Do not give an AI “JDE access.” Give it approved capabilities under a real identity.
Secure JD Edwards AI with explicit user identity, approved MCP tools, existing JDE permissions, optional local models and auditable execution.
The broadest possible AI integration is also the hardest to defend. A safer pattern is to expose only named, reviewed tools and let the underlying JDE or enterprise resource continue to enforce the permissions it already has.
Security principles
- authenticate a real human or deliberate automation identity;
- publish only approved tools;
- keep JDE Orchestration security authoritative;
- record which agent invoked which capability;
- separate read-only investigation from response actions;
- use local models where data residency requires it.
Beyond JDE
Steward can place the same identity and MCP boundary around non-JDE enterprise tools, while BrainStorm can combine JDE and non-JDE capabilities in one session.
Security beyond the ERP boundary
Everest Security extends these same identity, policy, evidence and local-model principles into broader cybersecurity investigation. Steward is the shared gateway layer, and JDE Citizen Developer explains the secure MCP pattern independently.