An AI reads your customer's request and drafts a quote — but never touches your accounting system. A deterministic engine executes the draft under your rules. You approve the exact version. A separate read-only account reads it back and confirms it matches. Every step lands on an append-only record.
Pruvato starts with customer quotations — where a wrong price, a below-floor discount, or a quote that goes silent for six weeks each costs a deal, a margin, or a customer relationship.
The quote is drafted for you and bound to the version you approve. Sending it stays with you — the connection has no permission to message your customer.
Paste the customer's WhatsApp message. The model drafts a plan — line items, prices, terms — grounded against your real catalogue and rules.
Every field is grounded or becomes a question. Numbers come from the customer's text or your price list — never invented, never averaged into existence.
Exceptions reach you as a named decision on an exact document hash. Change one line afterward and the approval no longer covers it. "Ok 👍" is not an approval; this is.
The engine — not the model — performs the work, under the approved plan, with rules enforced in the execution path. A below-floor quote isn't flagged. It cannot be sent.
The part that checks the work reads your systems back independently, and reports Confirmed, Doesn't match — needs you, or Not confirmed yet — never assumed. Every action lands on your record, permanent and searchable by your team — and trustworthy to an auditor.
A system is doing governed AI execution only if all five are true. Fewer than five is something else, and the difference shows up on the day something goes wrong.
What was supposed to happen, what the system says happened, and what your books show. Most tools stop at the second. The verdict here only ever comes from the third.
Two clocks on every row — when it happened, and when it reached the record — because a slow check and a late entry are different things, and the record says which. Drawn from real sandbox runs; identifiers shortened.
Every decision is stamped with the exact rules in force at that moment. Update your rules next month and old records stay judged by the rules of their day — nothing is quietly re-graded.
Two lists, kept separate on purpose: things that need your decision, and things that couldn't be determined yet (a system didn't answer, a check is still due). Blurring those is how real problems hide in noise.
The new quantity stands as a documented exception. Your reason is required and recorded word-for-word — a ruling must say why.
Fix it in Zoho (or ask us to draft the correction), and the same read-only account re-reads your books until they match your approval again.
The same read-only account checks your books again after the fix — the case closes once they actually match your approval.Your ruling never rewrites the mismatch — it's added beside it, so the record keeps both the problem and the decision, in order, forever.
Snapshotting the rules beside an action lets violations be reviewed after the money moved. Here, the rules are what the engine executes under — violations don't need catching, because they can't run.
Watching actions can't see the action that never happened. A declared plan can: the registration that was skipped, the follow-up that never went out — surfaced as Unknown, never assumed done.
The identity that writes holds no power to verify; the identity that verifies is read-only at the provider itself — a ceiling we can prove, by attempting a write and keeping the refusal on record. The record is trustworthy because no one gets to grade their own homework.
Governance is arriving everywhere, and that's good — the question underneath it is who sits in the judging seat. Here, a read-only account reads your system of record and compares values, line by line — no second model forming an opinion about the work. That account holds no permission to write, so its findings stand on their own.
A growing number of products now verify what an AI agent claims it did — checking after the action, so a false "done" can be caught before it reaches a customer. That work is real and worth doing. What Pruvato adds is the layer before: making the wrong action structurally unable to occur in the first place.
These are two different things, and the difference is written down rather than promised. What follows are the default rules for a new connection — yours are generated for your own setup and may differ. The right-hand list isn't a feature we haven't built yet — it's a set of actions this connection is structurally unable to perform in your account.
Confirming that a quotation arrived correctly is done by a separate read-only user in your own Zoho — one that cannot create, edit or delete anything, enforced by Zoho itself rather than by us.
We prove it rather than assert it: that user attempts a write, Zoho refuses, and we keep the refusal on record.
Default rules shown · v1.0.0 · once these are yours, changing any line requires your approval.
Example — what your dashboard shows. Not live customer data.
Three buckets, never blended into one score — a single "98% healthy" number is exactly the kind of reassurance that hides the AED 3,927. Every figure opens to its own quotes.
Right now, Pruvato is a concierge partnership, not a self-serve product. We do the Health Check analysis ourselves; we set up the workflow with each design partner personally; we're in the loop for the decisions that shape how the product itself evolves. As the product matures, more of this becomes self-serve — but pretending we're there today would be inaccurate. Founding partners get setup work and access that later customers will pay for separately; we get to build against real quoting operations instead of assumed ones. That trade is honest, and it's the shape of the company for the next several months.
Pricing shape without a number, because a wrong number is worse than none: Founding-partner terms during the design-partner phase, in exchange for setup work we do with you and unusual access to how the workflow gets shaped. Standard annual contracts at production launch. If pricing certainty matters to you now, that's an honest reason to wait — or to start with the Health Check, which is free and doesn't depend on the platform's commercial model.
The path is the same: Health Check first. It's how we learn your business, and it's how you learn whether the platform's shape actually fits the way you do business.