“Can AI do this?” is the wrong first question. In a lumberyard, the safer sequence is: What is the job? What record does it depend on? What may the system do? What must stop and go to a person?

AI can help with low-authority work before it is trusted with a customer, inventory, financial, or safety-relevant action. That distinction matters because a fluent answer can still be based on stale stock, the wrong unit, an expired quote, a protected account, or an unsupported assumption.

The governance basis

The NIST AI Risk Management Framework is voluntary, general guidance—not an LBM standard, certification, or proof that a product is safe. It organizes risk work around Govern, Map, Measure, and Manage. NIST’s generative-AI profile and human-AI interaction guidance add risks such as confabulation and the need to define human roles. This guide applies those ideas to candidate lumberyard situations; every control still needs local validation.

The five-level assistance ladder

  1. ObserveRead or transcribe an approved source without changing a business record. Example: capture a caller’s words and timestamp. Record consent and source boundaries where required.
  2. StructureTurn unstructured input into fields, a summary, or a candidate classification. Preserve the original and expose uncertainty. Example: extract item, quantity, unit, job, and due date from an email for review.
  3. CoordinateRoute work, name an owner, monitor an aging state, or prepare a reminder. Do not mistake routing for resolution. Example: send a technical request to the specialist with the source attached.
  4. PrepareAssemble a draft answer, quote packet, comparison, order draft, or customer message from current authorized data. A draft is not approval; show assumptions and changed fields.
  5. Execute within explicit authorityTake a reversible, logged action only when the role, data, policy, conditions, and fallback are defined and tested. Any step outside that envelope stops and escalates.

This is not a universal maturity model. A neutral, non-committal acknowledgment may be automated. Every action involving pricing, credit, substitutions, equipment, loading or unloading, routing, or safety requires explicit human authorization; AI may only gather, structure, or prepare information for that decision.

When the system must stop

Conditions that require a block or human review
ConditionSafe responseHuman owner
Stale, missing, or conflicting dataState what is unavailable, block the dependent answer or action, and present the source discrepancy.System owner plus the role responsible for the record.
Price, margin, freight, tax, or quote validityPrepare from current approved rules; require an authorized person to review and release every price or customer commitment.Authorized salesperson, quote owner, or sales manager.
Credit, terms, past-due status, deposit, or refundLimit data access and prepare a summary only for authorized staff. Require an authorized person to make every credit, terms, deposit, refund, or disclosure decision.Credit, accounting, or owner/GM.
Substitution or technical selectionShow candidate differences and sources; require an authorized person to approve every substitution or technical selection.Product specialist, estimator, supplier, customer, or qualified designer as applicable.
Physical stock, will-call, loading, or unloadingRequire authorized human confirmation. Do not operate equipment, release material, direct loading or unloading, or make safety decisions.Yard lead, driver, or operations/safety authority.
Delivery ETA, route, or site-condition changeUse the last confirmed status, capture the request, and send it to dispatch. Require an authorized person to approve every reroute or timing commitment.Dispatcher, driver, or operations manager.
Named account or protected relationshipRespect ownership, contact preference, channel, consent, and suppression rules; route with context.Account owner or sales manager.

Design for failure, not just the happy path

A useful system should make failure visible. If an integration is unavailable, it should not silently use an old answer. If a message is retried, it should not create a duplicate request or send twice. If the model is uncertain, it should not turn uncertainty into a customer commitment.

  • Fail closed: block the dependent action when source freshness, mapping, policy, or authority cannot be established.
  • Keep the original: store the call, message, file, or record reference beside the extracted fields.
  • Show the source: expose which system, field, timestamp, rule, and version produced the draft.
  • Make review meaningful: highlight assumptions, conflicts, and changes instead of asking a person to rubber-stamp a polished answer.
  • Record the outcome: log the reviewer, action, system result, customer communication, and eventual disposition.
  • Provide a manual fallback: define what the team does when access is read-only, broken, or unsupported.

What public vendor pages show

Vendor pages show that AI language is entering LBM software, but they do not establish independent reliability or outcomes. Flitch describes an LBM copilot spanning calls, quotes, orders, delivery, and human transfer. TOOLBX labels Forge AI “coming soon.” Rundoo describes AI-assisted reporting, purchase-order, and follow-up work. Epicor describes Prism as a set of AI applications around Epicor products.

Those are attributed product descriptions. This guide did not independently test availability, accuracy, integrations, production use, adoption, or results. Second Counter is being built and does not claim these capabilities today.

Yard-AI control checklist

  • What one situation is being assisted? Use the last five real examples, not a generic use case.
  • Is the system observing, structuring, coordinating, preparing, or executing?
  • Which exact records, fields, timestamps, policies, and versions support the output?
  • Which role owns the decision and which role owns the system failure?
  • What conditions block action rather than invite a best guess?
  • Which customer, financial, inventory, technical, delivery, or safety commitments are prohibited?
  • How are consent, access, retention, private account notes, and sensitive payment data handled?
  • Can retries, duplicate requests, partial failures, overrides, and reversals be traced?
  • What is the safe manual fallback?
  • What evidence would justify increasing—or reducing—the authority later?

The operating principle

Authority should grow slower than usefulness. A system can become valuable by capturing, organizing, routing, and preparing work while the yard keeps control of the decisions that carry real consequences. The goal is not to make a counter disappear. It is to keep a busy counter from losing the thread.

Sources and limitations

  1. National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0), January 26, 2023. Voluntary and not LBM-specific.
  2. NIST, Generative Artificial Intelligence Profile, July 26, 2024. General guidance; it does not validate a vendor or architecture.
  3. NIST AI Resource Center, Human-AI Interaction guidance. Workflow-level controls still require local testing.
  4. NIST, AI RMF Playbook. Implementation suggestions, not certification or legal advice.
  5. OSHA, Lumber and Building Material Dealer Industry — Hazards and Solutions, plus 29 CFR 1910.176. These sources are not a complete compliance program; applicability is fact-specific.