Skip to main content

Actions and tools

Revizo AI does not “know” what to do in the sense that it has access of its own to the system. It receives a fixed instruction, a catalogue of allowed tools, and the context the user is in. From that it formulates a reply or proposes one or more tool calls. Revizo executes the call — or presents it to the user as a card.

This page describes the four mechanisms that govern this, and lists all tools with risk class.


1. Fixed instructions (system prompt)​

Every request starts with an instruction Revizo has written and versions in code. It specifies among other things:

  • Identity and scope. The assistant is called Revizo, replies in Norwegian, and only answers questions about Revizo, Norwegian accounting deadlines (facts), current statutory text via Lovdata, and the user’s own data.
  • Prohibitions. Never accounting or legal advice. Never invent deadlines, rates, or statutory text. Never show data from other organisations, national ID numbers, or bank account numbers. Never discuss competitors, prices, politics, or create creative content.
  • Honesty about actions. Never say that something has been done before the tool has returned a successful result. Never claim that a task or routine “already exists” unless a tool in the conversation has shown it.
  • Required disclaimers. Deadlines shall always be followed by “Verify current deadlines at skatteetaten.no”. Legal quotations shall always have act, section, and a link to Lovdata, with an encouragement to verify.
  • Tool guidance. When an action should be answered in the chat (reading) versus when it should navigate (display). Rule of thumb in the instruction: “When in doubt, reply in the chat. It is safer.”

The instruction is a steering document for the model, not a security boundary. The security boundaries sit in the tools and in the server’s controls — see Security controls.


2. Tool catalogue​

The model can only call tools that exist in the catalogue. Each tool has a name, a description of when it should be used, and a strict schema for the arguments. The catalogue is filtered per organisation:

  • lookup_lovdata is only included when the organisation has Lovdata access.
  • Kundetiltak tools (AML) are only included when the organisation’s plan includes Kundetiltak.
  • Tripletex tools are only included when Tripletex actions are enabled.

Risk classes​

ClassMeaningControl
L — ReadReturns data, changes nothingTenant filter. No confirmation.
V — DisplayChanges only what the user sees (filters, navigation)No data is changed. No confirmation.
S — Write in RevizoCreates or changes data in the organisationExecuted when the user has asked for it. Logged in the audit log.
K — CardThe tool writes nothing itself; it shows a cardExecuted only when the user clicks the card.
U — OutboundSends something to people outside the organisationRequires a card (Send) or explicit two-step confirmation with a number.
R — Accounting systemWrites to the customer’s accounting systemOnly when the integration is enabled. Logged.

Clients and reconciliation​

ToolClassWhat it does
search_clientsLFinds clients by name or account number
get_client_statusLStatus for one client: transactions, unmatched, matches
get_unmatched_summaryLUnmatched items per client
get_clients_by_assignedLClients distributed by responsible person
get_clients_with_deviationLClients with deviation above threshold
get_clients_summaryLTotals for the organisation
compare_client_balancesVOpens balance comparison for two or more clients
filter_clients_by_assigned · filter_clients_by_deviation · filter_clients_unreconciled · clear_client_filters · apply_saved_view · list_saved_viewsV / LFilters the client list in the interface
run_smart_matchSRuns Smart Match once for one client. Verifies that the client belongs to the organisation. Logs match.created.
send_report_emailS / USends a PDF report with open items. Default recipient is the user themselves; another recipient only when the user specifies it.
run_anomaly_scan · get_anomaly_findingsS / LRuns and reads anomaly detection on transaction data
open_close_period · get_close_period_status · run_close_auto_checksS / LPeriod close: open, read status, run automatic checks

Tasks and smart tasks​

ToolClassWhat it does
get_my_tasksLFetches tasks the user has access to see
create_task · create_tasks_batchSCreates tasks. Logs task.created.
update_task · update_task_status · add_subtasks · remove_subtasks · update_subtasks_checked · add_task_noteSChanges tasks the user can see. Logs task.updated.
create_smart_match_taskSRecurring Smart Match for one client. The instruction requires a summary and “yes” before the call; the first cycle runs on creation.
create_document_request_taskK / UShows a send card with recipient and message. The email is sent only when the user presses Send. The task is completed when the files have been uploaded.
redistribute_absent_tasksLProposes distribution of a colleague’s tasks. Moves nothing — the user completes it in “Transfer tasks”.

Accounts and routines​

ToolClassWhat it does
search_accountsLFinds accounts in the chart of accounts
propose_account_descriptionKShows a proposed routine description as a preview. Saved only on Save. HTML is sanitised server-side. Existing routine text is kept outside the model’s context.

Contacts and communication​

ToolClassWhat it does
lookup_contactLLooks up a contact; multiple hits give a choice card
send_message_to_contactUSends email to a registered contact with text the user has confirmed in the conversation. Logs agent.message_sent with recipient. See the note below.
get_notification_preferences · update_notification_preferenceL / SReads and changes the user’s own notification channels
open_team_chatVOpens team chat with a colleague

Calendar, team, and navigation​

ToolClassWhat it does
create_reminder · deactivate_reminder · get_my_reminders · get_my_calendarS / LThe user’s own reminders and calendar. Logs reminder.created / reminder.deleted.
get_team_workload · get_team_absences · get_time_savings_reportLAggregated workload, absence, and time savings
navigate_to · list_tutorials · get_upcoming_deadlinesV / LNavigation, guided walkthroughs, deadlines
switch_dashboard_layout · create_dashboard_layoutV / SThe user’s dashboard
list_archive_folders · search_archive_documentsLFolders and document metadata in the archive — not document content
log_feature_requestSRegisters a request to the Revizo team
ask_choiceKShows a choice card. Max one per reply.

Export and lookups​

ToolClassWhat it does
create_exportS / KCreates Excel, CSV, or PDF from tasks, time tracking, or reconciliation. The file is shown as a download card, deleted after 24 hours. Logs export.generated.
lookup_lovdataLLooks up current Norwegian statutory text. Public source.

Customer due diligence (AML) — when the plan includes it​

ToolClassWhat it does
run_aml_portfolio_followupUSends a reminder or starts Kundetiltak for customers who lack or have overdue measures. Two steps: the first call returns numbers only; sending requires a new call with bekreftet=true after the user’s “yes”. Max 100 emails per run. The same customer is not reminded twice within 20 hours.
create_aml_portfolio_followup_taskS / URecurring version of the above, visible in Tasks. Same two-step confirmation.

Tripletex — when the integration is enabled​

ToolClassWhat it does
tripletex_list_companies · tripletex_search_accounts · tripletex_search_customers · tripletex_search_suppliers · tripletex_get_vat_types · tripletex_search_invoices · tripletex_search_supplier_invoices · tripletex_search_vouchers · tripletex_get_ledger_postings · tripletex_get_bank_transactions · tripletex_search_employees · tripletex_search_departmentsLLookups in the customer’s Tripletex via encrypted integration token
tripletex_create_voucherRCreates a voucher directly in the general ledger. The postings must balance. Logs tripletex.voucher.created.
tripletex_create_invoiceRCreates an outgoing invoice. Logs tripletex.invoice.created.
tripletex_approve_supplier_invoiceRApproves a supplier invoice. Logs tripletex.supplier_invoice.approved.

Tripletex writing is executed when the user asks for it, in the same way as creating a task. Organisations that want confirmation cards also for accounting writes can leave the integration disabled in chat and use Revizo’s ordinary Tripletex flow. See Tripletex actions.


3. Context from where the user is​

Tool choice is affected by where in the app the user is:

The user isEffect
On the matching page for a clientClient ID is known. “Run Smart Match” does not need a follow-up question.
In an open task panelThe task is known. “Mark as done” applies to that task. Simple questions about the task are answered without a tool catalogue at all.
On a page with an active companyThe company name is known for reports and routines.
Has clicked a choice cardThe choice is included as a marker; the assistant should not ask again.

4. Revizo cards: confirmation instead of silent execution​

For actions where a mistake is costly or leaves the organisation, the tool does not finish writing. It returns a card that Revizo shows in the chat. The model never sees the card’s technical content — only that a card was presented.

CardWhenWhat the user seesWhat happens on click
Choose (choose)Several contacts or accounts matchUp to 4 alternatives + “None of these”The choice is sent back to the conversation
Confirm (confirm)Routine description on an accountPreview of the text, Save buttonThe text is saved on the account. Can be undone from the card.
Send (send)Documentation requestRecipient’s name and email, editable messageEmail is sent and a smart task is created
Download (download)ExportFilename, format, size, number of rowsThe file is downloaded. Expires after 24 hours.

Rules the server enforces:

  • Max one choice card per reply. A second choice card is rejected, and the model is told so before it finishes writing.
  • A card with invalid form is discarded in its entirety. It is not shown half-finished.
  • The card’s payload (for example existing routine text) is removed from the tool result before the result goes back to the model.
  • A click on the card goes to a separate API route with the same authentication and tenant filter as the rest of Revizo.

Note on outbound email without a card​

Two tools can send email based on confirmation in the conversation, not on a card:

  • send_message_to_contact — email to a contact that is already registered in the organisation. The recipient cannot be a free address; it must exist in the contact register. The sending is logged with recipient.
  • send_report_email — reconciliation report. Default recipient is the user themselves.

The Kundetiltak tools use two-step confirmation with an explicit bekreftet=true parameter and show the number of recipients first.

We consider this acceptable because the recipients are limited to the organisation’s own register or the user themselves, and everything is logged. Organisations that want cards for these as well can request it; it is on our development plan. See Security controls → Limitations we are open about.


Last updated: September 2026