FlowplaneBook a pilot
Blog
CompanyZero trust tunnel, Unified MCP endpoint, Watchtower

An open RDP port, a Copilot with a service account, and an auditor with two questions.

Acme NV runs an ERP on a Windows server and 340 people on Microsoft 365. The NIS2 audit asked who can reach the ERP and which AI has access to what. This is how those two questions got a CSV for an answer.

Acme NV makes industrial filters, employs 340 people, and runs an ERP on a Windows server that its vendor maintains over RDP. Sales lives in Salesforce, everything else in Microsoft 365. In spring 2026 the CyberFundamentals assessor asked two questions the IT manager could not answer: who reached the ERP last quarter, and which AI systems have access to what.

Before

people

  • Port 3389 open to the internet so the vendor could do maintenance. No MFA, no session log.
  • A VPN for staff that landed on the same subnet as the ERP, the file server and the badge system.
  • Seventeen integrations found during the audit, none inventoried, four belonging to people who had left.

AI

  • Sales had wired Copilot to Salesforce through a shared service account. Every rep's agent could read every account.
  • Finance was piloting an agent against the ERP's REST API with a key from the vendor's admin user.
  • Nobody could say which agent had read which customer record, because nothing wrote it down.

What changed

The ERP behind the tunnel. A connector next to the server. Port 3389 closed on the firewall the same day. The vendor now signs in with Entra ID and MFA from a registered device, for a maintenance window Acme opens and closes. Every session is in the log with the vendor's name on it.

Agents bound to people. Copilot connects to Acme's MCP URL as the rep using it. Reps see their own accounts and their team's, the way Salesforce already defined it. The service account was deleted in week two, which is when three undocumented reports stopped working and were rebuilt properly.

The ERP as governed tools. The vendor's OpenAPI spec was uploaded as it was. Invoice list and get are allowed for finance agents, create for two named people, delete for nobody. The vendor's admin key went back to the vendor.

One log, exportable. Every login and every tool call, exported once a quarter as CSV in the form the assessor accepts. The two questions now take two filters.

Watchtower on. Switched on before the second assessment, because the assessor asked what would happen if an agent misbehaved. This is what happened when one did.

time2026-09-14 09:50:12 UTCprincipalagent:sales-assistant for jan.peeters@acme.bepattern4,120 customer records read in 9 minutes usual: about 30 a daysignalsuspiciousalertedsecurity@acme.be, Slack #securitymodelFlowplane Watchtower our own models, EUstored ineu-west, Belgium retained 24 months

The assessor asked who reached the ERP in Q3. We sent a CSV. That was the whole conversation.

What it took

Names and figures in this case are a composite of pilot conversations. The two questions are real; every NIS2 assessor asks them.