Actions and tools
Revizo AI does not “know” what to do in the sense that it has access of its own to the system. It receives a fixed instruction, a catalogue of allowed tools, and the context the user is in. From that it formulates a reply or proposes one or more tool calls. Revizo executes the call — or presents it to the user as a card.
This page describes the four mechanisms that govern this, and lists all tools with risk class.
1. Fixed instructions (system prompt)
Every request starts with an instruction Revizo has written and versions in code. It specifies among other things:
- Identity and scope. The assistant is called Revizo, replies in Norwegian, and only answers questions about Revizo, Norwegian accounting deadlines (facts), current statutory text via Lovdata, and the user’s own data.
- Prohibitions. Never accounting or legal advice. Never invent deadlines, rates, or statutory text. Never show data from other organisations, national ID numbers, or bank account numbers. Never discuss competitors, prices, politics, or create creative content.
- Honesty about actions. Never say that something has been done before the tool has returned a successful result. Never claim that a task or routine “already exists” unless a tool in the conversation has shown it.
- Required disclaimers. Deadlines shall always be followed by “Verify current deadlines at skatteetaten.no”. Legal quotations shall always have act, section, and a link to Lovdata, with an encouragement to verify.
- Tool guidance. When an action should be answered in the chat (reading) versus when it should navigate (display). Rule of thumb in the instruction: “When in doubt, reply in the chat. It is safer.”
The instruction is a steering document for the model, not a security boundary. The security boundaries sit in the tools and in the server’s controls — see Security controls.
2. Tool catalogue
The model can only call tools that exist in the catalogue. Each tool has a name, a description of when it should be used, and a strict schema for the arguments. The catalogue is filtered per organisation:
lookup_lovdatais only included when the organisation has Lovdata access.- Kundetiltak tools (AML) are only included when the organisation’s plan includes Kundetiltak.
- Tripletex tools are only included when Tripletex actions are enabled.
Risk classes
| Class | Meaning | Control |
|---|---|---|
| L — Read | Returns data, changes nothing | Tenant filter. No confirmation. |
| V — Display | Changes only what the user sees (filters, navigation) | No data is changed. No confirmation. |
| S — Write in Revizo | Creates or changes data in the organisation | Executed when the user has asked for it. Logged in the audit log. |
| K — Card | The tool writes nothing itself; it shows a card | Executed only when the user clicks the card. |
| U — Outbound | Sends something to people outside the organisation | Requires a card (Send) or explicit two-step confirmation with a number. |
| R — Accounting system | Writes to the customer’s accounting system | Only when the integration is enabled. Logged. |
Clients and reconciliation
| Tool | Class | What it does |
|---|---|---|
search_clients | L | Finds clients by name or account number |
get_client_status | L | Status for one client: transactions, unmatched, matches |
get_unmatched_summary | L | Unmatched items per client |
get_clients_by_assigned | L | Clients distributed by responsible person |
get_clients_with_deviation | L | Clients with deviation above threshold |
get_clients_summary | L | Totals for the organisation |
compare_client_balances | V | Opens balance comparison for two or more clients |
filter_clients_by_assigned · filter_clients_by_deviation · filter_clients_unreconciled · clear_client_filters · apply_saved_view · list_saved_views | V / L | Filters the client list in the interface |
run_smart_match | S | Runs Smart Match once for one client. Verifies that the client belongs to the organisation. Logs match.created. |
send_report_email | S / U | Sends a PDF report with open items. Default recipient is the user themselves; another recipient only when the user specifies it. |
run_anomaly_scan · get_anomaly_findings | S / L | Runs and reads anomaly detection on transaction data |
open_close_period · get_close_period_status · run_close_auto_checks | S / L | Period close: open, read status, run automatic checks |
Tasks and smart tasks
| Tool | Class | What it does |
|---|---|---|
get_my_tasks | L | Fetches tasks the user has access to see |
create_task · create_tasks_batch | S | Creates tasks. Logs task.created. |
update_task · update_task_status · add_subtasks · remove_subtasks · update_subtasks_checked · add_task_note | S | Changes tasks the user can see. Logs task.updated. |
create_smart_match_task | S | Recurring Smart Match for one client. The instruction requires a summary and “yes” before the call; the first cycle runs on creation. |
create_document_request_task | K / U | Shows a send card with recipient and message. The email is sent only when the user presses Send. The task is completed when the files have been uploaded. |
redistribute_absent_tasks | L | Proposes distribution of a colleague’s tasks. Moves nothing — the user completes it in “Transfer tasks”. |
Accounts and routines
| Tool | Class | What it does |
|---|---|---|
search_accounts | L | Finds accounts in the chart of accounts |
propose_account_description | K | Shows a proposed routine description as a preview. Saved only on Save. HTML is sanitised server-side. Existing routine text is kept outside the model’s context. |
Contacts and communication
| Tool | Class | What it does |
|---|---|---|
lookup_contact | L | Looks up a contact; multiple hits give a choice card |
send_message_to_contact | U | Sends email to a registered contact with text the user has confirmed in the conversation. Logs agent.message_sent with recipient. See the note below. |
get_notification_preferences · update_notification_preference | L / S | Reads and changes the user’s own notification channels |
open_team_chat | V | Opens team chat with a colleague |
Calendar, team, and navigation
| Tool | Class | What it does |
|---|---|---|
create_reminder · deactivate_reminder · get_my_reminders · get_my_calendar | S / L | The user’s own reminders and calendar. Logs reminder.created / reminder.deleted. |
get_team_workload · get_team_absences · get_time_savings_report | L | Aggregated workload, absence, and time savings |
navigate_to · list_tutorials · get_upcoming_deadlines | V / L | Navigation, guided walkthroughs, deadlines |
switch_dashboard_layout · create_dashboard_layout | V / S | The user’s dashboard |
list_archive_folders · search_archive_documents | L | Folders and document metadata in the archive — not document content |
log_feature_request | S | Registers a request to the Revizo team |
ask_choice | K | Shows a choice card. Max one per reply. |
Export and lookups
| Tool | Class | What it does |
|---|---|---|
create_export | S / K | Creates Excel, CSV, or PDF from tasks, time tracking, or reconciliation. The file is shown as a download card, deleted after 24 hours. Logs export.generated. |
lookup_lovdata | L | Looks up current Norwegian statutory text. Public source. |
Customer due diligence (AML) — when the plan includes it
| Tool | Class | What it does |
|---|---|---|
run_aml_portfolio_followup | U | Sends a reminder or starts Kundetiltak for customers who lack or have overdue measures. Two steps: the first call returns numbers only; sending requires a new call with bekreftet=true after the user’s “yes”. Max 100 emails per run. The same customer is not reminded twice within 20 hours. |
create_aml_portfolio_followup_task | S / U | Recurring version of the above, visible in Tasks. Same two-step confirmation. |
Tripletex — when the integration is enabled
| Tool | Class | What it does |
|---|---|---|
tripletex_list_companies · tripletex_search_accounts · tripletex_search_customers · tripletex_search_suppliers · tripletex_get_vat_types · tripletex_search_invoices · tripletex_search_supplier_invoices · tripletex_search_vouchers · tripletex_get_ledger_postings · tripletex_get_bank_transactions · tripletex_search_employees · tripletex_search_departments | L | Lookups in the customer’s Tripletex via encrypted integration token |
tripletex_create_voucher | R | Creates a voucher directly in the general ledger. The postings must balance. Logs tripletex.voucher.created. |
tripletex_create_invoice | R | Creates an outgoing invoice. Logs tripletex.invoice.created. |
tripletex_approve_supplier_invoice | R | Approves a supplier invoice. Logs tripletex.supplier_invoice.approved. |
Tripletex writing is executed when the user asks for it, in the same way as creating a task. Organisations that want confirmation cards also for accounting writes can leave the integration disabled in chat and use Revizo’s ordinary Tripletex flow. See Tripletex actions.
3. Context from where the user is
Tool choice is affected by where in the app the user is:
| The user is | Effect |
|---|---|
| On the matching page for a client | Client ID is known. “Run Smart Match” does not need a follow-up question. |
| In an open task panel | The task is known. “Mark as done” applies to that task. Simple questions about the task are answered without a tool catalogue at all. |
| On a page with an active company | The company name is known for reports and routines. |
| Has clicked a choice card | The choice is included as a marker; the assistant should not ask again. |
4. Revizo cards: confirmation instead of silent execution
For actions where a mistake is costly or leaves the organisation, the tool does not finish writing. It returns a card that Revizo shows in the chat. The model never sees the card’s technical content — only that a card was presented.
| Card | When | What the user sees | What happens on click |
|---|---|---|---|
Choose (choose) | Several contacts or accounts match | Up to 4 alternatives + “None of these” | The choice is sent back to the conversation |
Confirm (confirm) | Routine description on an account | Preview of the text, Save button | The text is saved on the account. Can be undone from the card. |
Send (send) | Documentation request | Recipient’s name and email, editable message | Email is sent and a smart task is created |
Download (download) | Export | Filename, format, size, number of rows | The file is downloaded. Expires after 24 hours. |
Rules the server enforces:
- Max one choice card per reply. A second choice card is rejected, and the model is told so before it finishes writing.
- A card with invalid form is discarded in its entirety. It is not shown half-finished.
- The card’s payload (for example existing routine text) is removed from the tool result before the result goes back to the model.
- A click on the card goes to a separate API route with the same authentication and tenant filter as the rest of Revizo.
Note on outbound email without a card
Two tools can send email based on confirmation in the conversation, not on a card:
send_message_to_contact— email to a contact that is already registered in the organisation. The recipient cannot be a free address; it must exist in the contact register. The sending is logged with recipient.send_report_email— reconciliation report. Default recipient is the user themselves.
The Kundetiltak tools use two-step confirmation with an explicit bekreftet=true parameter and show the number of recipients first.
We consider this acceptable because the recipients are limited to the organisation’s own register or the user themselves, and everything is logged. Organisations that want cards for these as well can request it; it is on our development plan. See Security controls → Limitations we are open about.
Last updated: September 2026