Skip to content

Should AI Be Allowed to Change Your Business Records?

An AI that reads your business and gets it wrong wastes your time. An AI that writes to your business and gets it wrong corrupts your records. That difference should shape every automation decision you make.

By Karani Geoffrey, Founder & CEO, Upeosoft
In short

AI should be allowed to prepare changes to your records but not to save them unsupervised. The safe pattern is draft, review, approve - with the AI acting only within the user's existing permissions, every action written to an audit trail, and a way to reverse anything. Reading is low risk; writing is where automation becomes an internal control question.

Key takeaways
  • Reading and writing carry completely different levels of risk.
  • A wrong entry spreads through your books and is discovered late, if at all.
  • The safe pattern is draft and approve, not act and notify.
  • AI must inherit the user's permissions, never bypass them.
  • Every automated action needs an audit trail your accountant can follow.
  • If it cannot be reversed, it should not be automated.

The moment every automation project reaches

It arrives in the same way each time. The AI has prepared the purchase order. The order is correct. Everybody in the room can see it is correct. And somebody asks the reasonable question: why not just let it save?

Requiring a human to tap approve feels like ceremony at that moment - friction added for its own sake. The honest answer is that the approval step is not there for the times the AI is right. It is there for the times it is not, and you cannot tell in advance which is which.

That is the whole argument, and it is worth having deliberately rather than by default.

Reading and writing are not the same risk

It is tempting to treat AI capabilities as one category with one risk level. They are not.

When AI reads your data and produces a wrong figure, you look at it, something feels off, you check. The cost is a few minutes. The mistake stays on a screen and never enters your business.

When AI writes and gets it wrong, the mistake becomes part of your records. It flows into stock counts, supplier balances and financial statements. You do not find out when it happens - you find out weeks later when something does not reconcile, and by then you are unpicking which entry was wrong and what else depended on it.

One of those is an inconvenience. The other is the reason an automation project gets switched off and never restarted.

The pattern that keeps automation safe

The working pattern is draft, review, approve - and it is close to how you would treat a capable new employee in their first months.

  • The AI prepares the document in full: lines, quantities, prices, supplier.
  • It shows you what it prepared and, ideally, the reasoning behind it.
  • Nothing is saved to your records until a person with the right authority approves.
  • The approval is recorded against the person who gave it.
  • The action can be reversed cleanly if it turns out to be wrong.
  • Everything outside these defined paths is read-only by design, not by policy.

Permissions are not optional

There is a failure mode that is easy to create by accident: the AI runs with elevated access, so a member of staff who cannot create a purchase order by hand can get the AI to create one for them.

That is not automation. That is a back door around your internal controls, and it is worse than the manual process it replaced because it looks like software rather than like a bypass.

An AI feature should act as the person using it, through the same permission model your system already enforces. If they cannot do it manually, the AI cannot do it on their behalf. This is a straightforward technical requirement and it is worth confirming explicitly with any vendor, because it is not always the default.

The audit trail is for you, not the auditor

Most people think of audit trails as a compliance obligation. They are more useful than that once automation is involved.

A complete trail records what was asked, what the system did, what it produced, and who approved it. That gives you three practical things: your accountant can distinguish AI-prepared entries and see who signed each off; you can trace any odd figure back to its origin; and when something is wrong, correcting it is a lookup rather than an investigation.

It also changes the conversation with your team. When every automated action carries a name against it, nobody is left wondering whether the system did something on its own. Accountability stays with people, which is where it belongs.

The benefit owners do not anticipate

Businesses come to the approval step expecting to tolerate it. What they often report afterwards is that it turned out to be useful for an unexpected reason.

When the system drafts an order and shows its reasoning - this item, this quantity, because it has been selling at this rate and this much cover remains - the approval screen becomes a small regular lesson in the business. Owners start noticing the patterns behind the drafts. Some change their own reorder habits after a few weeks, independently of anything the automation actually did.

An action taken silently teaches nobody anything. An action proposed, explained and approved teaches somebody something every time it happens.

How Upeosoft implements this

We build automation into business systems for Kenyan companies, and our position on write access is consistent: the machine prepares, the person decides.

In the systems we build, every automated action that touches records is drafted for approval, scoped to the user's existing permissions, written to a full audit log, and reversible. We would rather ship a feature that asks one extra question than one that quietly creates a problem you find at year end.

If you are planning automation that will touch your stock, purchasing or financial records, talk to us before it goes live. The controls are much easier to design in than to retrofit after the first bad entry.

Frequently asked questions

Isn't an approval step just friction that defeats the point?

The labour has still been removed - the lookup, the arithmetic, the typing are all done. What remains is the judgement, which takes seconds. You are not doing the work; you are confirming it. That is a very different cost from preparing the document yourself, and it is the difference between a system you supervise and one you hope about.

What could actually go wrong if AI writes directly?

A purchase order created against the wrong supplier. A stock adjustment based on a misread figure. An invoice entry with a transposed quantity. Individually these look small. The problem is that they flow onward into stock counts, supplier balances and accounts, and nobody notices until a reconciliation fails weeks later - at which point you must work out which of hundreds of entries was the fabricated one.

Where does AI writing to records genuinely help?

In preparation. Reading a photographed supplier invoice and drafting the purchase entry saves real time and real typing errors. Proposing a purchase order for an item about to run out, with the quantity worked out from actual sales history, is genuinely useful. In both cases the AI has done the tedious part and left the decision where it belongs.

How does the audit trail help me in practice?

Three ways. Your accountant can see which entries were AI-prepared and who approved each one. You can trace any suspicious figure back to the moment it was created. And when something does go wrong, the fix takes minutes instead of a forensic exercise. It is also increasingly what auditors expect once automation touches financial records.

What should I check before switching on any automation?

Three things. What can it change without asking? Can I see everything it has done? Can I undo it? If the answers are 'nothing', 'yes in full' and 'yes', you can proceed carefully. If any answer is unclear, that is where your risk is, and you should resolve it before the feature is live rather than after.

Karani Geoffrey
Karani Geoffrey
Founder & CEO, Upeosoft

Karani Geoffrey is the Founder & CEO of Upeosoft, a software and automation company rooted in Kenya. He builds custom software, AI systems, and production-grade ERPNext for businesses across East Africa, and writes about the Kenyan realities - eTIMS, M-Pesa, SHIF, unreliable internet and power - that make or break real systems.

Next step

Want this working in your business?

Upeosoft builds and hardens the systems behind this article - for real Kenyan operations, with eTIMS, M-Pesa and offline realities handled.

Keep reading

AI and Automation for Business

AI Agents Explained: What Digital Workers Mean for You

A plain-language explanation of AI agents, how they differ from ordinary chatbots, and where these digital workers genuinely help a Kenyan business.

7 min readRead article →
AI and Automation for Business

Why AI Reporting Tools Give You Wrong Numbers (And How to Tell)

The dangerous failure in AI reporting is not an error message. It is a clean, confident number that happens to be wrong - and here is why it happens so often.

7 min readRead article →
Risk, Continuity and Governance

Business Continuity: Preparing for Disruptions You Can't Predict

You cannot forecast the fire, the flood or the sudden absence, but you can decide in advance how your business survives one. Business continuity is that decision, made while things are calm.

7 min readRead article →