Pinnokio

The agentic harness

A language model
is not an accounting agent.

The language model is a component, and it can be replaced. What makes an agent reliable in accounting is what surrounds it: specialised agents, business knowledge, memory, controls before every journal entry and a record of everything that was done. This is what we call Pinnokio's harness.

The funnel

A request or a document
  1. Choose the agent
  2. Frame
  3. Check
  4. Decide

Each stage narrows what the agent can do. The last one belongs to the authorised person.

Why the model is not enough

Plugging a language model into an input box makes convincing demonstrations. In production the same limits come back: the model does not know your chart of accounts, forgets that supplier's rule, and can invent an account or a tax rule. A harness is everything built around the model so that these limits do not reach your books.

It does not know your file

Company, period, chart of accounts, supplier rules: Pinnokio supplies them to the agent when needed, instead of asking it to guess.

It can be confidently wrong

Journal entries go through controls written in code, applied before anyone is asked to approve.

It forgets

The file's memory is kept, organised by scope and subject to lifetime rules.

It gets replaced

Models evolve quickly, in quality and in price. A well-designed harness does not depend on a single provider.

The funnel: five stages between your request and the entry

Each stage removes options from the agent. The further it goes, the less latitude it has, and the more verifiable what it does becomes.

  1. 1

    1. Choose the agent

    The request goes to the suitable specialised agent. It is available only if the person has the right to it and the company has the module.

  2. 2

    2. Apply the right recipe

    When a tooled recipe exists (reconciliation, closing, import), the code determines which one applies. The model decides only how to carry it out.

  3. 3

    3. Load the right scope

    The agent sees only the tools and business-knowledge chapters of its mission, including the country's rules.

  4. 4

    4. Check before acting

    Business preconditions, existence of accounts and contacts, completeness. If a check fails, nothing is executed.

  5. 5

    5. Decide

    The entry is proposed as an approval card. The authorised person approves, edits or rejects it.

Agentic parity: the agent sees what you see

In Pinnokio, the screen and the agent are not two products bolted together. They are two ways of using the same ERP. Every action on screen goes through the same engine, the same access points and the same controls as the agent's. The agent has no private write path. We call this agentic parity.

The same access points

When the agent creates an entry, it calls the same server function as the button on screen, with the same controls. No back door for the agent, so no rule is bypassed.

The same questions

If the screen asks you to choose (which account, which warehouse), the agent asks the same question instead of deciding for you. A warning on screen becomes a line on the approval card.

Data you can see

What Pinnokio knows about your file is not buried inside a model. It is structured data, which you browse on screen like in any ERP.

A memory you control

The company's memories and the rules learned per supplier are listed in the interface. You can edit them or make them forgotten, and what you correct takes precedence over what the agent learned.

What it has learned, and what it has not

Learning takes the form of readable rules (account, VAT, category per supplier), not opaque weights. You check what is acquired and what is still to be taught.

Craftsmanship

Each module is taken over screen by screen: what the screen decides, flags or blocks, the agent takes up in its own form (approval card, instruction, recipe). It is long, hand-made work, module by module. It is what separates an agent bolted onto an ERP from one designed with it.

A team of specialised agents

Pinnokio is not a single assistant claiming to do everything. A main agent delegates to specialised agents, each with its own tools, knowledge and a model size matched to the difficulty of the task.

Documents and emails

Sorting and filing in your Drive, reading incoming emails, routing to the right processing.

Cockpit

Dashboards and charts, read-only: this agent cannot write anything into your books.

Human resources

Payroll, depending on the country. Reserved for companies that have the module.

Sales and projects

CRM, contracts, projects, behind the corresponding modules.

Onboarding

Taking over a file: chart of accounts, journals and entities imported.

A shared workspace

What one agent has just found (a folder, an invoice) is passed to the others so they do not look for it twice. This workspace is cleared with the session; durable memory is elsewhere.

Business knowledge, not guesswork

What an accounting agent knows does not come from the model. It is built, reviewed and corrected like any professional content.

A knowledge library

About fifty chapters: reconciling the bank, editing an invoice, closing a period, following a project. They are loaded according to the module and the company's context.

More than 90 tooled recipes

Step-by-step procedures for frequent cases, mostly in accounting, available in several languages.

Each country's rules

VAT, chart of accounts, payroll: the country's rules are read from a database maintained separately from the model. If a rule is missing, the instruction is not to invent it and to say so.

More than 500 capabilities

The real actions: creating an entry, reconciling, producing a PDF, searching the web. The agent sees only a selection, suited to its mission.

See how capabilities chain together

A memory with rules

Remembering is only useful if you know what to keep, for whom and for how long.

Working memory

Shared between agents for the length of a session, then cleared.

Durable memory

Preferences, facts and decisions of the file, organised by scope (personal, per company, shared within the company) and by lifetime. A preference is never forgotten; a fact that is no longer used eventually fades.

Learning by supplier

Account, VAT, category: Pinnokio keeps what has been approved for each supplier. What you correct by hand always takes precedence over what it learned on its own, and it does not ask again what it already knows.

A framed memory reflex

After a conversation, Pinnokio keeps something only if the session justifies it (corrections, edited approvals, stated preferences). This is a code rule, not the model's choice. An inferred memory enters the context only after it has proved useful several times.

Controls before any entry

The journal entry is where an error is costly. That is why the harness is strictest there.

Draft first

An entry is created as a draft. Posting it is a separate step, always subject to approval.

Integrity before approval

Completeness, existence of accounts and contacts, business rules: these checks happen before the card is shown to you, not after.

If approval fails, nothing goes out

If the approval mechanism itself meets a technical error, the action is blocked, not allowed by default.

Execution on frozen content

What you approve is exactly what is executed. If a parameter changes, a new approval is requested.

Behavioural safeguards

Loop detection, caps on calls and errors per task: the agent stops instead of persisting.

Reversal is possible

Reversal entry, return to draft, undoing an import batch, closing and reopening a period.

You set the level of approval

You can lighten approvals for one type of action during a session, with a periodic check. Posting, cancellation, period closing, payments and payroll are never approved automatically.

Everything is traced

For a fiduciary firm, knowing who did what, when and on which decision is not a comfort. It is the condition for entrusting work to an agent.

A timeline per task

Each step of a task is added to its history, with no erasure.

Every tool call is recorded

Which agent, which tool, which outcome, including what was approved, edited, rejected or left to expire.

Sensitive data is not copied

Logs keep the names of parameters, not their values, so personal data is not duplicated.

Live statuses

You see which agent is working, on what, and how far along it is.

The language model is a component

This follows directly from the rest: if the harness carries knowledge, memory and controls, the model can change without the work changing.

A size, not a model

Agents ask for a small, medium or large model; the infrastructure chooses which. Changing model does not require rewriting the agents.

Several providers

The harness works with several model providers and can switch between them.

Swiss hosting as an option

For Swiss companies, requests can be processed by a Swiss host; this is mandatory for the healthcare sector. The choice of models is narrower there, and quality may differ.

Tested like software

Tests that block release

More than 360 test files, about 6,000 cases: contracts, consistency between the interface and the agent, simulated scenarios. A test that is added is never removed.

A single write path

The agent calls the same functions as the interface, with the same server-side controls. It has no parallel route.

What is delivered, what is rolling out

Specialised agents, memory, controls and traceability

Available

In production, within the limits described above.

Scenarios (skills): monthly close, payroll cycle, weekly reconciliation

Available

The first scenarios are available; the library is growing.

Habits confirmed by repetition

Available

A rule becomes a habit after several identical human approvals.

Company usage profile injected into the agent

Available

What Pinnokio observes of the company's usage is made available to the agent.

Agentic parity: the screen and the agent share the same access points

Available

In production.

Talk to Pinnokio from ChatGPT or Claude (MCP)

Rollout in progress

Query Pinnokio from your usual assistant.

See the MCP page

What this harness does not promise

It promises neither the absence of errors nor automatic approval of everything. It limits what the agent can do alone, makes every action verifiable and leaves the decision to the authorised person. We prefer to describe our controls rather than announce zero risk.

See how Pinnokio works

Frequently asked questions

Is Pinnokio a wrapper around ChatGPT?

No. The language model is only a component, and it can be replaced. The work rests on orchestration, business knowledge, memory, controls and the audit trail. For repetitive operations, Pinnokio relies on learned rules and signatures rather than isolated generation.

What happens if the model gets it wrong?

Controls written in code apply before any approval. The entry stays a draft until a person approves it, posting is always subject to approval, and it can be undone by a reversal entry. An error is not ruled out: it is made visible and reversible.

Can I limit what the agent does on its own?

Yes. Tasks proceed within the scope you authorise, and you choose what requires approval. Some actions, such as posting, payments or payroll, always require approval.

Does Pinnokio learn from my corrections?

Yes, for suppliers: a correction made by hand always takes precedence over what Pinnokio learned on its own. A rule becomes a habit after several identical human approvals, and the company's usage profile enriches the agent's context.

Can an agent see another company's data?

Rights are checked per user, per company and per module, and the company concerned comes from the session, not from parameters written by the model. No security certification is claimed on this page.

Where does the model process my data?

By default with the model providers Pinnokio uses. Swiss companies can choose processing by a Swiss host, mandatory for the healthcare sector, with a narrower choice of models.

What is agentic parity?

It is the principle that the agent has no private write path: it uses the same engine, the same access points and the same controls as the screen. You can therefore see on screen how data is structured, what the agent has learned and what it can do, instead of relying on a black box.

Pricing

How much does it cost?

You pay as you go, in credits, with no mandatory subscription. Here is the order of magnitude.

See the full price list
Supplier invoice processed
65 credits
Bank transaction reconciled
35 credits
Document routed
15 credits
Assistant interaction
~3-5 credits

5'000 credits offered on sign-up, no credit card required.

See how it works on your own scenario

A business situation, your tools, your rules: the demo starts from your reality.

See pricing