RESOURCES · TECHNICAL
Connecting CMMS, SCADA, MES & ERP — the architecture & the safeguards.
A reference for the IT and engineering teams who have to sign off. How AutomAssist reads each industrial source as it is — protocols, connectors, security model and deployment options — without an ETL rebuild or a migration.
THE MODEL One read-only connector per source, joined by a graph.
Rather than copying everything into a warehouse, AutomAssist places a dedicated, read-only agent on each source and reads it in place. A Knowledge Graph links the entities across sources so a query can travel between them. Nothing is normalised up front; nothing is moved or written without an explicit, audited action.
- Documentsconnectors to SharePoint, Google Drive, OneDrive, NAS and CMMS attachments — text, OCR and schematics indexed with line-level citations.
- CMMS / GMAOAPI or secure database connector (Odoo, SAP PM, Maximo, Carl, Coswin…). Work orders can flow both ways when enabled.
- ERPa secure read-only connector indexes the relevant entities — no ETL rebuild, no schema migration.
- SCADA / PLCOPC-UA and MQTT, plus native SDKs for major vendors, for live tags and alarms — read-only.
- MES & historiansSAP ME, Critical Manufacturing, Aveva; PI, Wonderware, InfluxDB, Timescale — lots, batches, events and time-series.
THE SECURITY MODEL Read-only by default. Your data, your boundary.
- Read-only by defaultagents read; writes (e.g. raising a work order) are explicit and audited, never silent.
- Encrypted & authenticatedconnections are encrypted in transit (TLS) and at rest; each connector authenticates with scoped, read-only credentials — API keys or SSO where available — never shared logins.
- Three deployment modesour isolated SaaS (per-tenant), your own Azure tenant (AKS, MACC-eligible), or fully air-gapped on-premise with a local model.
- Data residencyyour data stays where you decide — it does not have to leave your boundary for the agents to work.
- Traceabilityevery answer cites the document or record it came from; no over-claiming, auditable end to end.
THE CHECKLIST A low-risk integration sequence.
- 01Scope one source + one linestart with the CMMS for a critical line, read-only. Prove value before widening.
- 02Confirm access & protocolAPI key or DB connector for the CMMS/ERP; OPC-UA/MQTT endpoints for SCADA; connector credentials for documents — read-only scopes only.
- 03Choose the deployment boundarySaaS, your Azure tenant, or air-gapped — decide where the data and model run before connecting.
- 04Sync & validate citationsindex the source, then check that answers trace back to the right records — the trust test for the floor.
- 05Extend along the graphadd ERP, SCADA, MES as cross-system questions demand — each new source enriches the graph, no new pipeline.
FAQ What IT asks before sign-off.
- Does our data have to go to your cloud?
- No. You can run AutomAssist in your own Azure tenant or fully air-gapped on-premise with a local model. Your data stays inside your boundary; the agents come to it.
- Is it strictly read-only?
- Read-only by default. Any write — like creating a work order — is an explicit, audited action you enable, not a silent background change.
- Do we need to rebuild ETL or migrate schemas?
- No. AutomAssist reads each source in place through read-only connectors. There is no warehouse to fill and no schema migration.
- Which protocols do you use for SCADA/PLC?
- OPC-UA and MQTT, plus native SDKs for major vendors, for live tags and alarms — all read-only so supervision is never disrupted.
- Who maintains the connectors as our systems change?
- We do. Carrying the connector and tech-watch is part of the service, so your team isn’t maintaining a growing web of point-to-point integrations.
Review the architecture with our team.
Bring your stack and your security requirements — we’ll map the connectors, the boundary and the first source together.
Book a technical demo