surehand

Agents do the matching. Your controller signs.

Nothing posts without a person.

Agents work every invoice, reconciliation and vendor change in your AP queue. They stop for the person your policy names before anything posts.

  1. 01rules you sign
  2. 02checked before it acts
  3. 03your approver on hard calls
  4. 04a record that shows any edit
[ what changes ]

Your close, minus the matching.

Invoice matching, exceptions, reconciliations and vendor master changes. All of it under one set of rules your controller signs. Every action is checked before it runs. Anything outside the rules waits for your approver. The agent proposes. It posts nothing.

[ the queues ]

Four queues. One set of rules.

Pick a queue. What the agent reads and touches, what it may do, where it must stop, and what goes on the record. Then one run of it, simulated.

01 / 04 · Finance

Invoice matching

Three-way match · Tolerance breaks · Duplicate invoices

Every invoice matched to its PO and receipt, then coded. Inside tolerance, it proposes release. Outside, it stops.

Reads
  • Invoice
  • Purchase order
  • Goods receipt
  • Vendor
Touches
  • NetSuite
  • SAP
  • QuickBooks
  • AP inbox
  • Receiving
May do
Match, code, propose release within tolerance
Stops for
Your controller: any variance outside tolerance, any duplicate, any missing PO
On the record
Every match, the tolerance it passed or hit, who released it, hash-sealed
fig. 01 · SimulatedRUN-3C8Q1 · manifest v3 · accounts payable
  1. PASSrun opened, policy check
  2. PASSINV-2291-C matched to PO-88214
  3. PASSquantity matched to receipt GRN-5502
  4. HELDunit price 12.40 against PO 12.02, variance 3.2%, tolerance 1.0%

    held for controller · price variance

    • INV-2291-C · 2,976.00
    • PO-88214 · unit price 12.02
    • invoice · unit price 12.40
    • tolerance · 1.0% · manifest v3

    released · controller · 09:41:37

  5. RELEASEDreleased by controller, price change confirmed with the buyer
  6. SEALEDrecord sealed

CHAINED BY SHA-256 · EXPORTS IN OPEN FORMATSOne invoice exception, held for the controller.

[ your first agent ]

Bring the report that eats your close.

Pick one. The match your team does by hand. The reconciliation that eats the close. The vendor inbox nobody owns. We study it with you, write the rules your controller signs, and run the agent with your approver in the loop.

  1. 01

    Study

    We map the queue, the systems and who signs today. You keep the write-up.

  2. 02

    Deploy

    Your controller and we write the rules. You sign. The agent works inside NetSuite, SAP or QuickBooks under them. Your cloud or ours.

  3. 03

    Run

    Your controller clears the first stopped invoices. Every release and decline goes on the record, with a name.

[ what finance teams bring first ]

Bring the question nobody can answer fast.

  1. 01

    Which invoices in the inbox match their PO and receipt within tolerance?

    Queue: Invoice matching
  2. 02

    Which invoices were paid twice, or nearly?

    Queue: Invoice matching
  3. 03

    What is still open on the bank reconciliation, and why?

    Queue: Close and reconciliations
  4. 04

    Which vendor changes came in this week, and who confirmed them?

    Queue: Vendor master changes
  5. 05

    Which vendors are asking about the same payment run?

    Queue: Vendor and payment queries
  6. 06

    Who released yesterday's exceptions, and against which tolerance?

    Queue: Invoice matching
[ Gatehouse ]

Controls your auditor already expects.

Four controls. Your technical team gets the detail on the Gatehouse page.

manifest

What the agent may post: nothing.

The manifest allows read, match, propose and hold. Posting and release stay with your controller, in NetSuite, SAP or QuickBooks.

policy check

Tolerances enforced before, not reconciled after.

Every action is checked against the manifest as it happens. A variance outside tolerance stops before it moves, not in next month's review.

approver

Segregation of duties, kept.

No agent approves its own match, and no person approves their own. The hold goes to the name in the manifest, with the evidence gathered.

sealed record

Every match your auditor can replay.

Each run is chained by SHA-256 and exports in open formats. Internal audit reads it without Gatehouse installed.

[ security ]

What your auditors can check today.

01

Rules your accountable person signs

Systems, actions, limits and approvers. Written down. Signed before the agent runs.

02

Checked before every action

Every action is checked against your rules as it happens. Not named means refused. The refusal goes on the record.

03

The agent never signs

No agent approves, posts or releases. No one approves their own work. Every step lands on a record your auditors can replay.

04

A record any edit breaks

Every run is chained by SHA-256. It exports in open formats. Your auditors read it without Gatehouse.

Your cloud or ours. You decide, and the manifest records it.

No SOC 2 report or ISO 27001 certificate today. Your security team gets a walkthrough of the four controls and where the deployment runs. We answer your questionnaire in writing and tell you where certification stands.

Read the security answers
[ composite case ]

One deployment, from queue to record.

Built from more than one engagement. Names and figures changed. No performance figures, because none were measured on a single engagement.

[ read before you start ]

The questions finance teams ask us first.

Each one answered in full, with its sources. No sign-up to read them.

[ faq ]

Asked before every start.

Not here? Write to support@surehand.io. A person replies, usually inside two business days.

Talk to the people who run it
Where does our ledger data live?

Your cloud or ours. You decide, and the rules record it. They name every system the agent may read or write. Nothing else is touched.

Can the agent approve, post or release an invoice?

No. Your rules don't allow it. The agent matches and proposes. The person your policy names approves. Every step is on the record, with who took it.

Does it work with NetSuite, SAP or QuickBooks?

Those are the ledgers finance teams bring most. What the agent may read and write in yours is settled in the teardown, before anything is signed.

How long before we see the first held invoice?

We quote a timeline after the teardown, not before. It covers one queue and the people who sign for it today.

Does this replace our ERP or our AP tool?

No. The agent works inside them, under your rules. Gatehouse sits in front of the agent, not your systems.

Are you SOC 2 certified?

Not today. Your security team gets a walkthrough of the controls and where the deployment runs. We answer your questionnaire in writing. You hear it from us first when this changes.

Start here

Bring us the queue nobody wants.

Tell us what comes in, who handles it and where it waits. We study it with your team and tell you straight if an agent belongs there. A person replies, usually inside two business days.

support@surehand.io