Responsible AI
It proposes. A person decides. The decision is logged.
AI is useful in donor operations for one thing above all: reconstructing the explanation a human would otherwise spend forty minutes assembling. It is not useful for deciding where money goes.
No AI feature in Beneora can move money, post a financial record, issue or alter a receipt, or send a donor message without a person accepting the proposal first. There is no administrator override for this.
Last updated March 1, 2026
The approval gate
A proposal, its sources and a person who has to say yes
Agent proposes
Suggested match, merge or reminder
Carried with its sources, confidence, the exact records it would change and the cost of running it.
Only then, effect
Applied, attributed and reversible
The approver, the proposal and the undo path are written to the immutable activity log. No agent moves money or edits a receipt.
What every proposal must carry
- Its sources — the specific records it read, linked so you can check the reasoning.
- A confidence value, and the threshold below which it is not surfaced as a suggestion.
- The effect it would have if accepted, described in the same terms as a manual action.
- An estimated cost where the operation consumes model capacity.
- The approval step, naming the role permitted to accept it.
What AI may do here
Prototype- Propose a cause for a reconciliation exception, with evidence.
- Propose duplicate merges, with the differing fields shown.
- Draft donor outreach for a failed recurring payment, for a human to review and send.
- Summarise a donor relationship from records the requesting user already has permission to read.
What AI may never do
- Post, match or reverse a financial record.
- Create, alter or reissue a receipt.
- Send any donor-facing message unattended.
- Bypass permissions, tenant scope, consent state or feature gating.
- Read across tenants, or use one organization's data to answer another's question.
Data and training
Tenant and donor data is not used to train models by default. Donor personal data is not placed into model context for convenience — where a task can be done with identifiers and amounts, that is what the model receives.
AI activity is recorded in an immutable log: what was proposed, on what evidence, who accepted or rejected it, and when.
Current status
PrototypeThe agent surfaces, evidence display, confidence scoring, approval thresholds, preview and undo all exist in the product as prototypes on illustrative data. The governance rules above are how they are built, and they apply from the first real deployment rather than being added later.
Something here unclear, or a claim you think we cannot support? Tell us — correcting this page is cheaper than defending it.
Design-partner program
Judge us on the mechanisms, not the marketing
We are working with a small number of US and Canadian nonprofits who feel the reconciliation and donor-data pain most acutely. Partners shape the sequence, see the honest status of every module, and are never charged for a capability that is still a prototype.
Direct answers
What people ask about AI in Beneora
- Does Beneora use AI to act on donor records automatically?
No. Agents propose; a person approves. Each proposal carries its sources, confidence, the exact records it would change and the cost of running it. No agent moves money, edits a receipt or bypasses a permission, and the approver, the proposal and the undo path are written to an immutable log.
See the approval gate- Is donor data used to train AI models?
Not by default. Tenant and donor data is not training material, and donor or beneficiary personal information is not exposed to model providers as a product feature. Where a model is called to draft or match, the request is scoped to the task and the result is a proposal a person reviews.
Read the data rules
