Demo Guide
How to run this demonstration in front of a finance or security audience, including timings, talking points and honest answers to the hard questions.
- Reset the demo so every scenario starts from its intended state.
- Turn on presenter mode to reveal talking points on each page.
- State the disclaimer once, clearly: synthetic data, no production connectivity, not production ready.
- Decide your audience: finance first, or security first. Do not mix the two runs.
Agent-operated. Finance-controlled. Every journal explainable.
Agents do the preparation work. Deterministic controls decide what is allowed. Authorized people approve anything material. The audit trail explains all of it.
| Time | Do this | Say this |
|---|---|---|
| 0:00 | Open the Executive Walkthrough | Set the problem: journals fail at Oracle submission for avoidable reasons, and exceptions are found late. |
| 1:30 | Close Command Centre | Show the shape of the close: volume, value, risk and the exceptions that need attention. |
| 3:00 | Open JE-2026-09161 in the Journal Workbench | A network infrastructure accrual with a high risk score. |
| 4:00 | Run Agentic Review | Nine stages, each with a named agent, a finding and a human checkpoint. |
| 5:30 | Controls tab | A deterministic control has failed: the journal exceeds its evidence by CAD 18,250. |
| 6:30 | Supporting Evidence | Show the vendor statement and the checksum linkage. |
| 7:30 | Correct the amount | A person makes the decision and records a reason. Controls rerun and risk falls. |
| 9:00 | Oracle Upload Readiness | Structural readiness is assessed separately from accounting validity. |
| 10:00 | Approvals | An independent controller approves with a comment. Self-approval is impossible. |
| 11:00 | Simulate Oracle Submission | A synthetic document number is issued. No production connectivity. |
| 11:30 | Audit Trail | Every action, agent version, rule version and reason, in one immutable record. |
| Time | Do this | Say this |
|---|---|---|
| 0:00 | CISO Walkthrough scene 1 | Agents change the risk surface. Identity, boundaries, logging and reversibility. |
| 1:30 | Agent Team | Named owners, scoped tools, declared prohibited actions and emergency disable. |
| 3:00 | Disable an agent | Show the process continuing under human control. |
| 4:00 | Security & Compliance, denied actions | The strongest evidence is what the system refused to do. |
| 5:30 | Threat scenarios | Prompt injection, exfiltration, replay, identity risk and model unavailability. |
| 6:30 | Audit Trail | Append-only, hash chained, deletion attempts recorded. |
| 7:30 | Proof of Value production gates | Twenty-eight gates before any production use. |
No. Mandatory rules are deterministic code. AI explains findings and recommends actions; a person decides anything material.
No. Approval is reserved for authorized humans, and posting in this prototype is simulated only.
Deterministic controls still run and still block. A wrong explanation cannot pass an invalid journal.
The process fails closed to manual preparation. Controls and audit continue.
No. There is no production connectivity of any kind. Submission responses are synthetic.
No. Every persona, vendor, journal and amount is fictional and generated locally.
In browser local storage for demonstration state only. That is not a security boundary and is not a production design.
Threat modelling, penetration testing, DLP and prompt-injection testing, Oracle interface design approval, identity and network approval, and the full set of production gates.