Automating an ERP with AI: what actually attaches to a WinLine system
Talking about AI on an ERP is easy as long as the question is whether something could be attached to it. The second question is harder: what should the system be allowed to do? That second question decides the project. I split this into three levels. The first one runs at our place with seven read tools, the second is described for incoming invoices in an earlier post, and the third consists of exactly one write tool.

Level 1: asking questions, with read rights
An agent gets curated questions and a database access that permits reading only. That saves minutes per transaction and adds up anyway. The tool catalog of our agent environment contained seven tools on 01 October 2026: resolve a customer by name, translate customer article numbers, order and invoice status per customer, lost articles year over year, customers whose revenue fell away, a quote check that shows where we quoted and did not get the order, and a multi-year comparison per article.
All seven only read. Writing runs through a separate path, on our side a single tool for one field change in the item master, deliberately kept out of that same list.
Level 2: the model proposes, a person books
An incoming document arrives as a PDF, a model reads it, and a booking proposal lands in a queue. Approval happens afterwards. In one publication on document extraction (preprint of 22 October 2025, no peer review) the same documents produced 94 percent overall field accuracy and 5 percent math-validation errors on the model path, against 63 and 20 percent on the classic route through layout and OCR. A person decides in both cases, and those 5 percent are the reason approval should not be built as a formality.
Level 3: the agent acts
An agent posts entries, sends reminders, or places orders. From here it stops being a technology question: a booking needs an audit trail, and a customer reads an unjustified reminder. One rule from the AI Act is useful as a design constraint here, in force since 02 August 2026: systems that speak to people directly have to identify themselves as such. Anyone building such an agent should document the approval position in the same breath.
Why the path leads through the database
WinLine is an ERP from Austria, founded in 1978, with around 10,000 customers and more than 65,000 licensed installations according to the vendor; the company is registered in the Vienna commercial register as mesonic datenverarbeitung ges.m.b.h. under FN 103141d. The help documentation the vendor keeps publicly available belongs to Edition 2026, version 12.34. It documents a form editor, background processes, a monitor and an audit trail. It does not document an API, REST or a web service, and we looked for an MCP or agent connection three ways: in the help, in the search function, and with the vendor. Neither exists.
That is a decision, not a defect. An ERP of this class is built for people working through masked screens, and integration runs through reports, background processes and partner add-ons. Anyone who wants to attach an agent has to attach it at the database. That is Microsoft SQL Server, and the maintained way up from there runs through Data API builder and its SQL MCP server.
Microsoft's design decision there is the most interesting sentence in this whole story: the documentation explicitly does not support NL2SQL, translating a question into a query, because models do not produce deterministic results. Instead a JSON file defines which tables, views and procedures are released and which rights apply per object. The agent receives seven tools, among them read_records and aggregate_records, and a disabled tool disappears from the tool catalog instead of merely being rejected. One further warning in the documentation concerns exactly the mistake everyone warns about: without field descriptions in the entity model, agents guess column names. Curated views with description text beat raw tables.
Read-only is a property of the database
Model Context Protocol currently carries the version number 2026-07-28 and is, per its own site, a project of LF Projects, LLC. The specification contains one sentence everyone offering a database connection as a tool should read: the tool properties readOnlyHint and destructiveHint are hints without any guarantee, and a client should never base a tool decision on hints from an untrusted source. A few lines further down sits the requirement that a human stays in the decision path and must be able to decline a tool call.
In one line of SQL that means: the login for agents gets db_datareader and nothing else, plus a timeout and a row limit. The reason is not distrust of the model but an operational failure that sits open in an issue tracker: without a timeout a query keeps running indefinitely and slows down the ERP's SQL Server. The dbhub server (MIT, 37 contributors, v1.4.0 dated 28 September 2026) ships read mode, row limit and timeout as a feature. On mssql_mcp_server (MIT) the timeout and read-only questions have been open for months, and the last movement in the repository was November 2025. Of three projects we put through an adoption test, one held up. On the driver side the picture has been clear since September 2026: mssql-python from Microsoft is described by the project as production-ready in version 1.15.0 of 11 September 2026, and pyodbc 5.3.0 has been running alongside it for years.
What the vendor already has, and what it does not deliver
WinLine AIDA is the AI feature mesonic markets, with document recognition, account coding proposals inside the document, monitoring of open items and order suggestions. The same page states the mechanics: the system calls Gemini, ChatGPT or Claude, the customer supplies the key for that service, and availability is listed as expected from autumn 2026, meaning not deliverable on 01 October 2026. A data movement into a cloud has to be known in the process, otherwise it hangs in every answer later.
Two figures from official surveys frame the demand. The survey on ICT usage in enterprises 2025 (fieldwork February to July 2025, enterprises with ten or more employees) underlies the Chamber of Commerce analysis of November 2025: just under 56 percent of Austrian enterprises implement AI in 2025 by buying commercial software, more than 20 percent through external providers, 31 percent adapt commercial software with their own staff, and more than 17 percent develop in house. A third is therefore adapting with their own people, a fifth buys the competence outside. Just above that: a media report of 24 June 2026 on the same official data, with 30 percent AI use in Austria against 20 percent across the EU, and 77 percent of Austrian non-users having never considered AI.
One note on data quality from the audit side: a KPMG report on AI in finance ERP systems names poor data quality and stale inventories as the first risk, leading to wrong forecasts and audit findings, with data governance, audit trails and monitoring as the countermeasure. An AI project on an ERP with an untidy item master is a data quality project with extra work attached.
Four points before anyone writes a line of code
- One process with a measurable size: document throughput, quote after follow-up, dunning run. "We want AI" is not an assignment.
- A dedicated read user with
db_datareader, a timeout and a row limit. No shared administrator account. - Ten reference cases where the correct result is known. An answer that reproduces no known result is not an answer.
- An approval position that can genuinely decline, and a place where the generated query is stored. Otherwise the same result is a different result twice.
If you want this done for your ERP, I do it: contact. The start is one hour with a read user, one process and those four points.
Further sources
- WinLine AIDA, vendor page on the AI features: https://d.mesonic.com/winline-aida (accessed 01 October 2026)
- WinLine help, overview of Edition 2026: https://www.mesonic.com/cwlhelp/WordDocuments/winlinehilfe.htm (accessed 01 October 2026)
- Austrian commercial register, mesonic datenverarbeitung ges.m.b.h., FN 103141d: https://www.evi.gv.at/f/103141d (accessed 01 October 2026)
- Microsoft SQL MCP server based on Data API builder: https://learn.microsoft.com/en-us/azure/data-api-builder/mcp/overview (updated May 2026)
- Tools of the SQL MCP server, including the per-tool switch: https://learn.microsoft.com/en-us/azure/data-api-builder/mcp/data-manipulation-language-tools (updated June 2026)
- What field and entity descriptions change in the agents answers: https://learn.microsoft.com/en-us/azure/data-api-builder/mcp/how-to-add-descriptions (accessed 01 October 2026)
- Model Context Protocol, version status and the advisory character of tool annotations: https://modelcontextprotocol.io/specification/versioning (accessed 01 October 2026)
- dbhub, database MCP server with read mode and timeout: https://github.com/bytebase/dbhub (as of 01 October 2026)
- mssql_mcp_server, open issue state on timeout and read-only: https://github.com/RichardHan/mssql_mcp_server (as of 01 October 2026)
- mssql-python, the Microsoft driver: https://pypi.org/project/mssql-python/ (version 1.15.0, 11 September 2026)
- Document extraction, measurement of two paths (preprint): https://arxiv.org/abs/2510.15727 (22 October 2025)
- KPMG, risk picture for AI in finance ERP systems: https://kpmg.com/kpmg-us/content/dam/kpmg/frv/pdf/2026/ai-driven-erp-systems-in-finance.pdf
- Austrian Chamber of Commerce, AI implementation 2025 based on the ICT survey: https://www.wko.at/statistik/wgraf/2025-35-ikt-ki-2025.pdf (November 2025)
- Statistik Austria, ICT usage in enterprises 2025: https://www.statistik.at/statistiken/forschung-innovation-digitalisierung/digitale-wirtschaft-und-gesellschaft/ikt-einsatz-in-unternehmen
- Der Standard on 30 percent AI use in Austria against 20 percent EU-wide: https://www.derstandard.at/story/3000000328634/oesterreichs-unternehmen-bei-ki-nutzung-im-eu-spitzenfeld (24 June 2026)
- EU AI Act timeline including the shifts from the Digital Omnibus: https://artificialintelligenceact.eu/implementation-timeline/ (as of 31 August 2026)
Does our ERP vendor have to ship an interface for this?+
No, and mesonic WinLine does not currently offer one. The help documentation for Edition 2026 (version 12.34) documents no API, no REST and no web service, and searching for an MCP connection comes back empty. The access path that works is the database, with a dedicated read user and a thin tool layer in front of it. The vendor does sell its own AI feature, WinLine AIDA, which calls Gemini, ChatGPT or Claude with the customer's own key and is described on the vendor page as expected from autumn 2026.
Isn't a language model on my ERP database a security problem?+
In the common pattern, yes: the model writes the query itself and the database user can do everything, because the prompt says it should only read. A tool description marked as read-only is, per specification, a hint with no guarantee. Read-only has to be enforced by the database itself, as db_datareader without write rights, plus a query timeout and a row limit.
What does a project like this cost and how long does it take?+
The technical part is small: one read user, an MCP server or Data API builder, and half a dozen approved views. The effort goes into defining the metrics, master data quality, and deciding who signs off a result. A sensible start is one process with a measurable size and ten reference cases where the correct answer is already known.
senn-tech