GoldFinch AI helps organizations automate document processing, analyze operational data, and flag actions that need attention while preserving human oversight and existing business controls.
GoldFinch is built on Salesforce and uses the organization’s authorized business data to provide context-aware assistance. AI-generated results are designed to support employees—not replace their judgment, approval responsibilities, or established accounting and operational controls.
Security Within Salesforce
GoldFinch AI operates within the security framework established for your Salesforce organization. Access to GoldFinch records and functions is controlled through applicable Salesforce and GoldFinch security settings, including:
- User authentication
- Profiles and permission sets
- Object and field-level permissions
- Record-level sharing
- Role and organizational access
- Approval processes
- Salesforce audit and activity records
Users should receive only the permissions required for their responsibilities. For example, a user who can review an AI-generated purchase invoice does not automatically need permission to post or approve it.
Your organization remains responsible for maintaining appropriate user access, segregation of duties, approval limits, and security policies.
How Business Data Is Used
GoldFinch AI may use authorized business information to understand documents, validate extracted information, analyze operational conditions, and prepare recommendations.
Depending on the enabled feature, this information may include:
- Vendors and customers
- Purchase orders and receipts
- Sales orders
- Items and units of measure
- Inventory and warehouse information
- Supply and demand records
- Accounting dimensions
- Transaction statuses
- Documents submitted for processing
GoldFinch uses this business context to produce more useful and reliable results than general-purpose AI tools that do not understand the organization’s ERP data or business rules.
Data access is limited by the user’s permissions and the configuration of the applicable GoldFinch AI service.
AI Service Providers
Certain GoldFinch AI capabilities may use approved third-party AI services to analyze submitted information. The AI provider and processing method may vary by feature, product release, customer agreement, and configuration.
Before enabling an AI service, organizations should review:
- The information that will be processed
- The selected AI service provider
- Applicable data-processing terms
- Data location or residency requirements
- Retention policies
- Industry-specific confidentiality requirements
- Internal policies governing AI use
GoldFinch can provide additional information about the applicable service architecture and configuration during implementation or security review.
AI Document Processing
GoldFinch AI Document Processing can extract information from documents and validate it against live GoldFinch data.
For purchase invoices, validation may include:
- Matching the vendor
- Identifying purchase orders and receipts
- Matching items and units of measure
- Comparing quantities and amounts
- Identifying missing information
- Detecting potential duplicate invoices
- Applying relevant accounting dimensions
- Highlighting exceptions for review
AI-assisted extraction reduces manual entry, but it does not guarantee that every value will be interpreted correctly. Document quality, layout, handwriting, incomplete information, and unusual formats can affect the result.
Human Review Remains Required
GoldFinch AI is designed around human review and user-approved action.
AI-generated results may be incomplete, inaccurate, or require additional business context. Users should review important information before approving, posting, communicating, or acting on it.
For example, GoldFinch AI may prepare a draft purchase invoice, but an authorized user should verify:
- The vendor and invoice number
- Invoice and posting dates
- Purchase order and receipt matches
- Quantities, prices, taxes, and totals
- General ledger accounts and dimensions
- Payment terms
- Supporting documents
- Identified warnings or exceptions
Existing GoldFinch permissions, approval workflows, and posting controls continue to apply. AI assistance does not give a user authority beyond the permissions already assigned to that user.
Drafts, Recommendations, and Approved Actions
GoldFinch AI may produce:
- Draft business transactions
- Extracted document information
- Exception summaries
- Planning insights
- Recommended next steps
- Draft customer or vendor communications
- Explanations of operational or accounting conditions
Treat these outputs as decision-support information. Where a feature allows GoldFinch AI or GoldFinch Scout to initiate an action, the action remains subject to configured permissions, business rules, and approval requirements.
GoldFinch AI does not replace management authorization, accounting review, or professional judgment.
Correcting AI-Generated Results
If an AI-generated result is incorrect or incomplete, authorized users can review and correct the information before completing the transaction.
Depending on the feature, users may be able to:
- Edit extracted values
- Correct document mappings
- Update the draft transaction
- Resolve validation exceptions
- Provide missing information
- Regenerate the result
- Reject or delete the draft
- Process the document again
Organizations should establish procedures to review AI-generated results and escalate unusual or high-risk exceptions.
Recommended Customer Controls
We recommend that organizations:
- Limit AI feature access to authorized users
- Maintain appropriate segregation of duties
- Require review before posting financial transactions
- Use approval workflows for material or sensitive transactions
- Review user permissions regularly
- Avoid submitting information that is unnecessary for the business process
- Train users to evaluate AI-generated recommendations critically
- Monitor exceptions, corrections, and processing results
- Test significant configuration changes in a sandbox
- Periodically review applicable AI-provider and data-processing terms
Responsible Use
GoldFinch AI is intended to improve productivity, identify exceptions, and help users make informed decisions. Do not treat it as an independent authority for accounting, legal, tax, regulatory, or operational decisions.
Organizations remain responsible for:
- Reviewing AI-generated information
- Approving transactions
- Maintaining internal controls
- Protecting confidential data
- Complying with applicable laws and policies
- Determining whether an AI-assisted action is appropriate
Learn More
GoldFinch AI features, service providers, and available controls may vary by edition, release, and customer configuration.
For questions about security, data processing, permissions, or enabling GoldFinch AI for your organization, contact GoldFinch Clientcare or your GoldFinch implementation consultant.
Comments
0 comments
Please sign in to leave a comment.