Skip to content

Autopilot with limits

Let it post. Keep the brake.

Everyone is shipping AI that writes to your books on its own. Poof does too, with one difference that matters when it is wrong: it posts inside limits you set, and it stops itself the first time you correct it.

Off by default. Every new account asks about everything until its owner turns this on.

Before it posts on its own

Every gate is code. None of them is the model's opinion.

A transaction posts by itself only when all of these pass. If one fails, it waits on a card, and the card says which one, in the words the system actually uses.

  1. 01

    Not a new account

    If the AI suggests a category the chart of accounts does not have yet, the transaction waits. The chart may not cover it, and that is a person's call.

    held: AI suggested a new account — the chart may not cover this yet

  2. 02

    Under your ceiling

    You set a dollar limit. Anything over it goes to the inbox with the reason. Nothing is dropped.

    held: $2,310.00 is over the $2,000.00 auto-post ceiling

  3. 03

    The merchant agrees with itself

    At least your minimum number of prior reviewed transactions for this merchant, and every one of them carrying the same category. Unanimity is the load-bearing check.

    held: this merchant has been categorized more than one way before (7 prior transactions)

  4. 04

    Enough history

    A merchant seen once is a merchant a person should see. The default is three prior transactions; you can raise it.

    held: only 1 prior transaction for this merchant, 3 required

  5. 05

    Confidence clears your bar

    The model reports a confidence. It is never enough on its own, because it is the model describing itself. It is the last check, not the first.

    held: confidence 82% is below the 90% bar

  6. 06

    Or: it replays your own correction

    If a person already corrected this exact merchant once, Poof replays that answer. That path is deterministic and trusted on its own.

    posted: replays a prior human correction for this merchant

One night, replayed

Turn it on, set the limits, and watch a sweep run.

Move the ceiling and the history bar and see which rows post and which wait. Then correct one, and watch the rule stop.

Nightly sweep · 8 rows3 posted · 5 held for you
  • 09/16
    FERGUSON ENT #1204Job Materials
    posted: 5 prior transactions, all Job Materials · confidence 97%
    $612.40
  • 09/16
    FERGUSON ENT #1204Job Materials
    held: $2310.00 is over the $2000.00 auto-post ceiling
    $2310.00
  • 09/16
    SHELL OIL 57442119Fuel
    posted: 22 prior transactions, all Fuel · confidence 94%
    $71.40
  • 09/16
    HOME DEPOT #0472Job Materials
    held: confidence 88% is below the 90% bar
    $86.12
  • 09/16
    AMAZON MKTPLShop Supplies
    held: this merchant has been categorized more than one way before (7 prior transactions)
    $148.30
  • 09/16
    JOHNSTONE SUPPLYJob Materials
    held: only 2 prior transactions for this merchant, 3 required
    $412.00
  • 09/16
    QT 1187Fuel
    posted: replays a prior human correction for this merchant
    $54.20
  • 09/16
    CITY OF MESA PERMITSPermits & Inspections
    held: AI suggested a new account — the chart may not cover this yet
    $430.00

The gates and their wording are the product's own. The rows are a demo. Defaults in the app: ceiling unset until you choose one, three prior transactions, a 90% bar.

Standing rules

Rules are derived, not authored.

Autopilot handles the categorization sweep. For anything beyond it, you grant a standing rule from a card you already read, and it carries its own limits.

Built from reviewed work

Poof derives the rule from the card in front of you: the merchant these rows share, the agreement in their history, a limit above the largest one. It shows the rule in plain sentences and how much of the card it covers before you grant it.

A ceiling, always

A rule that writes to the ledger must carry a dollar limit. One without a limit does not run. Anything over goes to the inbox.

A daily cap

A rule has a daily count. The overflow waits for the next day or for you; it is never dropped.

It stops itself

Correct anything the rule is about, not only a row it touched, and it pauses, names the correction that stopped it, and waits. Revoking is instant; its earlier work stands with its name on it.

Never a customer

No rule can send an invoice, a credit note, or a message to a customer. That is always a person's decision.

Tied to a person

A rule stops working if the person who granted it loses the permission it needs. Every rule lives on one page with what it has handled and who allowed it.

See the rule pause itself on the homepage demo, or read what a QuickBooks bank rule costs you.

Six questions

What people ask before they turn it on.

Is Autopilot on by default?
No. Every new account asks about everything. Autopilot is a setting you turn on, with a confidence bar, a minimum merchant history, and a dollar ceiling you set. Standing rules are granted one at a time from work you already reviewed, never from a settings screen.
What does Autopilot need before it posts a transaction on its own?
Four things, all checked by code, not by the model. The category must not be a new account the chart does not have yet. The amount must be under your ceiling. The merchant must have at least your minimum number of prior reviewed transactions, and every one of them must carry the same category. And the AI's self-reported confidence must clear your bar. If any one fails, the transaction waits on a card with the reason it was held.
Why does merchant history matter more than the AI's confidence?
Because the confidence number comes from the model describing itself, and self-reported confidence is weakly calibrated. Merchant history is a deterministic database check: has this merchant been categorized this way, unanimously, enough times by a person. A merchant categorized three different ways is exactly the one a person should look at, even if a naive count would wave it through.
What happens when Autopilot gets one wrong?
Correct it. Any correction to a transaction a rule is about pauses that rule, records which correction stopped it, and notifies you. The rule covers nothing until you resume or revoke it. Its earlier work stands, with the rule's name on each entry, so you can review what it touched.
Can Autopilot send an invoice or an email to a customer?
No. No rule, however it was granted, can send anything to a customer. Invoices and credit notes are always a person's decision. A rule that writes to the ledger must carry a dollar limit, and anything over the limit goes to the inbox rather than being dropped.
How is this different from a QuickBooks bank rule?
A QuickBooks rule matches text and posts, and it keeps posting until somebody notices it is wrong. A Poof rule is derived from work you reviewed, checks the merchant's history agrees, carries a dollar ceiling and a daily cap, and stops itself the first time you contradict it.

The work disappears. The evidence doesn't.

Thirty days free, no card, every feature. Or book twenty minutes and bring your books.

Start free trial