Skip to content

Copilots for finance ops

Copilots that cite their sources and stop before touching money.

Finance teams ask the same questions of the same documents every week. We build copilots that answer from your policies, contracts and ledgers with a citation on every claim, respect the permissions of the person asking, and hand anything that moves money to a human for approval.

Where it fits

  • The problem

    Staff hunt policy answers in PDFs and Slack threads, then ask a colleague to confirm. New-joiner questions queue behind one expert. The chat tool the team tried last year answered confidently with no source, no record of who asked what, and no regard for who was allowed to see the file.

  • What we build

    A retrieval grounded assistant over your own corpus, with access controls travelling with the query so a user only sees passages they could open themselves. Tools are declared and narrow. Read steps run freely, write steps pause for approval, and every action is logged with the prompt and the sources.

  • How we engage

    Senior engineers build it against your identity provider and your document stores, on infrastructure you already run. No hosted middleman holds your corpus. The retriever, the tool definitions and the approval flow are yours to change, and the licence terms are written down before the first commit.

What we build

Six parts of a copilot a risk officer will sign off.

Answers with citations

Every answer names the paragraph and document version it came from, with a link that opens the source. Users learn quickly which questions the corpus can support. When retrieval finds nothing close enough, the copilot says so and offers the nearest policy owner instead of composing something plausible.

Permissions on every query

The user's identity travels with the retrieval call, so a contractor searching contract terms sees only what their group already opens in the document store. Filters are applied in the index query rather than after generation. Audit logs record the identity, the query and the passages returned.

Multi step workflows

A close checklist or a dispute case involves several lookups and a draft. The copilot plans the steps, shows them, and runs the read only ones. State is stored per case so a colleague can pick it up, and a failed step surfaces rather than being retried silently.

Approval before money moves

Any step that changes a balance, releases a payment or edits a customer record produces a proposal with its evidence attached, so nothing posts on the model's word alone. A named approver confirms in the system of record. Limits and dual approval come from your existing policy, and the copilot cannot raise its own limit.

Narrow tool surface

Tools are declared one at a time with typed inputs, scoped credentials and rate limits. There is no general shell, no free form SQL against production, no outbound call the security review has not seen. A new tool is a code change with a review, and the log shows every invocation.

Answer quality tracking

Thumbs, override rates and the questions that ended in refusal all feed a weekly review. Gaps point at missing documents more often than at model weakness. Regression tests over past questions run before each release, so a prompt change cannot quietly break the answers finance already relies on.

In production

Try a grounded copilot with citations and approvals

The demo answers from a synthetic policy set, shows the passage behind each claim, and holds payment actions for approval.

How we work

  • Discover

    Systems, constraints, and the regulation you operate under get mapped before implementation starts, so the design accounts for what already runs and for what examiners will ask about.

  • Architect

    A design that fits your stack. Integration-first, self-hostable, and built to change as rules, regulation, and volume do.

  • Build

    Senior engineers ship in tight increments, each tested and reviewed as it goes, so the system is reviewable at every step instead of only at the end.

  • Harden

    Security, compliance, and load-testing run inside the build, so controls, audit trails, and peak-volume behavior are proven before launch.

  • Run

    The handover includes clean, documented systems, with the option to keep the same engineers operating them once they are live.

Why Oxagile

  • Citations make it reviewable

    An answer without a source cannot be checked, so nobody trusts it and the questions go back to the expert. We wire the citation into the response format and test for it, which means a reviewer can confirm or reject in seconds and the copilot earns its use.

  • Permissions before convenience

    Retrieval over a shared index is the fastest way to leak a board pack. Access checks sit in the query path and are tested with accounts from each role, including leavers. Logs show who asked what, which is what your auditors and your privacy team will request first.

  • Humans hold the money path

    The copilot drafts, gathers evidence and explains its reasoning against sources. A person approves anything with financial effect, under the limits your policy already sets. Exceptions route to a named owner with the case history attached, so an unusual request does not stall in a queue.

20+
Years in software engineering
300+
Engineers
50+
Clients incl. Fortune 500

Questions

How do we stop it answering outside its knowledge?

Retrieval scores gate the response. Below the threshold the copilot declines and points at the owner of that topic, and the unanswered question is logged as a content gap. Prompts constrain it to the supplied passages, and evaluation includes questions the corpus cannot answer, so silence gets tested as carefully as accuracy.

Can an agent move money on its own?

No. Write actions are proposals until a person with the right authority approves them in the system of record. Amount limits, dual approval and segregation of duties come from your policy, applied outside the model where they cannot be argued away by a prompt. Every proposal, approval and rejection is logged with the evidence it carried.

What does it connect to?

Document stores, your identity provider, ticketing, the ERP or core banking API, and whatever data warehouse holds the reporting tables. Connectors run with scoped service accounts and read only credentials where reading is all that is needed. We start with two or three sources that answer the questions your team repeats most, then widen once the logs show what people ask.

How do you handle audit and model risk review?

Documentation comes with the build. Purpose, in-scope questions, tool inventory, permission model, logging and the human approval points get written for your second line. Conversation logs with sources and approvals give evidence of control operation. Release notes record prompt, model and index changes, so a review covers a known version of the system.

Part of AI in Finance

AI put to work in finance operations, grounded, governed, and running in production.

Get AI into production,
not just a demo.

Have a workflow begging for AI, whether documents, copilots or forecasting? Tell us the use case and we'll take it to production, governed for risk.