Skip to Content

PMIS AI Browser Operator

Bring AI-assisted work into Odoo—without bypassing Odoo security

PMIS AI Browser Operator helps organizations explore AI-assisted business work through the familiar Odoo interface.

Authorized employees submit instructions through dedicated Odoo Discuss conversations. An external AI browser operator receives those instructions and works through the standard Odoo web interface using its own dedicated account—much like a digital member of the team.

The result is a controlled and visible way to delegate work while keeping people, permissions, and accountability at the center.

Built for Odoo 18 Community, the addon currently supports supervised pilot projects.

Familiar for business users, controlled by your organization

Your team decides:

  • Who may submit instructions
  • Which conversations are authorized
  • What business information the bot can access
  • Which Odoo operations its account may perform
  • Which actions require confirmation or must be refused

The requester does not lend their permissions to the bot. The browser operator can only use the access granted to its dedicated Odoo account.

If Odoo prevents that account from seeing a record or completing an operation, the AI must stop and report the limitation. It cannot switch users, inherit the requester’s privileges, or bypass the normal workflow.

Potential pilot activities include:

  • Looking up business information
  • Preparing draft quotations or other records
  • Updating permitted business data
  • Creating activities or notes
  • Supporting routine work through existing Odoo screens

What is feasible depends on the installed applications, configured workflows, bot permissions, company access, and capabilities of the external browser operator.

A visible workflow from request to result

Each command follows a clear sequence:

  1. Request
    An authorized employee sends an instruction in a configured one-to-one Odoo Discuss conversation with the bot.
  2. Validate
    The addon verifies the requester, conversation, participants, and message origin. It then preserves the authorized instruction.
  3. Claim
    The assigned bot opens its queue and claims the command. Authorization and source-message integrity are checked again before work starts.
  4. Execute
    The external operator performs the task through Odoo’s normal interface. It can return to the originating Discuss conversation to communicate with the requester.
  5. Report
    The bot records progress and the reported outcome, then completes or fails the work. It can reject unsuitable pending commands, while active work can be canceled with a recorded reason.

The queue gives operators and managers a shared view of delegated work without turning the addon itself into an execution engine.

Clear oversight for managers

Pending and in-progress commands are presented in kanban and list views, with oldest-first ordering and explanations when a command is no longer eligible for execution.

Managers can:

  • Inspect captured instructions and their origin
  • Review progress, results, and lifecycle history
  • Add separate administrative observations
  • Cancel active commands with a required reason
  • See who performed each recorded intervention

Manager oversight remains separate from bot execution. Managers cannot impersonate another bot, perform its execution transitions, or overwrite its operational results.

Terminal commands and audit events are protected against modification and deletion through normal use of the addon, preserving a dependable application-level history.

Security responsibilities remain separate

The architecture deliberately separates three questions:

Who may issue a command?

The addon validates the exact combination of authorized requester and one-to-one Discuss conversation.

What may the bot do?

Odoo’s access rights, record rules, allowed companies, and business workflows govern the dedicated bot account. Requester permissions do not elevate it.

What should the AI do?

The external operator’s policy determines which permitted actions may be automatic, which require human confirmation, and which must be refused.

A valid command is therefore not unlimited authority. Work may proceed only where command authorization, bot access, and AI operating policy all allow it.

Designed to treat business content as data—not instructions

The authorized command is preserved with its provenance and a SHA-256 content identifier.

Other content encountered while browsing—including attachments, chatter, emails, linked pages, product descriptions, notes, and business records—does not become an authorized command through this module.

Maintaining that distinction is essential for reducing prompt-injection risk and preventing ordinary business content from silently expanding the operator’s assignment.

Technical foundation

The addon provides:

  • Bot-user configuration
  • Authorized requester and direct-chat configuration
  • Verified Discuss command capture
  • Preserved instruction snapshots and provenance
  • Stable SHA-256 content identification
  • Individual concurrency-safe command claiming
  • Execution-eligibility checks and explanations
  • Bot-specific command queues
  • Audited progress and result reporting
  • Separate manager observations
  • Reasoned administrative cancellation
  • Protected terminal history

Operators are restricted to their own queues. Trusted managers can inspect commands across configured bots, but this does not grant general access to private Discuss history or additional business permissions.

Deliberately separate from the AI platform

PMIS AI Browser Operator does not contain:

  • An AI model or provider integration
  • A browser automation engine
  • A generic ORM execution interface
  • Business-action automation
  • Requester impersonation
  • Privilege elevation

The AI model and browser environment are supplied separately and authenticated in Odoo as the dedicated bot user.

This separation allows organizations to evaluate different browser-capable AI platforms without moving Odoo command authority or business security into the AI integration itself.

Start with a supervised pilot

Begin with a dedicated internal bot user, carefully selected business permissions, a small number of authorized requesters, and clearly designated command conversations.

During the current pilot phase, every eligible text message from an authorized requester becomes a separate command—including acknowledgments and follow-up questions. Authorized chats should therefore be reserved for complete, standalone instructions. Saved progress notes are separate from Discuss replies.

The current version does not include scheduling, worker leases, abandoned-task recovery, built-in confirmation workflows, or automatic verification of business outcomes.

Completion records the operator’s reported result. Cancellation changes the queue state, but it cannot interrupt an external browser or undo business changes already performed.

PMIS AI Browser Operator is designed for organizations that want to explore practical AI assistance in Odoo while retaining human oversight, established access controls, and a clear record of delegated work.

PMIVerse Multi-Agent Harness (What it is)
Making AI Software Development Safer, More Controlled and More Trustworthy