Skip to content

Autonomy & Safety

This page is the single source of truth for the question every accountant asks first:

"What will Kraal do to my client's books without asking me?"

Kraal is built for supervised autonomy. It does as much of the routine work as it safely can on its own, holds anything that needs professional judgment for your approval, and records every action so you can verify and reverse it. Autonomy is set per client, so a brand-new client and a client you have worked with for a year can operate at different levels of trust.

The three tiers of AI action

Every AI capability in Kraal falls into one of three tiers.

TierWhat it coversApproval
1 — Always autonomous (read-only)Reading ledgers, building the trial balance / P&L / balance sheet, checking close readiness, investigating reconciliations, flagging AP/AR issues, drafting suggestions and categorizations, extracting data from uploaded documents.None needed — nothing is written to the ledger.
2 — Supervised posting (routine, within limits)Posting supported low-risk, routine transaction families only when the client is in supervised mode and the action is inside every guardrail below. Recurring Journal Entries use the separate workflow described in Recurring Entries.Eligible entries post automatically, then appear in your review ledger. Reversible.
3 — Always waits for youAnything high-risk or judgment-heavy: tax provisions, equity and retained-earnings entries, revenue recognition, goodwill and impairment, related-party entries, going-concern items, prior-period adjustments, chart-of-accounts changes, deletions, and sending anything to a client.Held in your judgment queue until you explicitly approve.

Tier 1 is always on. Tier 3 always waits. Tier 2 is the tier you control with the client's autonomy mode.

The two autonomy modes (per client)

Each client runs in one of two modes. You set this during onboarding and can change it at any time from the client's Autonomy & Trust controls.

  • Supervised (default). Kraal may post Tier-2 routine entries on its own, but only inside the guardrails below. Everything it posts is logged in Auto-Posted Entries and can be undone with one click.
  • Approval-first (Locked Down). Kraal posts nothing on its own. Every proposed entry — even routine ones — waits in your judgment queue for explicit approval. Use this for new clients, sensitive engagements, or any client where you want to see everything before it lands.

Pausing autonomy

You can pause autonomous posting for a single client or your whole portfolio at any time from the Autonomy & Trust controls (this switches the client to Approval-first). Paused work does not disappear — it waits in your judgment queue.

The guardrails on supervised posting

Even in Supervised mode, an entry only posts automatically if it passes every one of these checks. If any check fails, the entry is held for your review with a plain-language reason.

  • Risk tier. Only low-risk transaction families auto-post. High-risk families (see Tier 3 above) are always held, regardless of amount or mode.
  • Amount caps. Per-entry, per-account, and per-client-per-month dollar caps. The default Conservative preset uses modest limits; a Trusted preset raises them. The active limits are always visible on the client's autonomy settings.
  • Daily volume limit. A maximum number of automatic posts per client per day.
  • Evidence confidence. The supporting evidence must clear a minimum confidence bar. Low-confidence items go to review.
  • New vendor / new merchant hold. The first time Kraal sees a merchant, that entry waits for your approval rather than auto-posting.
  • Restricted categories. Sensitive categories (for example, Payroll) never auto-post.
  • Materiality. Amounts above the client's materiality threshold are routed to you.
  • Open period only. Posting into a locked or closed period is refused (see Period locks below).
  • Duplicate detection. Kraal refuses to post something that looks like a duplicate of an entry it already made.
  • Trust ratchet. If a particular kind of entry recently needed a correction, Kraal automatically moves that kind of work back to review until it re-earns trust.
  • Error cooldown. After a failed post, Kraal pauses that lane before trying again.

Illustrative default limits (Conservative preset) — the live values always show in the app and can be adjusted per client:

GuardrailConservative default
Per-entry cap (low-risk)$1,000
Per-entry cap (moderate-risk)$5,000
Per-client-per-month cap$25,000
Per-account cap$50,000
Automatic posts per day10

Period locks and close

When you finish and lock a period, Kraal refuses to post into it — automatically or manually — until the period is reopened by an authorized user with an audit trail.

Lock the period to seal it

Finishing a close and locking the period are what seal it against further posting. If you want a period sealed the moment it is signed off, use the Lock period action on the client's close.

Everything is reversible and audited

Autonomy is only safe if you can see and undo it. For every AI action, Kraal records who or what did it, when, the inputs, and the result.

  • Auto-Posted Entries lists every entry Kraal posted on its own, each with a one-click Undo that creates the correcting reversal.
  • Audit Center and the Audit Trail & Activity Log show the full, tamper-evident history of AI and human actions per client, including why an entry was posted or held.
  • Execution Replay lets you step through exactly what an AI run did.

See Audit Center and Audit Trail & Activity Log for how to verify and export this history.

Kraal — AI-powered accounting for modern firms