RESOURCES · TECHNICAL

Connecting CMMS, SCADA, MES & ERP — the architecture & the safeguards.

A reference for the IT and engineering teams who have to sign off. How AutomAssist reads each industrial source as it is — protocols, connectors, security model and deployment options — without an ETL rebuild or a migration.

THE MODEL One read-only connector per source, joined by a graph.

Rather than copying everything into a warehouse, AutomAssist places a dedicated, read-only agent on each source and reads it in place. A Knowledge Graph links the entities across sources so a query can travel between them. Nothing is normalised up front; nothing is moved or written without an explicit, audited action.

  • Documentsconnectors to SharePoint, Google Drive, OneDrive, NAS and CMMS attachments — text, OCR and schematics indexed with line-level citations.
  • CMMS / GMAOAPI or secure database connector (Odoo, SAP PM, Maximo, Carl, Coswin…). Work orders can flow both ways when enabled.
  • ERPa secure read-only connector indexes the relevant entities — no ETL rebuild, no schema migration.
  • SCADA / PLCOPC-UA and MQTT, plus native SDKs for major vendors, for live tags and alarms — read-only.
  • MES & historiansSAP ME, Critical Manufacturing, Aveva; PI, Wonderware, InfluxDB, Timescale — lots, batches, events and time-series.

THE SECURITY MODEL Read-only by default. Your data, your boundary.

  • Read-only by defaultagents read; writes (e.g. raising a work order) are explicit and audited, never silent.
  • Encrypted & authenticatedconnections are encrypted in transit (TLS) and at rest; each connector authenticates with scoped, read-only credentials — API keys or SSO where available — never shared logins.
  • Three deployment modesour isolated SaaS (per-tenant), your own Azure tenant (AKS, MACC-eligible), or fully air-gapped on-premise with a local model.
  • Data residencyyour data stays where you decide — it does not have to leave your boundary for the agents to work.
  • Traceabilityevery answer cites the document or record it came from; no over-claiming, auditable end to end.

THE CHECKLIST A low-risk integration sequence.

  1. 01Scope one source + one linestart with the CMMS for a critical line, read-only. Prove value before widening.
  2. 02Confirm access & protocolAPI key or DB connector for the CMMS/ERP; OPC-UA/MQTT endpoints for SCADA; connector credentials for documents — read-only scopes only.
  3. 03Choose the deployment boundarySaaS, your Azure tenant, or air-gapped — decide where the data and model run before connecting.
  4. 04Sync & validate citationsindex the source, then check that answers trace back to the right records — the trust test for the floor.
  5. 05Extend along the graphadd ERP, SCADA, MES as cross-system questions demand — each new source enriches the graph, no new pipeline.

FAQ What IT asks before sign-off.

Does our data have to go to your cloud?
No. You can run AutomAssist in your own Azure tenant or fully air-gapped on-premise with a local model. Your data stays inside your boundary; the agents come to it.
Is it strictly read-only?
Read-only by default. Any write — like creating a work order — is an explicit, audited action you enable, not a silent background change.
Do we need to rebuild ETL or migrate schemas?
No. AutomAssist reads each source in place through read-only connectors. There is no warehouse to fill and no schema migration.
Which protocols do you use for SCADA/PLC?
OPC-UA and MQTT, plus native SDKs for major vendors, for live tags and alarms — all read-only so supervision is never disrupted.
Who maintains the connectors as our systems change?
We do. Carrying the connector and tech-watch is part of the service, so your team isn’t maintaining a growing web of point-to-point integrations.

Review the architecture with our team.

Bring your stack and your security requirements — we’ll map the connectors, the boundary and the first source together.

Book a technical demo