Glossary

The regulations, in plain English.

Every term below is a step or a signed checkpoint in a GreatCTO autopilot — not a PDF you read later. Each entry links to the autopilot where it bites.

Financial controls

Accounting · tax · audit

SOX (Sarbanes–Oxley Act)

US law requiring internal controls over financial reporting for public companies. The IT side (ITGC) covers access control, change management, and segregation of duties. SOX ITGC audit autopilot →

Segregation of Duties (SoD)

No single person holds end-to-end authority over a sensitive process: whoever requests a change doesn't approve it, whoever approves doesn't deploy it. In an autopilot this maps to distinct human checkpoints held by different named owners. Bookkeeping autopilot →

ASC 606

US GAAP revenue-recognition standard: revenue is recognized when performance obligations are satisfied, not when cash arrives. Misclassification is a restatement risk, which is why a controller signs the close. Bookkeeping autopilot →

§7216 (Internal Revenue Code)

Restricts how tax preparers may use or disclose tax-return information — consent is required before data leaves the engagement. A credentialed preparer signs every filing. Tax-prep autopilot →

Healthcare & pharma

Coding · prior auth · safety

HIPAA

Protects health information (PHI): minimum-necessary access, audit trails, breach notification, business-associate agreements. Any autopilot touching patient data runs inside these rails. Medical-coding autopilot →

False Claims Act

Liability for submitting false claims to government programs — treble damages, per-claim penalties. The core legal risk in coding and billing automation, and the reason a certified coder signs the risky claims. Medical-coding autopilot →

Prior authorization

Payer approval required before a treatment or drug is covered. A denial without a physician's signature is a legal landmine — so the denial path always routes through a human. Prior-auth autopilot →

21 CFR Part 11

FDA rule for electronic records and signatures: tamper-evident audit trails and validated systems in pharma and clinical workflows. Pharmacovigilance autopilot →

Legal & financial crime

Documents · screening · lending

UPL (Unauthorized Practice of Law)

State-law prohibition on non-lawyers giving legal advice. Document automation can draft; the advice that crosses the UPL line carries a licensed attorney's signature. Legal-docs autopilot →

OFAC sanctions screening

Checking counterparties against the US Treasury's SDN and sanctions lists. Strict liability — which is why screening is a mandatory flow step, not a periodic batch job. KYC/AML autopilot →

KYC / AML

Know Your Customer / Anti-Money-Laundering: identity verification, sanctions and PEP screening, suspicious-activity monitoring and SAR filing. A compliance officer signs the escalations. KYC/AML autopilot →

ECOA / Reg B

US fair-lending law: credit decisions must not discriminate on protected characteristics and must produce adverse-action notices. Lending autopilots carry disparate-impact testing as a gate. Mortgage autopilot →

TCPA & STIR/SHAKEN

Consent rules for calls/texts (TCPA) and caller-ID authentication (STIR/SHAKEN) — the constraints on any outbound voice or collections outreach. Collections autopilot →

Autopilot mechanics

How the rails work

Human checkpoint (gate)

A step where a named, qualified human reviews and signs before the flow continues. Every irreversible action — payment, denial, filing — sits behind one.

Straight-through processing

The cases an autopilot clears end-to-end with no human touch — high-confidence, low-risk, reversible work. Everything else escalates.

Confidence floor

The threshold below which the autopilot refuses to act autonomously and routes the case to a person. Tunable per function, audited per decision.

Audit trail

Tamper-evident record of every autonomous decision: who decided, what, on what evidence, at what confidence. The artifact a regulator actually asks for.

Compliance pack

A domain's regulations turned into flow steps, reviewers, and gates — attached automatically to the matching autopilot. All packs →

The regulation is a step in the flow.

Name the function.
Get the work done.

$ npx great-cto init
Open source · MIT · self-hosted · your data never leaves your machine