraph.
Both vendors also say that many jobs need less than an agent. OpenAI’s guide says that when a job does not meet its criteria, “a deterministic solution may suffice,” meaning fixed rules that give the same output every time. Anthropic recommends “finding the simplest solution possible, and only increasing complexity when needed,” and adds that for many applications, a single model call with retrieval and examples “is usually enough.” Retrieval means the system finds the relevant records and hands them to the model, as RAG explains.
Where AI agents still fail
- Errors compound. Anthropic writes that “the autonomous nature of agents means higher costs, and the potential for compounding errors,” and recommends extensive testing in sandboxed environments with guardrails. An agent that misreads one line early in a task can carry the mistake through every later step.
- Answers can be wrong. Anthropic’s documentation on reducing hallucinations says even the most advanced models “can sometimes generate text that is factually incorrect or inconsistent with the given context.”
- Instructions can hide in the content. The OWASP Gen AI Security Project defines prompt injection as inputs that “alter the LLM’s behavior or output in unintended ways.” In the indirect form, the instructions arrive inside outside content, “such as websites or files.” For an agent that reads customer email, every inbound message and attachment is outside content.
- Working screens is slow and less reliable. When an agent operates software through screenshots and clicks, Anthropic’s computer use documentation says it “might be too slow compared to regular human-directed computer actions,” that the model “might make mistakes or hallucinate,” and that reliability “might be lower when interacting with niche applications.” It advises against using it for “tasks requiring perfect precision or sensitive user information without human oversight.”
Five agent jobs at a manufacturer or distributor
These examples are generic. Each one starts with the agent drafting and a person deciding, and the table at the end of the section sums them up.
Order entry from email
A customer emails a purchase order as a PDF. The agent reads it, matches the customer and each line to your part numbers and prices, and flags anything that does not match, such as a price that differs from the quote or a part number it cannot find. It then creates a draft sales order in the ERP. A person checks the flagged lines and releases the order. AI for ERP covers how an agent connects to the ERP you already run.
Quote drafting for review
A request for quote arrives with a drawing. The agent pulls the material, quantity, tolerances and finish from the request, finds similar past jobs with their costs and run times, and drafts a quote. The estimator checks the assumptions, sets the price and sends it. The agent saves the search through old jobs, and the pricing decision stays with a person.
Supplier follow-up
Each morning the agent lists purchase order lines that are late or due this week and drafts a follow-up email to each supplier. When a supplier replies with a new date, the agent proposes the change to the expected date in the ERP, and the buyer confirms it. AI in procurement covers purchasing work in more depth, and AI invoice processing covers the supplier invoices that follow.
Stock questions
Sales and customer service staff ask in plain words how many of a part are on hand, how many are already allocated to orders and when the next receipt is due. The agent answers from the ERP with read-only access and shows the record behind each number. AI for inventory management goes further into forecasts and reorder points.
Reading an old ERP’s screens
Some older ERP systems have no API, the connection one program uses to call another. An agent can still work their screens the way a person does, through computer use: it takes screenshots, reads them and clicks. Given the limits above, start it on reading and drafting, and have a person confirm anything it would save. Legacy ERP automation explains how that setup works.
The five jobs side by side
| Job | What the agent does | What a person approves | Access the agent needs |
|---|---|---|---|
| Order entry from email | Reads the purchase order, matches customer, parts and prices, drafts the sales order | Releasing the order | Read the order mailbox, read customers, parts and prices, create draft orders |
| Quote drafting | Extracts the requirements, finds similar past jobs, drafts the quote | The price and sending the quote | Read requests for quote, drawings, past quotes and job costs |
| Supplier follow-up | Lists late purchase order lines, drafts emails, proposes new dates | Each email and each date change | Read purchase orders, draft emails, propose updates |
| Stock questions | Answers on-hand, allocated and due quantities with their source | Nothing, because it only reads | Read-only inventory data |
| Old ERP screens | Reads and fills screens where there is no API | Every change it would save | Its own ERP login with limited rights, on a dedicated virtual machine |
Pick the first job together
Tell Derik which of these jobs takes the most hours at your company and which system it runs through. He will tell you whether an agent fits and what it would need to reach.
Start a conversationGuardrails to set before an agent touches your systems
OWASP lists excessive agency in its 2025 top 10 risks for LLM applications. It describes it as the weakness that “enables damaging actions to be performed in response to unexpected, ambiguous or manipulated outputs from an LLM,” and traces it to too much functionality, too many permissions or too much autonomy.
- Approval before any action. OpenAI’s guide says actions that are “sensitive, irreversible, or have high stakes” should trigger human oversight “until confidence in the agent’s reliability grows.” In practice, a named person approves every email sent, record changed and order created. Human in the loop explains which actions need approval and how to set the step up.
- Only the tools and permissions the job needs. OWASP’s example is a mailbox tool that summarizes email and therefore needs only to read it, with no ability to send or delete. Give the agent its own account with read access first, and add write rights one action at a time.
- Permissions checked outside the model. OWASP advises enforcing authorization “in downstream systems rather than relying on an LLM to decide if an action is allowed.” The ERP should refuse what the agent’s account may not do, whatever the agent asks.
- Logs of every run. Record the input, each tool call, each approval and each change, so you can trace any result back to its source. OWASP recommends logging and monitoring for this reason.
- Tests before and after every change. Keep a set of past jobs with known answers and rerun it whenever the prompt, the model or a connected system changes. AI evals covers how.
OWASP describes an assistant that could read a mailbox and also send messages. A crafted incoming email told it to search the inbox for sensitive information and forward it to the attacker. OWASP lists three fixes: a tool that can only read mail, a sign-in with read-only rights, or a person who reviews and sends every email the assistant drafts.
For the wider picture, AI security covers threats and controls, and AI governance covers policies and Canadian law.
How to start with an AI agent
- Pick one job. Choose work your team repeats every week, and write down who does it and how many hours it takes.
- Collect past examples. Pull 30 to 50 recent cases with the answer your team gave. They become the test that tells you whether the agent is right.
- Start read-only. The agent reads and drafts, and a person decides.
- Run it beside your team. For a few weeks, compare the agent’s drafts with what your team did.
- Add write access one action at a time, each behind an approval, and keep rerunning the tests.
How to build an AI agent sets out these steps with a timeline. AI agent builder platforms compares the tools you could build on, and AI training covers preparing the staff who will review the agent’s work.
Questions people ask
What is an AI agent in simple terms?
What can AI agents do for a small manufacturer or distributor?
Are AI agents safe to connect to our ERP?
What is the difference between an AI agent and a chatbot?
What is the difference between an AI agent and RPA?
How do we start with AI agents?
How ThriveAI helps
ThriveAI is an AI engineering company in Ottawa. It builds private AI systems on the client’s own data for manufacturers and distributors in Ontario and Quebec, including agents that draft work in the ERP for a person to approve. Derik Lawlis, the founder, leads every project and stays close to the build.
The platform is designed to keep each client’s data on its own server in Canada. You choose the model: one that runs on that server, or a hosted model under a written zero data retention agreement, under which the provider keeps no copy of a request or its answer. A hosted model may process requests outside Canada, so the contract names the model. A named person at your company approves every action before anything is sent or saved. For how the pieces fit together, see enterprise AI platform, and for the company, About ThriveAI.