Finance · Colleague: Fin

Every dollar approved, every write traceable

Fin, your Finance Colleague, handles card issuance, expense approvals, invoice status, vendor onboarding, and month-end close — with your approval matrix on every write and an audit trail on every step.

Phase 5 · Q3
Capability 01

23 pre-built Finance playbooks

Corporate card issuance · expense submission · receipt matching · PO status · vendor onboarding · bill payment approval · weekly digest · licence-cost tracking · month-end close · T&E policy Q&A · reimbursement · card lock · limit adjustment · wire approval · vendor risk · AR aging · GL setup · equity support · subscription changes · Zip access · Zip out-of-office · Zip portfolio owner · spend monitoring.
grounded answer · sources
answer

Priya’s Okta lockout can be cleared via self-serve MFA challenge — no IT intervention required. If MFA fails, escalate to IT on-call.

cited from
01
IT · Okta account lockout policy
runbook · updated 4d ago
02
HR · Emergency access procedure
policy · updated 2w ago
03
Ticket #48211 · priya · resolved
past ticket · similar match
Capability 02

Approvals-first, always

Every write action ships in manual approval mode by default. Auto-mode is opt-in per action, per amount tier, with the approval chain configured in Approval Policies. Wire transfers require two-person + treasury; card issuance requires finance-manager; expenses route on your matrix.
approvals · pending 4
unlock okta account
priya.sharma · self-serve · read-only
denyapprove
refund $128.40
stripe · ord_A4b2c · manager approval
denyapprove
revoke prod IAM role
aws · role/analyst · step-up MFA
denyapprove
reset zoom SSO
kiran.mehta · self-serve
denyapprove
Capability 03

Connected to your GL

NetSuite, QuickBooks, Xero, SAP S/4HANA, Oracle Fusion Cloud, Microsoft Dynamics Finance, Sage. Read for status and reporting; write for approved transactions. Every write is idempotent, replayable, and reversed cleanly if the approval is later revoked.
context · priya.sharma
priyateamon-calloktagithubworkday
Capability 04

Connected to your cards and AP

Ramp, Brex, Bill, Coupa, Zip, Airbase, Expensify, SAP Concur, SAP Ariba. Fin issues cards, matches receipts, routes bills, and updates cost centres — with per-action approval rules that respect your delegation-of-authority policy.
reports · this week
Auto-resolved
78.4%
+4.1 pt
Avg. loop time
11.4s
-2.1s
Approvals pending
12
-3
Coverage
94%
+1.2 pt
monsun
Capability 05

Audit-ready from day one

Every action writes to the immutable audit_events log — actor, action, target entity, before/after state, IP, timestamp. OCSF-format for direct SIEM ingest. SOC 2 Type II report available; ISO 27001 and HIPAA-BAA on Enterprise. Passes procurement without a spreadsheet.
grounded answer · sources
answer

Priya’s Okta lockout can be cleared via self-serve MFA challenge — no IT intervention required. If MFA fails, escalate to IT on-call.

cited from
01
IT · Okta account lockout policy
runbook · updated 4d ago
02
HR · Emergency access procedure
policy · updated 2w ago
03
Ticket #48211 · priya · resolved
past ticket · similar match
Capability 06

Month-end close, choreographed

A single playbook runs the close checklist: accruals collection, JE aggregation, blocker escalation, controller sign-off. Every task tracked, every hand-off logged. Close completes on schedule with the underlying data one click from the summary.
approvals · pending 4
unlock okta account
priya.sharma · self-serve · read-only
denyapprove
refund $128.40
stripe · ord_A4b2c · manager approval
denyapprove
revoke prod IAM role
aws · role/analyst · step-up MFA
denyapprove
reset zoom SSO
kiran.mehta · self-serve
denyapprove
The BeforeQuery method

Visibility. Reasoning. Action.

Every playbook, every action, every answer follows the same three-beat rhythm — one that keeps every write behind evidence and every decision behind policy.

01

Visibility

Read the full context — who is asking, what they own, what they can access, what breaks if we touch it. Nothing acts on incomplete signal.

02

Reasoning

Match the request to a grounded answer or a playbook. Cite the source paragraph, weigh the risk tier, and route to the correct approver where policy demands it.

03

Action

Execute the write on your systems with an audit-log id, an entity list, and a rollback path. Confirm the outcome with the requester in the same thread.

How every request flows

From ask to resolution in one loop

Six stages every request travels. What changes is how many stages policy lets the agent execute without waiting on a human.

01
Request

In Slack, email, widget, MCP, or the helpdesk. Same voice, same context.

Slack · Teams · Zendesk · Widget · MCP
02
Retrieve

Grounded lookup against your knowledge with source paragraphs held aside.

Knowledge Studio
03
Reason

Read the Context Graph — who, what they own, what breaks if we touch it.

Context Graph
04
Approve

Route to the correct approver per policy. Reversible writes gated, destructive step-up.

Approval matrix
05
Execute

Act on Okta, Stripe, Workday, GitHub, or your own systems. Logged and attributable.

Actions runtime
06
Verify

Confirm the outcome with the requester. Feed the result back into future decisions.

Feedback loop
Watch it work

Expense receipt → filed and approved in 30 seconds

Photo of a receipt in Slack becomes a compliant expense line with the approval chain routed correctly.

slack · #it-help
live
$priya @ #expenses:[receipt photo] client dinner Berlin sales trip
·
fin OCR receipt: Restaurant Nobelhart · €73.00 · 2026-08-17 vision.ocr
·
fin cross-check calendar: dinner with Acme Corp contact confirmed gcal.event#82c
·
fin categorise: client meal · CC-SALES-EU · policy compliant (under €75) policy.check
·
fin file expense line + route to manager Sarah concur.exp#4211
finpriya:Filed under CC-SALES-EU with the Acme meeting attached. Sarah gets it next.
resolved · 24s · 0 back-and-forth·audit trail · policy-compliant

For over-per-diem or missing-receipt cases, Fin drafts the exception request instead of filing. Same flow, different last step.

Enterprise-grade by default

The controls your security team is going to ask about

SOC 2 Type II
audited annually
GDPR
EU data residency
HIPAA-ready
BAA available
SSO / SAML
Okta · Entra · Google
SCIM 2.0
auto-provision
Audit log
every write, traceable
Bring your key
AES-256-GCM at rest
Bring your model
Anthropic · OpenAI · self-host
Zero training
your data stays yours
Rollback
every write reversible
TLS 1.3
in transit
99.9% uptime
SLA on Enterprise

Frequently asked questions

Common questions about Agentic Finance

GL: NetSuite, QuickBooks, Xero, SAP S/4HANA, Oracle Fusion, Microsoft Dynamics Finance, Sage. Spend / AP: Ramp, Brex, Bill, Coupa, Zip, Airbase, Expensify, SAP Concur, SAP Ariba. Billing: Chargebee, Recurly, Zuora, Anrok. All ship in Phase 5.
No. Wire transfers require two-person approval plus treasury sign-off with step-up MFA on both reviewers. Beneficiary must be on the approved-vendor list. Any deviation (new beneficiary, unusual amount) escalates. Zero exceptions.
Nightly cron reads card transactions from Ramp/Brex, matches against submitted receipts by amount + date + merchant. Unmatched receipts (or unreceipted transactions) surface to the employee via Slack DM with a 7-day nudge window; escalation to manager after.
SOC 2 Type II report is issued end of Phase 5; audit-log format is already SOC 2-ready today. ISO 27001 in the same window. HIPAA + BAA available on Enterprise for healthcare-adjacent finance flows. We ship you the report on request during procurement.
Fin Colleague + 23 Finance playbooks + NetSuite / QuickBooks / Xero / SAP Concur / Chargebee integrations + approval chains with step-up MFA + audit log with SIEM export. All writes default to manual approval — you flip individual actions to auto only after you've watched them in Copilot mode.

Run finance on BeforeQuery

Book a demo and see what Agentic Finance does on your own data — usually within 45 days.