Solutions · Finance approvals
Put a person where the money moves.
AI can draft a refund or a bulk delete in seconds. qbrin checks the proof first. Small, well-backed actions go. Weak proof is held. Big or irreversible ones go to a person, and every decision leaves a receipt.
- Go, hold or ask a person: live
- Who can act: early access
- A receipt for every decision
Scope
Give it the policy. Not the ledger.
An agent that prepares approvals needs your policies and the request in front of it. It does not need payroll, HR files or every customer’s mail.
What it usually gets.
- Read access to the ledger, payroll and HR files.
- Standing permission to pay, refund or delete.
- A shared login used by several tools and people.
- No list of what it has read or done.
What this job needs.
- Your approval policy and the open requests.
- No payroll, HR files or other teams’ data.
- A name, an owner and an off switch for every key.
- A person in the loop for big or irreversible actions.
- Approval policyLimits and who signsAllowed
- Approval requestsWhat is waitingAllowed
- Payroll sheetsNot shared
- HR filesNot shared
- Customer mailNot shared
- A payments tool with its own loginqbrin cannot narrow a login it does not hold. It shows up as residual exposure, so you can see it.Not narrowed
How a limit works.
qbrin narrows what passes through qbrin: its own agents, and keys that call qbrin’s MCP or API.
- You pick the sources a job needs. A source you did not name is left out.
- For agents, a preview shows what the limit would have cut from the last 30 days.
- A login that qbrin does not hold is shown as exposure, not hidden.
Check
Weak proof stops. Big moves go to a person.
qbrin looks at what the action is, whether it can be undone, and whether the proof holds up. Then it answers go, hold or ask a person.
What gets checked.
- Is the proof from a system you trust?
- Does it match the order, the amount and your limits?
- Can it be undone? Your rules can require a person if it cannot.
- GoThe proof checks out. The action runs.
API: allow - HoldNot enough proof. It stops and nothing happens.
API: hold - Ask a personThe owner decides. Nothing happens until then.
API: escalate
The AI wants toDelete 10,000 customer records
- Passed: The AI is allowed to ask for this
- Failed: It can be undone
- Failed: Your rules say a person must approve it
Every decision leaves one, whether it was go, hold or ask a person. Look any receipt up by its id.
- Action
- Refund ₹95,000 to a customer
- Decision
- Hold
- Why
- The invoice says ₹9,500, not ₹95,000
- Proof checked
- How much was examined, and how much bound
- The call
- A fingerprint of the exact call, not a copy of it
The public sandbox runs in shadow mode: it shows what would be held and enforces nothing. Try the sandbox
Know
Know who can act on money.
People, AI agents, API keys and connections, in one scored list. You see who can move money or delete data, and who has to ask first.
- Ops agent AI agentCan act without sign-offFix: Require a person’s sign-off.High
- Payments key API keyToken has full accessFix: Replace it with a token limited to read.High
- Finance admin PersonAdmin has not been seen in a long timeFix: Confirm they still need admin.Medium
- Report exporter AI agentNo explicit policyFix: Write a policy so the rules are yours.Low
What you will see.
- Agents that can act with no sign-off are flagged.
- Require a person’s sign-off for an agent in one step.
- See what was held or sent to a person, by day.
Keep a person in the loop.
Book a demo to see a large refund held and a delete go to the owner.