Microsoft made Dynamics agent-ready. It didn't make your agents work.
We build the retrieval, workflows and agents that run inside your Dynamics transaction layer — then we operate them. With an accuracy number, a run cost, and a name on the pager.
Trusted by leading enterprises and healthcare teams
The integration problem is solved. The delivery problem isn't.
Wave 1 2026 turned Dynamics 365 into an agent-addressable system. Agents now operate inside the transaction layer using the same data models, rules, permissions and audit trails as any user. Business Central shipped MCP support. Dataverse exposes plug-ins as MCP servers. The custom-API layer that used to justify six-figure integration scopes has been absorbed into the platform.
Which means the interesting question is no longer can AI reach my Dynamics data. It is: does the agent retrieve the right record, does it stop when it should, what does it cost per transaction, and who fixes it at 2am when the vendor master changes.
Those are delivery and operations questions. They are not answered by a platform licence, and they are not answered by a proof of concept.
One idea, three layers
Everything below this point is a detail of this diagram.
The three layers of AI on Dynamics 365. Layer 1 is now platform. Layers 2 and 3 are ours.
What CheiAI delivers on Dynamics
Most engagements need all three. We scope them as a single system with one data contract and one governance model — not as three separate projects that meet for the first time in production.
RAG grounded in your Dynamics estate
Answers sourced from your actual records, not the model's memory. We index across the structured and unstructured halves of the estate and keep permissions intact end to end.
- Dataverse tables, Finance & Operations entities, custom fields and legacy taxonomies
- SharePoint attachments, contracts, email trails and scanned documents via DocuFindr
- Row-level and field-level security honoured at retrieval time — no shadow index that leaks
- Citation back to the source record, so a reviewer can verify in one click
- Retrieval evaluation set built from your own historical queries before anything ships
AI workflows that accelerate what already runs
We don't replace your Dynamics processes. We take the steps that stall them — reading, matching, classifying, drafting, chasing — and move those into an orchestrated pipeline.
- Deterministic steps stay deterministic; only the judgement steps use a model
- Copilot Studio and Power Automate orchestration, extended where the standard surface stops
- Human approval gates on every state change that touches money, compliance or a customer
- Confidence thresholds tuned per step, with defined fall-through to a person
- Full audit trail written back into Dynamics, not into a side system
Agents that transact, under guardrails you set
Agents that act inside the Dynamics transaction layer via MCP — same permissions, same rules, same audit trail as a user. Scoped tightly, monitored continuously, reversible by design.
- MCP-native so the agent survives platform updates instead of breaking on them
- Thresholds and approval rules defined up front and visible to approvers before anything posts
- Multi-agent orchestration where a process genuinely spans functions — not for show
- Registered in Microsoft Agent 365 so IT sees inventory, permissions and behaviour in one place
- Credit consumption metered per workflow before scale-up, so procurement gets a real number
Where this lands in a live Dynamics estate
The pattern that works is narrow and high-frequency: one process, high volume, clear success criteria, a human in the loop at the point of consequence. Start there, prove the number, then widen.
| Dynamics module | The step that stalls it | What CheiAI puts in place | What gets measured |
|---|---|---|---|
| Sales | Reps re-researching accounts and rebuilding context before every call | Retrieval agent that assembles account history, open service issues and prior pricing from Dataverse and email into a pre-call brief | Time to first meaningful contact; brief accuracy against reviewer spot-check |
| Customer Service | Case triage, duplicate detection and knowledge lookup on every inbound | Classification and routing workflow with grounded draft response; escalation on low confidence | Time to first response; routing accuracy; deflection without CSAT loss |
| Finance | Invoice-to-PO matching, exception chasing and vendor payment enquiries | Matching workflow with agent-driven exception triage; vendor enquiry agent answering from ledger state | Straight-through match rate; days to close exceptions; enquiry volume absorbed |
| Supply Chain | Supplier follow-up, delivery confirmation and disruption triage | Supplier communication agent that confirms, chases and flags — writing status back to the order | Confirmation cycle time; percentage of late signals caught before impact |
| Field Service | Work order write-up, parts lookup and handover documentation | Retrieval-backed drafting from technician notes, with asset and manual grounding | Documentation completeness; technician admin time per job |
| Project Operations | Time-entry approvals and change orders stalling billing prep and month-end | Approvals workflow clearing routine entries under threshold; change orders assembled for review | Approval cycle time; days to billing-ready; month-end close duration |
Sector-specific patterns — pre-denial validation and prior-authorisation in healthcare, screening and regulatory workflows in fintech — are built on the same three layers.
Built on your Microsoft stack, not beside it
No parallel data platform. No copy of your CRM in someone else's vector store. The agent runs where your governance already runs.
Where agents on Dynamics break — and what catches it
In an ERP context, 99% accuracy is a failure, not a headline. These are the failure modes we design against before we write a line of orchestration.
Retrieval returns the plausible record, not the right one
Near-duplicate accounts, superseded contracts, closed-but-similar cases. Caught by an evaluation set built from your own historical queries, plus mandatory citation to the source record.
Permissions leak through the index
A retrieval layer that ignores row-level security will surface data a user cannot open in the app. Caught by enforcing security at query time and testing with deliberately restricted personas.
The agent acts confidently on an edge case
Unusual but legitimate transactions look like errors to a model. Caught by confidence thresholds with defined fall-through to a named human, not a generic queue.
Credit consumption outruns the business case
A single business event can trigger dozens of model-backed steps. Caught by metering the heaviest workflow — not the average — before scale-up, and reporting cost per transaction monthly.
Silent drift after a data or process change
A renamed field or new vendor category degrades accuracy without throwing an error. Caught by continuous evaluation against a held-out set and alerting on accuracy decay, not just on exceptions.
Agent sprawl with nobody accountable
Five agents built by five teams, none reviewed. Caught by registering every agent in Agent 365 with a named owner, a defined scope and a review cadence from day one.
Delivered, then operated
Most vendors in this market end at go-live. That is the point where the work actually starts.
Weeks 1–2
Select one high-frequency process. Map the current Dynamics flow, the data it touches and the decision points. Build the evaluation set from historical cases. Agree the success metric and the run-cost ceiling before anything is built.
Weeks 3–6
Build retrieval, workflow and agent in your environment. Run against live volume with approval gates on every consequential step. Publish accuracy against the evaluation set and measured credit consumption at real volume.
Ongoing
We run it. Continuous evaluation, drift monitoring, exception review, threshold tuning, cost reporting. Monthly report covering accuracy, volume absorbed, exceptions escalated and cost per transaction.
What you own at the end
Everything. The agents run in your tenant, on your licences, under your governance. The evaluation harness, the prompts, the workflow definitions and the documentation are yours. We are not building a dependency — we are building an asset you could take in-house, and we will help you do that if it is the right call.
What we won't do
We won't rebuild a process that Microsoft's first-party agents already handle well — we will tell you to use those and scope around them. We won't ship an agent without an evaluation set. We won't quote a fixed price on a process nobody has measured. And we won't publish a client metric we haven't been given permission to publish.
CheiAI on Dynamics, answered.
Common questions about building and operating AI on Microsoft Dynamics 365.
