- Entity, account, period, currency, and decimals
- Use stable identifiers and exact decimals; bind bank and book accounts to one legal entity; preserve sign and original currency; separate transaction, value, settlement and posting dates; enforce cutoff and period locks; and reject cross-account or unexplained currency matches.
- Source completeness and provenance
- Retain original statements, events, extracts and digests; prove opening plus movement to closing totals; record access and ingestion; expose missing sequences, partial periods, duplicates and corrections; and never replace bank or book evidence with generated text.
- Match hierarchy and versioning
- Order exact identifiers before combinations and ranking; version date windows, tolerances, grouping, text rules, models, retrieval and evaluation; calculate every group deterministically; prevent member reuse; surface ties and alternatives; and bind decisions to effective versions.
- Permission, segregation, and commit
- Separate ingest, propose, confirm, investigate, adjust, approve, post, reconcile, certify, reopen and administer capabilities; scope credentials to entity, account and tool; enforce materiality and conflicts; use idempotency and receipts; log denials; review and revoke access.
- Exceptions, age, and visible correction
- Own unmatched, partial, duplicate, stale, returned, reversed, missing and conflicting items; distinguish timing from error; set age and escalation rules; require support for release or adjustment; roll items forward visibly; and preserve rejection, reopen and correction history.
- Security, retention, and recovery
- Minimize and encrypt financial and personal data, isolate tenants and environments, protect secrets, sanitize hostile artifacts, monitor access and tool use, back up and test restore, reconcile after replay, retain by qualified policy, support complete export and retire providers safely.