Visibility ERP + private AI
AI for Visibility ERP: On-Prem AI for ETO Aerospace and Electronics Manufacturers
Short answer
Visibility ERP, Aptean's engineer-to-order and configure-to-order system built on Progress OpenEdge and used heavily in aerospace, defense, and electronics manufacturing, holds exactly the project, configuration, and traceability data that AI works best on. A private model grounded in Visibility's project, contract, and MRP tables answers order status, configuration impact, and shortage questions in plain language, running on infrastructure the company controls so ITAR and export-controlled technical data never has to leave the building.
- ERP
- Visibility ERP
- Industries
- Aerospace, Defense, Electronics, High-Tech
- Written for
- VP Operations
Visibility ERP has built a lasting niche among engineer-to-order and configure-to-order manufacturers, particularly in aerospace, defense, and high-complexity electronics, precisely because it handles project-based manufacturing, configuration management, and government-contract accounting better than most horizontal ERPs. Its customers are frequently small and mid-size suppliers to primes, running Progress OpenEdge under the hood, with a robust advanced planning and scheduling module and deep project and contract structures that a generic ERP would struggle to represent.
That specialization also concentrates a specific kind of pain. Engineer-to-order and defense electronics work means constant configuration changes, contract modifications, and multi-tier component traceability that someone has to track by hand across Visibility's project, engineering, and material screens. A program manager asking which open contracts are affected by a customer-directed engineering change, or a buyer trying to figure out which long-lead components are actually at risk, is doing real analytical work that a grounded AI assistant can do faster without removing the human judgment call at the end.
The regulatory backdrop is unforgiving of shortcuts in a way that matters more here than in most ERP segments. A significant share of Visibility's customer base handles ITAR-controlled technical data, works toward CMMC 2.0 Level 2 for DoD contracts, and is subject to DFARS 252.204-7012 and NIST SP 800-171 controls. Sending program, configuration, or technical data through a public AI API is not a theoretical risk for this customer base, it is a deemed-export and CUI-handling question that a compliance officer has to be able to answer clearly, and 'we do not know where that data went' is not an acceptable answer.
The practical response fits the same architecture that works across this customer base generally: an open-weight model served on infrastructure the company controls, air-gapped where the contract requires it, reads Visibility's project, contract, engineering, and material data through the system's own interfaces, and any write suggestion still goes through a human before it becomes part of the official record. Nothing about adding AI here requires relaxing the technical-data handling discipline these companies already practice.
What usually gets in the way
The problems we hear most from vp operations teams running Visibility ERP.
Engineering and contract change impact is manually tracked
A customer-directed engineering change or contract modification touches multiple open projects, configurations, and material commitments in Visibility, and working out the full impact today is a manual cross-check across several screens by a program manager or engineer.
Long-lead and export-controlled component visibility
Aerospace and defense electronics programs depend on long-lead components that are often themselves export-controlled or single-source, and tracking which open contracts are actually at risk from a specific shortage requires pulling material, purchasing, and project data together manually.
ITAR and CUI handling constrains every tool decision
Any new software touching program, configuration, or technical data has to satisfy ITAR technical data controls and, for DoD-facing suppliers, CMMC 2.0 Level 2 and NIST SP 800-171 requirements, which rules out sending that data to a public AI API without a documented, defensible data flow.
Project-based costing and billing complexity
Government and prime contract accounting inside Visibility, cost-plus, milestone billing, progress payments, involves financial questions that take real expertise to answer quickly, and a small finance team is often stretched thin during proposal or audit season.
Thin bench for a growing security and compliance workload
As CMMC enforcement tightens and more primes flow down security requirements to sub-tier suppliers, the compliance workload on a small Visibility ERP customer grows faster than most companies this size can staff for internally.
Where AI earns its place in Visibility ERP
Each use case names the ERP objects it reads or writes, so your ERP team can judge the integration effort before anyone commits budget.
Engineering change and contract modification impact assessment
Given an engineering change or contract modification, lists the open projects, configurations, and material commitments it affects across Visibility, so a program manager can sequence the change without a manual screen-by-screen check.
Touches: Project and configuration records, engineering change data, contract line items, material requirements
Outcome: cuts the manual impact-check time for a routine engineering or contract change from hours to minutes
Long-lead and shortage risk triage
Surfaces which open contracts and delivery dates are actually at risk from a specific long-lead or single-source component shortage, pulling material, purchasing, and project schedule data together.
Touches: Material requirements, open purchase orders, project schedules, contract delivery dates
Outcome: program managers focus expedite and mitigation effort on the contracts genuinely at risk, not a full manual review
Configuration and traceability lookup
Answers where-used and configuration history questions on a specific serialized component or assembly, referencing Visibility's configuration management and traceability records.
Touches: Configuration management records, serial and lot tracking, BOM where-used data
Outcome: cuts configuration and traceability research from a manual multi-screen trace to a direct, sourced answer
Purchase order and supplier follow-up drafting
Drafts routine follow-up on open purchase orders approaching or past their promise date, for a buyer to review and send, escalating only genuine delivery risks to a program's schedule.
Touches: Open purchase order records, vendor master, promise dates, project schedules
Outcome: buyers spend follow-up time on delays that actually threaten a program schedule, not routine status chasing
MRP and APS exception triage
Surfaces which materials or work orders need planner attention today across MRP and advanced planning and scheduling exception lists, instead of a planner reviewing every line manually.
Touches: MRP action messages, APS schedule exceptions, planned order records
Outcome: planners resolve the daily exception list in a fraction of the time spent on a manual review
Export control and technical data access review support
Helps a compliance officer review who has access to export-controlled technical data and project records in Visibility against who should hold that access, flagging discrepancies for human review.
Touches: User role and permission assignments, project and document classification metadata
Outcome: a faster, more consistent periodic access review that a small compliance team can keep up with as CMMC obligations tighten
Natural-language questions across project, engineering, and material data
Lets a program manager or finance lead ask a question once, such as which programs have open material commitments against a delayed shipment, and get an answer grounded in Visibility's actual data without knowing the table structure.
Touches: Project, engineering, material, and finance data accessed through read-only interfaces
Outcome: fewer one-off status questions land on program management or finance staff as manual lookups
Reference architecture
The architecture keeps program, configuration, and technical data inside a boundary the company controls, air-gapped where the contract requires it, and reads Visibility's project, engineering, and material data through the system's own interfaces rather than a public AI service.
- 1
Visibility ERP connector
Read-only access to project, contract, engineering/configuration, material, and purchasing data through Visibility's database and integration layer, isolated from any direct write path into production.
- 2
Data and semantic layer
A unified view mapping project, configuration, and material terminology across Visibility's modules, plus a document index over specifications, drawings metadata, and quality procedures where applicable.
- 3
Model serving
An open-weight model (Llama, Qwen, Mistral, or Gemma class) served with vLLM or Ollama on GPUs the company owns, air-gapped where contract terms require it, with no default outbound path to an external API.
- 4
Retrieval and agents
Retrieval-augmented generation grounds answers in current project, engineering, and material data; any agent proposing a write, such as a draft supplier follow-up, stops for human review before anything is recorded.
- 5
Governance and audit
Every query and response is logged against the user's role, giving compliance and program management a documented trail supporting CMMC, DFARS 7012, and customer security reviews.
Integration notes for your ERP team
- Connects to Visibility ERP's Progress OpenEdge database and integration layer for project, contract, engineering, and material data, read-only by default.
- Any write-back action, such as a finalized supplier follow-up or an updated project note, goes through Visibility's own interfaces rather than direct database writes, preserving built-in validation.
- Document sources such as specifications, work instructions, and quality procedures are indexed inside the same boundary as the ERP data, not in an external SaaS document tool.
- A shared identity layer maps each user's existing Visibility ERP role to what the assistant can see, so access never exceeds what the user could already see directly in the system.
- For air-gapped deployments, model updates and any document reindexing follow the same controlled change process already used for other software inside the secure boundary.
- SSO via the company's existing identity provider where available, so users authenticate the same way they do for Visibility ERP today.
Deployment options
Air-gapped on-prem
Suppliers handling ITAR-controlled technical data or CUI under a CMMC-scoped contract
The model, retrieval index, and connectors run entirely inside the company's own network with no outbound internet path, giving the clearest possible answer when a prime or DoD contracting officer asks where technical data is processed.
Private, non-shared cloud instance
Suppliers without in-house GPU capacity whose contracts do not require full air-gapping but do require documented data handling
A dedicated instance outside any shared multi-tenant infrastructure, giving a defensible answer on data location and access without the capital cost of owning GPU hardware.
Hybrid across commercial and defense programs
Suppliers running both commercial aerospace or electronics work and defense-contracted programs on the same Visibility ERP instance
Air-gapped processing for CUI-scoped programs, a private cloud instance for commercial work, with one governance layer giving program management a consistent experience across both.
Compliance and data control
How the architecture supports your obligations. Certification and accountability stay with your organisation; the design keeps the evidence straightforward.
ITAR technical data controls
Keeping the model and its data entirely on infrastructure the company controls, with no default call to a public AI API, avoids the deemed-export risk that arises when technical data is sent to a model hosted or operated by a foreign person or outside the company's control.
CMMC 2.0 Level 2 / DFARS 252.204-7012 / NIST SP 800-171
The assistant operates inside the same security boundary and access controls the company already maintains for CUI, with logging that supports the documentation a CMMC assessment or DFARS 7012 review would expect.
Export control and technical data access reviews
Access to controlled technical data through the assistant mirrors Visibility's own role-based restrictions, supporting the periodic access reviews export compliance already requires rather than creating a new, broader access path.
AS9100 traceability (where applicable)
Configuration and lot traceability queries are grounded directly in Visibility's own records, so the audit trail on an AI-assisted answer is reviewable by the same internal and external auditors who check AS9100 conformance today.
Where Netray fits
Custom build
Visibility ERP's project, configuration, and contract structures are specific enough that engineering change impact assessment and long-lead shortage triage need a purpose-built connector and workflow logic rather than a generic ERP integration.
DataRay
Specifications, drawings metadata, and quality procedures that sit outside Visibility ERP as file shares or a document store can be indexed and searched alongside project and material data using the same on-prem, air-gap-capable approach.
How an engagement runs
Phase 1 . 2-3 weeks
Discovery
- -Inventory of Visibility ERP modules in use, including APS, project accounting, and configuration management
- -Review of ITAR, CMMC, and DFARS 7012 scope for the planned use cases
- -Use case shortlist ranked by effort and time saved for program management, planning, and compliance staff
- -Air-gapped or private-instance GPU sizing estimate
Phase 2 . 6-8 weeks
Pilot
- -One use case live in read-only or draft-only mode with a defined user group
- -Model evaluation against real project, engineering, and material data
- -Draft data flow documentation reviewed against ITAR and CMMC requirements
- -User feedback loop with program managers, planners, and buyers
Phase 3 . 6-10 weeks
Production
- -Hardened deployment with role-based access tied to existing Visibility ERP roles
- -Full audit logging available for CMMC assessment and customer security reviews
- -Signed-off data flow documentation supporting DFARS 7012 and NIST SP 800-171 controls
- -Runbook covering model updates, monitoring, and incident response inside the secure boundary
Phase 4 . Ongoing
Scale
- -Additional use cases added from the original shortlist based on pilot results
- -Rollout to additional programs or business units under the hybrid model where relevant
- -Refresher briefings for compliance and program management stakeholders
- -Quarterly review of model performance and any newer open-weight model worth evaluating
Questions to ask any vendor, including us
A short list that separates real Visibility ERP AI work from a chatbot demo.
- Where does the model physically run, and can that be confirmed for a CMMC assessment or a prime's security review?
- Does any part of the pipeline call a non-domestic or third-party API by default, including for a secondary function like embeddings?
- Can the assistant's access be scoped to match our existing Visibility ERP roles and export control access reviews?
- How does a draft write action, such as a supplier follow-up, reach a human for approval before anything is recorded?
- Can we export the full query and response log for a DFARS 7012 or CMMC audit?
- What is the fallback if the air-gapped system or private instance is unavailable during a program deadline?
- What happens to our data, model, and configuration if we end the engagement?
- Has this been deployed against Visibility ERP's Progress OpenEdge database specifically, or only against a generic ERP schema?
Frequently asked questions
Does Aptean offer AI directly for Visibility ERP?
Aptean's visible AI investment is concentrated in its newer cloud platforms rather than Visibility ERP specifically. Visibility ERP customers wanting AI value now generally add a private layer grounded in their existing Progress OpenEdge database rather than waiting on a vendor-native feature for this product.
Can AI touch ITAR-controlled technical data without creating an export risk?
Yes, provided the model and the data it processes never leave infrastructure the company controls, whether that is fully air-gapped or a private, non-shared instance, and there is no default call to a public AI API. That keeps the AI layer inside the same boundary the company already uses to control ITAR technical data, rather than introducing a new export question.
Does this help with CMMC 2.0 Level 2 compliance?
Yes, indirectly. The assistant's access controls and logging are designed to sit inside the same CUI boundary and security practices a CMMC Level 2 assessment already checks, giving compliance staff documentation to support an assessment rather than a separate, unreviewed AI tool outside that boundary.
Is this realistic for a small sub-tier supplier, not just a large prime?
Yes, the deployment scales down cleanly. A smaller Visibility ERP customer can run a modest on-prem or air-gapped setup, or a small private instance, with the same architecture principles applying regardless of company size. The scope should start with one or two use cases with a clear before and after.
How is this different from a generic AI chatbot layered onto Visibility ERP?
A generic chatbot typically calls a public model API and has no structured understanding of Visibility's project, configuration, or contract data model. This approach grounds every answer in the operator's actual project and material records through retrieval, shows the source records behind an answer, and keeps processing inside a boundary the company controls.
What is the realistic first use case for a Visibility ERP customer?
Engineering change impact assessment and long-lead shortage risk triage tend to show value fastest, since both are frequent, well-defined tasks with a clear existing manual process the assistant speeds up. Configuration and traceability lookup is a strong second use case once configuration management data is well indexed.
Does Visibility ERP's Progress OpenEdge database make this harder to integrate than a SQL Server-based ERP?
It requires the right connector, but it is not a barrier. Progress OpenEdge is a well-understood database platform, and read-only access through its own interfaces works the same way structurally as it would against SQL Server or Oracle, provided the integration is built by people who know the platform.
Related guides
ITAR-Compliant AI for ERP Technical Data
How to add generative AI to your ERP without creating a deemed export under ITAR. On-prem architecture patterns an Empowered Official can sign off on.
AS9100D + on-prem AIAI for AS9100 Quality Management on Your ERP
AI on top of your ERP quality module for AS9100D suppliers: NCR/CAPA drafting, FAI support, counterfeit parts screening, with a full audit trail.
On-prem AI, any ERP, A&DOn-Prem AI for ERP in Aerospace, Defense, and Electronics Manufacturing
A hub guide to on-prem AI across SAP, Infor LN, Costpoint, IFS, and Oracle EBS for aerospace, defense, and electronics manufacturers under ITAR, CMMC, and AS9100.
CMMC 2.0 + on-prem AICMMC Level 2 AI for ERP Without Blowing Up Your Scope
How to deploy AI inside your CMMC 2.0 Level 2 assessment boundary without expanding CUI scope. Enclave architecture a CISO can defend to a C3PAO.
Ask your ERP anythingNatural Language Query for ERP Data: Ask SAP, Infor, or Oracle a Question in Plain English
See how natural language query over SAP, Infor, Oracle, and NetSuite data works: grounded text-to-SQL, role-based permissions, and a visible audit trail.
QAD + on-prem AIAI for QAD Adaptive ERP in automotive and industrial manufacturing
Add AI to QAD Adaptive ERP or Enterprise Edition for automotive and industrial manufacturing, grounded on QXtend and QAD's API layer, on-prem or private cloud.
Plan it with numbers
ITAR AI Workload Compliance Assessment
Score your AI deployments across eight dimensions of ITAR exposure, from technical data classification and US persons access control to technology control plan coverage.
Free ToolCMMC 2.0 Level 2 Readiness Assessment
Answer 10 questions mapped to NIST SP 800-171 control families and get an instant CMMC Level 2 readiness score with prioritized next steps.
Free ToolDefense Contractor AI Readiness Assessment
A 9-question assessment measuring whether your defense manufacturing business can adopt AI productively and compliantly - across governance, data, infrastructure, and skills.
GuideEngineer-to-Order ERP Challenges and Solutions
Solve ERP challenges unique to engineer-to-order manufacturing. Project costing, dynamic BOMs, engineering integration, and progress billing solutions.
GuideITAR and CMMC Handling of AI Workloads
How ITAR and CMMC apply to AI workloads: technical data boundaries, CUI handling, assessed environments, and where on-prem AI is the only option.
GuideOn-Prem AI for Defense Contractors: The Complete Guide
On-prem AI for defense contractors: deploy LLMs and AI agents inside your CMMC and ITAR boundary. Architecture, hardware costs, timelines, and vendor options.
Talk it through with an engineer who knows Visibility ERP
Bring one real question your team cannot answer from the ERP today. We will map the data path, the model, and where it runs, and tell you honestly if AI is the wrong tool for it.