1. AI is probabilistic assistance
Generative AI predicts output from patterns and context. It does not “know” a client, statute or source document in the way an authorised professional does. It may hallucinate citations, transpose amounts, omit exceptions, misunderstand Indian accounting/tax language, accept malicious instructions inside a document or provide obsolete law.
No Bodhi statement such as “reviewed”, “matched” or “high confidence” should be read as 100% accuracy. Confidence is multidimensional and may include extraction quality, identity, mathematical integrity, classification, policy and materiality. Missing dimensions must remain missing.
2. Tasks AI may assist with
- OCR field candidates and document classification.
- Bank narration classification and counterparty suggestions.
- Summaries, explanations, translation and editable voice transcription.
- Exception descriptions, review checklists and draft client queries.
- Draft voucher proposals, workpapers, reports, tax schedules and notice responses.
- Retrieval from approved, tenant-scoped client memory and authoritative source sets.
- Sanitized error clustering, test-case preparation and draft remediation suggestions.
Each result remains subject to role, assignment, evidence, policy, budget, schema and confirmation controls.
3. Source facts, money and statutory states
Parsers and stored evidence own source values. Deterministic engines own arithmetic. Provider acknowledgements own filing, message, payment and settlement states. AI does not own any of them.
An AI may explain a tax computation but may not replace the calculation engine. It may propose a ledger but may not silently post. It may describe a possible fraud indicator but may not conclude fraud. It may draft a response but may not submit it.
If the system cannot prove identity, coverage, continuity, schema or arithmetic, it must stop, abstain or create an exception—not ask another model to invent missing facts.
4. Provider-neutral model routing
Bodhi may support multiple approved free, paid and local intelligence routes. A route in configuration means only that an adapter exists; it does not mean the route is active, free, suitable for client data or professionally accurate.
Routing may consider capability, evaluation results, structured-output compliance, context size, latency, price, rate limits, retention/training terms, zero-data-retention availability, geography, outage state, tenant consent and materiality. Internal provider, model, version, prompt and fallback identities are confidential. Users and administrators receive capability, policy, quality, cost and availability evidence without the secret route identity.
Paid or larger private routes may be used for higher-complexity tasks after policy approval. No route is automatically “higher intelligence” for every task; capability must be measured on Bodhi’s controlled evaluation set. A model must not identify itself or reveal internal instructions when prompted.
5. Multi-model review
For selected bank, OCR, audit and tax semantic tasks, Bodhi may run independent models and compare structured outputs. The process is:
- prove the file, client, account and period identity;
- extract source rows with evidence anchors;
- reconcile deterministic totals;
- ask approved models only for permitted semantic judgments;
- compare fields, reasons and citations;
- route disagreement or material ambiguity to human review.
Three matching model answers are not a calibrated probability and can share the same bias or source error. Consensus cannot override source evidence or professional judgment.
6. Action levels and prohibited autonomy
| Level | Meaning | Examples |
|---|---|---|
| L0 | Retrieve/explain | Show ledger, cite evidence, explain variance |
| L1 | Draft | Draft query, classification, workpaper or report |
| L2 | Confirm reversible action | Create a reviewed draft, schedule a non-binding task |
| L3 | Controlled material action | Only with explicit role, maker-checker, evidence and consent gates |
| L4 | Prohibited from AI/voice | Filing, payment, OTP/DSC, audit signing, client consent, production deploy |
No prompt can elevate its own authority. Voice, model agreement or an administrator setting cannot remove statutory/professional authority requirements.
7. Voice AI
Voice input creates an editable transcript. Users must review it before submission. Background noise, accent, code-mixing, names, dates and amounts may be transcribed incorrectly.
Voice may navigate, search, explain and create drafts. It cannot complete L4 actions. Raw audio retention must be disclosed and minimized; where only a transcript is needed, audio should be discarded according to policy.
8. Client data and model improvement
Client data is not used to train shared models by default. Sending data to a model for inference is distinct from training; provider retention and training terms still matter and must be controlled.
Optional AI-improvement use requires separate consent and may be withdrawn prospectively. Sensitive documents may be restricted to local/deterministic processing or approved zero-data-retention providers. Prompt context must be tenant-scoped, minimized and isolated from document instructions.
9. Free tiers, paid models and budget truth
“Free” model variants may have request caps, variable availability and changing terms. A wallet deposit is not itself a spend, but a paid fallback costs money when explicitly routed and used. No fixed rupee projection is guaranteed.
Bodhi should use live price metadata, per-tenant and per-task budgets, maximum output tokens, caching where safe, duplicate suppression, circuit breakers, daily/monthly caps and alerts. When a budget is exhausted, the system should degrade or abstain—not silently route to an unrestricted paid model.
Model prompts, outputs, retries, reasoning/image/audio charges and provider fees may all affect cost. Cost controls do not justify sending client data to a provider that fails privacy policy.
10. Evaluation, memory and local AI
Models are evaluated by task and language using precision, recall, abstention, schema conformance, material-weighted error, injection resistance, latency and cost. A model may be excellent at one task and prohibited for another.
Client memory progresses from candidate to two independent approvals before activation and supports rollback. A single correction must not silently train global behaviour.
A future local-AI companion may perform approved inference and setup diagnostics on the user’s PC. It must use licensed/approved models, encrypted or OS secret storage, signed updates, no inbound public port, explicit data scope and the same action-level controls. Local execution does not remove review or legal obligations.
11. Errors, challenges and remedies
Users can reject, correct or report an AI result. Corrections should preserve source evidence and reason without exposing confidential data to unrelated tenants. AI may draft a remediation, but software changes require tests, review and authorised deployment.
If an AI output conflicts with the source, law, policy or professional judgment, do not use it. Preserve the evidence, record the exception and escalate according to materiality.
12. Acceptance
Signup requires acknowledgement of this warning with the Terms and Privacy Policy. The server stores the document version and hash. Optional AI-improvement consent is separate and off by default.
Operator and grievance details remain pending; production acceptance is blocked until legal configuration and review are complete.