Smartflow for Payroll governs AI agents that touch pay. Agents reconcile, answer questions and prepare changes. Direct deposit changes, off-cycle payments and pay-rate updates pause for a payroll approver, personal identifiers are redacted before they reach a model, and every decision lands in a tamper-evident record.
Why is payroll different?
Payroll is where an agent's mistake becomes money that leaves the company. It is also where attackers already work. The FBI has warned since 2018 about payroll diversion: criminals impersonate employees, ask HR or payroll to change direct deposit details, and redirect the next paycheck. In April 2025 it warned of fake employee self-service portals used to steal credentials and redirect deposits. The FBI's 2025 Internet Crime Report counted about $3.0 billion in adjusted losses from business email compromise.
An agent that accepts a change request from an email or chat message and applies it is the ideal target for that scheme. It reads the request, finds the employee, updates the account and moves on. The attacker needs one convincing message.
What do the rules require?
- Sarbanes-Oxley Section 404 and SEC Rule 13a-15(f). Enforceable for public companies. Internal control over financial reporting must provide reasonable assurance that expenditures are made only in accordance with authorizations of management. Payroll is an expenditure, and a change an agent makes is still subject to that authorization.
- Nacha Operating Rules, fraud monitoring. Binding on ACH network participants by agreement. Since June 2026, every participant must have risk-based processes to identify payments authorized under false pretenses, including impersonation of an employee.
- FBI IC3 public service announcements, 2018 and 2025. Advisory. The FBI advises heightened scrutiny of direct deposit changes initiated by employees.
The practical requirement is the one payroll teams already apply to people: separation of duties, verification of the person requesting a change, and a record of who authorized it.
How does Smartflow apply it?
Take a payroll operations agent that receives an email asking to change an employee's direct deposit account. It finds the employee and prepares the update. Your policy holds every change to bank details, so the call pauses as an approval ticket. The payroll approver steps up to re-verify their identity, calls the employee on the number already on file, learns the employee sent no such request, and denies it. The change never applies, and the record shows the request, the policy, the approver, the decision and the time.
- Payment changes pause for approval. Direct deposit changes, new payees, off-cycle payments and rate changes pause as approval tickets for a person with payroll approval rights, who can be required to step up first.
- Verification stays independent of the request. The approver confirms the change with the employee through a channel already on file, not the one the request arrived through. The ticket holds the change until they do.
- Redaction. Social Security numbers and other personal identifiers, such as dates of birth and home addresses, are redacted before a prompt reaches a model.
- Evidence. Every decision is hash-chained and time-stamped under RFC 3161, and exports to Splunk, Datadog, OTLP, and JSON logs your SIEM can ingest, ready for the control testing your auditors perform. Turn on the WORM archive to write records to Azure immutable blob storage in your account, and set retention to your records schedule; the audit default is 365 days.
| Action the agent prepares | The record captures |
|---|---|
| Change an employee's direct deposit account | Employee, change, channel of request, approver |
| Add a new payee or an off-cycle payment | Payee or employee, amount, reason, approver |
| Change a pay rate or bonus | Employee, old and new rate, approver; see the HR guide |
| Change tax withholding | Employee, form, effective date, approver |
| Approve the pay run | Run, totals, exceptions, approver |
| Change a general ledger mapping | Mapping, before and after, approver |
Answering pay questions, reconciling exceptions, preparing registers and drafting reports pass through and are recorded.
What changes for your auditors?
Control testing for payroll changes usually means sampling tickets and emails to find the approval. With Smartflow, each agent change has one record with the request, the approver, the decision and the arguments of the change, sealed and time-stamped at the moment it happened. If your team works in ServiceNow, Smartflow can open GRC findings there, so exceptions land where the controls team already works.
Rollout
- Map the flows. List every path by which bank details, rates and payments change, and which of them an agent can touch.
- Redact first. Turn on redaction for employee identifiers.
- Hold every payment change. Set policy so direct deposit, tax, payee and off-cycle changes pause for approval.
- Choose approvers. Grant payroll approval rights to the people who own these decisions, and require step-up on bank changes and off-cycle payments.
- Walk auditors through the record before the next testing cycle.
Quick answers
Why verify the employee instead of the requester?
Payroll diversion works by impersonating the employee through a channel the attacker controls: an email, a chat message, a fake portal. Confirming the change with the employee through a channel already on file, independent of the channel the request arrived through, breaks the scheme. Smartflow holds the change until the approver decides.
Does this satisfy SOX?
Smartflow produces evidence of authorization for each change an agent prepares: who approved it, when, and exactly what changed. Your auditors decide whether your controls are effective. The record gives them a complete population to test.
Can an agent run payroll?
It can prepare the run, reconcile exceptions and draft the register. Approval of the run stays with a payroll approver, and release of payment files stays with treasury, each recorded.
Download the full guide
The PDF adds a control map from SOX 404 and Nacha fraud monitoring to Smartflow's record, the full decision map, a rollout checklist, and the questions to ask any vendor that proposes to govern payroll agents.
Sources
Verified as of September 25, 2026.
- FBI Internet Crime Complaint Center: PSA I-091818-PSA, September 18, 2018; PSA I-091019-PSA, September 10, 2019; PSA I-042425-PSA, April 24, 2025; 2025 Internet Crime Report, April 2026.
- 15 U.S.C. 7262, Sarbanes-Oxley Section 404; 17 CFR 240.13a-15.
- Nacha, fraud monitoring rules.
Put this in the path of your own agents.
Policy enforced inline between your agents and every model and tool they reach, with a record bound to the human who owns it.
Request a Demo Read the docs