Autopilot with limits
Let it post. Keep the brake.
Everyone is shipping AI that writes to your books on its own. Poof does too, with one difference that matters when it is wrong: it posts inside limits you set, and it stops itself the first time you correct it.
Off by default. Every new account asks about everything until its owner turns this on.
Before it posts on its own
Every gate is code. None of them is the model's opinion.
A transaction posts by itself only when all of these pass. If one fails, it waits on a card, and the card says which one, in the words the system actually uses.
- 01
Not a new account
If the AI suggests a category the chart of accounts does not have yet, the transaction waits. The chart may not cover it, and that is a person's call.
held: AI suggested a new account — the chart may not cover this yet
- 02
Under your ceiling
You set a dollar limit. Anything over it goes to the inbox with the reason. Nothing is dropped.
held: $2,310.00 is over the $2,000.00 auto-post ceiling
- 03
The merchant agrees with itself
At least your minimum number of prior reviewed transactions for this merchant, and every one of them carrying the same category. Unanimity is the load-bearing check.
held: this merchant has been categorized more than one way before (7 prior transactions)
- 04
Enough history
A merchant seen once is a merchant a person should see. The default is three prior transactions; you can raise it.
held: only 1 prior transaction for this merchant, 3 required
- 05
Confidence clears your bar
The model reports a confidence. It is never enough on its own, because it is the model describing itself. It is the last check, not the first.
held: confidence 82% is below the 90% bar
- 06
Or: it replays your own correction
If a person already corrected this exact merchant once, Poof replays that answer. That path is deterministic and trusted on its own.
posted: replays a prior human correction for this merchant
One night, replayed
Turn it on, set the limits, and watch a sweep run.
Move the ceiling and the history bar and see which rows post and which wait. Then correct one, and watch the rule stop.
- 09/16$612.40FERGUSON ENT #1204→ Job Materialsposted: 5 prior transactions, all Job Materials · confidence 97%
- 09/16$2310.00FERGUSON ENT #1204→ Job Materialsheld: $2310.00 is over the $2000.00 auto-post ceiling
- 09/16$71.40SHELL OIL 57442119→ Fuelposted: 22 prior transactions, all Fuel · confidence 94%
- 09/16$86.12HOME DEPOT #0472→ Job Materialsheld: confidence 88% is below the 90% bar
- 09/16$148.30AMAZON MKTPL→ Shop Suppliesheld: this merchant has been categorized more than one way before (7 prior transactions)
- 09/16$412.00JOHNSTONE SUPPLY→ Job Materialsheld: only 2 prior transactions for this merchant, 3 required
- 09/16$54.20QT 1187→ Fuelposted: replays a prior human correction for this merchant
- 09/16$430.00CITY OF MESA PERMITS→ Permits & Inspectionsheld: AI suggested a new account — the chart may not cover this yet
The gates and their wording are the product's own. The rows are a demo. Defaults in the app: ceiling unset until you choose one, three prior transactions, a 90% bar.
Standing rules
Rules are derived, not authored.
Autopilot handles the categorization sweep. For anything beyond it, you grant a standing rule from a card you already read, and it carries its own limits.
Built from reviewed work
Poof derives the rule from the card in front of you: the merchant these rows share, the agreement in their history, a limit above the largest one. It shows the rule in plain sentences and how much of the card it covers before you grant it.
A ceiling, always
A rule that writes to the ledger must carry a dollar limit. One without a limit does not run. Anything over goes to the inbox.
A daily cap
A rule has a daily count. The overflow waits for the next day or for you; it is never dropped.
It stops itself
Correct anything the rule is about, not only a row it touched, and it pauses, names the correction that stopped it, and waits. Revoking is instant; its earlier work stands with its name on it.
Never a customer
No rule can send an invoice, a credit note, or a message to a customer. That is always a person's decision.
Tied to a person
A rule stops working if the person who granted it loses the permission it needs. Every rule lives on one page with what it has handled and who allowed it.
See the rule pause itself on the homepage demo, or read what a QuickBooks bank rule costs you.
Six questions
What people ask before they turn it on.
- Is Autopilot on by default?
- No. Every new account asks about everything. Autopilot is a setting you turn on, with a confidence bar, a minimum merchant history, and a dollar ceiling you set. Standing rules are granted one at a time from work you already reviewed, never from a settings screen.
- What does Autopilot need before it posts a transaction on its own?
- Four things, all checked by code, not by the model. The category must not be a new account the chart does not have yet. The amount must be under your ceiling. The merchant must have at least your minimum number of prior reviewed transactions, and every one of them must carry the same category. And the AI's self-reported confidence must clear your bar. If any one fails, the transaction waits on a card with the reason it was held.
- Why does merchant history matter more than the AI's confidence?
- Because the confidence number comes from the model describing itself, and self-reported confidence is weakly calibrated. Merchant history is a deterministic database check: has this merchant been categorized this way, unanimously, enough times by a person. A merchant categorized three different ways is exactly the one a person should look at, even if a naive count would wave it through.
- What happens when Autopilot gets one wrong?
- Correct it. Any correction to a transaction a rule is about pauses that rule, records which correction stopped it, and notifies you. The rule covers nothing until you resume or revoke it. Its earlier work stands, with the rule's name on each entry, so you can review what it touched.
- Can Autopilot send an invoice or an email to a customer?
- No. No rule, however it was granted, can send anything to a customer. Invoices and credit notes are always a person's decision. A rule that writes to the ledger must carry a dollar limit, and anything over the limit goes to the inbox rather than being dropped.
- How is this different from a QuickBooks bank rule?
- A QuickBooks rule matches text and posts, and it keeps posting until somebody notices it is wrong. A Poof rule is derived from work you reviewed, checks the merchant's history agrees, carries a dollar ceiling and a daily cap, and stops itself the first time you contradict it.
The work disappears. The evidence doesn't.
Thirty days free, no card, every feature. Or book twenty minutes and bring your books.