Guide
AI for ERP and CRM: the vendor's built-in features or a layer of your own
The AI built into an ERP or CRM, such as Salesforce Agentforce, Copilot in Microsoft Dynamics 365, SAP Joule or NetSuite's AI features, is the right place to start for work that happens inside that one system: summarising a record, drafting an email, filling a field. It already follows the system's permissions, and the vendor maintains it. Build your own layer around the systems when the work crosses them, when you need to choose the model or control the cost of each task, or when you need a record the vendor does not keep for you. The deciding question is usually access. Each vendor now sets its own terms for outside AI reaching its data, from an open connector with published guardrails to a policy clause that restricts AI agents. The vendor terms on this page were read on 29 September 2026.
AI layer for ERP and CRM. Software a business owns that connects an AI model to its ERP, CRM and other systems through their published interfaces, with its own permissions, checks and records, instead of relying only on the AI each vendor builds into its product.
1AYM is an OpenAI Select Partner. Its founder holds personal Claude certifications. 1AYM is not an Anthropic partner.
Checked . Vendor facts were read on each vendor's own pages. Prices are US list prices where a vendor publishes them; SAP and NetSuite do not publish the price of their AI units on the pages read, so those are quote-only. Vendors change prices, packaging and access terms without notice, so confirm them on the sources below before you rely on them.
Two ways to put AI on a system of record
Each of the four vendors on this page now sells AI inside its product. Salesforce has Agentforce, Microsoft puts Copilot and prebuilt agents in Dynamics 365, SAP has Joule, and NetSuite has AI features such as Text Enhance and Ask Oracle [1, 5, 8, 10]. The pitch is the same everywhere: the AI already sits next to your data, so you switch it on.
The other route is a layer you own. It is software that reads from and writes to those systems through their published interfaces, calls a model you choose, and keeps its own checks and records. It can be an agent you build, or an assistant such as ChatGPT or Claude connected through the vendor's own connector.
I think the choice usually gets framed as a contest, and it is not one. Built-in AI is good at work that starts and ends inside one system. A layer earns its cost on work that crosses systems, such as a renewal decision that needs the contract from the CRM, the invoices from the ERP and the support history from somewhere else. I would expect a mid-sized business to end up with both, so the useful decision is which work goes where.
What each vendor offers, charges and allows
The table sets out what each vendor's own pages said on the date below. It is not a ranking. The four products serve different systems, and the relevant one is almost always the one attached to the system you already run. The row that matters most for a layer of your own is the last one.
| Dimension | Salesforce | Microsoft Dynamics 365 | SAP | NetSuite |
|---|---|---|---|---|
| Built-in AI [1, 5, 8, 10] | Agentforce agents for employees and customers across Sales, Service and other clouds, with Prompt Builder and Agentforce Builder | Copilot in Dynamics 365 and prebuilt agents such as the Sales Close Agent (in preview), with access included in Sales Enterprise | Joule, SAP's assistant, and AI embedded in SAP applications (Base AI); Joule Agents that carry out multi-step work (Premium AI) | AI features including Text Enhance, Prompt Studio, Ask Oracle and NetSuite Next; Bill Capture is a separate add-on module |
| How the built-in AI is charged [1, 5, 8, 10] | Flex Credits at US$500 per 100,000, with a standard action using 20 credits; or US$2 per conversation; or add-ons from US$125 per user per month for unmetered employee use | Sales Enterprise at US$105 per user per month, paid yearly, includes Copilot; Sales Premium at US$150 lists 1,000 Copilot Credits per user a month among its extras; agents run on Copilot Credits | Base AI included with SAP cloud subscriptions; Premium AI paid in AI Units, 0.02 per agent action; the price of an AI Unit is quote-only | 1,000 AI Units a month per General Access user included; more are sold in packs whose price the page does not give, so quote-only |
| Choosing the model inside the vendor's AI [3, 5, 6, 8, 10, 15] | Offered: Salesforce's bring-your-own-LLM option lets its generative features use a third-party model | Copilot in Dynamics 365 runs on OpenAI models in Azure; agents built in Copilot Studio, which runs Dynamics 365 agents, can use models from Anthropic (Claude), xAI or Mistral once an admin allows them | Not stated on SAP's pricing page; custom agents built in Joule Studio are billed on the compute, storage, transactions and AI tokens they use, and running them in production is free through the end of 2026 | Not offered: NetSuite says customers cannot bring their own model or AI provider to its built-in features |
| Route for an outside AI layer [4, 7, 9, 10, 11, 12] | Headless 360 MCP Server (open beta) and Data 360 MCP Server (generally available), which Salesforce says keep the same identity and permissions | Dataverse MCP server, usable from Claude and other clients; since 15 December 2025 charged when agents built outside Copilot Studio use it, unless Premium or Microsoft 365 Copilot licences cover it | API Policy clause 2.2.2 prohibits API use by AI systems that plan, select or execute sequences of API calls, except through SAP-endorsed pathways | NetSuite AI Connector Service for Claude, ChatGPT and other clients; runs with the user's own role, never an Administrator role, and uses no AI Units |
Two things stand out. The meters differ in kind: Salesforce and SAP count actions, Microsoft counts credits on top of a per-user licence, NetSuite draws down units that come with each user licence, and Salesforce also sells flat per-user access. You cannot compare those without your own volumes, which is why the guide below starts from the work, not the price.
The terms for outside AI now differ more than the built-in features do. NetSuite has opened a connector with published guardrails, Salesforce is building towards any authorised agent reaching its platform, Microsoft charges for that access in some cases, and SAP's policy restricts it unless you go through a pathway SAP endorses. This is not legal advice. What you may do depends on your own agreement with the vendor, which can differ from what the vendor publishes.
Which route fits which job
Five questions settle most cases. Answer them for one piece of work at a time rather than for a whole system, because a single CRM can hold work that suits each route.
| Dimension | Use the vendor's AI when | Build your own layer when |
|---|---|---|
| Data access | Everything the task needs lives in the one system, and the user can already see it | The task needs data from two or more systems, or from documents and email the vendor's AI cannot reach |
| Workflow depth | The task is a step inside the vendor's own screens: summarise, draft, fill a field, suggest the next action | The task is a process in its own right, running across systems, with its own checks before anything is written back |
| Cost | Volumes are modest, or a flat per-user price covers the people who need it | Volumes are high enough that a per-action meter costs more than the model calls plus the engineering to run them |
| Control and audit | The vendor's settings and logs answer what your security team and auditors will ask | You need to choose the model, set limits for each task, or keep your own record of every input, check and approval |
| Lock-in | You expect to stay on the system for years and are content to follow the vendor's roadmap | You may change systems, or want the same AI working across vendors, so the logic should not live inside any one of them |
Where the answers split, I would split the work: the vendor's AI for help inside its own screens, and a layer of your own for the few processes that cross systems. Before you design that layer, check the last row of the vendor table for your system, because the access route decides what the layer may do and what it costs.
What each route really costs
The vendor route looks cheaper because it arrives on an invoice you already pay. Check what runs the meter. At Salesforce's list prices, a standard Agentforce action of 20 Flex Credits works out at 10 cents [1], so an agent that takes five actions to close a case costs 50 cents a case on that meter alone. SAP prices its agents per action as well [8], and has announced that later in 2026 most generative AI capabilities that now need AI Units move into Base AI at no extra cost [8], so expect that line to change. Microsoft includes Copilot in the Sales Enterprise licence and meters agents in Copilot Credits [5], and NetSuite includes an allowance of AI Units with each user licence and sells more in packs [10].
A layer of your own moves the cost rather than removing it. You pay a model provider per token, you pay for the engineering to build and run the layer, and you may still pay the vendor for access: Microsoft charges Copilot Credits when agents built outside Copilot Studio use its Dataverse MCP tools, unless your licences cover it [7]. Price all three lines before you compare, because the model calls are the only one with a public price list.
The cost nobody prices is agreeing what a correct answer is. In engagement file D-06, connecting an AI workspace to a company's finance data took an afternoon, and the week that followed, agreeing definitions with the finance director, was the actual work. That week is the same whichever route you choose.
Where the lock-in actually sits
Lock-in used to mean the cost of moving your data. With AI it also means where your business logic lives. Instructions, prompts and approval rules written inside Agentforce Builder, Copilot Studio or Joule Studio stay there if you leave. That is a fair trade if you will run the system for a decade, and a poor one if the same process has to span systems from two vendors.
Access is the other half. SAP's API Policy, version 4.2026a, says that outside SAP-endorsed architectures, data services or service-specific pathways, SAP prohibits API use for interaction or integration with AI systems that plan, select or execute sequences of API calls, and for large-scale data extraction [9]. The policy does not list which pathways SAP endorses, so ask SAP in writing which one covers your use before you design around it. The same policy says it does not limit data export the law requires [9].
The other three vendors are opening up, on different terms. NetSuite's connector lets outside assistants act with the user's own role [11, 12]. Salesforce says its Headless 360 MCP Server lets agents in Claude, ChatGPT and other platforms use Salesforce capabilities with the same identity and permissions, though that server is in open beta [4]. Microsoft's Dataverse MCP server works with clients such as Claude and bills some of that use [7]. The Microsoft charge started on 15 December 2025 and SAP's policy is a 2026 version, so I would expect these terms to move again. Keep each vendor's connection in one piece you can replace. This is not legal advice: whether a use is allowed depends on your own agreement, and your legal adviser should read it.
What a layer of your own has to get right
NetSuite's published guidance on outside AI works as a checklist for any of the four systems [12]. It warns that prompt injection and hallucination can lead an agent to make payments or grant approvals the user never intended, to change or delete data, or to disclose sensitive data. It recommends granting access only to users who need it, keeping high-privilege roles away from AI, starting with read-only tools, and asking for confirmation before high-impact actions. Those points, plus three of our own, are what to ask of anyone who builds the layer for you.
- Least access, never an admin
- The layer acts as the person it serves, or as its own identity with the least access the task needs. NetSuite blocks Administrator roles from its AI connector by design [12], and the same rule is worth applying on every system.
- Read before write
- Start with questions and drafts. Allow writes only once the answers hold up against real past cases, and then only through checks.
- Checks before anything lands
- Every proposed write passes business rules and a reconciliation against the system of record, and anything that fails goes to a person with the reason attached. This is the pattern where the model proposes and a deterministic check decides.
- Definitions agreed once
- What a customer, a booking or a period means is written down once, and every answer uses it, so the layer and the finance team give the same number.
- A record of every run
- Who asked, which model and prompt version answered, which tools ran, which checks passed and who approved, kept where your auditors can read it.
- One replaceable connector per vendor
- Each vendor's access route sits behind its own module, so a changed policy or price means replacing one piece rather than rebuilding the layer.
Where 1AYM fits
Building that layer is what our AI integration and automation service does: AI inside the systems a business already runs, NetSuite among them, with every write checked, traceable and reversible, and never more access than the person it acts for. The closest documented case is the finance connector above, which carries each person's existing permissions so nobody sees more than they already could.
If you have not yet decided which work belongs on which route, our AI Opportunity & Feasibility Sprint scores the candidate processes on value, feasibility and risk over a typical two to four weeks, and gives you the answer in writing. If the scope is already clear, a fixed-scope build can start within a day of sign-off, and a job you have already scoped can be resourced on contract from the associates who work with 1AYM, held to the same standard. US clients can contract through 1AYM's US entity. We have built on the ERP and CRM vendors' own AI tools as well as OpenAI's and Anthropic's, so the recommendation follows your systems rather than the partnership. The next step is a short call, booked from the end of this page.
For engineers: access routes, identity, limits and failure modes
The integration pattern in engineering terms, with each vendor-specific fact sourced. Check them against your own tenant, because edition and region change what is available.
- Access route per system
- Salesforce: hosted MCP servers (Headless 360 MCP in open beta, Data 360 MCP generally available) [4]. Dynamics 365: the Dataverse MCP server, enabled per Power Platform environment with an allow-list of clients [7]. NetSuite: the AI Connector Service over OAuth 2.0, with a per-account server URL and SuiteApp tool namespaces [11]. SAP: Published APIs only, within the API Policy's controls, and nothing that plans or chains API calls outside an SAP-endorsed pathway [9].
- Identity
- Use delegated, per-user authorisation so the model inherits the user's entitlements. NetSuite never runs its MCP tools under Administrator or full-access roles, disables Run as role, and stops tools calling Suitelets or making outbound HTTP requests [12]. Mirror that on the other systems with custom least-privilege roles.
- Untrusted content
- Treat record text, email and documents as data, never as instructions. NetSuite's guidance names prompt injection, tool poisoning and tool drift, and asks for clients that fail closed when a policy cannot be enforced [12].
- Writes
- Make writes idempotent on a request ID, run each through schema, business-rule and reconciliation checks, and give every write path a dry-run mode that shows the diff before it lands.
- Limits and quotas
- SAP documents rate limits, quotas and bulk-extraction limits per API [9]. NetSuite's N/llm module allows five concurrent generate calls and five concurrent embed calls, and returns an error beyond that [14]. Queue and back off rather than retrying in a loop.
- Models inside the vendor
- N/llm sends requests to OCI Generative AI, consumes NetSuite AI Units and is available only in certain regions [13]. Copilot in Dynamics 365 runs on Azure OpenAI, and Microsoft says prompts and responses are not used to train OpenAI models, or Microsoft's without a tenant opt-in [6]. Agents built in Copilot Studio can use external models from Anthropic, xAI or Mistral, once an admin turns them on for the environment and allows each provider [15]. Salesforce says prompts and responses sent to third-party models through its Trust Layer are not stored or used for training, and that sensitive data can be masked [2].
- Embeddings
- Protect embeddings like the data they came from. NetSuite's documentation says embeddings carry the source's semantic information and must be stored, logged, retained and deleted under the same rules [13].
- Audit
- Log each run: user, model and prompt version, tool calls and arguments, check results, approver and timestamps. NetSuite logs all MCP tool use [12]; join its logs with your own.
- Portability
- Keep prompts, tool definitions and rules in your repository, and each vendor connector behind one interface, so changing the model or the system is a module change.
Sources
- [1]Salesforce, Agentforce pricing, read 29 September 2026
- [2]Salesforce, Trusted AI and the Einstein Trust Layer, read 29 September 2026
- [3]Salesforce, You have many AI choices: use a platform that works with all of them (3 December 2024), read 29 September 2026
- [4]Salesforce, Salesforce turns enterprise applications into enterprise capabilities (19 August 2026), read 29 September 2026
- [5]Microsoft, Dynamics 365 Sales pricing, read 29 September 2026
- [6]Microsoft Learn, FAQ for Copilot data security and privacy in Dynamics 365 and Power Platform (updated 29 May 2025), read 29 September 2026
- [7]Microsoft Learn, Connect to Dataverse with Model Context Protocol (updated 5 June 2026), read 29 September 2026
- [8]SAP, SAP Business AI software packages and pricing, read 29 September 2026
- [9]SAP, SAP API Policy v.4.2026a (PDF), read 29 September 2026
- [10]Oracle NetSuite documentation, AI Units FAQ, read 29 September 2026
- [11]Oracle NetSuite documentation, Connect to the NetSuite AI Connector Service, read 29 September 2026
- [12]Oracle NetSuite documentation, Associated risks, controls, and mitigation strategies, read 29 September 2026
- [13]Oracle NetSuite documentation, N/llm module, read 29 September 2026
- [14]Oracle NetSuite documentation, Concurrency limits for N/llm methods, read 29 September 2026
- [15]Microsoft Learn, Select a primary AI model for your agent (Copilot Studio, updated 18 September 2026), read 29 September 2026
Frequently asked questions
Is the AI built into Salesforce or Dynamics 365 enough?
For work inside the CRM, often yes: summaries, drafted emails and suggested next steps, all within the permissions a user already has. It stops being enough when a task needs data from other systems, when you need to choose the model, or when per-action pricing at your volumes costs more than running the work yourself.
Can ChatGPT or Claude connect to NetSuite?
Yes. Oracle documents how to connect both through the NetSuite AI Connector Service, which uses the Model Context Protocol, runs with the user's own NetSuite role and cannot be used with an Administrator role. It does not consume NetSuite AI Units. The feature is off by default, so an administrator has to grant the permission and install the tools first.
Can we connect our own AI agent to SAP?
Through SAP's published APIs, within limits. SAP's API Policy, version 4.2026a, prohibits API use by AI systems that plan, select or execute sequences of API calls, except through SAP-endorsed architectures, data services or pathways. Ask SAP which pathway covers your case, and have your legal adviser read your own contract. This is not legal advice.
What does Agentforce cost?
Salesforce's pricing page, read on 29 September 2026, lists Flex Credits at US$500 per 100,000 credits with a standard action using 20, a per-conversation option at US$2, and per-user add-ons from US$125 a month for unmetered employee use. Unused Flex Credits do not roll over to the next term. Prices change, so check the page before you budget.
Does building our own AI layer mean replacing the ERP or CRM?
No. The layer sits beside the systems and uses their published interfaces. The ERP and CRM stay the systems of record: the layer reads from them, proposes changes, and writes back only through checks.
Which route is cheaper?
Neither, in general. The vendor route charges per user, per action or per credit. Your own layer charges per model token plus the engineering to build and run it, and sometimes a vendor fee for access. Price one named workflow at its real volume on both routes before you decide.
Further
- AI integration and automation services · The engagement this guide leads to: AI inside the systems you run, with writes that are checked, traceable and reversible.
- Engagement file D-06 · Finance answers through a connector that carries each person's existing permissions.
- AI agents for business · Where agents fit in a business, and the controls they need first.
- Private LLM · Where the model inside a layer of your own should run.
We build these systems for a living. See the engagement files for what that looks like in practice, or write to us if yours is the next one.
Last reviewed · 1AYM