Skip to content
FactorFox

Treasury

Every rail out of your business runs through one door.

Written for whoever presses the button on funding day. ACH, wire, and whatever manual instruction gets sent when something has to go out now. Three rails, three habits, and usually three different sets of controls, of which one is a spreadsheet and a phone call.

In FactorFox they are one door. Nothing reaches a payment file without passing release, and the machine is permitted to stop money but never to let it through.

Release queue · ACH batch, 15:40 cutoff

1 held

Kestrel Logistics

142,900

Released

Bright Lane Staffing

88,150

Awaiting second approval

Corriedale Metals

310,000

Held, bank account change

The held item cannot enter the file. A bank account change is under a human only hold, and automated approval of it is refused outright.

NACHA PPD · generated from released items only · gates re evaluated at execution

Illustration of the release queue before file generation. The hold behaviour, the four eyes state, the release only file rule and the audit fields are the platform’s own. Names and figures come from a seeded demonstration book.

Why this exists

The controls are usually strongest on the rail that moves the least money.

ACH batches get scrutiny because they are routine. The one off wire at four o'clock on a Friday is the one that goes out on a verbal, and it is also the one that is irreversible.

The ACH file is built from a spreadsheet somebody assembles from the funding queue, and the assembly step is where an amount can change without anyone knowing.
The file is generated from released items only. There is no assembly step, because there is nothing between the release record and the file except formatting.
A wire is sent on an instruction that came by email, against details that were in the email, because the client was waiting.
A payment cannot reference a bank account that is under hold, on any rail. Urgency does not open a side door, because there is no side door for it to open.
Somebody funds against availability that was true this morning and stopped being true at eleven.
Net availability is evaluated at execution, not at request. A release approved against a book that has since moved is refused and states what changed.
The audit trail for payments is the bank's, which means reconstructing who authorised what means asking your bank for records about your own decisions.
Every release records the actor, the evidence, the policy version, the approvals and the origin, and audit records are immutable at the database level.

Asymmetric automation

The machine may stop money. Only a named human may let it through.

This is the single rule that shapes the whole of treasury in FactorFox. Automation is allowed to apply the brake and is never allowed to apply the accelerator. Every gate can refuse. No gate can approve.

Certain gates can never be made advisory. Not by a role, not by a configuration flag, not by a large customer asking firmly. A gate that protects the movement of money is either enforced or it is not present, and the platform does not offer a middle setting that a busy quarter could turn into a habit.

Four eyes is the default and it lives underneath every surface. The requester cannot approve their own release from the web application, from a phone, or from Microsoft Teams, because the rule is not implemented in any of those places. It is implemented once, below all of them. Changing surface changes nothing about who may approve.

Solo operators are not exempted. In solo mode an AI counter review is recorded where the second officer’s name would sit, and it refuses outright when any underlying fact has changed since the request was raised. It is not a rubber stamp with a friendly name. It is a second check that is entitled to say no and does.

And every approval is re evaluated at execution. An approval is a statement about a book that existed when it was given. Between then and the file being built, availability may have compressed, a verification may have failed, a debtor limit may have filled or a hold may have gone on. The gates run again at the moment of effect, and a release that no longer qualifies is refused with the change named.

Why the asymmetry

A machine that wrongly stops a payment costs you an hour and an apology.

A machine that wrongly releases one costs you the payment, and in the cases that matter most it costs you the payment to somebody who chose you precisely because they expected the release to be automatic.

The two errors are not symmetric, so the permissions are not either.

The rails

What FactorFox produces, and what your bank still does

FactorFox generates files and instructions. Your bank executes them. That boundary keeps your banking relationship and your bank's own controls exactly where they are.

Payment rails and their controls
RailWhat is producedWhat sits in front of it
NACHA ACHPPD credit files for your originating bank. Ninety four character fixed records, blocked correctly, generated from released items only.Release control, four eyes, availability re evaluated at execution, and no reference permitted to an account under hold.
APCA direct entryAustralian ABA direct entry files in CS2 format, one hundred and twenty character records.Identical controls. The discipline does not change because the country does.
FedwireWire instruction export for same day movement, formatted for your bank's upload, for the large single releases that should not wait for a batch.The same release control, plus the bank account change hold, which is where the wire fraud you read about actually gets stopped.
Manual instructionA recorded release for a movement executed outside the platform, so the record exists even when the rail does not.Still a release. An off system payment that leaves no record in the system is the gap every examiner looks for first.

Every originating bank certifies its own dialect. Generate one file, send it, have it certified, and then trust the rest. We would rather tell you that at the demonstration than let you discover it on your first funding day.

Funding day

From an approved schedule to a file your bank accepts

  1. Qualify

    Net availability decides what can move

    Eligible collateral at advance, less reserves, less what is already outstanding. A request beyond availability does not become a negotiation with the system. It becomes a stated shortfall with the ineligibles and reserves that caused it named.

  2. Request

    The release is raised with its evidence

    The schedule, the verification record, the debtor limits it consumes, the gates it must pass, and the effect on the client's availability if it executes.

  3. Approve

    Two people, wherever they are

    Four eyes by default, from the web application or from Teams on a phone, with the audit record naming the actor and the origin. The requester is refused by name if they try to approve their own.

  4. Re evaluate

    The gates run again at execution

    Against the book as it stands now, not as it stood at approval. Anything that changed is named. This is the step that catches the release approved twenty minutes before a hold went on.

  5. Generate

    The file is built from released items only

    NACHA PPD, APCA CS2, or a wire instruction. No intermediate spreadsheet, no manual assembly, nothing between the release record and the formatting.

  6. Record

    What went out, under whose authority

    Actor, evidence, policy version, approvals and origin, in an audit record that is immutable at the database level. The reconstruction later does not require a request to your bank.

FactorFox Forecast screen showing portfolio confidence, expected to collect and capital at risk, confidence stated separately for each aging bucket, expected cash arrival by week, and debtor payment confidence with verification status and average days to pay.
The Forecast screen, which is where the question of what can move safely starts. Confidence is stated for each aging bucket rather than for the book as a whole, cash arrival is projected week by week, and the debtor panel separates what is verified from what is only expected. Figures are from a seeded demonstration book, not from a customer.

The rest of the treasury surface

What else moves, and what watches it

Bank account change hold

A hold in front of every rail. Verified out of band by a named person against a contact established before the request arrived. Automated approval is refused outright and there is no configuration that changes it.

Reserve release

The client's reserve, moved when the conditions for moving it are met and recorded as a release with its own authority, rather than as an adjustment nobody can trace.

Days to zero

Net availability projected forward on the client's own funding pattern and collection velocity, so a compression reaches the briefing before it reaches the funding queue.

Same day pressure

Wires exist because some money genuinely cannot wait. The controls are unchanged for them, which is the entire point of having built them once underneath every rail.

Delivery wall

Remittance advice and payment notices leave through the same wall as every other channel, including the sandbox rules that stop a test from reaching a real counterparty.

Approvals that travel

The person who has to approve is often not at a desk. They approve from Teams with the evidence attached, and every control that applies in the browser applies there identically.

Straight answers

What a treasury manager checks before signing

Will your NACHA file work with our originating bank?

Ninety four character fixed records, blocked correctly, PPD credits. That is the standard. What is not standard is your bank, because every originating institution certifies its own dialect and has opinions about batch headers, company identification, discretionary data and addenda. Generate one file, send it, get it certified, then trust the rest. Any vendor who tells you their file works everywhere without certification has not sent enough files.

Does FactorFox move money?

No. FactorFox produces files and instructions your bank executes, and it decides what is allowed to reach that point. That boundary is deliberate. It means your banking relationship, your controls and your bank's own fraud checks stay exactly where they are, and it means the platform never holds a credential that could move funds on its own.

What is the bank account change hold window actually for?

It exists so that the time between a request and a payment is time somebody uses. A changed account cannot be referenced by any payment while the hold stands, on any rail. A named human verifies the change out of band, against a contact established before the request arrived, and releases it. Automated approval is refused outright rather than being an option somebody could enable.

Can we fund from Australia and the United States in one operation?

Yes. APCA direct entry files in CS2 format with one hundred and twenty character records for Australian banks, and NACHA PPD for United States originating banks. The release control, the gates, the four eyes rule and the audit record are identical on both, because the discipline should not depend on which country the money leaves from.

What stops a release that passed every gate yesterday from executing today?

The gates are re evaluated at execution rather than trusted from when the request was raised. Availability may have compressed, a verification may have failed, a hold may have gone on. A card or a queued approval is a rendering of a decision, and the decision is checked against current state at the moment it would take effect.

How do we handle a release that has to go out today and the second approver is on a plane?

Four eyes is enforced in the platform rather than in any one surface, so the answer is not to change surface. It is that the second approver can approve from wherever they are, including from Teams on a phone, with the evidence attached and the audit record naming them and the origin. If nobody is available, the release waits. That is the control working, not the control failing.

Watch a release get refused.

The most useful ten seconds of any demonstration is the one where the requester tries to approve their own funding and the platform names them and says no.