The mechanism

The workflow the Health Check leads into.

An AI reads your customer's request and drafts a quote — but never touches your accounting system. A deterministic engine executes the draft under your rules. You approve the exact version. A separate read-only account reads it back and confirms it matches. Every step lands on an append-only record.

Pruvato starts with customer quotations — where a wrong price, a below-floor discount, or a quote that goes silent for six weeks each costs a deal, a margin, or a customer relationship.

See if this fits your business — start a Health Check →

How it works

One governed path from request to proven outcome.

Describe the work AI proposes

Paste the customer's WhatsApp message. The model drafts a plan — line items, prices, terms — grounded against your real catalogue and rules.

The compiler disposes Deterministic

Every field is grounded or becomes a question. Numbers come from the customer's text or your price list — never invented, never averaged into existence.

You approve — bound to the version Human

Exceptions reach you as a named decision on an exact document hash. Change one line afterward and the approval no longer covers it. "Ok 👍" is not an approval; this is.

Deterministic execution Engine

The engine — not the model — performs the work, under the approved plan, with rules enforced in the execution path. A below-floor quote isn't flagged. It cannot be sent.

Independent verification, on the record Independent check

The part that checks the work reads your systems back independently, and reports Confirmed, Doesn't match — needs you, or Not confirmed yet — never assumed. Every action lands on your record, permanent and searchable by your team — and trustworthy to an auditor.

The five properties

A system is doing governed AI execution only if all five are true. Fewer than five is something else, and the difference shows up on the day something goes wrong.

01The AI has no hands.It proposes; only the deterministic engine touches your systems.
02Rules are enforced in the path.A rule-breaking action doesn't get flagged — it can't run.
03Nothing is invented.Every value grounds to a real source, or the system asks.
04Authority is granted before the action,bound to the exact version approved.
05The result is checked by something that didn't do the work— a read-only account, reading your own books, comparing to what was approved.

The full definition, and the honest limits →

Proof, up close

Every action is three stories. Only one of them counts.

What was supposed to happen, what the system says happened, and what your books show. Most tools stop at the second. The verdict here only ever comes from the third.

Expectedfrom the version you approved Quote QT-000148 · AED 17,010.00
3 lines · VAT 5% excl. · valid to 03 Sep
approved by name, tied to fingerprint b8ef…
Claimedwhat the tool reported — unverified "Registered successfully"
a receipt is what we were told,
not what is true — so it's drawn in a dashed box
Observedread back from your Zoho, independently 1 quotation found · matches
read by a separate account that cannot write
observed 14:31 · compared line by line
Confirmed. Your books agree with what you approved, checked by an independent read-back. That's the only green we show.
Expectedfrom the version you approved Quote QT-000152 · line 2 · qty 50
GI Conduit 25mm × 50 @ 28.00
Claimednothing — the change was made quietly No report at all
edits made behind the system's back
produce no claim to check, so nothing here would ever raise the alarm
Observedread back from your Zoho, independently Line 2 quantity is 65
50 ≠ 65 · exactly one field differs
named precisely, nothing else disturbed
Doesn't match — you hear it first. A quantity changed after your approval. It's flagged with the exact line and nothing goes further until you decide.

The trail behind the green box

01Draft prepared and priced from your own listhappened 10:51:10 · recorded 10:51:10prepared
02Prices confirmed current against your cataloguehappened 10:51:12 · recorded 10:51:12 · confirmed live, against the catalogue at that momentchecked
03You approved this exact version, by namehappened 10:51:40 · recorded 10:51:40 · fingerprint b8ef… sealed to your answeryou
04Registered in Zoho — the tool's own receipthappened 10:51:44 · recorded 10:51:45 · a receipt is a claim, so it can't close the caseclaimed
05Read back by the read-only account — matches your approvalhappened 10:51:49 · recorded 10:51:49 · this is the row that actually turns the case greenconfirmed

Two clocks on every row — when it happened, and when it reached the record — because a slow check and a late entry are different things, and the record says which. Drawn from real sandbox runs; identifiers shortened.

See three real receipts →

Your rules, sealed

Decided under your rules — and the record keeps which rules.

Every decision is stamped with the exact rules in force at that moment. Update your rules next month and old records stay judged by the rules of their day — nothing is quietly re-graded.

The facts at decision time
Quote totalAED 17,010.00 Largest line discount0% Validityto 03 Sep 2026 Effect requesteddraft only Rules versionyour-rules · v1.0.0
Checked against your rules — all passed
Discount floor respectedno line priced below your declared minimum
Validity date presentevery quote carries an expiry — quotes that can't expire die undecided
Draft-only ceilingnothing may send, accept, or change status on your behalf
Named approval required for this valueabove your threshold, a person answers — every time
Sealed, not photographed: these rules aren't a note beside the action — they're what the engine ran under. A quote that breaks them doesn't get flagged for review. It stops, and asks you. And changing any rule requires your approval, tied to the new version.
When it doesn't match

Exceptions come to you with the facts — and your ruling goes on the record.

Two lists, kept separate on purpose: things that need your decision, and things that couldn't be determined yet (a system didn't answer, a check is still due). Blurring those is how real problems hide in noise.

Needs your decision

Quote in Zoho differs from what you approved

You approvedline 2 · qty 50
Your Zoho showsline 2 · qty 65
Value affectedAED 441.00

Accept the change

The new quantity stands as a documented exception. Your reason is required and recorded word-for-word — a ruling must say why.

Have it corrected — then we re-check

Fix it in Zoho (or ask us to draft the correction), and the same read-only account re-reads your books until they match your approval again.

The same read-only account checks your books again after the fix — the case closes once they actually match your approval.

Your ruling never rewrites the mismatch — it's added beside it, so the record keeps both the problem and the decision, in order, forever.

Why it's different

Evidence tools watch agents. Pruvato governs the work.

Rules run inside execution

Policy in the execution path

Snapshotting the rules beside an action lets violations be reviewed after the money moved. Here, the rules are what the engine executes under — violations don't need catching, because they can't run.

Omissions caught

The absent step has nowhere to hide

Watching actions can't see the action that never happened. A declared plan can: the registration that was skipped, the follow-up that never went out — surfaced as Unknown, never assumed done.

No self-vouching

Separated by construction

The identity that writes holds no power to verify; the identity that verifies is read-only at the provider itself — a ceiling we can prove, by attempting a write and keeping the refusal on record. The record is trustworthy because no one gets to grade their own homework.

Judged by a program

Judged deterministically

Governance is arriving everywhere, and that's good — the question underneath it is who sits in the judging seat. Here, a read-only account reads your system of record and compares values, line by line — no second model forming an opinion about the work. That account holds no permission to write, so its findings stand on their own.

Where this sits

The layer before the check.

A growing number of products now verify what an AI agent claims it did — checking after the action, so a false "done" can be caught before it reaches a customer. That work is real and worth doing. What Pruvato adds is the layer before: making the wrong action structurally unable to occur in the first place.

What it can do inside your account

What it can do, and what it's allowed to do here.

These are two different things, and the difference is written down rather than promised. What follows are the default rules for a new connection — yours are generated for your own setup and may differ. The right-hand list isn't a feature we haven't built yet — it's a set of actions this connection is structurally unable to perform in your account.

Authorised hereWhat it may do
  • Create a draft quotation, after you approve that exact version
  • Read your customers and price list, to ground the quote in your real data
  • Read a quotation back to confirm it arrived exactly as approved
Not authorisedWhat it cannot do
  • Send a quotation to your customerSending stays with you — the connection has no permission for it
  • Change a quotation's status, or accept one on your behalfDraft is the ceiling; no status transition is permitted
  • Edit or delete anything already in your booksNo edit or delete permission exists on this connection
  • Touch invoices, payments, or anything outside quotationsOutside the agreed scope entirely
The part that checks the work holds no power to change it

Confirming that a quotation arrived correctly is done by a separate read-only user in your own Zoho — one that cannot create, edit or delete anything, enforced by Zoho itself rather than by us.

We prove it rather than assert it: that user attempts a write, Zoho refuses, and we keep the refusal on record.

Default rules shown · v1.0.0 · once these are yours, changing any line requires your approval.

Product status

What this looks like across a whole account.

Example — what your dashboard shows. Not live customer data.

Confirmed in your booksAED 812,400independently read back and matched — the only figure we call done
Doesn't match — with youAED 3,9271 quote differs from its approval · awaiting your ruling
Not confirmed yetAED 41,780checks still due or a system hasn't answered — never counted as done

Three buckets, never blended into one score — a single "98% healthy" number is exactly the kind of reassurance that hides the AED 3,927. Every figure opens to its own quotes.

The current commercial shape

What kind of thing this is, right now.

Right now, Pruvato is a concierge partnership, not a self-serve product. We do the Health Check analysis ourselves; we set up the workflow with each design partner personally; we're in the loop for the decisions that shape how the product itself evolves. As the product matures, more of this becomes self-serve — but pretending we're there today would be inaccurate. Founding partners get setup work and access that later customers will pay for separately; we get to build against real quoting operations instead of assumed ones. That trade is honest, and it's the shape of the company for the next several months.

Pricing shape without a number, because a wrong number is worse than none: Founding-partner terms during the design-partner phase, in exchange for setup work we do with you and unusual access to how the workflow gets shaped. Standard annual contracts at production launch. If pricing certainty matters to you now, that's an honest reason to wait — or to start with the Health Check, which is free and doesn't depend on the platform's commercial model.

Interested in the platform?

The path is the same: Health Check first. It's how we learn your business, and it's how you learn whether the platform's shape actually fits the way you do business.

Email partners@pruvato.com →