Operations
Finance Operator Runbooks and Recovery
Daily, period-end, custody, automation, integration, export, and incident procedures for Finance Management.
First created Last updated
Evidence to record for every procedure
Record partner/event scope, currency, cutoff/timezone, record/reference, command receipt/correlation ID, actor role, resulting lifecycle, journal/audit link, and sanitized screenshot when required. Never copy tokens, full bank details, provider secrets, personal data, raw Sanity URLs, or URL query parameters into tickets or docs.
Daily transaction and exception review
- Open Overview and record source, cutoff, freshness, currency, pending outflows, reconciliation coverage, and exceptions.
- Open Transactions with the same scope and inspect unreconciled, missing-evidence, reversal, and unusual-amount filters.
- Drill into each exception; verify balanced lines, source, dimensions, evidence, approvals, and receipt.
- Correct through the owning domain or a linked reversal/correction. Never edit a posted line.
- Success evidence is a reproducible currency-scoped total and resolved or assigned exceptions.
Escalate immediately for an unbalanced journal, unexplained cross-partner/event row, duplicate authoritative transition, or total that cannot be reproduced.
Outflow request through payment
- Create the request with payee, account, scope, exact amount/currency, due date, purpose, reference, and evidence.
- Submit once and retain the receipt. A different authorized checker reviews policy, evidence, threshold, period, and account.
- Schedule only after approval. The payer records external payment reference/evidence and marks paid once.
- Verify canonical paid state, balanced journal effect, audit chain, and provider notification state.
- Cancel only before payment where allowed; after posting use the approved correction/reversal path.
On timeout, search by reference/idempotency and inspect the receipt before retrying. Never create a replacement request merely because the browser did not receive the first response.
Statement import and reconciliation commit
- Choose account/currency and create a statement session.
- Upload a supported statement, then review parsed count, date range, opening/closing values, digest, duplicates, and errors.
- Resolve lines by match, classify, exclude with reason, or permitted adjustment. Confirm suggestions against amount, date, reference, account, and source.
- Review the evidence-package summary and acknowledgement. Commit only when populations are complete and the difference is acceptable under policy.
- Verify the sealed session, cleared book result, remaining exceptions, journal links, and audit receipt.
If candidates become stale, refresh and rematch. If the digest or duplicate status changes, stop and investigate the source file. A committed session is corrected through accountable follow-up, not destructive reopen.
Event finance and mapping review
- Select an event and currency on Overview or Events.
- Record authoritative available cash, pending outflows, book net, coverage, exceptions, source, cutoff, and freshness.
- Drill into transactions, accounts, categories, settlement, and reconciliation state.
- If mapping is wrong, preview the effective-date impact and check conflicts before submitting the versioned change.
- Reopen the same event/currency snapshot and confirm the expected server-owned result.
Missing snapshots must appear unavailable. Do not estimate by dividing partner totals.
Bill, invoice, expense, and budget operations
- Payable: verify vendor/reference uniqueness, dates, currency, lines, tax, dimensions, evidence, approval, outstanding, and payment applications. Credits and partial payments retain history.
- Receivable: verify debtor, terms, lines, due date, allocations, unapplied collection, outstanding, aging, and journal effect. Never over-allocate.
- Expense: verify claimant, itemized rows, dates, scope, evidence, policy results, exception approval, and approved outstanding before reimbursement.
- Budget: verify version, owner, period, currency, dimensions, exact line total, revisions/transfers, actuals, commitments, available, variance, thresholds, and publication state.
For all four, stop on duplicate reference, locked period, missing/quarantined evidence, stale version, maker-checker conflict, or mixed-currency total.
Period close and correction
- Complete statement reconciliation and inspect trial balance/summary.
- Resolve checklist items and exceptions; assign an owner for every unresolved item.
- Collect required independent sign-offs and evidence.
- Submit close once. Verify lock state and the close receipt.
- Attempt a safe read-only post-close check and confirm normal posting is rejected.
Reopen only through an authorized reasoned command, then perform the correction and re-close with a complete audit chain. A direct edit to closed-period journal truth is prohibited.
Custody checkout, count, handover, and close
- Bind custodian, cash account, event, purpose, and currency.
- Enter denomination counts in the guided rows; independently compare their calculated opening total with physical cash.
- Record movements as they occur. The assigned custodian acknowledges and counts; do not share an actor session.
- At handover or return, both required actors count and acknowledge the same denomination result.
- If counted differs from expected, record the discrepancy and escalate under policy; normal close must remain blocked.
- Success evidence is a closed session with expected, counted, difference, participants, timestamps, and audit receipt.
For offline/provider failure, preserve the physical chain of custody and controlled evidence; do not invent a browser completion. Reconcile when the authoritative service returns.
Automation failure, quarantine, and replay
- Open the rule and job detail; record condition/action version, destination type, attempts, lease, error class, next retry, and provider receipt.
- Test/dry-run the rule against the intended scope. Disable only when continued execution is unsafe.
- Fix configuration or reauthorize the linked destination. Wait for an active lease or reclaim only after policy-defined expiry.
- Replay from the canonical job control when idempotency confirms no duplicate authoritative action.
- Verify job completion, downstream receipt, and audit chain.
Never copy bot tokens or raw destination identifiers into screenshots. A delivered notification is not proof that the underlying finance mutation succeeded; verify the authoritative record.
Integration connect, sync, and recovery
- Choose bank, accounting, or interchange type and review requested scopes.
- Connect/test, map accounts, and preview initial import boundaries before enabling sync.
- Verify last/next sync, imported/duplicate/rejected counts, health, and mapping coverage.
- On revocation or credential rotation, pause, reauthorize, retest, and resume from the recorded checkpoint.
- Disconnect only after reviewing pending jobs, import scope, retained audit/evidence, and downstream effect.
On duplicate imports, compare source hashes and idempotency receipts. On stale leases, do not launch competing manual jobs until expiry/reclaim rules are satisfied.
Account and policy administration
- Review current version and impact preview.
- For a cash account, choose a ledger account owned by the same partner and with matching currency.
- Set opening balance only before postings. Once used, do not change ledger, currency, or opening balance; archive instead of deleting history.
- For defaults, roles, thresholds, close/custody policy, numbering, currencies, or notifications, record effective behavior and affected workflows.
- Submit the versioned change and verify refreshed settings plus audit receipt.
Export, incident, and restore response
For export, preserve requested scope, cutoff, currency grouping, result count, schema/profile version, digest, expiry, requester, and proxy artifact receipt. Treat an export without disclosed truncation or row count as incomplete.
For an incident, collect visible code/message, correlation ID, route, timestamp, partner/event without private identifiers, browser state, last safe action, and whether retry occurred. Stop repeated mutation on conflict, lock, unknown timeout, evidence quarantine, custody difference, or provider ambiguity.
After restore, compare migration set, journal counts/digest, currency/event aggregates, cash balances, allocations, reconciliation sessions, custody sessions, close locks, job leases, evidence metadata, and audit receipts at the same cutoff. Logical fixture digest success is useful but does not replace a native database restore and hosted canary.
Escalation ownership
| Symptom | First owner | Escalate when |
|---|---|---|
| Validation or stale version | Finance operator | Current projection cannot be safely reapplied |
| Approval/threshold/lock | Finance administrator or close owner | Policy appears inconsistent or blocks required correction |
| Custody difference | Custody supervisor and finance lead | Difference remains unexplained or dual control failed |
| Provider revocation/sync failure | Integration owner | Reauthorization, checkpoint, or idempotency is uncertain |
| Missing/quarantined evidence | Evidence/security operator | Scan, ownership, or retention state is unclear |
| Authorization or cross-scope exposure | Security/platform owner | Any unauthorized row, action, or artifact is visible |
| Journal imbalance/duplicate transition | Finance and engineering incident leads | Immediately; treat as integrity incident |
| Restore mismatch | Database/platform owner | Any authoritative digest or population differs |