Controller resource · Journal controls

Journal entry approval controls for human and AI-prepared drafts.

Use this control matrix to evaluate a journal workflow from initiation through posting. The central question is not whether AI touched the entry; it is whether authority, evidence, review, exceptions, and the final posting action are explicit and testable.

Prepared by Sebastian Product & EngineeringUpdated July 20, 2026Educational worksheet · not audit advice
How to use it

Evaluate one real workflow, not a generic promise.

A journal workflow should preserve the difference between preparation and authorization. A balanced entry can still be inappropriate, unsupported, duplicated, mistimed, or outside the preparer’s authority. Automation therefore needs to strengthen the review record instead of treating debit-equals-credit as the finish line.

Test recurring and nonstandard entries separately. Define who may initiate each class, which supporting evidence is required, which reviewer is independent of preparation, and which conditions require escalation. For an agent-prepared entry, retain the source context and reasoning available to the reviewer, but never treat generated reasoning as evidence by itself.

Original controller worksheet

Eight controls to test

  1. 01

    Entry classification

    Ask: Is the entry recurring, nonstandard, estimate-based, system-generated, or correcting?

    Retain: A required classification with policy-linked support requirements.

  2. 02

    Initiator authority

    Ask: Can the named preparer or service initiate this entry type for this entity and period?

    Retain: Role mapping tested against a denied unauthorized attempt.

  3. 03

    Source completeness

    Ask: Are the population, cutoff, calculations, and source versions identifiable?

    Retain: Source reference, parameters, control totals, and calculation support.

  4. 04

    Double-entry validation

    Ask: Do debits equal credits and are required dimensions present?

    Retain: Server-side validation with rejected imbalance and missing-dimension tests.

  5. 05

    Independent review

    Ask: Is approval distinct from preparation for the entry’s risk class?

    Retain: Preparer and reviewer identities, timestamps, and decision history.

  6. 06

    Unusual-entry routing

    Ask: Do timing, amount, account, user, or description anomalies trigger a different review path?

    Retain: Documented risk criteria and exception results retained with the entry.

  7. 07

    Posting boundary

    Ask: Which actor performs the final post, and can preparation bypass that step?

    Retain: A negative test showing a draft cannot post without required authorization.

  8. 08

    Change and reversal history

    Ask: Can the reviewer see edits, rejection, posting, and reversal without overwriting history?

    Retain: Append-only activity or equivalent version history tied to the entry.

Decision tool

Minimum evidence by lifecycle state

The status name matters less than its invariant. A “pending review” record should be impossible to confuse with a posted ledger transaction.

State / scoreMinimum evidenceDecision rule
DraftLines, memo, date, entity, preparer type, source references, and validation result.No ledger effect; editable with history.
Pending reviewBalanced and complete draft plus required support and assigned reviewer.No posting authority; rejection returns with reason.
Posted / rejectedNamed decision-maker, timestamp, final lines, disposition, and immutable activity.Any later change requires a new controlled action.
Completed teaching example

Worked example: agent-prepared payroll accrual

This fictional entry illustrates a controlled lifecycle. It is not a customer result, a posting record, or evidence that a vendor integration exists.

FieldCompleted exampleInterpretation
Entry classRecurring estimate · agent-preparedRecurring does not remove the need to inspect estimate support and period cutoff.
DraftDr Payroll expense 125,000 · Cr Accrued payroll 125,000Balance is necessary but not sufficient for approval.
SupportJune register v3 · headcount bridge · controller policy §4.1The reviewer receives source references and calculation context.
Exception testReject duplicate entity/period/source-version keyA retry cannot silently create a second draft for the same source.
DispositionPending review · no ledger effectA named reviewer must approve the final posting action.
Product boundary

How this maps to Sebastian today

Sebastian persists manual, imported, and agent-prepared entries in one journal lifecycle. The agent tool uses an explicit approval interrupt before execution, validates double-entry balance, and creates an entry in pending review with agent authorship and an optional reasoning trace.

A reviewer can inspect and post or reject the persisted entry. The agent tool itself does not post. That distinction is the control boundary this worksheet is designed to test.

The public product does not claim broad ERP journal write-back, enforced segregation-of-duties policy, or period-lock enforcement. Buyers should verify those requirements against their ERP and control environment rather than infer them from the draft workflow.

Primary references

Standards context, with applicability boundaries.

Go deeper

See the work up close.

Journal entry automation

See Sebastian’s implemented approval-gated draft lifecycle.

Close automation checklist

Classify the broader close workflow before automating it.

Security and controls

Review exact product control boundaries and tenant protections.

Keep your ERP. Close and plan in one pane.

AI for accounting and FP&A on the ledger you already run. No migration. No rip and replace.

Agents at work · Matching an invoice to its PO line…