Automatic recovery (re-enqueue stuck work) is separate and non-AI. Corrective retry is a human/ops action with its own safety model — see Recovery.
Design rules
- CargoWise capture bytes stay immutable evidence. AI does not claim CargoWise was edited.
- Missing or contradictory fiscal data still fails or waits — AI does not guess RFCs, FX, balances, or parent links.
- Live stamps that change interpretation require human approval when Edward proposes a fix.
- Accountant-owned source issues stay with the accountant path; Edward does not take those over.
Gus
Gus helps you understand invoice status, why a document stopped, and what the note means — using the same workspace labels you already see (Failed, Waiting for parent, Auto fixing, Stamped, and so on). Gus can:- Look up invoices in your current organization
- Explain failures and AI-review outcomes in operational language
- Point you to the right document in Lambda
- Retry stamps, change amounts, or edit CargoWise
- Leave your organization scope
- Invent fiscal fields that are not in the evidence
Edward
Edward runs after a stamp failure when Lambda classifies the issue as a system-owned interpretation mistake — not an accountant source-data problem and not a hard infrastructure outage. Typical path:- A stamp fails for a recoverability class Edward is allowed to handle.
- The document moves to Auto fixing while Edward inspects the ingress capture and related evidence.
- Edward may validate a candidate fix in the org test environment.
- If a live stamp is warranted, the document moves to Awaiting approval and platform admins are notified.
- A human approves or denies. On deny, Edward stops and reports; it does not keep trying live stamp.
What you see in the workspace
These labels sit alongside the ordinary stamping statuses. Read Statuses for the full set.