Your name is on the number. The system has to show its work.
Your people have already started using AI, and some of them have not mentioned it. Meanwhile the carrier questionnaire asks, §7216 and the Safeguards Rule apply whether or not anyone has written the policy, and the first annual evaluation of the firm’s quality management system falls due by 15 December 2026 — which asks you to describe how you monitor what your people actually do.
The modules that matter when the entities are clients
Each one runs a real workflow, in the order it runs. Every one of them ends with a person, because that is the part your licence cares about.
Your firm’s coding judgment accumulates as policy rather than staying in one person’s head.
Reconciling items carry a history and an owner instead of living in a workbook copied forward.
The schedules that turn into audit adjustments stay current instead of being rebuilt each year end.
A contract change shows you its catch-up instead of quietly restating a month you already closed.
The process is written down, not living in one person’s head over one busy season.
“Who approved this entry, and on what basis” has an answer before anyone asks it.
The questionnaire stops being a scramble, because the inventory already exists.
If your firm would rather own the thing than rent it, this is the foundation to start from. See what is inside →
Modules you do not need are switched off rather than shipped as clutter. What each one does across your client base — their entities, calendars, charts of accounts, materiality thresholds and your review steps — is configured during the build.
One rule holds across every workflow above
The AI retrieves, analyses, drafts and proposes. Deterministic code calculates and checks. An authorised person approves anything that reaches the ledger. There is no unsupervised posting, and no setting that turns it on.
Four-tier action gate
Every action is classified into exactly one side-effect tier. Ledger and customer-facing writes are proposal-first, human approval only. An unrecognised action fails closed into the most-gated tier.
Preparer and approver
Review policy set per entity, with role floors and per-check materiality overrides, and separate preparer and approver roles wherever the control requires segregation.
Readable proposals
Each proposal carries before and after, its source data, risk level, the role required to approve it, a content fingerprint, an expiry, and its execution record.
One audit chain
The prompt, the run, each tool call, the proposal, the approval or rejection, the sync — recorded as one chain you can walk backwards.
Circuit breaker
When a task’s accuracy degrades, the system revokes that task’s autonomy and alerts. It can only demote. It can never promote itself.
Grounded answers
Answers cite period, basis, source reference and sync timestamp. Prose claims are verified against facts captured at the tool boundary; anything unverified is marked.
Two ways in. Both end with you owning it.
The rungs are an engagement — we run the client work while your people watch it happen, and at twelve months they take it over. The shelf underneath is the same thinking sold as materials, for a firm that would rather build it now. Both end in the same place.
The AI Register
Name the AI tools your people already use on client work and the register builds itself — the inventory the first annual evaluation of your quality management system asks for, due 15 December 2026.
The Close Teardown
Bring the client close that costs you the most hours and we go through it together. No demo, no pitch, and no obligation at the end of it.
The Pilot
Pick the client close that costs you the most every month, and we run it — not a report about running it, the close itself, on your deadline, against their books. You watch it happen on an engagement you already own.
The Run
We keep running it, then the second engagement, then the third. An evidence pack every close — what ran, what it proposed, who approved it, what changed. Your review steps, your materiality, your sign‑off.
The Handover
After a year of it running, your own people take it in‑house — the source, the training, and support while they settle into it. This is the plan from the first day, not the thing the contract is written to avoid.
If you would rather own it outright from the start, we build it that way instead — scoped against what your practice actually runs, so it carries no published price. Most firms do not start there. The teardown is where you find out whether you should.
Or build it yourself
The same ideas, sold as materials rather than as an engagement. Not a decision you have to make now — the teardown costs nothing and is the fastest way to tell which one fits.
The 101
What the tools actually do, what they cannot do, and the vocabulary the rest of this is built on. Written for someone who has never opened a terminal.
The Sprint
You answer eleven questions about how your firm actually works — which system holds the books, who may approve what, whether anything may reach a client ledger at all — and it writes the build instructions for your own coding agent. Nothing gets built until you approve it.
The Bootcamp
The Sprint, run with you, over four weeks — the same build, with the judgment calls made out loud and your questions answered while you are inside the file rather than after.
Both paths end in the same place: your firm owning what it runs on.
Find the layer that is least ready to carry it.
Twelve questions across six control layers. About six minutes, and the result stays on your screen — sharing it is optional.